Skip to main content

Choose how you build

TaruviBase gives your app data tables, sign-in, access policies, storage, functions, secrets, and analytics. Your code reaches them through an SDK, the Refine integration, or plain HTTP requests. Pick the one that fits where your code runs; they all talk to the same API.

Compare the options#

JavaScript SDKPython SDKRefine providers
Package@taruvi/sdktaruvi@taruvi/refine-providers
Runs inBrowser, Node.js, React NativePython 3.10–3.13React with Refine 5
Usual credentialThe signed-in user's sessionAn API keyThe signed-in user's session
StyleImmutable query builders and service classesSync or async client with modulesRefine data, auth, and access-control providers

For Next.js, React, Vue, React Native, Node.js, and Python project setup, see the framework guides.

What every client needs#

Every client needs the same three values. Find them in TaruviBase Console under your app's Settings → Connect:

ValueWhat it is
TARUVI_SITE_URLYour site's HTTPS address. Every request goes here.
TARUVI_APP_SLUGThe app's identifier. It appears in most API paths.
A credentialWho the request acts as. See the next section.

Pick a credential#

The credential decides which user TaruviBase treats as the caller, and so which roles and access policies apply.

  • In a browser or mobile app, use the signed-in user's session. Users sign in on TaruviBase's hosted page, and the JavaScript SDK sends the session as X-Session-Token.
  • On your server, for a signed-in user, use that user's session token. Forward it from your frontend and pass it to the SDK client.
  • On your server, for a job or service, use an API key, which acts as the user who created it: api_key= in the Python SDK, or authMode: 'apiKey' in the JavaScript SDK.
  • Inside a TaruviBase function, use the client TaruviBase passes in: def main(params, user_data, sdk_client).
Keep API keys on the server

Anyone holding an API key acts as the organization member who created it, with organization access that skips app roles and row policies. Use keys only for trusted server jobs, and never ship TARUVI_API_KEY in browser or mobile code or in a public build variable such as VITE_* or NEXT_PUBLIC_*.

Call the API directly#

Call TaruviBase over HTTP from any language. Send requests to your site address, TARUVI_SITE_URL, with an Authorization: Api-Key TARUVI_API_KEY header for server-side calls. Product guides include REST examples where one exists for the task. See API request lifecycle for the response format and error handling.

New to TaruviBase?#

Follow Create your first task to create a tasks table and store a record with JavaScript or Python.

Add a capability#

Deploy your app#

Deploy with GitHub Actions to publish your frontend and backend configuration on every merge.