How to set up Supabase Edge Functions for AI workloads

Quick Answer: Create the function with `supabase functions new ai-handler`, write a Deno handler that reads the user JWT, calls a model provider, and writes results back via the Supabase client with row-level security. Deploy with `supabase functions deploy ai-handler` and call from the frontend using `supabase.functions.invoke()` with the user's session token.

Why Edge Functions Fit AI Workloads

Supabase Edge Functions run on Deno Deploy, co-located with the database, and inherit row-level security via a forwarded user JWT. For AI workloads — embedding ingestion, RAG retrieval, model orchestration — that proximity to Postgres matters because most AI calls bracket a database read or write.

Step-by-Step Setup

  1. Install the Supabase CLI and authenticate: supabase login
  2. Initialise the project locally if it is not already: supabase init
  3. Create the function: supabase functions new ai-handler
  4. Write the handler in supabase/functions/ai-handler/index.ts:
import { createClient } from "jsr:@supabase/supabase-js@2";

Deno.serve(async (req) => {
  const authHeader = req.headers.get("Authorization");
  if (!authHeader) return new Response("unauthorized", { status: 401 });
  const supabase = createClient(
    Deno.env.get("SUPABASE_URL")!,
    Deno.env.get("SUPABASE_ANON_KEY")!,
    { global: { headers: { Authorization: authHeader } } }
  );
  const { prompt } = await req.json();
  const r = await fetch("https://api.openai.com/v1/chat/completions", {
    method: "POST",
    headers: {
      "Authorization": `Bearer ${Deno.env.get("OPENAI_API_KEY")}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify({
      model: "gpt-4o-mini",
      messages: [{ role: "user", content: prompt }],
    }),
  });
  const data = await r.json();
  await supabase.from("ai_logs").insert({ prompt, response: data });
  return new Response(JSON.stringify(data), { headers: { "Content-Type": "application/json" } });
});
  1. Set environment secrets: supabase secrets set OPENAI_API_KEY=sk-...
  2. Deploy: supabase functions deploy ai-handler
  3. Call from the frontend: await supabase.functions.invoke("ai-handler", { body: { prompt } })

Operational Notes

Edge Functions on Supabase Pro have a 150-second wall-clock limit per invocation as of May 2026. Long-running AI tasks (above this limit) should be queued via Postgres pg_cron + a dedicated worker, or moved to a Vercel Edge Function or a self-hosted runtime. For streaming responses, return a ReadableStream from the handler and process the SSE on the client.

Common Mistakes

Two recurring issues: forgetting to set the OPENAI_API_KEY secret (causing 500 errors on first call), and using the service role key in the function (bypassing RLS, which silently expands attack surface). Always pass the anon key and forward the user JWT for AI handlers that read or write user-scoped data.

Related Questions

Written & reviewed by Rafal Fila · Last updated:

Related Tools

Related Rankings

Dive Deeper

comparison

Keystroke vs n8n in 2026: Agent-Built TypeScript vs the Visual Canvas

Keystroke, launched in July 2026 by Y Combinator W24 company Sprint Labs, is a code-first automation platform where AI coding agents write workflows as TypeScript in the user's repository. n8n, founded in 2019, is the most widely deployed source-available visual workflow platform, with 200,000+ users and a $2.5 billion valuation. This comparison covers the agent-authored versus canvas building models, durable execution, licensing (Elastic License 2.0 vs the Sustainable Use License), verified July 2026 pricing including Keystroke's usage metering, and the maturity gap between a days-old platform and an established ecosystem.

comparison

QuantumBPM vs Camunda 2026: Single-Binary Challenger vs the BPMN Incumbent

QuantumBPM (launched 2026, Coroid s.r.o., Slovakia) packages a BPMN 2.0 runtime and DMN 1.5 decision engine into one Go binary backed by Temporal and PostgreSQL. Camunda (Berlin, founded 2013) is the category incumbent: Camunda 7 (Apache 2.0, in maintenance) and the Zeebe-based Camunda 8 platform. This comparison covers product structure, architecture, DMN TCK conformance with recording dates, deployment, pricing, and vendor maturity, verified July 2026.

case-study

Migrating 23 Make Scenarios to Self-Hosted n8n: a 3-Week Breakdown

Anonymized retrospective of a DTC ecommerce brand migrating 23 Make scenarios to a self-hosted n8n instance over three weeks. Tooling cost dropped from $348/month on Make Teams to roughly $12/month on a Hetzner VPS, but credential and webhook recreation consumed about 40% of total project time.