A skill your agent uses when enabling WebSocket subscriptions for live database changes, presence/multiplayer state, or when debugging clients that connect but receive no events

MITAuto-check passedBackend & APIs

Install Realtime

skills CLI
$ npx skills add butterbase-ai/butterbase-skills --skill realtime -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install butterbase-ai/butterbase-skills realtime --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/butterbase-ai/butterbase-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/realtime .claude/skills/realtime && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
realtime
GitHub stars
534
Token cost
~2.1k tokens
SKILL.md length
852 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when enabling WebSocket subscriptions for live database changes, presence/multiplayer state, or when debugging clients that connect but receive no events

  • Works in 8 steps: The mental model → Prerequisites → Configure tables → …
  • Enabling WebSocket subscriptions for live database changes
  • SKILL.md covers 1. The mental model, 2. Prerequisites, 3. Configure tables and 4. Connect from a client, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Realtime is an agent skill from butterbase-ai/butterbase-skills. Use when enabling WebSocket subscriptions for live database changes, presence/multiplayer state, or when debugging clients that connect but receive no events

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Realtime and WebSockets and Debugging. The repository describes itself as: Plugin for Butterbase.ai. The licence is MIT.

When your agent uses it

  • Enabling WebSocket subscriptions for live database changes
  • Presence/multiplayer state
  • Debugging clients that connect but receive no events

Example prompts

  • “/realtime”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. The mental model
  2. Prerequisites
  3. Configure tables
  4. Connect from a client
  5. RLS enforcement (the critical pitfall)
  6. Connection lifecycle
  7. Common patterns
  8. Anti-patterns

What it can do on your machine

Read from SKILL.md and the folder at commit aa8ae69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript, json, typescript and sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Realtime loads about 2.1k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 852 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from butterbase-ai/butterbase-skills at commit aa8ae69, republished under its MIT licence (© butterbase-ai). 852 words, ~2,148 tokens.

Download SKILL.mdSave it as .claude/skills/realtime/SKILL.md (or your agent's skills folder).
name
realtime
description
Use when enabling WebSocket subscriptions for live database changes, presence/multiplayer state, or when debugging clients that connect but receive no events

Butterbase Realtime

Live database change notifications over WebSocket, with per-row RLS enforcement. Once a table is enabled, INSERT/UPDATE/DELETE events stream to subscribed clients filtered by the same RLS policies that gate reads.

One tool: manage_realtime with two actions: configure and get.


1. The mental model

Postgres (data plane)              Control API                       Browser
─────────────────────              ────────────                      ────────
INSERT/UPDATE/DELETE  ──trigger──► realtime.changes  ──WAL listener─► WebSocket ──► client
                                          │
                                          └── RLS check per (role, user) ──► filter rows

When you configure a table:

  1. A Postgres trigger is installed → writes every change to realtime.changes.
  2. A LISTEN connection in RealtimeManager reads those changes.
  3. For each connected client, the change is RLS-checked as that user before broadcasting.
  4. Clients only receive events for rows they could read with a regular SELECT.

2. Prerequisites

Before calling configure, the table must:

  1. Exist. Run manage_schema (action: "apply") first. Realtime won't auto-create it.
  2. Have RLS configured (if you care about isolation). Realtime respects whatever policies exist via manage_rls. No policies = all events flow to all users of that role. This is the #1 silent leak.
  3. Have a primary key. RLS checks query by PK. Tables without one can't be realtime-enabled cleanly.

3. Configure tables

js
manage_realtime({
  app_id: "app_abc123",
  action: "configure",
  tables: ["messages", "presence", "documents"]
})
// → [{ table: "messages", status: "enabled" }, ...]
  • Idempotent — already-enabled tables are skipped.
  • All three events (INSERT / UPDATE / DELETE) are enabled together; per-event filtering happens client-side via subscription filter.
  • Validation: every named table must exist or you get VALIDATION_TABLE_NOT_FOUND.
Inspect current state
js
manage_realtime({ app_id: "app_abc123", action: "get" })
// → {
//     tables: [{ table_name, enabled, trigger_installed, drift, created_at, updated_at }, ...],
//     active_connection: true,
//     websocket_url: "wss://api.butterbase.dev/v1/app_abc123/realtime"
//   }

drift: true means the control-plane config says enabled but the data-plane trigger is missing — typically after a schema migration that dropped/recreated the table. Re-run configure to repair.


4. Connect from a client

wss://api.butterbase.dev/v1/{app_id}/realtime?token={JWT_or_API_KEY}

Browsers can't set custom headers on WebSocket upgrade, so the JWT goes in the query string. Server clients can use Authorization: Bearer ... instead.

js
const ws = new WebSocket(
  `wss://api.butterbase.dev/v1/${appId}/realtime?token=${userJwt}`
);

ws.onopen = () => {
  ws.send(JSON.stringify({ type: "subscribe", table: "messages" }));
};

ws.onmessage = (e) => {
  const msg = JSON.parse(e.data);
  if (msg.type === "change") handleChange(msg);  // { type, table, op, record, old_record, timestamp }
};

The Butterbase SDK wraps this:

ts
const realtime = client.realtime(appId, userJwt);
realtime.subscribe("messages", (change) => console.log(change.op, change.record));
Welcome and protocol

On connect, the server sends:

json
{ "type": "connected", "app_id": "app_abc123", "role": "butterbase_user" }

Then a heartbeat every 30s:

json
{ "type": "heartbeat", "timestamp": "..." }
Client → server messages
TypeBodyPurpose
subscribe{ table, filter? }Subscribe to changes; optional client-side filter { col: value }
unsubscribe{ table }Stop receiving
presence_track{ metadata }Announce yourself with arbitrary metadata (cursor, status)
event{ event, payload }Trigger a function with trigger: { type: "websocket", config: { event } }
Server → client messages
TypeBody
change{ table, op: "INSERT"|"UPDATE"|"DELETE", record, old_record, timestamp }
presence_state{ clients: [{ client_id, user_id, metadata }] }
heartbeat{ timestamp }

5. RLS enforcement (the critical pitfall)

For each broadcast, the server runs (roughly):

sql
SET LOCAL ROLE butterbase_user;
SET LOCAL request.jwt.claim.sub = '{user_id}';
SELECT 1 FROM "{table}" WHERE "{pk}" = {record_pk} LIMIT 1;

If the row is not visible under RLS, the change is silently dropped for that client. There is no error.

Common consequences:

  • Client connects, sees connected, subscribes — but receives no events. → RLS too restrictive (or no policies at all + access mode authenticated).
  • Client receives some events but not others. → RLS works for those rows; others are filtered out (often correct).
  • Service key clients see everything. → Service bypasses RLS. Don't use this to "verify realtime works" if testing user-scoped behaviour.

Always test with a real end-user JWT, not the service key.

Anonymous clients

If manage_app access mode is authenticated, anonymous WebSocket connections are rejected with close code 1008 (Policy Violation). To allow anon, the app must be in public mode AND the table must have a permissive policy for butterbase_anon.


Show full SKILL.md (372 more words)Show less

6. Connection lifecycle

Close codeMeaning
1008App requires authentication, no token provided
1013 (try again later)Plan limit hit (maxRealtimeListenersPerApp) — upgrade
1013 ("Realtime disabled by plan")Free / starter tiers may have realtime off entirely
Normal closeHeartbeat missed, client disconnected, or server eviction

The server caches table primary keys for 60s and batches RLS checks per (role, user) group, so connection cost is amortised.


7. Common patterns

Live chat
  1. manage_schema apply with a messages table (id, room_id, user_id, body, created_at).
  2. manage_rls create_user_isolation with user_column: "user_id" plus a custom policy that allows reading messages where room_id IN (SELECT room_id FROM members WHERE user_id = current_user_id()).
  3. manage_realtime configure with tables: ["messages"].
  4. Client connects, subscribes to messages, optionally filters { room_id: "..." }.
Live dashboard / activity feed
  1. Add a notifications table with user_id.
  2. RLS create_user_isolation so each user only sees their own.
  3. Realtime configure → notifications stream straight to the right user, no extra filtering needed.
Multiplayer cursor sharing

Use presence, not table changes:

js
ws.send(JSON.stringify({
  type: "presence_track",
  metadata: { cursor: { x: 100, y: 50 }, color: "#f00" }
}));

Other clients receive presence_state updates with everyone's metadata. No DB writes.

Debugging "client connects but no events"
  1. Confirm trigger installed: manage_realtime get → trigger_installed: true, drift: false.
  2. Confirm RLS allows the user to SELECT the row: select_rows with as_role: "user", as_user: "<id>" → does the row appear?
  3. If yes to both and still no events: check for plan limits in close codes; check that the change actually happened in Postgres (look at realtime.changes).

8. Anti-patterns

Don'tDo
Enable realtime before configuring RLSSet up policies first; otherwise events leak across users
Use a service key from the frontend "to make it work"Service bypasses RLS — ship-stopping leak. Use end-user JWTs.
Trust client-side filter for securityfilter is just a convenience to reduce client-side work; RLS is the security boundary
Hold thousands of subscriptions per clientOne connection, one or two subscribed tables — the server handles fan-out
Re-call configure in a loop on every page loadIt's idempotent but each call still touches the DB. Configure once during app setup.
Send custom auth headers from the browserWebSocket API can't set them — pass the JWT as ?token= query param

If a docs/butterbase/00-state.md exists in the working directory, prefer invoking via /butterbase-skills:journey-realtime so the journey orchestrator stays in sync.

© butterbase-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/realtime of butterbase-ai/butterbase-skills.

Open the folder on GitHubat commit aa8ae69

Compare with similar skills

Realtime next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Realtime compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Realtime this skillbutterbase-ai/butterbase-skills534—~2.1kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Debugging Websocket IssuesAgentWorkforce/relay8671 repos~1.3kAutomated safety check: PassApache-2.0
Debug Logsadam-s/intercept189—~1.1kAutomated safety check: PassMIT
Gateway Proxy Debugvercel-labs/vercel-openclaw-archived117—~573Automated safety check: PassMIT
Fullstack Devinfometa/workbuddyskills346—~1kAutomated safety check: PassMIT

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Debugging Websocket Issues

    AgentWorkforce/relay

    A skill your agent uses when seeing WebSocket errors like "Invalid frame header", "RSV1 must be clear", or "WSERRUNEXPECTEDRSV1" - covers multiple WebSocketServer conflicts, compression issues, and…

    867 GitHub starsUsed in 1 repo~1.3k tokens
    Backend & APIsAuto-check passed
  • Debug Logs

    adam-s/intercept

    Iterative debugging with targeted logs. An agent skill from adam-s/intercept.

    189 GitHub stars~1.1k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Gateway Proxy Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Gateway and proxy debugging for vercel-openclaw: /gateway routing, HTML injection, WebSocket rewrite, gateway-token handoff, waiting page, status heartbeat, sandbox port URL cache, and proxy auth.

    117 GitHub stars~573 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Fullstack Dev

    infometa/workbuddyskills

    Full-stack backend architecture and frontend-backend integration guide.

    346 GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • EasyEDA Pro API Bridge

    easyeda/easyeda-api-skill

    Gives an agent the EasyEDA Pro API reference and a WebSocket bridge to run code in a live EasyEDA client, for PCB, schematic and library work and extension development.

    872 GitHub stars~7.8k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from butterbase-ai/butterbase-skills

All 39 skills in this repo
  • AI

    butterbase-ai/butterbase-skills

    A skill your agent uses when calling the app's AI gateway from agent tools — chat completions, embeddings, listing models, configuring defaults or BYOK, reading token/cost usage

    534 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Auth Setup

    butterbase-ai/butterbase-skills

    A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

    534 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed
  • Build App

    butterbase-ai/butterbase-skills

    A skill your agent uses when building a new Butterbase app from scratch, creating a full-stack application, or when the user asks to set up a complete backend with database, auth, and deployment

    534 GitHub stars~4.9k tokensUpdated 4 days ago
    Auto-check passed
  • Contributing

    butterbase-ai/butterbase-skills

    A skill your agent uses when contributing to the Butterbase codebase, adding new MCP tools, creating API routes, writing migrations, or understanding the monorepo architecture

    534 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check passed
  • Debug Rls

    butterbase-ai/butterbase-skills

    A skill your agent uses when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase

    534 GitHub stars~3.5k tokensUpdated 4 days ago
    Auto-check passed
  • Deploy Frontend

    butterbase-ai/butterbase-skills

    A skill your agent uses when deploying a frontend (React, Next.js, or static HTML) to a live URL on Butterbase, or when troubleshooting deployment issues like MIME type errors or blank pages

    534 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Realtime

What does Realtime do?

A skill your agent uses when enabling WebSocket subscriptions for live database changes, presence/multiplayer state, or when debugging clients that connect but receive no events. Realtime is an agent skill from butterbase-ai/butterbase-skills.

When should I use Realtime?

Realtime fits situations like: enabling WebSocket subscriptions for live database changes; presence/multiplayer state; debugging clients that connect but receive no events.

How do I install Realtime in Claude Code?

Run `npx skills add butterbase-ai/butterbase-skills --skill realtime -a claude-code`. Or copy the skill folder (skills/realtime in butterbase-ai/butterbase-skills) into .claude/skills/realtime in your project. Claude Code loads it when a task matches its description.

How do I install Realtime in Codex?

Run `npx skills add butterbase-ai/butterbase-skills --skill realtime -a codex`. Or copy the skill folder (skills/realtime in butterbase-ai/butterbase-skills) into .agents/skills/realtime in your project. Codex loads it when a task matches its description.

Can I use Realtime in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add butterbase-ai/butterbase-skills --skill realtime -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/realtime, .gemini/skills/realtime, .github/skills/realtime and .opencode/skills/realtime in your project.

What does Realtime need to run?

SKILL.md names no scripts, command-line tools or credentials: Realtime is instructions for the agent only.

Does Realtime access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Realtime safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Realtime use?

Realtime is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Realtime use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Realtime?

Skills that share tags, products or a category with Realtime: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Debugging Websocket Issues (AgentWorkforce/relay, 867 stars), Debug Logs (adam-s/intercept, 189 stars) and Gateway Proxy Debug (vercel-labs/vercel-openclaw-archived, 117 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Realtime?

butterbase-ai (a GitHub organization) maintains it in butterbase-ai/butterbase-skills, which has 534 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 5, 2026.

Source: butterbase-ai/butterbase-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.