Functions

Invoke a function

Changed on

Invoke a function. The function's visibility decides which credentials may call it, and the function does not run for any other. A private function answers every credential but a service key exactly as a missing one, with 404, so its name and id cannot be discovered; an anon key on an authenticated function gets 403. An SDK calling by name resolves it first through GET /functions/resolve, which answers that anon key with 404 instead.

With Service Key (admin/background operations, every visibility):

  • Use for background jobs, webhooks, cron, admin operations
  • Function receives payload only (no user context)
  • Database queries bypass RLS (admin access)

With Auth User Token (user-facing, authenticated or public functions):

  • Use for user-initiated actions
  • Includes users from anonymous sign-ins
  • Function receives payload + __volcano_auth context:
    {
      user_id: "uuid",
      email: "user@example.com",
      project_id: "uuid",
      role: "authenticated" or "anonymous"
    }
    
  • Database queries enforce RLS (user-scoped data)

With Anon Key (public functions only):

  • Requires anon key permission: functions.invoke
  • Function must have visibility: public
  • Function receives payload only (no __volcano_auth)

Transport and CORS:

  • This operation is the authenticated direct RPC endpoint and always uses the POST {payload: ...} contract, including for functions whose DNS ingress is configured in HTTP mode.
  • The geo-routed DNS ingress is the function's invoke_url. It is on a different domain from this API, so it cannot be derived from the API host.
  • RPC-mode DNS ingress accepts POST at /. HTTP-mode DNS ingress accepts GET, HEAD, POST, PUT, PATCH, and DELETE at / and nested paths.
  • Direct and RPC-mode CORS preflight advertises POST, OPTIONS. HTTP-mode DNS preflight advertises GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.
  • http_auth_mode: none applies only to public HTTP-mode DNS ingress; this direct operation always requires a Volcano credential.

Durable functions are not invocable here. A durable function's id answers 404, whatever its visibility, because a synchronous call would run it with no execution record, no idempotency and no concurrency accounting. Start one with POST /durable-functions/{functionId}/executions.

post/functions/{functionId}/invoke

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/functions/{functionId}/invoke
  • Auth: one of:
    • HTTP bearer
    • HTTP bearer
    • HTTP bearer

Path parameters

functionIdstring uuid required

Function ID

Request body

payloadobject

Payload to send to the function.

If invoked with auth user token, Volcano automatically injects __volcano_auth context:

{
  ...yourPayload,
  __volcano_auth: {
    user_id: "uuid",
    email: "user@example.com",
    project_id: "uuid",
    role: "authenticated" | "anonymous"
  }
}

Response

Function response (passthrough from function runtime)

FunctionInvocationResponse required

Raw function response body returned by the invoked function.

Changes

    • ▲

      added the new path request parameter functionId

    • ▲

      the request's body type changed from no type to object

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the new optional request property

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ▲

      the request's body type changed from object to no type

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      the response's body type changed from object to no type for status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ▲

      removed the required property from the response with the status

    • ●

      deleted the path request parameter functionId

    • ●

      removed the request property

    • ●

      removed the optional property from the response with the status

    • ●

      removed the optional property from the response with the status

    • ●

      removed the optional property from the response with the status

    • ●

      removed the optional property from the response with the status

    • ●

      removed the optional property from the response with the status

    • ●

      removed the optional property from the response with the status