https://api.ub.bitbros.inPattern:
https://api.ub.bitbros.in/api/data/:collectionName
Replace :collectionName with the name of your collection (e.g., posts, products, orders).
API keys and write access
Use
sk_live for server-side writes. Use pk_live + RLS + a user JWT to let authenticated frontend users write their own data. See Row-Level Security for details.
Create a document
Endpoint:POST /api/data/:collectionName
By default, write operations require your secret key (sk_live_...). If you enable RLS on the collection, you can also write with a publishable key and a valid user JWT.
When writing with
pk_live and RLS enabled, you can omit the owner field from the body. urBackend will automatically set it to the authenticated user’s ID.Read documents
Read operations use your publishable key (pk_live_...) and never expose your secret key in frontend code.
Fetch all documents
Endpoint:GET /api/data/:collectionName
Fetch a single document
Endpoint:GET /api/data/:collectionName/:id
Query parameters
Use query parameters to filter, sort, and paginate results.Advanced filtering
You can append suffixes to field names in the query string to apply MongoDB comparison operators._regex patterns are capped at 128 characters; invalid or oversized patterns return 400 Bad Request.
Filtering example — published posts, newest first, price strictly greater than 10 and strictly less than 50 (exclusive bounds):
Update a document
PUT replaces specified fields using $set logic — you only send the fields you want to change, not the entire document. Nested field updates are supported using dot notation.
Endpoint: PUT /api/data/:collectionName/:id
Partial update
PATCH works the same way as PUT for partial updates. Use it when you want to update a subset of fields.
Endpoint: PATCH /api/data/:collectionName/:id
Soft delete and trash
When you delete a document usingDELETE /api/data/:collectionName/:id, your backend moves it to the trash instead of removing it immediately.
- Documents enter a 30-day grace period before permanent deletion.
- You can view trashed documents by appending the
include_deleted=truequery parameter to your read or aggregation requests. - A background BullMQ cleanup worker automatically hard-deletes expired documents after 30 days.
Your
databaseUsed quota is only reclaimed after the 30-day period when the cleanup worker permanently deletes the expired documents.Schema validation
If you define a schema for a collection in the dashboard, urBackend enforces it on everyPOST and PUT request. Supported field types include:
- String, Number, Boolean, Date — scalar values
- Object — nested JSON structures
- Array — lists of values
- Ref — references to documents in another collection (stores
_id)
400 Bad Request with a message describing which field failed and why.
