PreviewRustaBase OSS is in public preview. Build on managed PostgreSQL with APIs, authentication, storage, realtime, and server-side functions.Read the product direction

APIs and SDKs

Authentication and API keys

Requests are authenticated with a token in the Authorization header: a user session token from an auth table, a superuser token, or a Project API key for trusted server code.

Authenticate a user

Sign in against an auth table with an identity (email or username, depending on the table configuration) and a password. The response carries the user record and a token.

curl -X POST $PROJECT_URL/api/v1/collections/users/auth-with-password \
  -H "Content-Type: application/json" \
  -d '{"identity":"[email protected]","password":"a-strong-password"}'
JSON
{
  "token": "eyJhbGciOiJIUzI1NiIs...",
  "record": {
    "id": "b7s0x1c9k2m4q8f",
    "collectionId": "users_table_id",
    "collectionName": "users",
    "email": "[email protected]",
    "verified": true,
    "created": "2026-01-14 08:12:03.221Z",
    "updated": "2026-02-02 11:40:55.004Z"
  }
}

Send the token

Attach the token to every authenticated request. The SDKs do this for you once a sign-in succeeds, and they keep the session in their auth store.

curl $PROJECT_URL/api/v1/collections/posts/records \
  -H "Authorization: eyJhbGciOiJIUzI1NiIs..."

Available sign-in methods

MethodEndpointNotes
List methodsGET /api/v1/collections/{table}/auth-methodsWhat the table has enabled
PasswordPOST /api/v1/collections/{table}/auth-with-passwordIdentity fields are configurable per table
OAuth2POST /api/v1/collections/{table}/auth-with-oauth2Provider, code, verifier, redirect URL
One-time passwordPOST /api/v1/collections/{table}/request-otp then /auth-with-otpEmail-delivered code
RefreshPOST /api/v1/collections/{table}/auth-refreshExtends an existing session
ImpersonatePOST /api/v1/collections/{table}/impersonate/{id}Superuser only

When multi-factor authentication is enabled, the first step returns an mfaId that must be sent with the second factor.

Email flows

  • POST /api/v1/collections/{table}/request-verification and /confirm-verification
  • POST /api/v1/collections/{table}/request-password-reset and /confirm-password-reset
  • POST /api/v1/collections/{table}/request-email-change and /confirm-email-change

Project API keys

Create scoped API keys in the Project console for servers, automation, and CI. A key is shown once at creation, is sent in the same Authorization header, and can be revoked without touching user sessions.

  • Give each key the smallest set of tables and actions it needs.
  • Name each key after the system that uses it.
  • Rotate a key immediately if it appears in a log, a repository, or a browser bundle.

Superuser sessions and API keys must stay on the server. Browser and mobile applications should only ever hold a user session token.

REST API reference

Found something wrong on this page?

Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.