API reference

Databases

Browse and edit DynamoDB tables: items, indexes, metrics and settings.

These routes back the database explorer in Cloud. Each one works on a table the organization owns, found by its resource id; reads need resources:read and changes resources:write. See Databases.

GET /v1/orgs/:orgId/databases

The org's databases with live status, item count and size from DynamoDB.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).

Response 200

{
  databases: {
    table: {
      status: string
      itemCount: number
      sizeBytes: number
      partitionKey: {
        name: string
        type: "S" | "N" | "B"
      }
      sortKey?: {
        name: string
        type: "S" | "N" | "B"
      }
      indexCount: number
      deletionProtection: boolean
    }
    region: string
    type: "repository" | "database" | "bucket"
    name: string
    status?: "error" | "active" | "creating" | "deleting"
    createdAt?: number
    updatedAt?: number
    orgId: string
    resourceId: string
    createdBy: string
    projectId?: string
    location: string
    arn?: string
    physicalName: string
    restoredFrom?: string
    pendingSetup?: boolean
  } | {
    table: null
    error: "unavailable" | "missing"
    region: string
    type: "repository" | "database" | "bucket"
    name: string
    status?: "error" | "active" | "creating" | "deleting"
    createdAt?: number
    updatedAt?: number
    orgId: string
    resourceId: string
    createdBy: string
    projectId?: string
    location: string
    arn?: string
    physicalName: string
    restoredFrom?: string
    pendingSetup?: boolean
  }[]
}

Errors

StatusMessage
404Table not found

GET /v1/orgs/:orgId/databases/:resourceId

A database record and its live table description (keys, indexes, status). table is null when the table was deleted outside the platform.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Response 200

{
  database: {
    region: string
    type: "repository" | "database" | "bucket"
    name: string
    status?: "error" | "active" | "creating" | "deleting"
    createdAt?: number
    updatedAt?: number
    orgId: string
    resourceId: string
    createdBy: string
    projectId?: string
    location: string
    arn?: string
    physicalName: string
    restoredFrom?: string
    pendingSetup?: boolean
  }
  table: {
    partitionKey: {
      name: string
      type: "S" | "N" | "B"
    }
    sortKey?: {
      name: string
      type: "S" | "N" | "B"
    }
    name: string
    status: string
    indexes: {
      partitionKey: {
        name: string
        type: "S" | "N" | "B"
      }
      sortKey?: {
        name: string
        type: "S" | "N" | "B"
      }
      name: string
      kind: "local" | "global"
      projection: {
        type: "ALL" | "KEYS_ONLY" | "INCLUDE"
        attributes?: string[]
      }
      status?: string
      backfilling?: boolean
      itemCount?: number
      sizeBytes?: number
    }[]
    itemCount: number
    sizeBytes: number
    billingMode: string
    tableClass: string
    deletionProtection: boolean
    createdAt?: number
  }
}
| {
  database: {
    region: string
    type: "repository" | "database" | "bucket"
    name: string
    status?: "error" | "active" | "creating" | "deleting"
    createdAt?: number
    updatedAt?: number
    orgId: string
    resourceId: string
    createdBy: string
    projectId?: string
    location: string
    arn?: string
    physicalName: string
    restoredFrom?: string
    pendingSetup?: boolean
  }
  table: null
}

Errors

StatusMessage
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/scan

One page of a scan. Pass cursor from the previous page to continue.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredDefaultNotes
indexstringNoup to 255 characters
limitintegerNo251–100
cursorstringNoup to 8,000 characters
filtersobject[]No[]up to 10 items
filters[].attributestringYesmatches ^[^\u0000-\u001f]{1,255}$
filters[].op"=" | "<>" | "<" | "<=" | ">" | ">=" | "begins_with" | "contains" | "between" | "exists" | "not_exists"Yes
filters[].valueobject | object | object | object | objectNo
filters[].value2object | object | object | object | objectNo
match"all" | "any"No"all"
projectionstring[]Noup to 50 items; each matches ^[^\u0000-\u001f]{1,255}$

Response 200

{
  items: {
    [key: string]: {
      S?: string
      N?: string
      B?: string
      BOOL?: boolean
      NULL?: true
      M?: {
        [key: string]: {
          S?: string
          N?: string
          B?: string
          BOOL?: boolean
          NULL?: true
          M?: object
          L?: {
            S?: string
            N?: string
            B?: string
            BOOL?: boolean
            NULL?: true
            M?: object
            L?: object
            SS?: object
            NS?: object
            BS?: object
          }[]
          SS?: string[]
          NS?: string[]
          BS?: string[]
        }
      }
      L?: {
        S?: string
        N?: string
        B?: string
        BOOL?: boolean
        NULL?: true
        M?: {
          [key: string]: {
            S?: string
            N?: string
            B?: string
            BOOL?: boolean
            NULL?: true
            M?: object
            L?: object
            SS?: object
            NS?: object
            BS?: object
          }
        }
        L?: object
        SS?: string[]
        NS?: string[]
        BS?: string[]
      }[]
      SS?: string[]
      NS?: string[]
      BS?: string[]
    }
  }[]
  count: number
  scanned: number
  cursor?: string
  consumed?: number
}

Errors

StatusMessage
400No index named ….
400A condition is missing its value.
400Invalid page cursor. Run the request again.
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/query

One page of a query on the table or an index.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredDefaultNotes
indexstringNoup to 255 characters
limitintegerNo251–100
cursorstringNoup to 8,000 characters
filtersobject[]No[]up to 10 items
filters[].attributestringYesmatches ^[^\u0000-\u001f]{1,255}$
filters[].op"=" | "<>" | "<" | "<=" | ">" | ">=" | "begins_with" | "contains" | "between" | "exists" | "not_exists"Yes
filters[].valueobject | object | object | object | objectNo
filters[].value2object | object | object | object | objectNo
match"all" | "any"No"all"
projectionstring[]Noup to 50 items; each matches ^[^\u0000-\u001f]{1,255}$
partitionobject | object | object | object | objectYes
sortobjectNo
sort.op"=" | "<" | "<=" | ">" | ">=" | "begins_with" | "between"Yes
sort.valueobject | object | object | object | objectYes
sort.value2object | object | object | object | objectNo
forwardbooleanNotrue

Response 200

{
  items: {
    [key: string]: {
      S?: string
      N?: string
      B?: string
      BOOL?: boolean
      NULL?: true
      M?: {
        [key: string]: {
          S?: string
          N?: string
          B?: string
          BOOL?: boolean
          NULL?: true
          M?: object
          L?: {
            S?: string
            N?: string
            B?: string
            BOOL?: boolean
            NULL?: true
            M?: object
            L?: object
            SS?: object
            NS?: object
            BS?: object
          }[]
          SS?: string[]
          NS?: string[]
          BS?: string[]
        }
      }
      L?: {
        S?: string
        N?: string
        B?: string
        BOOL?: boolean
        NULL?: true
        M?: {
          [key: string]: {
            S?: string
            N?: string
            B?: string
            BOOL?: boolean
            NULL?: true
            M?: object
            L?: object
            SS?: object
            NS?: object
            BS?: object
          }
        }
        L?: object
        SS?: string[]
        NS?: string[]
        BS?: string[]
      }[]
      SS?: string[]
      NS?: string[]
      BS?: string[]
    }
  }[]
  count: number
  scanned: number
  cursor?: string
  consumed?: number
}

Errors

StatusMessage
400No index named ….
400A condition is missing its value.
400This table or index has no sort key.
400The sort key condition is missing a value.
400begins_with works on string and binary sort keys only.
400Invalid page cursor. Run the request again.
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/items/get

Strongly consistent read of one item by key.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
keyobjectYesvalues: any JSON

Response 200

{
  item: {
    [key: string]: {
      S?: string
      N?: string
      B?: string
      BOOL?: boolean
      NULL?: true
      M?: {
        [key: string]: {
          S?: string
          N?: string
          B?: string
          BOOL?: boolean
          NULL?: true
          M?: object
          L?: {
            S?: string
            N?: string
            B?: string
            BOOL?: boolean
            NULL?: true
            M?: object
            L?: object
            SS?: object
            NS?: object
            BS?: object
          }[]
          SS?: string[]
          NS?: string[]
          BS?: string[]
        }
      }
      L?: {
        S?: string
        N?: string
        B?: string
        BOOL?: boolean
        NULL?: true
        M?: {
          [key: string]: {
            S?: string
            N?: string
            B?: string
            BOOL?: boolean
            NULL?: true
            M?: object
            L?: object
            SS?: object
            NS?: object
            BS?: object
          }
        }
        L?: object
        SS?: string[]
        NS?: string[]
        BS?: string[]
      }[]
      SS?: string[]
      NS?: string[]
      BS?: string[]
    }
  }
}

Errors

StatusMessage
400A key has only ….
404Database not found
404Table not found
404Item not found

Errors from AWS are mapped as in AWS errors.

PUT /v1/orgs/:orgId/databases/:resourceId/items

Writes an item. With originalKey, replaces that item (a key change moves it); with expected, the write fails with 409 if the item changed since it was read.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body (up to 800 KB)

FieldTypeRequiredNotes
itemobjectYesvalues: any JSON
originalobjectNovalues: any JSON

Errors

StatusMessage
400A key has only ….
404Database not found
404Table not found
409An item with this key already exists.
409This item was deleted. Create it again instead.
413The item is larger than DynamoDB's 400 KB limit.

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/items/delete

Deletes items by key.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
keyobjectYesvalues: any JSON

Response 204 with no body.

Errors

StatusMessage
400A key has only ….
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/items/batch-delete

Deletes up to 100 items by key (batched). failed counts deletes DynamoDB kept throttling.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
keysobject[]Yes1–100 items; each values: any JSON

Response 200

{
  deleted: number
  failed: number
}

Errors

StatusMessage
400A key has only ….
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/items/import

Imports up to 100 items (typed DynamoDB JSON). overwrite replaces items with the same key; skip keeps existing ones. Nothing is written if any item is invalid.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body (up to 6 MB)

FieldTypeRequiredDefaultNotes
itemsobject[]Yes1–100 items; each values: any JSON
mode"overwrite" | "skip"No"skip"

Response 200

{
  written: number
  skipped: number
  failed: number
}

Errors

StatusMessage
404Database not found
404Table not found
413Send at most 6 MB of items per request.

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/restore

Restores the table as it was at time (epoch ms; default the latest restorable time) into a new database named name. Needs point-in-time recovery; the new table takes minutes or longer to appear.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
namestringYesmatches ^[a-z0-9][a-z0-9-]{1,38}[a-z0-9]$
timeintegerNo> 0

Response 202

{
  resource: {
    region: string
    type: "repository" | "database" | "bucket"
    name: string
    status?: "error" | "active" | "creating" | "deleting"
    createdAt?: number
    updatedAt?: number
    orgId: string
    resourceId: string
    createdBy: string
    projectId?: string
    location: string
    arn?: string
    physicalName: string
    restoredFrom?: string
    pendingSetup?: boolean
  }
}

Errors

StatusMessage
404Database not found

Errors from AWS are mapped as in AWS errors.

GET /v1/orgs/:orgId/databases/:resourceId/exports

The table's recent full exports to S3.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Response 200

{
  exports: {
    exportArn: string
    status: string
    startedAt?: number
    endedAt?: number
    bucket?: string
    prefix?: string
    itemCount?: number
    sizeBytes?: number
    failure?: string
    manifest?: string
  }[]
}

Errors

StatusMessage
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/exports

Exports the whole table (DynamoDB JSON, gzipped) into one of the organization's buckets under prefix. Needs point-in-time recovery; large tables take a while.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
bucketIdstringYesat least 1 character
prefixstringNoup to 512 characters

Response 202

{
  export: {
    exportArn: string
    status: string
    startedAt?: number
    endedAt?: number
    bucket?: string
    prefix?: string
    itemCount?: number
    sizeBytes?: number
    failure?: string
    manifest?: string
  }
}

Errors

StatusMessage
404Database not found
404Bucket not found
404Table not found
409Turn on point-in-time recovery in Settings to export the whole table.

Errors from AWS are mapped as in AWS errors.

POST /v1/orgs/:orgId/databases/:resourceId/indexes

Adds a global secondary index. The table answers with status UPDATING while DynamoDB backfills the index.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
namestringYesmatches ^[A-Za-z0-9_.-]{3,255}$
partitionKeyobjectYes
partitionKey.namestringYesmatches ^[A-Za-z_][A-Za-z0-9_.-]{0,254}$
partitionKey.type"S" | "N" | "B"Yes
sortKeyobjectNo
sortKey.namestringYesmatches ^[A-Za-z_][A-Za-z0-9_.-]{0,254}$
sortKey.type"S" | "N" | "B"Yes
projectionobjectYes
projection.type"ALL" | "KEYS_ONLY" | "INCLUDE"Yes
projection.attributesstring[]No1–20 items; each matches ^[^\u0000-\u001f]{1,255}$

Response 202

{
  table: {
    partitionKey: {
      name: string
      type: "S" | "N" | "B"
    }
    sortKey?: {
      name: string
      type: "S" | "N" | "B"
    }
    name: string
    status: string
    indexes: {
      partitionKey: {
        name: string
        type: "S" | "N" | "B"
      }
      sortKey?: {
        name: string
        type: "S" | "N" | "B"
      }
      name: string
      kind: "local" | "global"
      projection: {
        type: "ALL" | "KEYS_ONLY" | "INCLUDE"
        attributes?: string[]
      }
      status?: string
      backfilling?: boolean
      itemCount?: number
      sizeBytes?: number
    }[]
    itemCount: number
    sizeBytes: number
    billingMode: string
    tableClass: string
    deletionProtection: boolean
    createdAt?: number
  }
}

Errors

StatusMessage
400List the attributes to include.
400The sort key must differ from the partition key.
400… is already a … key attribute; use that type.
404Database not found
404Table not found
409Indexes can only be added to on-demand tables here.
409An index named … already exists.

Errors from AWS are mapped as in AWS errors.

DELETE /v1/orgs/:orgId/databases/:resourceId/indexes/:indexName

Removes a global secondary index.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.
:indexNameGlobal secondary index name.

Response 202

{
  table: {
    partitionKey: {
      name: string
      type: "S" | "N" | "B"
    }
    sortKey?: {
      name: string
      type: "S" | "N" | "B"
    }
    name: string
    status: string
    indexes: {
      partitionKey: {
        name: string
        type: "S" | "N" | "B"
      }
      sortKey?: {
        name: string
        type: "S" | "N" | "B"
      }
      name: string
      kind: "local" | "global"
      projection: {
        type: "ALL" | "KEYS_ONLY" | "INCLUDE"
        attributes?: string[]
      }
      status?: string
      backfilling?: boolean
      itemCount?: number
      sizeBytes?: number
    }[]
    itemCount: number
    sizeBytes: number
    billingMode: string
    tableClass: string
    deletionProtection: boolean
    createdAt?: number
  }
}

Errors

StatusMessage
404Database not found
404Table not found
404Index not found
409Local indexes can't be removed from a table.

Errors from AWS are mapped as in AWS errors.

GET /v1/orgs/:orgId/databases/:resourceId/metrics

Consumed capacity, throttles and latency from CloudWatch.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.
Query parameterTypeRequiredDefaultNotes
range``No"1h"

Response 200

{
  range: "24h" | "7d" | "1h"
  period: 300 | 3600 | 60
  from: number
  to: number
  series: {
    t: number
    read: number
    write: number
    readThrottles: number
    writeThrottles: number
  }[]
  latency: {
    operations: string[]
    points: {
      [key: string]: null | number
      t: number
    }[]
  }
}

Errors

StatusMessage
404Database not found

Errors from AWS are mapped as in AWS errors.

GET /v1/orgs/:orgId/databases/:resourceId/settings

Time to live, point-in-time recovery, deletion protection, table class and tags.

Auth: user access token or platform agent key · Scope: resources:read

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Response 200

{
  deletionProtection: boolean
  tableClass: string
  ttl: {
    status: "DISABLED" | "ENABLED" | "DISABLING" | "ENABLING"
    attribute?: string
  }
  pitr: {
    status: "DISABLED" | "ENABLED"
    recoveryPeriodDays?: number
    earliest?: number
    latest?: number
  }
  tags: {
    key: string
    value: string
  }[]
}

Errors

StatusMessage
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

PATCH /v1/orgs/:orgId/databases/:resourceId/settings

Time to live, point-in-time recovery, deletion protection and table class.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredNotes
ttlobjectNo
ttl.enabledbooleanYes
ttl.attributestringNomatches ^[^\u0000-\u001f]{1,255}$
pitrbooleanNo
deletionProtectionbooleanNo
tableClass"STANDARD" | "STANDARD_INFREQUENT_ACCESS"No

Also checked: Nothing to change.

Response 200

{
  deletionProtection: boolean
  tableClass: string
  ttl: {
    status: "DISABLED" | "ENABLED" | "DISABLING" | "ENABLING"
    attribute?: string
  }
  pitr: {
    status: "DISABLED" | "ENABLED"
    recoveryPeriodDays?: number
    earliest?: number
    latest?: number
  }
  tags: {
    key: string
    value: string
  }[]
}

Errors

StatusMessage
400Name the attribute that holds the expiry time.
404Database not found
404Table not found
409Time to live isn't enabled.

Errors from AWS are mapped as in AWS errors.

PATCH /v1/orgs/:orgId/databases/:resourceId/tags

Adds, changes or removes the table's own tags. si: tags are the platform's and can't be changed.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Request body

FieldTypeRequiredDefaultNotes
setobjectNo{}keys 1–128 characters, match ^[\p{L}\p{Z}\p{N}_.:/=+\-@]*$; values: string (up to 256 characters, matches ^[\p{L}\p{Z}\p{N}_.:/=+\-@]*$)
removestring[]No[]up to 50 items; each 1–128 characters, matches ^[\p{L}\p{Z}\p{N}_.:/=+\-@]*$

Also checked: Nothing to change.

Response 200

{
  tags: {
    key: string
    value: string
  }[]
}

Errors

StatusMessage
404Database not found
404Table not found

Errors from AWS are mapped as in AWS errors.

DELETE /v1/orgs/:orgId/databases/:resourceId

Deletes the table and its record. Refused while deletion protection is on.

Auth: user access token or platform agent key · Scope: resources:write

Path parameterDescription
:orgIdOrganization id (org_…).
:resourceIdResource id (res_…); for a group's access, the Serverless App Service id (prj_…) or the repository's resource id.

Response 204 with no body.

Errors

StatusMessage
404Database not found
404Table not found
409Turn off deletion protection first.
409Wait for index … to finish …, then try again.

Errors from AWS are mapped as in AWS errors.