Skip to content

Security & secrets

How credentials work

Who can call your Tadabase data, with what permissions, when.

Three layers of identity

  • Your account — who can edit the Vibe project.
  • Your bound Tadabase app — the data being read and written.
  • The end user signed into your published Vibe app — whose RLS scope applies to every API call.

RLS at the edge

Every call to /api/* runs server-side with the end user's Tadabase session. The Domain API enforces RLS row-by-row and field-by-field. Sensitive field types like Password are stripped before any response leaves the API.

Ready to build

Skip the docs.
Just describe it.

Tadabase AI builds it, hosts it and keeps it running. Real backend, real domain, real app.

Start Building