TspoonBase Agent Skill
This skill helps you build, deploy, and manage backends with TspoonBase — a TypeScript BaaS with SQLite, auth, realtime, file storage, AI tools, and vector search.
Quick Start
npm install -g tspoonbase
mkdir my-app && cd my-app
tspoonbase serve --dev --port 8090
This starts a full backend at http://localhost:8090 with REST API, Admin UI at /_/, and WebSocket realtime.
CLI Commands
| Command |
Description |
tspoonbase serve |
Start the server (--port, --dir, --dev) |
tspoonbase superuser-create <email> <password> |
Create admin account |
tspoonbase migrate up |
Run pending migrations |
tspoonbase migrate down [count] |
Rollback migrations |
tspoonbase migrate status |
Show migration status |
tspoonbase migrate create <name> |
Create a new migration file |
Key Features
Authentication
- Email/password auth via
/api/collections/:collection/auth-with-password
- OAuth2 (GitHub, Google, Discord, Facebook) via
/api/collections/:collection/auth-with-oauth2
- OTP (one-time password) via
/api/collections/:collection/auth-with-otp
- MFA/TOTP setup and verification
- JWT tokens with refresh, impersonation, and revocation
- Password reset, email verification, email change flows
Collections & Records
- Base, Auth, and View collection types
- 14 field types: text, number, email, url, bool, date, select, file, relation, json, editor, autodate, geoPoint, vector
- API rules per operation (list, view, create, update, delete) using
@request.* macro syntax
- Filter syntax:
field = 'value', field ~ 'substring', field > 10, field ?= 'array-element', (field1 = 'a' || field2 = 'b')
- Sort, pagination, field selection, record expansion
- Batch API (
/api/batch) with atomic transactions
File Storage
- Upload via
POST /api/collections/:c/records/:r/files (multipart)
- Serve via
GET /api/collections/:c/records/:r/:filename
- Protected file tokens via
POST /api/files/token
- Thumbnail generation (100x100, 300x300, 500x500) via sharp
- S3 storage driver (configured in Admin UI settings)
Realtime
- WebSocket at
ws://host:port/api/realtime
- SSE (Server-Sent Events) at
GET /api/realtime with Accept: text/event-stream
- Subscribe/unsubscribe to channels via
POST /api/realtime
- Record change events:
collections.{collectionId}.records
AI Tools
- Schema generator: generate collection schemas from natural language
- Rule generator: generate API rules from descriptions
- Data seeder: generate mock data for collections
- Chat assistant: conversational AI for managing your backend
- Supported providers: OpenAI, Anthropic, Ollama
Vector Search
- Cosine similarity via SQL
vector_cosine_similarity() function
POST /api/collections/:c/vector-search with query vector and limit
- Best for semantic search over stored embeddings
Admin UI
- Built React/Vite SPA at
/_/
- Manage collections, records, settings, logs, backups
- AI Assistant panel for schema generation and management
Migrations
- JavaScript migration files in
pb_migrations/
up() and down() functions per migration
- Auto-applied on server start, or manually via CLI
JavaScript Hooks
- Files in
pb_hooks/ with .js extension
- Events:
onBootstrap, onServe, onRecordCreate, onRecordUpdate, onRecordDelete, onCollectionCreate, onCollectionUpdate, onCollectionDelete
- Globals:
$app (settings, db, logger, etc.), console, setTimeout, fetch
- Timeout: 5 seconds per hook
Backups
- Create:
POST /api/backups with optional name
- List:
GET /api/backups
- Upload:
POST /api/backups/upload (multipart zip)
- Restore:
POST /api/backups/:key/restore
- Delete:
DELETE /api/backups/:key
- Includes data.db, auxiliary.db, and storage files
SDK Usage (Client-Side)
import TspoonBase from 'tspoonbase/client'
const pb = new TspoonBase('http://localhost:8090')
// Auth
const auth = await pb.collection('users').authWithPassword('email@example.com', 'password')
// CRUD
const records = await pb.collection('posts').getList(1, 20, { filter: 'status = "published"' })
const record = await pb.collection('posts').create({ title: 'Hello', content: 'World' })
await pb.collection('posts').update(record.id, { title: 'Updated' })
await pb.collection('posts').delete(record.id)
// Realtime (WebSocket)
pb.collection('posts').subscribe('*', (event) => {
console.log('Post changed:', event.action, event.record)
})
// File upload
const formData = new FormData()
formData.append('files', fileInput.files[0])
await pb.collection('posts').update(recordId, formData)
Environment Variables
| Env Var |
Purpose |
JWT_SECRET or TSPOONBASE_JWT_SECRET |
JWT signing secret (min 32 chars) |
TSPOONBASE_ENCRYPTION_KEY |
Encryption salt for settings secrets |
TSPOONBASE_DATA_DIR |
Data directory (default: ./pb_data) |
Deployment
Docker
docker compose up -d
Manual (Node.js 20+)
npm install -g tspoonbase
tspoonbase serve --port 8090 --dir ./pb_data
Programmatic
import { TspoonBase } from 'tspoonbase'
const app = new TspoonBase({ defaultDev: true })
await app.start(8090)
Common API Endpoints
| Method |
Endpoint |
Description |
| GET |
/api/health |
Health check (with DB connectivity) |
| GET |
/api/collections |
List all collections |
| POST |
/api/collections |
Create a collection |
| GET |
/api/collections/:c/records |
List records (with filter, sort, page) |
| POST |
/api/collections/:c/records |
Create a record |
| PATCH |
/api/collections/:c/records/:r |
Update a record |
| DELETE |
/api/collections/:c/records/:r |
Delete a record |
| POST |
/api/collections/:c/auth-with-password |
Auth with email/password |
| POST |
/api/batch |
Batch operations (transactional) |
Architecture
- Express server with middleware: helmet, CORS, rate limiting, auth token loading
- SQLite via better-sqlite3 with WAL mode — dual database design (data.db + auxiliary.db)
- WebSocket realtime via ws library, SSE fallback
- Zod for schema validation on settings and configuration
- Commander for CLI parsing
1---2name: tspoonbase3description: TspoonBase — a TypeScript backend-as-a-service with SQLite, auth, realtime, file storage, AI tools, vector search, and Admin UI. Use when a user wants to build a backend, scaffold a BaaS, add auth/CRUD/realtime to a project, deploy a PocketBase-like backend in TypeScript, or needs help with TspoonBase CLI commands, API usage, or deployment. TRIGGER when: code imports `tspoonbase`; user asks to create, deploy, or manage a backend; user mentions PocketBase, BaaS, SQLite backend, auth backend, realtime backend, or TspoonBase itself; project needs authentication, file uploads, realtime subscriptions, or an admin panel. SKIP: non-TypeScript projects, Go/Python/other language backends, general database questions not involving TspoonBase.4license: Apache-2.05---67# TspoonBase Agent Skill89This skill helps you build, deploy, and manage backends with **TspoonBase** — a TypeScript BaaS with SQLite, auth, realtime, file storage, AI tools, and vector search.1011## Quick Start1213```bash14npm install -g tspoonbase15mkdir my-app && cd my-app16tspoonbase serve --dev --port 809017```1819This starts a full backend at `http://localhost:8090` with REST API, Admin UI at `/_/`, and WebSocket realtime.2021## CLI Commands2223| Command | Description |24|---------|-------------|25| `tspoonbase serve` | Start the server (--port, --dir, --dev) |26| `tspoonbase superuser-create <email> <password>` | Create admin account |27| `tspoonbase migrate up` | Run pending migrations |28| `tspoonbase migrate down [count]` | Rollback migrations |29| `tspoonbase migrate status` | Show migration status |30| `tspoonbase migrate create <name>` | Create a new migration file |3132## Key Features3334### Authentication35- Email/password auth via `/api/collections/:collection/auth-with-password`36- OAuth2 (GitHub, Google, Discord, Facebook) via `/api/collections/:collection/auth-with-oauth2`37- OTP (one-time password) via `/api/collections/:collection/auth-with-otp`38- MFA/TOTP setup and verification39- JWT tokens with refresh, impersonation, and revocation40- Password reset, email verification, email change flows4142### Collections & Records43- Base, Auth, and View collection types44- 14 field types: text, number, email, url, bool, date, select, file, relation, json, editor, autodate, geoPoint, vector45- API rules per operation (list, view, create, update, delete) using `@request.*` macro syntax46- Filter syntax: `field = 'value'`, `field ~ 'substring'`, `field > 10`, `field ?= 'array-element'`, `(field1 = 'a' || field2 = 'b')`47- Sort, pagination, field selection, record expansion48- Batch API (`/api/batch`) with atomic transactions4950### File Storage51- Upload via `POST /api/collections/:c/records/:r/files` (multipart)52- Serve via `GET /api/collections/:c/records/:r/:filename`53- Protected file tokens via `POST /api/files/token`54- Thumbnail generation (100x100, 300x300, 500x500) via sharp55- S3 storage driver (configured in Admin UI settings)5657### Realtime58- WebSocket at `ws://host:port/api/realtime`59- SSE (Server-Sent Events) at `GET /api/realtime` with `Accept: text/event-stream`60- Subscribe/unsubscribe to channels via `POST /api/realtime`61- Record change events: `collections.{collectionId}.records`6263### AI Tools64- Schema generator: generate collection schemas from natural language65- Rule generator: generate API rules from descriptions66- Data seeder: generate mock data for collections67- Chat assistant: conversational AI for managing your backend68- Supported providers: OpenAI, Anthropic, Ollama6970### Vector Search71- Cosine similarity via SQL `vector_cosine_similarity()` function72- `POST /api/collections/:c/vector-search` with query vector and limit73- Best for semantic search over stored embeddings7475### Admin UI76- Built React/Vite SPA at `/_/`77- Manage collections, records, settings, logs, backups78- AI Assistant panel for schema generation and management7980### Migrations81- JavaScript migration files in `pb_migrations/`82- `up()` and `down()` functions per migration83- Auto-applied on server start, or manually via CLI8485### JavaScript Hooks86- Files in `pb_hooks/` with `.js` extension87- Events: `onBootstrap`, `onServe`, `onRecordCreate`, `onRecordUpdate`, `onRecordDelete`, `onCollectionCreate`, `onCollectionUpdate`, `onCollectionDelete`88- Globals: `$app` (settings, db, logger, etc.), console, setTimeout, fetch89- Timeout: 5 seconds per hook9091### Backups92- Create: `POST /api/backups` with optional name93- List: `GET /api/backups`94- Upload: `POST /api/backups/upload` (multipart zip)95- Restore: `POST /api/backups/:key/restore`96- Delete: `DELETE /api/backups/:key`97- Includes data.db, auxiliary.db, and storage files9899## SDK Usage (Client-Side)100101```typescript102import TspoonBase from 'tspoonbase/client'103104const pb = new TspoonBase('http://localhost:8090')105106// Auth107const auth = await pb.collection('users').authWithPassword('email@example.com', 'password')108109// CRUD110const records = await pb.collection('posts').getList(1, 20, { filter: 'status = "published"' })111const record = await pb.collection('posts').create({ title: 'Hello', content: 'World' })112await pb.collection('posts').update(record.id, { title: 'Updated' })113await pb.collection('posts').delete(record.id)114115// Realtime (WebSocket)116pb.collection('posts').subscribe('*', (event) => {117 console.log('Post changed:', event.action, event.record)118})119120// File upload121const formData = new FormData()122formData.append('files', fileInput.files[0])123await pb.collection('posts').update(recordId, formData)124```125126## Environment Variables127128| Env Var | Purpose |129|---------|---------|130| `JWT_SECRET` or `TSPOONBASE_JWT_SECRET` | JWT signing secret (min 32 chars) |131| `TSPOONBASE_ENCRYPTION_KEY` | Encryption salt for settings secrets |132| `TSPOONBASE_DATA_DIR` | Data directory (default: `./pb_data`) |133134## Deployment135136### Docker137```bash138docker compose up -d139```140141### Manual (Node.js 20+)142```bash143npm install -g tspoonbase144tspoonbase serve --port 8090 --dir ./pb_data145```146147### Programmatic148```typescript149import { TspoonBase } from 'tspoonbase'150151const app = new TspoonBase({ defaultDev: true })152await app.start(8090)153```154155## Common API Endpoints156157| Method | Endpoint | Description |158|--------|----------|-------------|159| GET | /api/health | Health check (with DB connectivity) |160| GET | /api/collections | List all collections |161| POST | /api/collections | Create a collection |162| GET | /api/collections/:c/records | List records (with filter, sort, page) |163| POST | /api/collections/:c/records | Create a record |164| PATCH | /api/collections/:c/records/:r | Update a record |165| DELETE | /api/collections/:c/records/:r | Delete a record |166| POST | /api/collections/:c/auth-with-password | Auth with email/password |167| POST | /api/batch | Batch operations (transactional) |168169## Architecture170171- **Express** server with middleware: helmet, CORS, rate limiting, auth token loading172- **SQLite** via better-sqlite3 with WAL mode — dual database design (data.db + auxiliary.db)173- **WebSocket** realtime via ws library, SSE fallback174- **Zod** for schema validation on settings and configuration175- **Commander** for CLI parsing