A dataset in, a priced API out.
Drop a file; we code, host, back up and serve the endpoints. You set the price and keep all of it.
Your API backlog is a Postgres table.
Register it once as type pg. Every table, view and materialized view is served as REST routes and as MCP tools.
Every role, decided on the table. Every call, on the record. The rows stay in your Postgres; nothing is copied out of it.
Minimal Core is in beta. Licences are set up with you in a session, or email us. What Minimal Core is.
Acme on Postgres
employee table, read and refused.A Postgres database registered as acme under the project people. Both requests are lifted from the Book of Minimal and run as printed against a deployment.
GET /minimal/api/rest/auto/v1/acme/people/pg/acme/employee?fc=id,full_name,department_id&oy=id.as&ps=5&pg=0 HTTP/1.1
Host: api.acme.example
LB-Access-Token: <your-access-token>[
{ "id": 1, "full_name": "Rafael Delacroix", "department_id": 11 },
{ "id": 2, "full_name": "Rafael Müller", "department_id": 7 },
{ "id": 3, "full_name": "Rafael Novak", "department_id": 8 },
{ "id": 4, "full_name": "Kwame Haddad", "department_id": 6 },
{ "id": 5, "full_name": "Rafael Haddad", "department_id": 6 }
]DELETE /minimal/api/rest/auto/v1/acme/people/pg/acme/employee?id=eq.5 HTTP/1.1
Host: api.acme.example
LB-Access-Token: <token · roles hr-analyst · key_type -r-->{
"code": 403,
"status": "Forbidden",
"message": "insufficient permissions for this operation on this table, got [hr-analyst]"
}The table is the last segment of the path. fc picks columns, oy orders, ps and pg page. The refusal names the roles the caller held; a read-only token could not have deleted the row whatever its role. Vol. I, Chapter 5 is the full query language; Chapter 6 covers the three gates.
What differs
The code is pg
pg is the path segment and the MCP type argument. The registration surface spells it postgres under the field db_type. The two never mix on one request.
Writes are transactional
A multi-row insert lands in one transaction: send ten rows and either all ten insert or none do. A PUT or DELETE that matches many rows runs as one statement, atomic the same way. Schema statements are transactional on Postgres only.
Views are read like tables
A view or a materialized view is read through the same route; the join, if there is one, was built into the view when the database was set up. Acme’s schema lists v_employee_directory and mv_headcount_by_department beside its tables.
Defaults stay with the database
department.id fills itself from the database and is still not-null, so an insert sends "id": null to let the default run. Leaving the key out is refused as a missing required field.
The boundary
The Auto API reads and writes one table per call: no joins, no subqueries, no aggregate functions. A join belongs in a view, or in a Custom API definition. Minimal Core does not issue your users’ credentials and does not connect your third-party services; both stay where they already are.
Also: MySQL and MariaDB · ClickHouse · All of Minimal Core · Pricing
Put it in front of a Postgres database.
Next on the shelf
Drop a file; we code, host, back up and serve the endpoints. You set the price and keep all of it.
Fill in a form and an agent runs the job over your own database, under an identity you scope.
The Minimal Core agent skill: session rule, discovery order, headers and refusals.