Your app's REST API and API docs
In shortIn the Admin tab, APIs turns your app's tables into REST endpoints that other software can call — list, get, create, update or delete records. You choose the table, the fields and who may call it (anyone for reading, or only callers with a project API key), then switch it on with Publish endpoint. When you want to share them, click Publish docs to put up an API reference page and an OpenAPI file for developers.
Sometimes other software needs your app’s data: a partner’s website that lists your products, a spreadsheet that pulls in new orders, a mobile app, an automation tool like Zapier or n8n. They talk to your app through an API — a set of web addresses (endpoints) that answer with data instead of pages. A REST API is the most common kind.
MonstarX makes one for you without code. You pick what to share, and it is live in seconds, with a reference page developers can read.
Where do I find it?
Section titled “Where do I find it?”Open your project, click Admin in the top bar, then APIs in the Admin sidebar. You see Project APIs: at the top, the API reference bar that publishes your API docs; your endpoints on the left, each marked Live or Draft; and API keys below them.
How do I create an endpoint?
Section titled “How do I create an endpoint?”-
In AdminAPIs, click New endpoint (or the + beside Endpoints).
-
Choose the Collection — the table the endpoint works on, like Recipes.
-
Choose the Operation:
Operation Method and address What it does List GET /recipesReturns records, a page at a time. Get GET /recipes/{id}Returns one record by its id. Create POST /recipesAdds a record. Update PATCH /recipes/{id}Changes some fields of a record. Delete DELETE /recipes/{id}Removes a record. -
Give it a Name, a URL path and, if you like, a Description. They appear in the API docs.
-
Under Exposed fields, tick exactly the fields callers may see or send. Anything unticked stays private. Fields that look sensitive, like passwords and tokens, are always left out.
-
Under Access, choose who may call it (see below).
-
Tick Publish endpoint and click Save & publish endpoint. A published endpoint is Live: it answers requests straight away. Leave the box unticked and Save endpoint keeps it as a Draft.
In the list, each endpoint says Live or Draft. The same word shows under Edit endpoint, followed by Unsaved changes until you save. Untick Publish endpoint and save to take it offline without deleting it; Delete removes it.
Who can call my endpoints?
Section titled “Who can call my endpoints?”| Access | Who can call it | Allowed for |
|---|---|---|
| Public read | Anyone with the address. | List and Get only |
| Project API key | Only callers that send one of your project’s API keys. | Every operation |
Endpoints that change data always need a key.
How do I create an API key?
Section titled “How do I create an API key?”-
In AdminAPIs, click API keys.
-
Type a name that says where the key will be used, like “Recipe widget server”, and click Create key.
-
Copy the key straight away — it starts with
mxapi_and cannot be shown again. Store it somewhere safe, like a password manager or the other service’s secrets.
One key opens every key-protected endpoint in the project, so give each service its own key. Click Revoke to switch a key off; anything using it stops working at once.
Callers send the key in the Authorization header: Authorization: Bearer mxapi_….
How do I try an endpoint?
Section titled “How do I try an endpoint?”Open the endpoint and click Test. Enter a Record ID, Bearer key or JSON body if the endpoint needs them and click Send request. You see the status (200 means it worked), how long it took and the answer. For an endpoint that needs a key, paste one of your keys from API keys into Bearer key.
Tests go to the real, live endpoint, so:
- A draft can’t be tested yet. The Test tab says This endpoint is a draft; click Save & publish endpoint there to publish it and test it.
- Save your changes first. With unsaved changes, the Test tab asks you to save before testing, with a Save endpoint button.
A test of Create, Update or Delete changes your real data.
The Code tab has a ready-made cURL command to copy, and the OpenAPI JSON file that API tools like Postman and Insomnia can import.
How do I publish and share my API docs?
Section titled “How do I publish and share my API docs?”Your API docs are an API reference page for developers: every live endpoint, its fields, whether it needs a key, a Try it box and a cURL example. Publishing an endpoint does not publish the docs — you choose when to share them.
-
Publish at least one endpoint, and save any changes. Until then, the API reference bar at the top of AdminAPIs says Unpublished and tells you what is missing.
-
Click Publish docs.
-
The bar now says Published. Click Copy docs link to share the address, or Open API docs under API keys to see the page. The address looks like
https://monstarx.com/api-docs/<your project id>.
The page opens with your project’s name and description, how many endpoints it lists, the project ID and the base address. Anyone with the link can read it, and search engines are told not to index it. It shows only live endpoints and never shows keys. OpenAPI JSON at the top links to the same description as a file.
To take the docs down, click Unpublish docs: the page and its OpenAPI file stop working, while your endpoints keep answering. If you take every endpoint offline, the docs are unpublished too, and you publish them again when you are ready.
What do requests and answers look like?
Section titled “What do requests and answers look like?”Every endpoint lives under https://monstarx.com/api/rest/<your project id>, followed by its path.
curl 'https://monstarx.com/api/rest/<project id>/recipes?page=1&limit=25'{ "data": [ { "id": "41a6…", "title": "Street tacos al pastor", "country_code": "MX" } ], "page": 1, "limit": 25, "hasMore": false}limit is 1 to 100 records per page (25 if you leave it out) and page is 1 to 100. hasMore says whether there is another page.
curl -X POST 'https://monstarx.com/api/rest/<project id>/recipes' \ -H 'Authorization: Bearer YOUR_PROJECT_KEY' \ -H 'Content-Type: application/json' \ -d '{"title": "Lemon ricotta pancakes", "country_code": "IT"}'The answer (status 201) has the new record under data and its id.
curl -X PATCH 'https://monstarx.com/api/rest/<project id>/recipes/RECORD_ID' \ -H 'Authorization: Bearer YOUR_PROJECT_KEY' \ -H 'Content-Type: application/json' \ -d '{"title": "Fluffy lemon ricotta pancakes"}'
curl -X DELETE 'https://monstarx.com/api/rest/<project id>/recipes/RECORD_ID' \ -H 'Authorization: Bearer YOUR_PROJECT_KEY'Update answers with the changed record; Delete answers { "deleted": true }.
Rules for what you send:
- A JSON object with
Content-Type: application/json, up to 64 KB. - Only exposed fields, each a plain value: text (up to 20,000 characters), a number,
true/falseornull. - The id cannot be set or changed, and neither can fields that are read-only in Admin.
When something is wrong, the answer has an error message and a status: 400 (the request is not right), 401 (a valid project API key is needed), 403 (that table or action is not allowed in Admin), 404 (no such endpoint or record), 409 (a conflict, like a duplicate), 413 (the answer would be over 1 MB — expose fewer fields or use a smaller page).
Frequently asked questions
Section titled “Frequently asked questions”Why can I not click Publish docs?
The docs need at least one live endpoint and no unsaved changes. Tick Publish endpoint on an endpoint, click Save & publish endpoint, then Publish docs.
Do I need to publish my app for the API to work?
No. The API reads and writes your project's database directly, so it works as soon as an endpoint is published. It uses the same data as your preview and your live app, and it needs no build, no AI and no credits.
Can a website call my API from the browser?
Yes, any website can call your endpoints. Use Public read endpoints from web pages, and keep key-protected calls on a server so the key stays secret.
I lost an API key. Can I see it again?
No, a key is shown only once. Create a new key, switch the service over to it, then Revoke the old one.
Why can I not publish an endpoint?
For Create, Update or Delete, switch that action on for the table in Admin first. An app whose live database runs on your own Cloudflare account cannot publish endpoints from MonstarX, because the database here holds the preview's practice data.
Can I get webhooks when data changes?
Not from Admin → APIs, which answers requests. Ask MonstarX to add a webhook to your app — for example "when an order is placed, POST it to this address".