Skip to content

Service role

Full data access for trusted Base44 backend code that skips row-level security entirely, so it has to be handled carefully.

Also called asServiceRole.

Inside a backend function, base44.asServiceRole.entities ignores every access rule you wrote. Scary, and useful.

A real one from my old site: anyone could sign up to the newsletter, but nobody outside could read the subscriber list. Good. Except then how do you stop duplicate sign-ups? The sign-up function used the service role to check the list on the server, without ever opening it to the public.

The rules I stick to:

  • Only in backend functions. It isn't available in the browser, and that's on purpose.
  • Check who's calling before touching anything. That means a signed-in user with the right role, or a verified webhook signature.
  • Validate input yourself, because the access rules aren't there to catch bad data any more.
  • Send back only what the caller needs.

The security scan flags functions anyone can run. On a function that uses the service role, take that warning seriously.