Computefor agentic workloads
Agent sandboxes and always-on backend services running inside your Supabase project — next to your data, behind your auth.
One runtime,two shapes of work
Sandboxes, APIs, and background jobs usually mean three vendors and a database somewhere else. Compute runs them all in Supabase alongside your application backend.
Isolated environments for agent code
Execute code in a secure, isolated environment — one per task, per session, or per agent.
- Per-session environment for executing code
- Provision programmatically via the API or MCP server
- Suspend and resume with state preserved
Always-on backends in any language
Transcription pipelines, embedding jobs, agent frameworks, and APIs — running as long as the work takes.
- Auto-scaling for traffic surges
- No wall-clock limits on execution
- Any runtime, static binary, or Dockerfile
- HTTP services, background jobs, and long-running pipelines
One primitive, every workload
Ephemeral sandboxes and always-on HTTP services, one primitive.
Any language
Node, Deno, or any Dockerfile.
Next to your database
Same network as Postgres — single-digit millisecond queries.
Scale to zero
Services suspend when idle and resume in under a second. You pay nothing while they sleep.
One trust boundary,preconfigured
Every sandbox and service inherits your project's auth, roles, and permissions the moment it starts, running in its own microVM with dedicated CPU and memory. Agents get a sandbox that is already scoped to the data it is allowed to touch — nothing more.
Short-lived credentials
Access runs through Supabase Auth with short-lived keys, not standing secrets.
Zero-config data access
Reach your database and Storage with the permissions your key already carries.
Per-workload firewalls
Define which external endpoints and ports each workload can reach.
Cloaked secrets
Scope secrets per workload, and cloak values so your code never sees them.
Patched automatically
Kernel-level security patches roll out automatically. Nothing to do on your part.
Dependency scanning
Dependencies are scanned at runtime, with alerts as new vulnerabilities land.
Deploy fromwherever you work
The same deployment surface serves humans and agents: one command in a terminal, one tool call in an agent session, one request against the API.
Join the waitlistFrequently asked questions
Run your next workloadnext to your data
Compute is in Private Alpha. Join the waitlist and we'll reach out as invites roll out.