DBSync developer docs

DBSync is plain HTTPS and JSON at https://dbsync.biz59.net/v1. Create a project and its collections in the console; the full API reference is at dbsync.biz59.net/api/docs.

1. Keys

KeyWhereWhat it can do
Public dbs_pub_…in your appSign users in by email code. With a user token: read and write that user's rows, read shared collections.
Secret dbs_sec_…your servers onlyAct for any user with X-DBSync-User: <your user id>(bring your own sign-in), write shared collections. Shown once; rotate it in the console.

2. Sign your users in

DBSync emails a 6-digit code from dbsync@email59.com with your project's name. Keep the user token on the device. Sign out with POST /v1/auth/logout. Prefer your own sign-in? Turn email sign-in off in the project settings and call DBSync from your server with the secret key.

POST https://dbsync.biz59.net/v1/auth/code
X-DBSync-Key: dbs_pub_...                 (the project's public key, from the console)
{ "email": "ana@example.com" }
-> { "code_sent": true, "expires_in_seconds": 600 }

POST https://dbsync.biz59.net/v1/auth/verify
X-DBSync-Key: dbs_pub_...
{ "email": "ana@example.com", "code": "123456" }
-> { "user_token": "dbs_user_...", "user_id": "u_...", "expires_at": "..." }   (180 days)

3. Push what changed

Up to 500 rows per call, each up to 64 KB of JSON. id is yours (up to 200 characters). lu is when the row changed on the device: the server keeps the later change and lists the others in skipped. A deleted row stays deleted. Set "encrypted": true if you encrypt on the device.

POST https://dbsync.biz59.net/v1/notes/push
X-DBSync-Key: dbs_pub_...
Authorization: Bearer dbs_user_...
{ "rows": [
  { "id": "n1", "data": { "title": "Milk", "done": false }, "lu": "2026-10-08T10:00:00Z" },
  { "id": "n0", "deleted": true, "lu": "2026-10-08T10:05:00Z" }
] }
-> { "applied": ["n1", "n0"], "skipped": [], "server_time": "..." }

4. Pull what's new

Keep the cursor and send it next time; keep pulling while has_more is true. Changes from the last second wait for the next pull, so a slow write never slips behind your cursor.

POST https://dbsync.biz59.net/v1/notes/pull
(same headers)
{ "cursor": null, "limit": 500 }
-> { "rows": [ { "id": "n1", "data": {...}, "lu": "...", "deleted": false, "encrypted": false } ],
     "cursor": "2026-10-08T10:00:01.123456+00:00|n1", "has_more": false }

5. From your server

curl -X POST https://dbsync.biz59.net/v1/notes/push \
  -H "X-DBSync-Key: dbs_sec_..." -H "X-DBSync-User: crm-42" \
  -H "Content-Type: application/json" \
  -d '{"rows":[{"id":"n1","data":{"title":"Imported"},"lu":"2026-10-08T12:00:00Z"}]}'

Without X-DBSync-User, the secret key works only on shared collections.

6. Other calls

GET /v1/methe signed-in user, the project's collections and whether it's writable
POST /v1/account/deletedeletes everything this user synced and signs them out (for your delete-account button)

7. Limits

FreePro ($5 a month, prepaid)
Projects315
Collections per project975
Synced data (per account)75 MB3 GB
App users per project30030,000
Sign-in emails a month60015,000

When Pro ends, data stays readable; your first 3 projects keep syncing within the free limits and the others become read-only.

8. Errors

JSON { "detail": "code: words" }. 400 bad input · 401 wrong key or sign in again · 402 plan limit · 403 not allowed (a shared collection from an app, or email sign-in is off) · 404 unknown collection · 413 row too big · 429 slow down · 507 storage full.

About DBSync · Terms · Privacy