Call the APIs around your Supabase app, straight from the browser
Supabase's own APIs are built for browser clients. For the maps, payments, AI and data APIs your app also uses, ProxifyEdge handles CORS and keeps their tokens on the server.
Access to fetch at 'https://api.example-maps.com/v1/geocode?q=Berlin' from origin 'https://your-app.example.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.
HTTP/2 200
access-control-allow-origin: https://your-app.example.com
x-proxify-ratelimit-remaining: 9999
Every third-party call turns into an Edge Function
A Supabase app talks to more than Supabase. When a third-party API doesn't allow browser calls, or needs a secret token, the usual answer is another Edge Function whose only job is to forward one request.
Each of those is more code to write, deploy and keep in step with the API it wraps.
How ProxifyEdge helps
Configured from the dashboard, enforced on every request.
-
Tokens in a vault, not in functions
Store third-party tokens as secrets and reference them as {{secret.NAME}}. They are inserted on the server for each request.
-
Bound to the right host
Each secret is bound to the hosts it may be sent to, so a maps token can only ever reach the maps API.
-
Locked to your app
A live key only answers your app's origins, so other sites can't send requests with it from their pages.
-
Batch requests
Fetch from several third-party endpoints in one round trip when a page needs them together.
-
Quotas per key
Monthly quotas and per-second limits on each key keep a busy page from running up a third-party bill.
Example
Supabase direct, everything else through ProxifyEdge
- Your Supabase client keeps calling Supabase directly; only the third-party request goes through ProxifyEdge.
- Bind the secret to the third-party API's host on the Secrets page.
- Lock the ProxifyEdge key to your app's origins before you launch.
import { createClient } from '@supabase/supabase-js';
// Supabase is still called directly, as usual.
const supabase = createClient(SUPABASE_URL, SUPABASE_ANON_KEY);
// The third-party API goes through ProxifyEdge, with its token kept server-side.
export async function geocode(query: string) {
const target = 'https://api.example-maps.com/v1/geocode?q=' + encodeURIComponent(query);
const res = await fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
headers: {
'X-API-Key': 'pk_your_public_key',
'X-Proxify-Upstream-Authorization': 'Bearer {{secret.MAPS_API_TOKEN}}',
},
});
return res.json();
}
Questions
Something else? Get in touch or read the docs.
Do I need ProxifyEdge for Supabase's own APIs?
Usually not. Supabase's database, auth and storage APIs are designed to be called from the browser. ProxifyEdge is for the other APIs your app depends on.
Does this replace Edge Functions?
For functions that only forward a request and add a token, often yes. Keep Edge Functions for real server-side logic, such as anything that writes to your database with elevated rights.
Where are the third-party tokens stored?
In ProxifyEdge's secrets vault, encrypted at rest. A stored secret can be replaced or deleted from the dashboard but never read back.
Can ProxifyEdge help if Supabase is unreachable on my network?
ProxifyEdge isn't a way around network blocks or legal restrictions on a service. For problems reaching Supabase itself, contact Supabase support.
Use each third-party API within its terms. ProxifyEdge is not affiliated with Supabase.