CarpoSDK docs

Server SDK

Use Carpo from trusted server code or preserve an incoming user's identity.

The server entry is split around the request trust boundary. Choose a request scoped client when data operations must use the incoming user's Project Auth identity and Database or Storage policies. Choose the trusted server client when server code needs direct libSQL queries or a server key for Storage.

ClientDatabase accessStorage accessAuth identity
createCarpoServerRequestClient()Policy checked Database Data APIPolicy checked Storage APIForwarded incoming identity headers
createCarpoServerClient()Direct libSQL connection when configuredProject API key with storage scope when configuredBetter Auth server client

The request scoped client does not open a direct Turso connection. The trusted client does not automatically apply the browser Data API's per user table policy to direct SQL.

Guides

Keep database tokens and project server keys in server only configuration. Never serialize the trusted client or its credentials into a response sent to the browser.

On this page