Every document here describes the current release unless stated otherwise. Planned work appears only in the Roadmap; release history is in the changelog. Start with the repository README for an overview.
| Document | Covers |
|---|---|
| HTTP API | Endpoint, transport, request flow, and the Universal JSON Contract |
| Action reference | Every public data action with examples |
| JSON request reference | Exact accepted fields and shapes |
| Response reference | Success and write envelopes, per-action messages |
| Errors and validation | Error envelope, every error code, failure handling |
| Frontend integration | Turning UI state into requests |
| Capability matrix | What each mode supports, side by side |
| Limitations | Intentional boundaries and known gaps |
| Document | Covers |
|---|---|
| JSON Query Mode | Client-composed SELECT, joins, CTEs, windows, set operations |
| Query functions | The complete function allowlist |
| Filtering, sorting, and pagination | Operators, sort rules, and paging across modes |
| Query examples | Worked requests |
| Metadata and routines | Metadata actions and routine calls |
| SQL Resource Mode | Executing server-owned SQL files by ID |
| SQL Resource authoring | Adding and reviewing SQL Resource files |
| Write API | INSERT, UPDATE, DELETE, and UPSERT on any user table |
| SQL Parser | Converting SQL into request JSON |
| Document | Covers |
|---|---|
| Architecture | Components, request flow, and process model |
| Local development | Launchers, bundled runtimes, local troubleshooting |
| Production security and deployment | Production hosting for IIS and Nginx, permissions, secrets, operator checklists |
| Windows Server IIS deployment | Step-by-step Windows installation |
| Database configuration | The database registry, encryption, ODBC, key rotation |
| Upgrading to V3 | V2 → V3 migration, compatibility changes, verification, rollback |
| Admin Console | Pages, availability controls, every Admin API action |
| Authentication and authorization | Modes, sessions, API keys, roles, user management |
| Runtime and performance controls | Timeouts, rate limits, sessions, request and page limits |
| Monitoring and health | Liveness, readiness, detailed health |
| Logging | Operational and audit logs |
| Backup and recovery | Application configuration backups and restore |
| Document | Covers |
|---|---|
| Security model | Current trust boundaries, controls, and accepted risks |
| Security verification | Verification history, findings register, deferred work |
| Penetration-test preparation | Handoff for the outstanding external penetration test |
| Document | Covers |
|---|---|
| AI development guide | Repository boundaries and invariants for maintainers and coding agents |
| Testing | Running the suite, coverage, static checks, deployment validation |
| Contributing | Change expectations and pull requests |
| Roadmap | Current, upcoming, and deferred work |
- Universal JSON Contract: the shared request dispatch (
action) and response envelope. - JSON Query Mode: the backend builds a validated SELECT from client-supplied structure.
- SQL Resource Mode: the client runs a server-owned, read-only SQL file by
ID, optionally with validated
executionmetadata. - Execution metadata: the request's declaration of approved SQL Resource output columns, filter mappings, and default sort; never arbitrary SQL.
- Write API: single-object INSERT, UPDATE, DELETE, or UPSERT on a table named in the request.
- Principal: the authenticated caller (session user, API key, legacy key, or anonymous), whose role permissions decide every authorization.
- Runtime configuration directory: the directory named by
GENERIC_RUNTIME_CONFIG_DIRholding users, roles, API keys, Admin settings, and availability state.