CarpoSDK docs
Database

Database

Read and write table rows through the policy checked Database Data API.

The React Database client calls Carpo's end user Database Data API. A Carpo owner or admin must enable the API and grant operations for each table and environment before app users can query it.

The browser client does not expose raw SQL, joins, or transactions. It sends a narrow set of parameterized table operations to the Worker. The Worker applies the current table schema, access policy, and optional owner scope on every request.

Define row types

Define the row, insert, and update shapes in one shared TypeScript module. These types improve compile time checks, but they are not sent to Carpo or validated at runtime. Keep them aligned with the real database schema.

export type AppDatabase = {
  todos: {
    Row: { id: number; title: string; completed: boolean; user_id: string }
    Insert: { id?: number; title: string; completed?: boolean }
    Update: { title?: string; completed?: boolean }
  }
}

const database = carpo.database.withSchema<AppDatabase>()
const todos = database.from('todos')

table() is an alias for from(). Without withSchema, pass a row type to from<Todo>('todos') or to an individual read method.

Authorization model

Production and Development have separate Data API settings. Permissions are assigned per table and action. For an owner scoped table, the API derives the owner from Project Auth and applies it to reads, inserts, updates, and deletes. An app supplied owner ID is ignored. Updates and deletes must include at least one condition.

See Project setup before debugging a denied request.

Guides

On this page