> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable core integration protection

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Turns on core integration protection for the app. Once it's on, the app's pages can no longer call Base44's built-in integrations, such as sending email or calling a language model, directly. Those calls have to come from the app's backend functions instead. File uploads and signed file URLs keep working as before.

On an app that only invited users or workspace members can open, those signed-in users can still make the calls directly. The protection matters most for an app anyone can open, where anyone could otherwise call the app's integrations.

Check `core_integration_recommendation` in [Get security scan](/api-reference/get-security-scan) first. `compatible` means turning protection on is safe. The call is refused while the app's code, or its published version, still calls a restricted integration directly. It's also refused until the app is published, so [deploy the app](/api-reference/deploy-an-app) first when the recommendation is `publish_required`.

The change applies right away. This endpoint can't turn the protection off.

This is limited to 30 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json post /api/apps/{app_id}/security/scan/core-integrations/protect
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/security/scan/core-integrations/protect:
    post:
      summary: Enable core integration protection
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Turns on core integration protection for the app. Once it's on, the
        app's pages can no longer call Base44's built-in integrations, such as
        sending email or calling a language model, directly. Those calls have to
        come from the app's backend functions instead. File uploads and signed
        file URLs keep working as before.


        On an app that only invited users or workspace members can open, those
        signed-in users can still make the calls directly. The protection
        matters most for an app anyone can open, where anyone could otherwise
        call the app's integrations.


        Check `core_integration_recommendation` in [Get security
        scan](/api-reference/get-security-scan) first. `compatible` means
        turning protection on is safe. The call is refused while the app's code,
        or its published version, still calls a restricted integration directly.
        It's also refused until the app is published, so [deploy the
        app](/api-reference/deploy-an-app) first when the recommendation is
        `publish_required`.


        The change applies right away. This endpoint can't turn the protection
        off.


        This is limited to 30 requests a minute per app for each workspace's
        personal API keys, so every key in a workspace shares one allowance.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: >-
        enable_core_integration_protection_api_apps__app_id__security_scan_core_integrations_protect_post
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      responses:
        '200':
          description: Protection is on.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CoreIntegrationProtectionEnabled'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key. Also returned when protection is
            already on or the app can't use backend functions, with the message
            `Core Integration protection is not available`.
        '404':
          description: App not found.
        '409':
          description: >-
            Turning protection on now would break the app, the app isn't
            published, or a change to who can open it isn't published yet. The
            message is `Core Integration calls must be migrated or published
            before protection is enabled`. It's `App changed while Core
            Integration protection was being enabled` when the app's code
            changed during the call.
        '429':
          description: Too many requests for this app in the last minute.
components:
  schemas:
    CoreIntegrationProtectionEnabled:
      properties:
        protected:
          type: boolean
          title: Protected
          description: Always `true`. The published app now enforces the protection.
          example: true
      type: object
      required:
        - protected
      title: CoreIntegrationProtectionEnabled
      description: Confirms core integration protection is on.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````