PreviewRustaBase OSS is in public preview. Build on managed PostgreSQL with APIs, authentication, storage, realtime, and server-side functions.Read the product direction

Functions and configuration

API keys

Give servers, workers, and automation their own scoped credentials, so they can call your Project without a user password.

When to use an API key

  • A backend service or worker that reads or writes Project data.
  • A CI job or script that imports or exports records.
  • A partner integration that needs access to a few tables only.

Never put an API key in a browser or mobile app. Anyone can read code that runs on a user's device. Those apps should sign users in instead.

Create a key

  1. Open your Project and select API keys.
  2. Select New API key and give it a clear name, such as Billing worker.
  3. Choose the permission: read only, or read and write.
  4. Under Allowed collections, pick the tables the key may use. Leave it empty to allow every table.
  5. Optionally set an expiry date.
  6. Select Create and copy the key right away. It is shown only once.

Use the key

Send the key in the X-API-Key header. The console's Copy cURL example button fills in your Project address for you.

curl "https://my-app.rustabase.net/api/v1/collections/orders/records"               -H "X-API-Key: YOUR_API_KEY"
import { createClient } from "rustabase";

const rb = createClient("https://my-app.rustabase.net");
const headers = { "X-API-Key": process.env.RUSTABASE_API_KEY };

const orders = await rb.from("orders").list({ sort: "-created", headers });

Rotate, disable, or revoke

ActionWhat happens
Rotate keyIssues a new secret. The old secret stops working at once. Update your service first.
Disable keyStops the key working but keeps it, so you can enable it again later.
Revoke keyDeletes the key for good. Any app using it loses access immediately.
const rotated = await rb.admin.apiKeys.rotate("KEY_ID"); // new secret, shown once

Good practice

  • Create one key per service, so you can rotate or revoke one without affecting others.
  • Give each key the fewest tables and the lowest permission it needs.
  • Set an expiry date for temporary access.
  • Check Last used on the keys list and revoke keys nobody uses.
  • Keep keys in your hosting provider's secret settings, never in a repository.

Protect data with row-level security

Found something wrong on this page?

Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.