Dokümantasyon

API Referansı

Tüm HTTP uçları, kimlik, scope’lar ve Node.js örnekleri. İndirilebilir docs.md de mevcut.

docs.md

Base URL

EDGE_BASE = projenin data_plane_url (örn. https://cdn-tr-01.liap.cloud)

Kalıp: {EDGE_BASE}/{service}/{path}

Proje X-Liap-Key (liap_live_…) ile seçilir — path’te UUID yok.

Servisler: auth, db, storage, realtime, functions, search, notifications, monitor, analytics, ai, webhooks, secrets

GET {EDGE}/health — kenar sağlığı (auth yok).

Node.js
const EDGE = process.env.LIAP_EDGE
const API_KEY = process.env.LIAP_API_KEY
const res = await fetch(`${EDGE}/db/tables/todos/rows`, {
  headers: { 'X-Liap-Key': API_KEY },
})

Kimlik doğrulama

İstek: {EDGE}/{service}/… + X-Liap-Key. Proje UUID yazılmaz. JSON’da project_id yok.

API key (liap_live_…) projeyi seçer — kullanıcı oturumu değildir.

Kayıt/giriş/anonymous/refresh: yalnız X-Liap-Key.

/auth/me, MFA, passkey, logout: X-Liap-Key + Authorization: Bearer lca_… birlikte.

401 → POST /auth/refresh ({ refresh_token } + X-Liap-Key). Rotation: eski çift geçersiz.

MethodPathAçıklama
401invalid key / missing scopeYetkisiz
—data:read / data:writedb, search, notifications, analytics
—storage:read / storage:writestorage
—realtime:subscribeSSE / WS / presence / broadcast
—functions:invokefunctions
—notifications:sendPOST /notifications/email — yalnız sunucu anahtarı
—auth:adminmonitor status/crashes, admin
Node.js
fetch(`${EDGE}/db/tables/todos/rows`, {
  headers: { 'X-Liap-Key': API_KEY },
})

Proje API anahtarından çözülür; path’te UUID gerekmez. Dashboard oturumu X-Liap-Project kullanabilir.

Auth

Yanıt: access_token (lca_…), refresh_token (lcr_…), expires_in (900), user — aynı alanlar tokens altında da gelir.

user.id UUID; user.user_metadata (alias metadata) kullanıcı yazabilir; user.app_metadata yalnız admin.

Kayıt: email, password, name?, user_metadata? (alias data/metadata). Kayıt sonrası profiles.id = user.id.

MFA açıksa login 200 + mfa_required + mfa_token → POST /auth/mfa/verify.

MethodPathAçıklama
POST/auth/registerKayıt (+ user_metadata)
POST/auth/loginGiriş (Key)
GET/auth/meMevcut kullanıcı (Key + Bearer lca_)
PATCH/auth/mename + user_metadata (kalıcı)
POST/auth/refreshToken yenile (Key + refresh_token)
POST/auth/logoutÇıkış (Key + Bearer; boş gövde OK)
POST/auth/anonymousAnonim oturum
GET/auth/usersAdmin liste (dashboard)
PATCH/auth/users/{id}Admin: role / metadata / verified
GET/auth/user-fieldsEk alan şeması
PUT/auth/user-fieldsEk alan şeması yaz
GET/auth/rolesProje rol listesi
PUT/auth/rolesRolleri kaydet
POST/auth/mfa/setupTOTP kurulum
POST/auth/mfa/verifyMFA doğrula
POST/auth/passkey/register/beginPasskey begin
GET/auth/oauth/google/startOAuth başlat
POST/auth/recoverŞifre sıfırlama iste
Node.js
const session = await fetch(`${EDGE}/auth/register`, {
  method: 'POST',
  headers: { 'Content-Type': 'application/json', 'X-Liap-Key': API_KEY },
  body: JSON.stringify({
    email: '[email protected]',
    password: 'demo12345',
    name: 'Demo',
    user_metadata: { username: 'demo' },
  }),
}).then(r => r.json())
const token = session.access_token

const me = await fetch(`${EDGE}/auth/me`, {
  headers: { 'X-Liap-Key': API_KEY, Authorization: `Bearer ${token}` },
}).then(r => r.json())

const profiles = await fetch(
  `${EDGE}/db/tables/profiles/rows?filter=id.eq.${session.user.id}`,
  { headers: { 'X-Liap-Key': API_KEY } },
).then(r => r.json())

Database

Document tablolar: id + data JSONB. İlişkisel tablolar: gerçek kolonlar, API'de data olarak sarılır.

GET /db/schema · POST /db/tables. Auth profiles.id = auth user UUID.

Insert/PATCH gövdesi: { "data": { ... } }.

filter=alan.op.değer · select · order · limit/offset.

MethodPathAçıklama
GET/db/schemaŞema grafiği
POST/db/tablesTablo oluştur
GET/db/tablesTablo listesi
GET/db/tables/{t}/rowsSatır listesi
POST/db/tables/{t}/rowsSatır ekle { data }
GET/db/tables/{t}/rows/{id}Tek satır
PATCH/db/tables/{t}/rows/{id}Merge güncelle { data }
DELETE/db/tables/{t}/rows/{id}Sil (204)
GET/db/tables/{t}/rlsRLS oku
PUT/db/tables/{t}/rlsRLS yaz
POST/db/rpcJSON-RPC (db.tables / db.list / …)
POST/db/queryHam SQL
POST/db/graphqlGraphQL (sınırlı şema)
Node.js
const headers = { 'X-Liap-Key': API_KEY, 'Content-Type': 'application/json' }
const created = await fetch(`${EDGE}/db/tables/todos/rows`, {
  method: 'POST',
  headers,
  body: JSON.stringify({ data: { title: 'Merhaba', done: false } }),
}).then(r => r.json())
const rows = await fetch(`${EDGE}/db/tables/todos/rows?filter=done.eq.false&select=title,done`, {
  headers: { 'X-Liap-Key': API_KEY },
}).then(r => r.json())

Storage

Public okuma: GET {EDGE}/storage/objects/{bucket}/{shortId} — auth yok, proje id yok.

Yazma: PUT {EDGE}/storage/objects/{bucket}/{key} + X-Liap-Key, raw body. Yanıt id = public short_id.

Boyut: ?w= & ?h= veya ?g=. Iframe: GET {EDGE}/upload?key=liap_live_…&bucket=…

DELETE bucket 204 (gövde yok).

MethodPathAçıklama
GET/storage/bucketsBucket listesi
POST/storage/bucketsBucket oluştur { name, public }
DELETE/storage/buckets/{bucket}Bucket sil (204)
GET/storage/objects/{bucket}Object listele (?prefix=)
PUT/storage/objects/{bucket}/{key}Yükle (raw body)
GET/storage/objects/{bucket}/{key}İndir (API)
DELETE/storage/objects/{bucket}/{key}Object sil
POST/storage/signed/{bucket}/{key}İmzalı URL
GET/storage/objects/{bucket}/{shortId}Public URL (auth yok)
GET/{shortId}Eski kısa URL
POST/storage/multipartMultipart başlat
GET/uploadUpload iframe (absolute)
Node.js
import { readFileSync } from 'fs'
const up = await fetch(`${EDGE}/storage/objects/data/logo.png`, {
  method: 'PUT',
  headers: { 'X-Liap-Key': API_KEY, 'Content-Type': 'image/png' },
  body: readFileSync('./logo.png'),
}).then(r => r.json())
console.log(`${EDGE}/storage/objects/data/${up.id}`)

Realtime

MethodPathAçıklama
GET/realtime/stream?table=SSE (tablo WAL)
WS/realtime/ws?table=WebSocket
GET/realtime/presence?channel=Presence oku
POST/realtime/presencePresence yaz
POST/realtime/broadcastBroadcast (204)
Node.js
const res = await fetch(`${EDGE}/realtime/stream?table=todos`, {
  headers: { 'X-Liap-Key': API_KEY },
})
// stream res.body …
// WS: wss://{EDGE}/realtime/ws?table=todos  Authorization: Bearer lca_…

Functions

MethodPathAçıklama
GET/functionsListe
POST/functions/{name}Invoke
PUT/functions/{name}Deploy kaynak
DELETE/functions/{name}Sil
GET/functions/runtimeRuntime
POST/functions/jobsArka plan iş
Node.js
const out = await fetch(`${EDGE}/functions/hello`, {
  method: 'POST',
  headers: { 'X-Liap-Key': API_KEY, 'Content-Type': 'application/json' },
  body: JSON.stringify({ a: 1, b: 2 }),
}).then(r => r.json())
console.log(out.result, out.logs)

Bildirimler

Push (Expo, FCM, APNs, Web Push), e-posta (Resend) ve uygulama içi bildirimler. Sağlayıcı anahtarları dashboard → API Bilgileri'nde. Ayrıntılı rehber: /docs/notifications.

API key + Bearer lca_ birlikte gönderildiğinde cihaz kaydı ve gelen kutusu oturumdaki kullanıcıya bağlanır.

MethodPathAçıklama
GET/notificationsKullanıcının bildirimleri (Bearer)
POST/notificationsUygulama içi bildirim oluştur (data:write)
POST/notifications/{id}/readOkundu (Bearer)
POST/notifications/devices{ platform?, token } — expo | fcm | apns | webpush (Bearer veya sunucu + user_id)
GET/notifications/devicesCihaz özeti { total, users, by_platform }
POST/notifications/push{ title, body?, user_id?, tokens?, data?, sound?, badge?, channel_id? } (data:write)
POST/notifications/email{ to, subject, html?, text?, from?, cc?, bcc?, reply_to? } (notifications:send)
GET/notifications/vapid-public-keyWeb Push VAPID public anahtarı
Node.js
// Push — kayıtlı cihazlara (Expo / FCM / APNs / Web Push)
await fetch(`${EDGE}/notifications/push`, {
  method: 'POST',
  headers: { 'X-Liap-Key': SERVER_KEY, 'Content-Type': 'application/json' },
  body: JSON.stringify({ title: 'Siparişin yolda', body: '#1042', user_id: userId, data: { orderId: 1042 } }),
})

// E-posta — projenin Resend anahtarıyla (notifications:send)
await fetch(`${EDGE}/notifications/email`, {
  method: 'POST',
  headers: { 'X-Liap-Key': SERVER_KEY, 'Content-Type': 'application/json' },
  body: JSON.stringify({
    from: 'Destek <[email protected]>',
    to: '[email protected]',
    subject: 'Hoş geldin',
    html: '<h1>Merhaba</h1>',
  }),
})

E-posta hataları: 412 Resend bağlı değil · 400 geçersiz alan / Resend reddi · 429 hız sınırı · 502 Resend'e ulaşılamadı.

Live (canlı log)

Edge'e gelen her istek proje bazında kaydedilir; istek gövdesi ve query string kaydedilmez. Dashboard oturumu veya auth:admin kapsamlı API key gerekir.

Başarılı veri değişiklikleri kind: "change" ve okunur bir label taşır (ör. "API bilgisi güncellendi: RESEND_API_KEY").

Konum Cloudflare ziyaretçi başlıklarından gelir (Managed Transforms → Add visitor location headers).

MethodPathAçıklama
GET/live?since={seq}{ seq, events, stats, edge } anlık görüntü
GET/live/streamSSE: hello · log · stats (2 sn)
GET/public/trafficKimliksiz SSE (hit) — IP/yol yok, konum ~11 km
GET/public/traffic/recent?since={seq}Aynı akışın yoklama sürümü
Node.js
const res = await fetch(`${EDGE}/live/stream`, { headers: { 'X-Liap-Key': ADMIN_KEY } })
const reader = res.body.getReader()
const decoder = new TextDecoder()
for (;;) {
  const { value, done } = await reader.read()
  if (done) break
  process.stdout.write(decoder.decode(value)) // event: log\ndata: {...}
}

Webhook’lar

Olay adları: db.insert / db.update / db.delete (insert/update/delete de kabul).

HTTPS veya http://127.0.0.1 / http://localhost.

MethodPathAçıklama
GET/webhooksListe
POST/webhooksOluştur { url, events }
DELETE/webhooks/{id}Sil (204)
POST/webhooks/dispatchTest gönder
Node.js
await fetch(`${EDGE}/webhooks`, {
  method: 'POST',
  headers: { 'X-Liap-Key': API_KEY, 'Content-Type': 'application/json' },
  body: JSON.stringify({
    url: 'https://example.com/hook',
    events: ['db.insert', 'db.update'],
  }),
})

API Bilgileri / flag

Dashboard'daki API Bilgileri bu servisi kullanır: EXPO_ACCESS_TOKEN, RESEND_API_KEY, RESEND_FROM. Değerler yalnız edge'de saklanır; listede maskelenir (RESEND_FROM gibi gizli olmayan ayarlar açık döner).

MethodPathAçıklama
GET/secretsListe (değerler maskeli)
PUT/secrets/{name}Yaz { value }
DELETE/secrets/{name}Sil (204)
GET/secrets/flagsFlag listesi
PUT/secrets/flags/{key}Flag yaz
DELETE/secrets/flags/{key}Flag sil (204)
Node.js
await fetch(`${EDGE}/secrets/STRIPE_KEY`, {
  method: 'PUT',
  headers: { 'X-Liap-Key': API_KEY, 'Content-Type': 'application/json' },
  body: JSON.stringify({ value: 'sk_live_…' }),
})

Analytics / Monitor

Tarayıcıda POST /analytics/events kullanmayın — uBlock/EasyList keser (HTTP 0 Failed to fetch).

Tarayıcı ve SDK: POST /monitor/events ve GET /monitor/summary (data:write / data:read).

/analytics/events ve /analytics/summary curl alias olarak durur.

GET /monitor/status ve /monitor/crashes → auth:admin.

MethodPathAçıklama
GET/monitor/statusServis sağlığı (auth:admin)
POST/monitor/eventsOlay yaz (önerilen)
GET/monitor/summaryÖzet metrikler (önerilen)
POST/analytics/eventsAlias — reklam engelleyici keser
GET/analytics/summaryAlias özet
POST/monitor/crashesCrash yaz (auth:admin)
GET/monitor/crashesCrash liste (auth:admin)
Node.js
await fetch(`${EDGE}/monitor/events`, {
  method: 'POST',
  headers: { 'Content-Type': 'application/json', 'X-Liap-Key': API_KEY },
  body: JSON.stringify({ name: 'page_view', properties: { path: '/' } }),
})
const summary = await fetch(`${EDGE}/monitor/summary`, {
  headers: { 'X-Liap-Key': API_KEY },
}).then(r => r.json())

Tam örnek: Todo

Node.js
const EDGE = process.env.LIAP_EDGE
const API_KEY = process.env.LIAP_API_KEY
const headers = { 'X-Liap-Key': API_KEY, 'Content-Type': 'application/json' }

const row = await fetch(`${EDGE}/db/tables/todos/rows`, {
  method: 'POST',
  headers,
  body: JSON.stringify({ data: { title: 'Liap ile ilk kayıt', done: false } }),
}).then(r => r.json())

const list = await fetch(`${EDGE}/db/tables/todos/rows?limit=20`, {
  headers: { 'X-Liap-Key': API_KEY },
}).then(r => r.json())

await fetch(`${EDGE}/db/tables/todos/rows/${row.id}`, {
  method: 'PATCH',
  headers,
  body: JSON.stringify({ data: { done: true } }),
})

Ham markdown: /docs.md indir. Kaynak: docs/api-reference.md

Docs · API

Markdown: docs.md indir · Quickstart