Dashier docs
Integrate Dashier with an existing application
Call Dashier REST endpoints from Next.js, React, Vue, Node.js, or Flutter without leaking keys.
Dashier’s API is ordinary JSON over HTTP, so an existing application can keep its own frontend and use Dashier for records and administrative workflows. The critical integration decision is where credentials live: any private API key must remain on a server you control, not in a browser bundle or a mobile app.
Start with the source endpoint
Create the data source and confirm its slug. For a source with slug members, the collection path is /api/v1/members. Configure the GET endpoint policy intentionally, then issue a scoped key or use a deliberately public read endpoint. The collection accepts pagination (page, per_page), search, sort, and filter_{field} query options.
Next.js: fetch in a server component or route
Keep the key in a server-only variable. This example uses a server-side fetch; avoid a NEXT_PUBLIC_ prefix for the key.
const response = await fetch(`${process.env.DASHIER_ORIGIN}/api/v1/members?page=1&per_page=20`, {
headers: { "x-api-key": process.env.DASHIER_API_KEY! },
cache: "no-store",
});
if (!response.ok) throw new Error(`Dashier request failed: ${response.status}`);
const result = await response.json();React in the browser
For browser-only React, call your own backend route, which adds the Dashier key on the server. A directly exposed browser request should use only an endpoint deliberately configured for public access and data that is safe to disclose. Do not paste the project key into React source code.
Vue
Use the same rule as React: call a protected application backend for private data, or call a carefully configured public Dashier endpoint for public data. The response is JSON; handle unsuccessful HTTP responses, empty lists, and loading state. Keep framework state separate from the service credential.
Node.js backend
A Node service can call Dashier directly. Store DASHIER_ORIGIN and DASHIER_API_KEY in server environment configuration, send the key in x-api-key, and check response.ok before parsing a response. Use separate keys for different services where possible, and rotate or revoke keys that no longer need access.
Flutter and other mobile clients
A compiled mobile application cannot keep a shared secret. Route private operations through your application backend. A mobile client may call a public endpoint only when the data and method are intentionally public and the endpoint policy reflects that choice. Never embed a Dashier admin/write key in the mobile package.
Verify the integration
Test the route without credentials, with the intended key, with a key lacking the needed scope, and with an invalid field value. Confirm the right status and JSON response for each. See API generation and Permissions for the available policies and endpoint map.