> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get app API reference

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns a reference for the app's own API, the one its code and other systems use to work with its data. It covers:
- Each entity's endpoints to list, read, create, update, and delete records
- The app's users
- Its backend functions
- Its agents

The reference is built from the app as it is now, so it can include entities and functions that haven't been published yet. Server addresses use the app's `base44.app` address, even when it also has a custom domain.

This is limited to 30 requests a minute per caller for each app. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json get /api/apps/{app_id}/openapi-spec
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/openapi-spec:
    get:
      summary: Get app API reference
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Returns a reference for the app's own API, the one its code and other
        systems use to work with its data. It covers:

        - Each entity's endpoints to list, read, create, update, and delete
        records

        - The app's users

        - Its backend functions

        - Its agents


        The reference is built from the app as it is now, so it can include
        entities and functions that haven't been published yet. Server addresses
        use the app's `base44.app` address, even when it also has a custom
        domain.


        This is limited to 30 requests a minute per caller for each app. Some
        workspaces have a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: get_openapi_spec_api_apps__app_id__openapi_spec_get
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      responses:
        '200':
          description: The app's API reference, as an OpenAPI 3.0.3 document.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AppOpenApiSpec'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: >-
            You don't have editor access to this app, your API key is read-only,
            or you used a workspace API key.
        '404':
          description: App not found.
        '429':
          description: >-
            Too many API reference requests for this app from you in the last
            minute.
components:
  schemas:
    AppOpenApiSpec:
      properties:
        openapi:
          type: string
          title: Openapi
          description: OpenAPI version of the document.
          example: 3.0.3
        info:
          additionalProperties: true
          type: object
          title: Info
          description: >-
            Title and description of the app's API. The title is the app's name
            followed by `API`.
          example:
            title: Nordwind Furniture API
            version: 1.0.0
        servers:
          items:
            additionalProperties: true
            type: object
          type: array
          title: Servers
          description: The app's API address, built from its slug.
          example:
            - description: API server
              url: https://my-crm-3c45a1f2.base44.app/api
        paths:
          additionalProperties: true
          type: object
          title: Paths
          description: >-
            One entry per endpoint of the app's entities, backend functions, and
            agents.
          example:
            /entities/Task:
              get:
                summary: List Task records
        components:
          additionalProperties: true
          type: object
          title: Components
          description: >-
            A schema for each entity, and the `api_key` header the app's API
            authenticates with.
          example:
            schemas:
              Task:
                type: object
      type: object
      required:
        - openapi
        - info
        - servers
        - paths
        - components
      title: AppOpenApiSpec
      description: An OpenAPI 3.0.3 document describing the app's own API.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````