WRONGNOTEBOOK PRODUCT / PERSONAL BAAS
A real backend. For your next idea.
Store JSON, add structure when you need it, and connect your apps with scoped API keys. One workspace for your side projects and small teams.
Start schemaless. Keep access scoped. Build at your own pace.
Request
curl -X POST "$API/v1/workspaces/$WORKSPACE/collections/todos/records" \ -H "Authorization: Bearer $PB_API_KEY" \ -H "Content-Type: application/json" \ -d '{"data":{"title":"Ship the dashboard preview","done":false}}'Response201 Created
{ "data": { "id": "0192f0b2-7c1e-7a3b-8f4d-2e5a9c1b6d40", "data": { "title": "Ship the dashboard preview", "done": false }, "version": 1, "createdAt": "2026-10-10T09:14:02.000Z" }}Request
curl -G "$API/v1/workspaces/$WORKSPACE/collections/todos/records" \ -H "Authorization: Bearer $PB_API_KEY" \ --data-urlencode 'filter=data.done == false' \ --data-urlencode 'limit=1'Response200 OK
{ "data": [ { "id": "0192f0b2-7c1e-7a3b-8f4d-2e5a9c1b6d40", "data": { "title": "Ship the dashboard preview", "done": false }, "version": 1 } ], "pagination": { "nextCursor": "eyJz…", "hasMore": true }}Delivered to your server
POST https://yourapp.com/hooks/baascontent-type: application/jsonx-baas-event: record.createdx-baas-delivery: 9f3c1a7e-…x-baas-timestamp: 1791406000x-baas-signature: v1=5d41402a…Bodyrecord.created
{ "id": "0192f0b4-1a5c-7d70-b3e8-6f2a0c9d4e51", "type": "record.created", "createdAt": "2026-10-10T09:14:02.000Z", "data": { "record": { "id": "0192f0b2-7c1e-7a3b-8f4d-2e5a9c1b6d40", "data": { "title": "Ship the dashboard preview", "done": false } } }}Verify v1= + hex(HMAC-SHA256(secret, timestamp + "." + rawBody)), reject timestamps more than five minutes old, then reply with any 2xx.
Illustrative examples with trimmed responses. Set $API to your deployment’s address, $WORKSPACE to your workspace id and $PB_API_KEY to an API key.
01 / FLEXIBLE DATA
Start with any JSON. Add structure when it earns its place.
A new collection accepts any JSON value, so you can build first and decide on a data model later. When the shape settles, publish a JSON Schema version and the API validates every write against it.
- Build a schema in the field builder, or edit the raw JSON Schema.
- Versions are append-only, each with optional migration notes.
- Activation checks your existing records first and stops if any would become invalid. Roll back to an earlier version at any time.
02 / COLLECTIONS
Query your data without writing a query layer.
Filter on any field with a small expression language, sort, search text, and page through large collections with cursors. Add JSON path indexes for the fields you query most.
- Import records from JSON or NDJSON. Dry-run first, and choose all-or-nothing or partial.
- Export any collection to JSON, NDJSON or CSV whenever you want.
- Duplicate a collection, or archive it. Archived collections can be restored.
03 / ACCESS CONTROL
Give every person and app exactly the access they need.
Issue API keys with explicit scopes such as records:read. Keys are shown once, stored as HMAC hashes and capped by your own access, so a key can never do more than the person who created it.
- Invite people to a workspace (owner, admin, member or viewer) or to a single collection (admin, editor or viewer).
- Invitations are tied to an email address and expire.
- Service accounts keep integrations off anyone’s personal credentials.
04 / CONNECTED TOOLS
Know what happened, and tell your other tools.
Signed webhooks notify your services when records, collections or schemas change. Every delivery is logged and retried with backoff. The audit log records important actions, and the usage page charts API requests and records written.
- Subscribe to specific events like
record.created, or to all of them. - Verify each delivery’s HMAC signature and timestamp before you trust it.
- Delivery is at-least-once, so de-duplicate on the delivery id.
From an idea to your first API call
Create a collection, save your first record, then add structure and access as your project grows.
- 01
Sign up and add a collection
Your personal workspace is created when you sign up. Add a collection, choose who can see it and start saving JSON straight away. No schema required.
- 02
Shape your data when you are ready
Add fields in the schema builder or paste a JSON Schema. Activate a version and every write is validated.
- 03
Issue a key and call your API
Create an API key with only the scopes your app needs, then read and write records over HTTP.
A backend for the projects you actually ship
If your data fits in collections of JSON documents, Personal BaaS can sit behind it.
To-do and habit trackers
Store tasks as JSON, filter by status and let a web or mobile client talk to a single API.
Bookmarks and read-later apps
Keep links, tags and notes in one collection and index the fields you search by.
Prototypes and hackathons
Skip the server setup. Start schemaless, then tighten the schema once the idea sticks.
Internal tools and admin panels
Give teammates viewer or editor access and keep an audit log of what changed.
Static sites and Jamstack apps
Read content at build time with a read-only key, or accept submissions with a create-only key.
Automations and integrations
Connect your data to other tools with service accounts and signed webhooks.
What is in every workspace
One place for your data, your keys, your people and your history.
- Collections
- Schemaless or schema-backed, with private, workspace, public read-only or unlisted visibility.
- JSON Schema
- Append-only versions, a field builder, dry-run validation and migration notes.
- Records
- JSON documents with filters, sorting, search and cursor pagination, plus history and restore.
- Indexes
- JSON path indexes for the fields you filter on, built in the background.
- Files
- Upload files to a collection and attach them to records.
- Import and export
- Import JSON or NDJSON with a dry run. Export to JSON, NDJSON or CSV.
- API keys
- Explicit scopes, optional expiry, rotation, shown once and stored as HMAC hashes.
- Service accounts
- Machine principals for integrations and automations.
- Members and roles
- Workspace and collection roles, with invitations by email.
- Webhooks
- Per-webhook secrets, retries with backoff, delivery logs and outbound URL checks that block private networks.
- Audit log
- A timestamped record of important actions.
- Usage
- API requests, records written and stored data over a date range.
Questions people ask before they build
Short answers about schemas, keys, teams and data.
What is a backend as a service (BaaS)?
A backend as a service gives your app the server-side pieces it needs, such as a database, an API, access control and webhooks, without building them yourself. Personal BaaS focuses on those pieces for side projects, prototypes and small teams.
What is Personal BaaS best for?
It suits side projects, prototypes, internal tools and small apps that need to store JSON, share it safely with a few people and expose it over an HTTP API. If you can describe your data as collections of JSON documents, you can start straight away.
Do I have to define a schema before I store data?
No. A new collection accepts any JSON. Add a JSON Schema version when your data needs structure. Before a version is activated, your existing records are checked and activation is refused if any would become invalid, unless you explicitly allow it. Activating a version does not rewrite existing records; each is validated against it on its next write.
How do API keys work?
Each key carries explicit scopes such as records:read or collections:read, so an app only gets the access it needs. Keys are shown once when you create them, stored as HMAC hashes and capped by your own access, which means a key can never do more than the person who made it. Keys can have an expiry date and can be rotated or revoked.
Can teammates or other apps get access?
Yes. Invite people to a workspace as an owner, admin, member or viewer, or to a single collection as an admin, editor or viewer. Invitations are tied to an email address and expire. For integrations and automations, create a service account so they never rely on a person’s credentials.
Can I import and export my data?
You can export any collection as JSON, NDJSON or CSV. To import, send a JSON array of records or NDJSON. Imports are all-or-nothing by default, so a failed import does not leave half your records behind, or you can choose partial mode. You can also dry-run an import first.
How do webhooks work?
Create a webhook with a target URL and the events you care about, such as record.created and record.updated. Each webhook is signed with its own secret so your server can verify the sender, failed deliveries are retried with backoff, and endpoints are checked against SSRF protections so they cannot point at private networks.
Is there a record of what happens in my workspace?
Yes. The audit log records actions such as api_key.created and collection.created with a timestamp, and the usage page tracks API requests, records written and stored data for a date range.
What happens if I delete something by mistake?
Archiving a collection moves it to the trash and can be reversed, and deleted records can be restored too. Permanently deleting a collection is separate, requires explicit confirmation, and cannot be undone.
Can I store files?
Yes. Upload files to a collection and attach them to records. Storage availability and limits depend on your deployment.
Your next project starts here.
Create a workspace, save your first record, and build from there.