Create and deploy a Supabase Edge Function, store your secret keys with supabase secrets, and call it from your app.
Move my OpenAI call into a Supabase Edge Function so the key isn't in the browser
How it works
- Find code that needs a server: Vovy scans your app for secret keys used in browser code, like an OpenAI or Stripe secret key, and lists what should move.
- Create the function: An Edge Function is a small piece of code Supabase runs on its servers. Vovy runs supabase functions new and writes the logic there.
- Store your secrets: Vovy runs supabase secrets set for each key, so they live encrypted in Supabase and never in your code or GitHub.
- Deploy the function: Vovy asks, then runs supabase functions deploy and watches the output until Supabase confirms it's live.
- Call it from your app: Vovy swaps your old code for supabase.functions.invoke, tests it, and opens the function's Logs tab to show the request worked.
What you provide
- Your Supabase project
- The secret keys to protect
What you get
- A deployed Edge Function
- Secrets stored server-side
- App calling the function
- Logs showing it works
FAQ
Why can't I call OpenAI from the browser?
Anything in browser code is visible to anyone. A leaked secret key lets strangers run up your bill.
I get a CORS error calling my function. What now?
Browsers need the function to reply with CORS headers, including to the OPTIONS preflight request. Vovy adds them.
What language are Edge Functions?
TypeScript, running on Deno. Most npm packages work through npm: imports.
Related tasks
All tasks