Server SDK
Use Carpo from trusted server code or preserve an incoming user's identity.
The server entry is split around the request trust boundary. Choose a request scoped client when data operations must use the incoming user's Project Auth identity and Database or Storage policies. Choose the trusted server client when server code needs direct libSQL queries or a server key for Storage.
| Client | Database access | Storage access | Auth identity |
|---|---|---|---|
createCarpoServerRequestClient() | Policy checked Database Data API | Policy checked Storage API | Forwarded incoming identity headers |
createCarpoServerClient() | Direct libSQL connection when configured | Project API key with storage scope when configured | Better Auth server client |
The request scoped client does not open a direct Turso connection. The trusted client does not automatically apply the browser Data API's per user table policy to direct SQL.
Guides
Initialize the server client
Connect Auth, the native Database driver, Storage, and Functions.
Request scoped client
Forward the current request identity to policy checked services.
Direct Database access
Run parameterized SQL through the official libSQL driver.
Privileged Storage
Use a server key for Storage operations and usage.
Keep database tokens and project server keys in server only configuration. Never serialize the trusted client or its credentials into a response sent to the browser.