AppBro developer docs
Everything AppBro sets up for your app, and the two small APIs Pro apps call. Sign in at appbro.biz59.net. Full API reference: appbro.biz59.net/api/docs.
1. Store links
| Store field | AppBro URL |
|---|---|
| App Store Connect: Privacy Policy URL · Play Console: Privacy policy | https://<address>/privacy |
| App Store Connect: Support URL | https://<address>/support (contact form to your inbox) |
| App Store Connect: Marketing URL | https://<address>/ |
| Play Console: Delete account URL | https://<address>/delete-account |
| Terms / EULA | https://<address>/terms |
| AdMob app-ads.txt | https://<address>/app-ads.txt (paste it in App details) |
The address is <your-app>.appbro.biz59.net, or your own domain once it's connected. Both keep working.
2. Your own domain
- At your registrar add an A record for the domain (and
wwwif you want it) with the value 138.197.240.239. Remove other A/AAAA records for those names. - In the console, Domain tab, enter the domain and save. When DNS has updated, press "Check DNS again".
- AppBro issues a free Let's Encrypt certificate within a few minutes, and your pages answer at your domain over HTTPS.
3. Pages
Every page is HTML you can edit. For safety, saving removes scripts, iframes, forms, event handlers and javascript: links. The header, footer links and the support / delete-account forms are added for you. Free apps have the five standard pages; Pro adds up to 10 extra pages and keeps every earlier version of each page.
4. Sign-in for your app's users (Pro)
Your app signs users in with osec.one, our sign-in service, using your app's appcode (shown in the console):
POST https://api2.osec.one/auth/request-otp
appcode: https://<your-app>.appbro.biz59.net
{ "email": "user@example.com" }
POST https://api2.osec.one/auth/verify-otp
appcode: https://<your-app>.appbro.biz59.net
{ "email": "user@example.com", "otp": "123456" } -> { "token": "..." }Apple and Google sign-in work through osec.one too. Send the token to AppBro as Authorization: Bearer <token>.
5. Cloud sync (Pro)
Add collections (like expenses, notes) in the console. Each user only ever sees their own rows. A row is a JSON document up to 64 KB with an id you choose and lu, the time the device changed it.
- The later
luwins; older changes come back inskipped. deleted: trueis final: a deleted row can't come back.- Set
encrypted: trueon rows you encrypt on the device; AppBro stores them as they are. - Pull pages by a server cursor, so a device with a wrong clock never misses a change. Keep the last
cursorand send it next time.
POST https://dbsync.biz59.net/expenses/push
X-AppBro-Key: appbro_app_... (from the console, Sign-in and sync tab)
Authorization: Bearer <osec.one token>
Content-Type: application/json
{ "rows": [
{ "id": "e1", "data": { "amount": 12, "note": "Taxi" }, "lu": "2026-10-08T10:00:00Z" },
{ "id": "e2", "deleted": true, "lu": "2026-10-08T10:05:00Z" }
] }
-> { "applied": ["e1", "e2"], "skipped": [], "server_time": "..." }POST https://dbsync.biz59.net/expenses/pull
(same headers)
{ "cursor": null, "limit": 500 }
-> { "rows": [ { "id": "e1", "data": {...}, "lu": "...", "deleted": false, "encrypted": false } ],
"cursor": "2026-10-08T10:00:01.123456+00:00|e1", "has_more": false }Also available at https://appbro.biz59.net/api/sync/<collection>/push. GET /api/sync/me returns the signed-in user and the app's collections; POST /api/sync/account/delete removes everything the user synced (wire it to your in-app "delete my account" button). Storage: 500 MB per Pro account.
6. Content API (Pro)
FAQ entries, what's new notes, announcements and remote config you edit in the console and your app reads as JSON:
GET https://appbro.biz59.net/api/public/apps/<your-app>/content?kind=faq
-> { "app": "tallyho", "items": [ { "kind": "faq", "title": "Does it work offline?", "body": "Yes...", "data": {} } ] }7. API for scripts and bots
Sign in with POST /api/auth and your email (a code arrives), then the same call with the code; or, on Pro, with an API key. Send Authorization: Bearer <session_key> to every /api/apps route.