Invoke a function
Changed onInvoke a function. The function's visibility decides which credentials may call it, and the function does not run for any other. A private function answers every credential but a service key exactly as a missing one, with 404, so its name and id cannot be discovered; an anon key on an authenticated function gets 403. An SDK calling by name resolves it first through GET /functions/resolve, which answers that anon key with 404 instead.
With Service Key (admin/background operations, every visibility):
- Use for background jobs, webhooks, cron, admin operations
- Function receives payload only (no user context)
- Database queries bypass RLS (admin access)
With Auth User Token (user-facing, authenticated or public functions):
- Use for user-initiated actions
- Includes users from anonymous sign-ins
- Function receives payload + __volcano_auth context:
{ user_id: "uuid", email: "user@example.com", project_id: "uuid", role: "authenticated" or "anonymous" } - Database queries enforce RLS (user-scoped data)
With Anon Key (public functions only):
- Requires anon key permission: functions.invoke
- Function must have visibility: public
- Function receives payload only (no __volcano_auth)
Transport and CORS:
- This operation is the authenticated direct RPC endpoint and always uses the POST {payload: ...} contract, including for functions whose DNS ingress is configured in HTTP mode.
- The geo-routed DNS ingress is the function's invoke_url. It is on a different domain from this API, so it cannot be derived from the API host.
- RPC-mode DNS ingress accepts POST at /. HTTP-mode DNS ingress accepts GET, HEAD, POST, PUT, PATCH, and DELETE at / and nested paths.
- Direct and RPC-mode CORS preflight advertises POST, OPTIONS. HTTP-mode DNS preflight advertises GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS.
- http_auth_mode: none applies only to public HTTP-mode DNS ingress; this direct operation always requires a Volcano credential.
Durable functions are not invocable here. A durable function's id answers 404, whatever its visibility, because a synchronous call would run it with no execution record, no idempotency and no concurrency accounting. Start one with POST /durable-functions/{functionId}/executions.
Request
- Base URL: https://api.volcano.dev
- URL: https://api.volcano.dev/functions/{functionId}/invoke
- Auth: one of:
- HTTP bearer
- HTTP bearer
- HTTP bearer
Path parameters
Function ID
Request body
Response
Function response (passthrough from function runtime)
Raw function response body returned by the invoked function.
Changes
- ▲
added the new path request parameter
functionId - ▲
the request's body type changed from no type to
object - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ▲
the response's body type changed from no type to
objectfor status - ○
added the new optional request property
- ○
added the optional property
to the response with the status - ○
added the optional property
to the response with the status - ○
added the optional property
to the response with the status - ○
added the optional property
to the response with the status - ○
added the optional property
to the response with the status - ○
added the optional property
to the response with the status - ○
added the required property
to the response with the status - ○
added the required property
to the response with the status - ○
added the required property
to the response with the status - ○
added the required property
to the response with the status - ○
added the required property
to the response with the status - ○
added the required property
to the response with the status
- ▲
- ▲
the request's body type changed from
objectto no type - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
the response's body type changed from
objectto no type for status - ▲
removed the required property
from the response with the status - ▲
removed the required property
from the response with the status - ▲
removed the required property
from the response with the status - ▲
removed the required property
from the response with the status - ▲
removed the required property
from the response with the status - ▲
removed the required property
from the response with the status - ●
deleted the
pathrequest parameterfunctionId - ●
removed the request property
- ●
removed the optional property
from the response with the status - ●
removed the optional property
from the response with the status - ●
removed the optional property
from the response with the status - ●
removed the optional property
from the response with the status - ●
removed the optional property
from the response with the status - ●
removed the optional property
from the response with the status
- ▲