The gate: your databases in your software, without Filarr reading them
How an end-to-end encrypted Filarr database can serve an API to your software, through a gate that runs on your side.
On this page
Documentation sections
Filarr encrypts your databases end to end: its servers store blocks they cannot read. For a piece of software (an ERP, a dashboard, a website, an AI assistant) to read a database, something has to decrypt it. That something is the gate (Filarr Gate): a small program you run yourself, to which you open one or more databases, and which serves your software from its copy.
Opening a database to an API is offered on every plan. The plan sets the number of accesses, the number of databases per access, writes (from Solo), live changes (from Solo) and allowed addresses (from Pro): see plans.
How it works
- In Filarr, you open a database to an API (Open a database to an API). Filarr shows you a token, once.
- You give that token to the gate, installed wherever you like: on your computer, on a company server (Docker), on your own Cloudflare account, or right inside your code.
- The gate downloads the encrypted blocks of those databases, decrypts them with keys derived from the token, and keeps the copy in memory. It serves your software at stable addresses (
/v1/clients,/v1/clients/clients-actifs), replays your views with Filarr's engine, accepts read-only SQL, sends signed webhooks and, if you allow it, writes to the database. - When you change a row in Filarr, the gate sees it within about a second (at your plan's polling interval on Free).
Your software never gets the token: each program receives from the gate its own app key, limited to what it needs.
Who sees what
| who | sees | never sees |
|---|---|---|
| Filarr's servers | encrypted blocks, sealed keys they cannot open, counters, the gate's IP address and version | the token, a database key, a row |
| the gate, and whoever runs it | every row and every column of the opened databases | your other databases, notes, files and vaults |
| your software | what its app key allows | the Filarr token |
Reads served by the gate never go through Filarr: they are neither counted nor limited by your plan.
What the gate is not
- A view is not a boundary. The gate reads the whole database you open to it, not only what your views show. To share less, open a database that holds less.
- An offline gate keeps its copy. If you revoke an access, a gate that can no longer reach Filarr keeps what it already copied until it reconnects or someone erases it on its machine.
- Whoever runs the gate reads the databases. Protect the machine as you would protect the data.
Install the gate
The gate's documentation, with step-by-step tutorials and complete examples in curl, JavaScript and Python, lives in its public repository: github.com/filarr-work/filarr-gate. It is published on npm (filarr-gate, @filarr/gate) and as a Docker image (ghcr.io/filarr-work/gate:0.2); the Cloudflare variant deploys from a copy of the repository.