Documentation
Everything you need to go from an empty directory to a running backend.
Introduction
Modback is a self-hosted Backend-as-a-Service written in Rust. It gives you a Postgres database, an authentication system, file storage, a GraphQL and REST API, and realtime subscriptions — all from a single deployable service.
The API server listens on 8080 and the admin dashboard
on 3000. If you haven't installed it yet, start with
the install steps on the homepage.
Quick start
Bring the whole stack up, then install the client:
git clone https://github.com/Nuvai/Modback.git
cd Modback
docker-compose up -d
npm install @modback/client
Point a client at the server and you're done:
import { createClient } from '@modback/client'
const modback = createClient({
url: 'http://localhost:8080',
apiKey: process.env.MODBACK_KEY,
})
Database
Modback runs PostgreSQL 16 with JSONB, pgvector and pg_trgm enabled. Every table you create gets an auto-generated REST endpoint, and row-level security is enforced by the database itself — so a misconfigured client cannot read another tenant's rows.
// Insert a row
const { data } = await modback
.from('todos')
.insert({ title: 'Ship it', completed: false })
// Query with filters
const { data } = await modback
.from('todos')
.select('*')
.eq('completed', false)
.limit(10)
Authentication
All of the following ship in the core:
- Email and password, with verification
- Magic link (passwordless) sign-in
- OAuth providers — GitHub, Google, Twitter and others
- Multi-factor authentication over TOTP or SMS
- SAML/SSO for enterprise tenants
- JWT session management
Storage
The storage API is S3-compatible and works against six providers without code changes. Objects support priority-based ACL, native replication, TTL auto-expiration and Redis-backed caching.
await modback.storage
.from('avatars')
.upload('user-1.png', file)
GraphQL
A schema is generated from your database automatically — types,
queries, mutations and subscriptions. An interactive playground is
served at /graphql.
query RecentTodos {
todos(order_by: { created_at: desc }, limit: 5) {
id
title
completed
owner { email }
}
}
Realtime
Subscriptions run over WebSocket with sub-10ms latency, and support database change streams, pub/sub, presence tracking and broadcast channels.
modback.channel('todos')
.on('postgres_changes', { event: '*', table: 'todos' },
payload => console.log(payload))
.subscribe()
REST API
Every table is exposed under /rest/v1/<table>. The
server issues an OpenAPI document, and Swagger UI is served at
/swagger-ui.
curl http://localhost:8080/rest/v1/todos \
-H "apikey: $MODBACK_KEY" \
-H "Content-Type: application/json" \
-d '{"title":"Ship it","completed":false}'
- POST /rest/v1/:table
- Insert rows
- GET /rest/v1/:table
- Select rows, with filters
- PATCH /rest/v1/:table
- Update matching rows
- DELETE /rest/v1/:table
- Delete matching rows