JSONPad documentation
JSONPad docs, API, SDK and CLI references, and offline checkers for write rules and flows.
- 0.1.0
- Version
- remote + npm
- Transport
- 14
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 14 tools scanned
- metadata: scanned
- packages: 1 checked
No findings.
Tools (14)
search_docs
Search the JSONPad documentation, the JavaScript SDK references and the command line tool reference. Returns the best-matching sections with a snippet and their jsonpad.io URL; read one with read_doc. Exact identifiers work well: error codes and names, headers, SDK methods, CLI commands, $jsonpad-var variables, "POST /lists/{listId}/items".
read_doc
Read a documentation page as markdown, or one section of it. Give a page slug ("indexing"), a /docs path, a jsonpad.io URL (with or without .md, and with an optional #anchor), "sdk/jsonpad-sdk", "sdk/jsonpad-realtime-sdk", "cli/reference" or "cli/readme". Long pages are cut at a section boundary; read on with the returned nextSection.
list_docs
List the documentation pages by section, with a description of each: the table of contents.
list_api_endpoints
List the REST API endpoints an API token can use, as method, path and title. Get one in full with get_api_endpoint.
get_api_endpoint
The full contract of one REST API endpoint: parameters, headers, request body, responses and examples, and the JavaScript SDK method that calls it. Find it by id (the docs page slug, e.g. "item-restore"), by method and path (templates or concrete paths both work: "/lists/my-list/items/abc"), or by a description.
get_sdk_method
The signature, description and example of a method in the JavaScript SDK (@basementuniverse/jsonpad-sdk) or the realtime SDK, and the REST endpoint it calls. Find it by name ("restoreItem") or by what it does.
get_cli_command
The usage, arguments and options of a jsonpad command line tool (@basementuniverse/jsonpad-cli) command, and whether it works offline. Find it by name ("rules test", "jsonpad sync-schema --dry-run") or by what it does.
lookup_error
What a JSONPad API error code means, its HTTP status, and the guides that explain it. Give the numeric code (10013) or the name (QUOTA_EXCEEDED), as found in an error response's "code" and "name".
get_plan_limits
The limits of each public plan (Free, Indie, Pro, Scale): requests per month and minute, the minimum gap between requests, storage, item size, versions kept, tokens, identities, realtime connections, webhooks and flows. null means unlimited. Sizes are in bytes, rateLimit in milliseconds, prices in GBP.
check_write_rules
Compile a list's write rules with the same engine the API uses, and run their tests (a rules-tests-v1 document). Returns every diagnostic with its line and column, and for each failing test what it expected, what happened, and how each rule came out. Costs nothing and sees no data: lookups find the test document's items. Use it before saving rules.
eval_write_rule
Check one write against a rule set, as the API would, and say whether it would be allowed, denied (403) or failed (400), which statement decided it, and (with trace) what every expression evaluated to. The write is shaped like a rule test case: action, identity, token, old, new, patch, merge, now. Costs nothing and sees no data.
check_flow
Compile a flow document (flows-v1) with the same engine the API uses, and run its tests (flow-tests-v1) against in-memory data. Returns diagnostics (with JSON pointers into the document), what the flow reads and writes, and why each failing test failed. Costs nothing and sees no data.
validate_sync_document
Check a schema sync document (sync-v1) as far as possible without an account: against the JSON schema the API uses, the API's rules for keys and indexes, and every rule set and flow in it with their tests. Documents that reference files (rulesFile, flowFile and their tests) are checked too if the files' contents are given in files. What a sync would change needs the account: the API server's plan_schema_sync, or jsonpad sync-schema --dry-run.
validate_token_permissions
Check an API token's permission rules against the schema the API uses, say which rule shape a broken one was meant to be, and warn about valid rules that probably don't do what was meant (rule order, restore without view, sync-schema alone, allow "*").