Skip to main content
Platform features need a Cordango workspace. You can sign up here and create one in a few minutes. The open foundation, meaning the CLI, the compiler and the standalone generator, needs no account and is available to everyone.
Every app that has been built exposes a generic, manifest-driven REST facade. It’s the same surface the Cordango frontend uses, so anything the product can do to a record, you can do over HTTP.

Base URL

{handle} is the app’s handle, not its id. A GUID also resolves, so older links keep working, but the handle is the address to write down. There’s no single shared api.cordango.com. A Cordango instance is your workspace, on your subdomain, or on a host you run yourself.

What’s on it

The app has to have been built. These routes are driven by the manifest, so without one there’s nothing to drive them.
GET /api/app/{handle}/openapi.json is generated from your own app’s manifest, so it lists your entities and your fields rather than a generic shape. Point a client generator at that rather than transcribing this page. It is trimmed to your permissions and names the server it came from, so a generated client is pointed at the right origin and cannot be built around a field you may not read.

Errors

Every error carries a stable machine-readable code beside a message rendered in the request’s language. Branch on code, show error.
Where an operation can fail several ways at once, the body also carries codes and errors arrays, and the first entry is repeated under code and error.

Status codes

no relationship
You have no relationship to this app at all. It answers the same way a genuinely missing app does, on purpose: whether an app exists isn’t something an unrelated caller gets to learn.
the role denies it
You have a relationship, and the roles it grants don’t permit this operation.
Read responses drop fields your role may not read. Writes that touch fields your role may not set are rejected rather than silently ignored.