Quickstart: Supabase Passwordless API
Use Supabase OTP flows when your product needs passwordless auth routes behind one Worker gateway. This guide covers both the auth request and verify endpoints.
Use Supabase OTP flows when your product needs passwordless auth routes behind one Worker gateway. This guide covers both the auth request and verify endpoints. If your app already uses Supabase Auth, this is the fastest path to edge-managed passwordless login.
Last reviewed: 2026-03-06
When to use this
Use these quickstart guides when you are setting up Serverless API Gateway for the first time or adding a new integration pattern. Each guide walks through one isolated concern so you can deploy incrementally instead of configuring everything at once.
Key concepts
Every quickstart produces a deployable
wrangler.tomland JSON config pair -- you can runwrangler deployat the end of each guide.Guides are ordered from simplest (health endpoint) to most complex (Auth0/Supabase passwordless), so earlier guides serve as prerequisites for later ones.
Config can come from a local file, Cloudflare KV, or the
SAG_API_CONFIG_JSONenvironment variable -- choose based on your deploy workflow.All guides use the same JSON config schema, so patterns you learn in one guide transfer directly to others.
Repo-grounded example
{
"authorizer": {
"type": "supabase",
"jwt_secret": "$env.SUPABASE_JWT_SECRET",
"issuer": "https://project.supabase.co/auth/v1",
"audience": "authenticated"
},
"paths": [
{
"method": "POST",
"path": "/api/v1/supabase/auth",
"integration": { "type": "supabase_passwordless_auth" }
},
{
"method": "POST",
"path": "/api/v1/supabase/verify",
"integration": { "type": "supabase_passwordless_verify" }
}
]
}This snippet configures the Supabase authorizer with the project JWT secret, issuer, and audience. The two paths use supabase_passwordless_auth and supabase_passwordless_verify integration types to handle OTP send and verify flows.
Troubleshooting
If
wrangler deployfails with a config error, validate your JSON against the schema file (api-config.schema.json) before investigating further.If the health endpoint returns 404, confirm that your
wrangler.tomlpoints to the correct main entrypoint and that the config file is being loaded.If JWT or Auth0 routes return 500, check that all required environment variables and secrets are set in your Cloudflare dashboard or
.dev.varsfile.Use
wrangler tailto stream live logs from the deployed worker and see the exact error message the gateway produces.
Related docs
Last updated