Skip to content
For Supabase apps

Call the APIs around your Supabase app, straight from the browser

Supabase's own APIs are built for browser clients. For the maps, payments, AI and data APIs your app also uses, ProxifyEdge handles CORS and keeps their tokens on the server.

Browser console, calling the API directly

Access to fetch at 'https://api.example-maps.com/v1/geocode?q=Berlin' from origin 'https://your-app.example.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.

The same request through ProxifyEdge
HTTP/2 200
access-control-allow-origin: https://your-app.example.com
x-proxify-ratelimit-remaining: 9999

Every third-party call turns into an Edge Function

A Supabase app talks to more than Supabase. When a third-party API doesn't allow browser calls, or needs a secret token, the usual answer is another Edge Function whose only job is to forward one request.

Each of those is more code to write, deploy and keep in step with the API it wraps.

How ProxifyEdge helps

Configured from the dashboard, enforced on every request.

  • Tokens in a vault, not in functions

    Store third-party tokens as secrets and reference them as {{secret.NAME}}. They are inserted on the server for each request.

  • Bound to the right host

    Each secret is bound to the hosts it may be sent to, so a maps token can only ever reach the maps API.

  • Locked to your app

    A live key only answers your app's origins, so other sites can't send requests with it from their pages.

  • Batch requests

    Fetch from several third-party endpoints in one round trip when a page needs them together.

  • Quotas per key

    Monthly quotas and per-second limits on each key keep a busy page from running up a third-party bill.

Example

Supabase direct, everything else through ProxifyEdge

  • Your Supabase client keeps calling Supabase directly; only the third-party request goes through ProxifyEdge.
  • Bind the secret to the third-party API's host on the Secrets page.
  • Lock the ProxifyEdge key to your app's origins before you launch.
Proxy reference
geocode.ts
import { createClient } from '@supabase/supabase-js';

// Supabase is still called directly, as usual.
const supabase = createClient(SUPABASE_URL, SUPABASE_ANON_KEY);

// The third-party API goes through ProxifyEdge, with its token kept server-side.
export async function geocode(query: string) {
  const target = 'https://api.example-maps.com/v1/geocode?q=' + encodeURIComponent(query);
  const res = await fetch(`https://api.proxifyedge.com/proxy?url=${encodeURIComponent(target)}`, {
    headers: {
      'X-API-Key': 'pk_your_public_key',
      'X-Proxify-Upstream-Authorization': 'Bearer {{secret.MAPS_API_TOKEN}}',
    },
  });
  return res.json();
}

Questions

Something else? Get in touch or read the docs.

Do I need ProxifyEdge for Supabase's own APIs?

Usually not. Supabase's database, auth and storage APIs are designed to be called from the browser. ProxifyEdge is for the other APIs your app depends on.

Does this replace Edge Functions?

For functions that only forward a request and add a token, often yes. Keep Edge Functions for real server-side logic, such as anything that writes to your database with elevated rights.

Where are the third-party tokens stored?

In ProxifyEdge's secrets vault, encrypted at rest. A stored secret can be replaced or deleted from the dashboard but never read back.

Can ProxifyEdge help if Supabase is unreachable on my network?

ProxifyEdge isn't a way around network blocks or legal restrictions on a service. For problems reaching Supabase itself, contact Supabase support.

Use each third-party API within its terms. ProxifyEdge is not affiliated with Supabase.

Make the request your browser was blocking.

Create an account, lock your key to your site, and send your first request through ProxifyEdge.

Are you sure?