Open-source personal finance app built with Next.js and Supabase.
Dragg is an open-source personal finance web app for tracking income, expenses, budgets, categories, payment methods, subscriptions, goals, reports, and monthly progress.
It is designed to be simple to self-host and inexpensive to operate, with Supabase handling authentication and data security through PostgreSQL + Row Level Security.
- Google OAuth and email/password authentication with Supabase Auth
- User-owned finance data isolated via Supabase Row Level Security
- Dashboard with monthly financial summary, planned expenses, and 50/30/20 split
- Full transaction flow: create, list, update, and delete
- Installment expenses and monthly subscription scheduling through transaction records
- Categories organized by Needs, Wants, and Savings
- Category emoji icons and monthly spending limits
- Payment methods management with protected Pix and Cash defaults
- Credit card due-day and closing-day support with planned invoice rows
- Goals screen with create, edit, fund, and delete flows
- Reports screen with monthly summaries, net worth progression, and export-friendly data
- LGPD-oriented privacy request table in the database schema
- Charts and progress indicators powered by Recharts
- Responsive experience for desktop and mobile
Requirements:
- Node.js 24.x
- pnpm 10.x through Corepack
- Supabase project
- Google OAuth provider configured in Supabase
- Email provider enabled in Supabase Auth
Clone and run locally:
git clone https://github.com/fsousac/Dragg.git
cd Dragg
corepack enable
pnpm install
cp .env.example .env.localSet your environment variables in .env.local:
NEXT_PUBLIC_SUPABASE_URL=your_supabase_project_url
NEXT_PUBLIC_SUPABASE_PUBLISHABLE_KEY=your_supabase_publishable_keyApply migrations and start:
supabase db push
pnpm run devOpen http://localhost:3000.
If you are not using Supabase CLI, apply SQL files from supabase/migrations in filename order through the Supabase SQL Editor.
- Architecture
- Authentication
- Database
- Security Notes
- End-to-End Tests
- Contributing Guide
- Security Policy
- Code of Conduct
- Changelog
Dragg currently targets:
- Next.js 16
- React 19
- TypeScript 5
- Node.js 24.x
- pnpm 10.x
- Supabase Postgres
Security is a core part of the project architecture.
- Keep RLS enabled for all user-owned tables
- Scope reads and writes by authenticated user ID
- Validate Server Action payloads at runtime (recommended with Zod)
- Never expose service-role keys or OAuth secrets in client code
- Keep migrations reproducible and free of production data
- Keep LGPD/privacy workflow data scoped by authenticated user ownership
For vulnerability reports, follow SECURITY.md.
pnpm run dev # Start local development server
pnpm run build # Production build
pnpm run start # Start built app
pnpm run lint # Run ESLint
pnpm run test # Run tests once
pnpm run test:watch # Run tests in watch mode
pnpm run test:coverage # Run tests with coverage
pnpm run e2e # Run Playwright E2E tests (see docs/e2e.md)
pnpm run e2e:ui # Run Playwright E2E tests interactivelyDragg is ready to deploy on Vercel.
- Import repository into Vercel.
- Configure the same environment variables used locally.
- Add production auth callback URLs in Supabase:
https://your-domain.com/auth/callbackhttps://your-domain.com/auth/update-password
- Apply migrations to the production Supabase project.
- Deploy.
The repository also includes GitHub Actions for CodeQL, quality checks, and production Vercel deployment after successful checks on main.
Contributions are welcome.
- Fork the repository.
- Create a feature branch.
- Keep changes focused and include tests when possible.
- Add migrations for any schema change.
- Update docs when behavior changes.
- Run lint, test, and build.
- Open a pull request with a clear description.
Issue and pull request templates are available under .github.
Dragg is released under the MIT License.