Data API

Create, read, update and delete records of any entity; run saved queries and stored procedures; filter, sort, page and aggregate.

Service
Data service
Base path
https://your-data-host/api/v1
Authentication
Bearer token and context headers. Every call is checked against your role's scope for the entity.

One set of endpoints serves every entity. The entity is named in the request, and the platform applies field rules, access scopes, approval locks, audit and your C# hooks.

Filters

A WhereClause is a list of Filters plus an optional FilterLogic such as 1 AND (2 OR 3), where the numbers are the filters' sequence. Each filter has a FieldName, an Operator and a Value.

OperatorValueOperatorValue
GreaterThan1Contains11
LessThan2NotContains12
EqualTo3StartsWith13
IN4EndsWith15
NOTIN5Between17
IsNULL6NotBetween18
IsNotNULL7ExistsIn21
NotEqualTo8NotExistsIn22
GreaterThanOrEqualTo9LessThanOrEqualTo10

Asynchronous writes

Writes are processed through the platform's message bus. When the result is ready within the wait window the response is 200 OK with the result; otherwise it is 202 Accepted with a CorrelationId. Read the record back, or listen on the real-time hub, to see the outcome.

POST/api/v1/records/insert

Create a record

Creates one record, including child records and lookups, in a single transaction. The platform stamps tenant, app, environment, owner and audit fields.

Authentication
Bearer token and context headers
Permissions
Create scope on the entity (Own, Team or All)

Request body

JSON
{
  "EntityName": "Vendor",
  "Fields": [
    {
      "FieldName": "Name",
      "Value": "Northwind Traders"
    },
    {
      "FieldName": "Country",
      "Value": "India"
    }
  ]
}

Response

  • 200 OK: the created record, in the platform's result envelope.
  • 202 Accepted: a CorrelationId when the write is still being processed.

Error responses

  • Validation errors from required fields, field rules or your C# validation hooks.
  • A permission error when your role's create scope for the entity is None.
  • A conflict error when a unique field already has the value.
  • 401 Unauthorized when the token is missing or expired.

Example request

curl -X POST "https://your-data-host/api/v1/records/insert" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "EntityName": "Vendor",
  "Fields": [
    {
      "FieldName": "Name",
      "Value": "Northwind Traders"
    },
    {
      "FieldName": "Country",
      "Value": "India"
    }
  ]
}'
PUT/api/v1/records/update

Update records that match a filter

Updates the listed fields on every record that matches WhereClause. A request without a where-clause is refused.

Authentication
Bearer token and context headers
Permissions
Update scope on the entity

Request body

JSON
{
  "EntityName": "Vendor",
  "Fields": [
    {
      "FieldName": "Country",
      "Value": "United Kingdom"
    }
  ],
  "WhereClause": {
    "Filters": [
      {
        "FieldName": "Id",
        "Operator": 3,
        "Value": "00000000-0000-0000-0000-000000000000"
      }
    ],
    "FilterLogic": "1"
  }
}

Response

  • 200 OK or 202 Accepted, as for insert.

Error responses

  • An approval-lock error when the record is under approval.
  • A permission error when the record is outside your update scope.

Example request

curl -X PUT "https://your-data-host/api/v1/records/update" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "EntityName": "Vendor",
  "Fields": [
    {
      "FieldName": "Country",
      "Value": "United Kingdom"
    }
  ],
  "WhereClause": {
    "Filters": [
      {
        "FieldName": "Id",
        "Operator": 3,
        "Value": "00000000-0000-0000-0000-000000000000"
      }
    ],
    "FilterLogic": "1"
  }
}'
DELETE/api/v1/records/delete

Delete records that match a filter

When the entity allows soft delete, records are marked deleted and disappear from queries; otherwise they are removed. Relationship rules decide whether children are cascaded or block the delete.

Authentication
Bearer token and context headers
Permissions
Delete scope on the entity

Request body

JSON
{
  "EntityName": "Vendor",
  "WhereClause": {
    "Filters": [
      {
        "FieldName": "Id",
        "Operator": 3,
        "Value": "00000000-0000-0000-0000-000000000000"
      }
    ]
  }
}

Response

  • 200 OK or 202 Accepted.

Example request

curl -X DELETE "https://your-data-host/api/v1/records/delete" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "EntityName": "Vendor",
  "WhereClause": {
    "Filters": [
      {
        "FieldName": "Id",
        "Operator": 3,
        "Value": "00000000-0000-0000-0000-000000000000"
      }
    ]
  }
}'
POST/api/v1/records/bulk-insert

Insert many records at once

Inserts rows in batches (default 1,000). Batches are sized to stay within the database's parameter limit.

Authentication
Bearer token and context headers
Permissions
Create scope on the entity

Request body

JSON
{
  "EntityName": "Vendor",
  "Fields": [
    "Name",
    "Country"
  ],
  "Values": [
    [
      "Northwind Traders",
      "India"
    ],
    [
      "Contoso Supplies",
      "United Kingdom"
    ]
  ],
  "Options": {
    "BatchSize": 1000
  }
}

Response

  • 200 OK with the insert result.

Example request

curl -X POST "https://your-data-host/api/v1/records/bulk-insert" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "EntityName": "Vendor",
  "Fields": [
    "Name",
    "Country"
  ],
  "Values": [
    [
      "Northwind Traders",
      "India"
    ],
    [
      "Contoso Supplies",
      "United Kingdom"
    ]
  ],
  "Options": {
    "BatchSize": 1000
  }
}'
POST/api/v1/queries/select

Run an ad hoc query

Selects fields from an entity with filters, sorting, paging, lookups, child includes, grouping and aggregates. Rows outside your read scope are never returned.

Authentication
Bearer token and context headers
Permissions
Read scope on the entity

Request body

JSON
{
  "EntityName": "Vendor",
  "SelectedFields": [
    "Id",
    "Name",
    "Country"
  ],
  "WhereClause": {
    "Filters": [
      {
        "FieldName": "Country",
        "Operator": 3,
        "Value": "India",
        "Sequence": 1
      }
    ],
    "FilterLogic": "1"
  },
  "Sort": [
    {
      "FieldName": "Name",
      "Direction": 1
    }
  ],
  "Pager": {
    "PageNumber": 1,
    "PageSize": 25
  }
}

Response

  • 200 OK: the matching rows and, when paging, the total count.

Example request

curl -X POST "https://your-data-host/api/v1/queries/select" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "EntityName": "Vendor",
  "SelectedFields": [
    "Id",
    "Name",
    "Country"
  ],
  "WhereClause": {
    "Filters": [
      {
        "FieldName": "Country",
        "Operator": 3,
        "Value": "India",
        "Sequence": 1
      }
    ],
    "FilterLogic": "1"
  },
  "Sort": [
    {
      "FieldName": "Name",
      "Direction": 1
    }
  ],
  "Pager": {
    "PageNumber": 1,
    "PageSize": 25
  }
}'
POST/api/v1/queries/execute/{appObjectName}/{queryName}

Run a saved query by name

Runs a saved query with parameters. You can add paging, sorting and a saved view.

Authentication
Bearer token and context headers
Permissions
Read scope on the entity
NameInRequiredDescription
appObjectNamepathYesEntity name.
queryNamepathYesSaved query name.

Request body

JSON
{
  "Reqtokens": {
    "Country": "India"
  },
  "Pager": {
    "PageNumber": 1,
    "PageSize": 25
  },
  "Sort": [
    {
      "FieldName": "Name",
      "Direction": 1
    }
  ]
}

Response

  • 200 OK: the rows the saved query returns for your scope.

Example request

curl -X POST "https://your-data-host/api/v1/queries/execute/{appObjectName}/{queryName}" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "Reqtokens": {
    "Country": "India"
  },
  "Pager": {
    "PageNumber": 1,
    "PageSize": 25
  },
  "Sort": [
    {
      "FieldName": "Name",
      "Direction": 1
    }
  ]
}'
POST/api/v1/queries/execute/{queryId}

Run a saved query by id

Authentication
Bearer token and context headers
Permissions
Read scope on the entity
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/lists/get

Get dropdown values, paged

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/database/execute

Run a stored procedure or function

Runs a named stored procedure or function in the app's database with bound parameters.

Authentication
Bearer token and context headers
Permissions
An authenticated caller in the app context

Request body

JSON
{
  "ObjectName": "usp_RecalculateVendorScores",
  "ObjectType": 1,
  "Parameters": []
}

Response

  • 200 OK with the procedure's result.

Example request

curl -X POST "https://your-data-host/api/v1/database/execute" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "ObjectName": "usp_RecalculateVendorScores",
  "ObjectType": 1,
  "Parameters": []
}'
GET/api/v1/access

Get your access scopes per entity

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/access/clone-role

Copy one role's access to another

Authentication
Bearer token and context headers
Permissions
Administrator

Request body

JSON
{
  "SourceRoleId": "00000000-0000-0000-0000-000000000000",
  "TargetRoleId": "00000000-0000-0000-0000-000000000000"
}

Response

  • 200 OK when the target role has the source role's access.

Example request

curl -X POST "https://your-data-host/api/v1/access/clone-role" \
  -H "Authorization: Bearer $TAF_TOKEN" \
  -H "TenantId: $TENANT_ID" \
  -H "AppId: $APP_ID" \
  -H "EnvironmentId: $ENVIRONMENT_ID" \
  -H "Content-Type: application/json" \
  -d '{
  "SourceRoleId": "00000000-0000-0000-0000-000000000000",
  "TargetRoleId": "00000000-0000-0000-0000-000000000000"
}'
GET/api/v1/permissions

Get your named permissions

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

WS/hubs/crud-notifications

Real-time hub for write results and record changes

A SignalR hub. Clients receive the result of asynchronous writes and change notifications for registered entities.

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.