Goal
Create Edge Functions that handle trusted backend work safely and cleanly.
When to Use
- The logic should not run in the client.
- A webhook, privileged API call, or server-side integration is needed.
- Supabase Edge Functions are the chosen execution layer.
Instructions
- Define the function trigger, caller, auth expectations, and side effects.
- Separate request validation, auth checks, business logic, and response shape.
- Handle secrets only in server-side environment configuration.
- Design retry, idempotency, and logging strategy for external calls.
- Consult
references/edge-function-checklist.mdwhen integration risk is non-trivial.
Constraints
- Never expose service-role credentials to the client.
- Do not put RLS-sensitive writes in the client if privileged logic is required.
- Keep each function focused on one job.
Output Format
- Function purpose
- Input/output contract
- Security notes
- Execution flow
- Implementation scaffold
Examples
- "Build a Supabase Edge Function for Stripe webhook handling."
- "Plan an edge function to generate AI reports."