HTTP
Send Authorization: Bearer unless the row says otherwise. Project routes need a project, from the host or from the token. Error bodies use { "error": "..." }.
Platform
Section titled “Platform”No project. The operator token is not a project key.
| Method | Path | Who | Effect |
|---|---|---|---|
GET |
/health |
anyone | Postgres and the blob store are reachable |
GET |
/platform/v1/projects |
operator | List refs |
POST |
/platform/v1/projects |
operator | Create a project. Returns ref, anon key, service key |
PATCH |
/platform/v1/projects/{ref} |
operator | Update the project row |
POST |
/platform/v1/migrate |
operator | Apply sql/project/ |
POST |
/platform/v1/domains/{host}/verify |
operator | Mark a domain verified |
GET |
/ask?domain= |
proxy | 200 when that custom domain is verified, otherwise 404 |
| Method | Path | Who | Body |
|---|---|---|---|
POST |
/auth/v1/signup |
anon key | { email, password } → session |
POST |
/auth/v1/token |
anon key, or the refresh token in the body | { email, password } or { refresh_token } → session |
POST |
/auth/v1/logout |
the refresh token in the body | { refresh_token } → 204 |
GET |
/auth/v1/user |
user access token | { id, email } |
POST |
/auth/v1/magic-link |
anon key | { email } → { ok: true } |
POST |
/auth/v1/verify |
project | { token } → session |
POST |
/auth/v1/recover |
anon key | { email } → { ok: true } |
POST |
/auth/v1/recover/complete |
project | { token, password } → session |
POST |
/auth/v1/invite |
service key | { email } → { ok: true } |
POST |
/auth/v1/invite/accept |
project | { token, password } → session |
A session is { access_token, refresh_token, user: { id, email } }.
Data, storage, functions
Section titled “Data, storage, functions”| Method | Path | Who |
|---|---|---|
| any | /data/v1/... |
anon, user, or service. Proxied to PostgREST |
POST |
/storage/v1/object/presign |
a project token. Body { bucket, key, method } |
GET or PUT |
/storage/v1/signed |
the signature on the query string |
POST |
/fn/v1/{name} |
a project token. Body is stdin. Names starting with _ are not public |
POST |
/fn/v1/_admin/functions/{name} |
service key. Body is a zip. ?promote=false keeps the previous version live |
POST |
/fn/v1/_admin/schedules |
service key. { function_name, body } |
POST |
/fn/v1/_internal/cron |
operator token |
Service key, except the public site host itself.
| Method | Path |
|---|---|
POST |
/sites/v1/deployments |
PUT |
/sites/v1/deployments/{id}/files/{path} |
POST |
/sites/v1/deployments/{id}/finish |
POST |
/sites/v1/deployments/{id}/fail |
PUT |
/sites/v1/files/{path} |
GET or PUT |
/sites/v1/env |
POST |
/sites/v1/routes with { path, function } |
POST |
/sites/v1/domains with { host } |
POST |
/sites/v1/domains/{host}/verify |
DELETE |
/sites/v1/domains/{host} |
On {ref}.{base_domain}, GET and the other methods are the site. / serves index.html.
Console
Section titled “Console”/console/v1 uses a console token. The pages and role rules are in Console. The first call is GET /console/v1/setup, then POST /console/v1/setup or POST /console/v1/login.