DBSync developer docs
DBSync is plain HTTPS and JSON at https://dbsync.biz59.net/v1. Create a project and its collections in the console; the full API reference is at dbsync.biz59.net/api/docs.
1. Keys
| Key | Where | What it can do |
|---|---|---|
Public dbs_pub_… | in your app | Sign users in by email code. With a user token: read and write that user's rows, read shared collections. |
Secret dbs_sec_… | your servers only | Act for any user with X-DBSync-User: <your user id>(bring your own sign-in), write shared collections. Shown once; rotate it in the console. |
2. Sign your users in
DBSync emails a 6-digit code from dbsync@email59.com with your project's name. Keep the user token on the device. Sign out with POST /v1/auth/logout. Prefer your own sign-in? Turn email sign-in off in the project settings and call DBSync from your server with the secret key.
POST https://dbsync.biz59.net/v1/auth/code
X-DBSync-Key: dbs_pub_... (the project's public key, from the console)
{ "email": "ana@example.com" }
-> { "code_sent": true, "expires_in_seconds": 600 }
POST https://dbsync.biz59.net/v1/auth/verify
X-DBSync-Key: dbs_pub_...
{ "email": "ana@example.com", "code": "123456" }
-> { "user_token": "dbs_user_...", "user_id": "u_...", "expires_at": "..." } (180 days)3. Push what changed
Up to 500 rows per call, each up to 64 KB of JSON. id is yours (up to 200 characters). lu is when the row changed on the device: the server keeps the later change and lists the others in skipped. A deleted row stays deleted. Set "encrypted": true if you encrypt on the device.
POST https://dbsync.biz59.net/v1/notes/push
X-DBSync-Key: dbs_pub_...
Authorization: Bearer dbs_user_...
{ "rows": [
{ "id": "n1", "data": { "title": "Milk", "done": false }, "lu": "2026-10-08T10:00:00Z" },
{ "id": "n0", "deleted": true, "lu": "2026-10-08T10:05:00Z" }
] }
-> { "applied": ["n1", "n0"], "skipped": [], "server_time": "..." }4. Pull what's new
Keep the cursor and send it next time; keep pulling while has_more is true. Changes from the last second wait for the next pull, so a slow write never slips behind your cursor.
POST https://dbsync.biz59.net/v1/notes/pull
(same headers)
{ "cursor": null, "limit": 500 }
-> { "rows": [ { "id": "n1", "data": {...}, "lu": "...", "deleted": false, "encrypted": false } ],
"cursor": "2026-10-08T10:00:01.123456+00:00|n1", "has_more": false }5. From your server
curl -X POST https://dbsync.biz59.net/v1/notes/push \
-H "X-DBSync-Key: dbs_sec_..." -H "X-DBSync-User: crm-42" \
-H "Content-Type: application/json" \
-d '{"rows":[{"id":"n1","data":{"title":"Imported"},"lu":"2026-10-08T12:00:00Z"}]}'Without X-DBSync-User, the secret key works only on shared collections.
6. Other calls
GET /v1/me | the signed-in user, the project's collections and whether it's writable |
POST /v1/account/delete | deletes everything this user synced and signs them out (for your delete-account button) |
7. Limits
| Free | Pro ($5 a month, prepaid) | |
|---|---|---|
| Projects | 3 | 15 |
| Collections per project | 9 | 75 |
| Synced data (per account) | 75 MB | 3 GB |
| App users per project | 300 | 30,000 |
| Sign-in emails a month | 600 | 15,000 |
When Pro ends, data stays readable; your first 3 projects keep syncing within the free limits and the others become read-only.
8. Errors
JSON { "detail": "code: words" }. 400 bad input · 401 wrong key or sign in again · 402 plan limit · 403 not allowed (a shared collection from an app, or email sign-in is off) · 404 unknown collection · 413 row too big · 429 slow down · 507 storage full.
About DBSync · Terms · Privacy