Skip to content
← All documentation

Dashier docs

Generated REST API: endpoints and authentication

Use Dashier’s per-source REST routes, API keys, policies, and pagination safely.

Dashier exposes a REST route for each data source. If a source slug is members, the collection path is /api/v1/members. Collection requests list or create records; append a record ID for a single-record read, update, or delete.

Endpoint map

  • GET /api/v1/{slug} lists records. Query options include page, per_page (up to 100), search, sort, dir, and field filters named filter_{field}.
  • POST /api/v1/{slug} creates a record after field validation.
  • GET /api/v1/{slug}/{id} reads one record.
  • PUT /api/v1/{slug}/{id} updates a record after validation.
  • DELETE /api/v1/{slug}/{id} deletes a record.

Collection responses include data, total, page, and per_page. Errors are returned as JSON with an HTTP status. Invalid queries return 400; invalid record values can return 422; authentication and policy failures return authorization-related statuses.

Authenticate requests

The API accepts a project API key in either the x-api-key header or Authorization: Bearer header. Keys have read, write, or admin scopes. The raw key is shown at creation; the server stores a SHA-256 hash. If no key is used, route resolution requires org and project query parameters; a signed-in organization member can also be checked against the project and membership policy.

curl -H "x-api-key: $DASHIER_API_KEY" "$DASHIER_ORIGIN/api/v1/members?page=1&per_page=20"

Store DASHIER_API_KEY in a server-side secret manager or environment variable. Do not put a private key in frontend JavaScript, a public repository, a mobile app, or a shared example. A deliberately public endpoint is different: configure its endpoint policy narrowly and avoid exposing private records.

Configure endpoint policy

Routes can be configured for Public, Authenticated, or Role access, and a route can be disabled or withheld from API exposure. Rate limits apply per key or IP according to policy. Test every HTTP method you plan to use, including a denied case. See Permissions for roles and Integrate with existing apps for framework examples.