# MiniUp Public Documentation
Source: https://www.miniup.io/docs/access
Description: Choose Public, Password, Invite-only, or Private access and understand which visitors can open a MiniUp Site.
# Choose Site Access
Site Access determines who can open a MiniUp Site. Choose Public for open content, Password for a shared unlock password, or Invite-only and Private for member-restricted content.
## Compare Site Access modes
| Mode | Who can open the Site | Best use |
| --- | --- | --- |
| Public | Anyone with the URL | Public reports, landing pages, portfolios |
| Password | Visitors who unlock with the shared password | Small-group sharing without individual member roles |
| Invite-only | Accepted invited members | Team portals and invitation-based apps |
| Private | Current members | Content reserved for an existing membership |
Invite-only and Private can require verified membership before protected Site files load. Public keeps the page publicly visible. A password unlock does not give the visitor a named member role for a Site Members Function.
## Change Site Access
1. Open **Dashboard → your Site → Page → Page settings → Access → Manage**.
2. Select the access mode. Owner or Admin access is required to manage Site Access.
3. For Password, configure the password using the password controls and save it.
4. For member access, [invite members and assign roles](https://www.miniup.io/docs/access/members).
5. Test the published URL while signed out and while signed in as the intended member.
## Example: protect a staff dashboard
Choose Invite-only, invite staff as Viewers, and assign Admin only to people who should manage access. Add a [Site Members Function](https://www.miniup.io/docs/functions/site-members) for protected app operations. Do not embed a private dataset into a Public Site and expect a hidden navigation link to protect it.
## Review data access separately
Changing Site Access does not share all datasets or automatically retract a dataset's Public link. Tables and hosted files have their own [dataset access settings](https://www.miniup.io/docs/data/access). Review every dataset the Site uses, including cross-site sharing.
## Related guides
- [Invite members and manage roles](https://www.miniup.io/docs/access/members)
- [Build an authenticated app](https://www.miniup.io/docs/authenticated-apps)
- [Security principles](https://www.miniup.io/docs/security)
---
Source: https://www.miniup.io/docs/access/members
Description: Invite members, choose Owner, Admin, Editor, or Viewer permissions, change roles, and remove access to a MiniUp Site.
# Invite Site Members and Manage Roles
Site members are signed-in people with a role on a MiniUp Site. Owners and Admins manage invitations and membership; the app can also use the member's trusted role inside a Site Members Function.
## Understand Site roles
| Role | Product permissions |
| --- | --- |
| Owner | Owns the Site and manages its content, access, and linked Functions. |
| Admin | Manages Site access and members, and can edit Site content. |
| Editor | Edits Site content and works with permitted data; does not manage membership. |
| Viewer | Views permitted content; cannot edit Site files or apply AI edits. |
The Owner cannot be removed or reassigned through the ordinary member controls. Site Function code and Secrets are managed by the owning account. An app's backend may define more specific business permissions for each role.
## Invite a member
1. Open **Dashboard → your Site → Page → Page settings → Access → Manage** as an Owner or Admin.
2. Enter the member's email address and choose **Viewer**, **Editor**, or **Admin**.
3. Select **Invite**. If MiniUp reports email delivery, the invitation was emailed. Otherwise copy the **Invite link** and share it directly.
4. Ask the recipient to open the invitation and sign in with the intended account to accept it.
5. Check the members list and status after acceptance.
## Resend, revoke, change role, or remove
Use **Resend** in pending invitations to refresh the invitation link or resend email where available. Use **Revoke** to cancel a pending invitation. Revoking a pending invitation is different from removing an already accepted member.
For an existing member, choose a different role in the **Role** selector. Use **Remove** to revoke that membership. The Site owner remains protected from these ordinary changes.
## Example: reduce a contractor's access
Change an Editor to Viewer when editing is no longer needed. Remove the member when they should no longer access a member-only Site. Check your app's protected operations again: a role change should affect backend authorization, not merely hide a button.
## Troubleshoot invitations
Confirm the email address, the signed-in account, and whether the invitation is still pending. Use a fresh invitation if the old link no longer works. If controls are disabled, check your role. On a Public Site, removing membership does not make the public page inaccessible.
## Related guides
- [Choose Site Access](https://www.miniup.io/docs/access)
- [Use env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user)
- [Enforce backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
---
Source: https://www.miniup.io/docs/ai/chatgpt
Description: Connect the MiniUp Plugin / App and publish Sites from HTML, uploaded files, Tables, and approved datasets.
# MiniUp with ChatGPT
## Get started
Open [ChatGPT Plugins](https://chatgpt.com/plugins) and connect MiniUp if it is available to your account. Sign in to MiniUp, review the requested permissions, and select MiniUp in your conversation. Plugins provide discovery; an App is the connected integration. Availability depends on your account and workspace.
For a custom connection, follow OpenAI's current [connection and testing guide](https://developers.openai.com/plugins/deploy/connect-chatgpt) and use `https://www.miniup.io/api/mcp`.
Try “Publish this HTML as a MiniUp Site,” or attach a CSV, spreadsheet, spatial dataset, or HTML project and describe the app you want. MiniUp accepts ChatGPT's authorized file handoff directly. If the attachment is unavailable, share it again through ChatGPT's supported file flow.
For existing data, ask MiniUp to list datasets, inspect the schema and sample, and use an approved Dataset Bundle. For updates, name the existing Site and ask the assistant to read its files first. Multi-file apps keep their HTML, CSS, JavaScript, and assets together.
Function permissions are separate from Site and data permissions. Saved secrets stay in MiniUp. See the [full workflows and examples](https://www.miniup.io/docs/chatgpt) and [AI connection overview](https://www.miniup.io/docs/ai).
## Related guides
- [AI connection overview](https://www.miniup.io/docs/ai)
- [Sites and publishing](https://www.miniup.io/docs/sites)
---
Source: https://www.miniup.io/docs/ai/claude
Description: Connect Claude to your MiniUp account to publish Sites and work with Tables, datasets, and Dataset Bundles.
# MiniUp with Claude
## Get started
Claude connects to the same MiniUp platform as other account-based AI clients.
1. In Claude, open **Customize → Connectors**.
2. Select **+**, then **Add custom connector**.
3. Enter `https://www.miniup.io/api/mcp` as the remote server URL.
4. Connect, sign in to MiniUp, and approve the access you need.
5. Enable the connector in your conversation.
For managed workspaces, an owner may need to add the connector in **Organization settings → Connectors** first. See Anthropic's [current custom connector instructions](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp).
Existing connections using `https://www.miniup.io/api/claude/mcp` keep working. You do not need to recreate them.
Start with “Publish this HTML,” “Show my MiniUp datasets,” or “Build a map from my approved Dataset Bundle.” Ask Claude to inspect your existing Site before editing it. MiniUp supports multi-file HTML, CSS, JavaScript, and assets and returns the exact published URL.
File transfer depends on what Claude makes available to the connector. MiniUp accepts an authorized HTTPS download URL through its general file workflow; a Claude-local attachment identifier alone is not a downloadable file. If transfer is unavailable, upload the dataset to MiniUp, then use its Data Catalog or a Dataset Bundle. Do not paste credentials into a file URL.
Compliant MCP Apps hosts can display MiniUp's shared result UI. The structured result and exact links also work without embedded UI.
## Related guides
- [AI connection overview](https://www.miniup.io/docs/ai)
- [Sites and publishing](https://www.miniup.io/docs/sites)
---
Source: https://www.miniup.io/docs/ai
Description: Build and keep improving real apps with ChatGPT, Claude, another MCP client, or paid x402 agents.
# Connect MiniUp to your AI
## Get started
Start with “Publish this HTML,” an uploaded file, or a dataset you own. Your assistant can publish a Site, inspect its real data, and update the same app later.
| Where you work | Connection | Resources |
| --- | --- | --- |
| [ChatGPT](https://www.miniup.io/docs/ai/chatgpt) | MiniUp Plugin / App | Your approved MiniUp account resources |
| [Claude](https://www.miniup.io/docs/ai/claude) | MiniUp custom connector | Your approved MiniUp account resources |
| [Other MCP clients](https://www.miniup.io/docs/ai/mcp) | MiniUp account connection | Your approved MiniUp account resources |
| [x402 agents](https://www.miniup.io/docs/ai/x402) | Wallet and payment | Resources owned by that wallet |
| [AI Studio](https://www.miniup.io/docs/chatgpt/ai-studio) | Open a Site in MiniUp | The Site you are editing |
Account connections and paid agents are separate. Paying for an operation does not grant access to your personal MiniUp account.
For data apps, ask your assistant to inspect the schema and sample before building. Choose an approved [Dataset Bundle](https://www.miniup.io/docs/data/bundles) when several datasets belong together. Review loading, empty, and error states and check the published URL.
Manage passwords, member invitations, API keys, and saved Function Secrets securely in MiniUp. Never paste them into a conversation.
## Related guides
- [AI connection overview](https://www.miniup.io/docs/ai)
- [Sites and publishing](https://www.miniup.io/docs/sites)
---
Source: https://www.miniup.io/docs/ai/mcp
Description: Connect a standards-based MCP client to your MiniUp account using the canonical endpoint.
# MiniUp with other MCP clients
## Get started
Use `https://www.miniup.io/api/mcp` for account access. MiniUp supports MCP `2026-07-28` and compatible 2025-era clients over Streamable HTTP. Your client discovers the sign-in flow; sign in and approve the requested permissions.
Site publishing, Site management, data reads, data changes, usage, and Function management have separate permission groups. Reconnect when a new operation needs access you have not approved. A client label never changes your permissions.
Discover tools for publishing HTML and multi-file projects, reading and updating Sites, managing Table records, inspecting datasets, using Dataset Bundles, and working with safe Functions. The workflow guide and capability resource help your assistant choose a path. Use the same `requestId` when retrying a Site publication.
Use an authorized HTTPS file URL or supported file content in the general file workflow. A local path or client-local attachment identifier is not remotely accessible. File upload features differ between clients. Hosted MiniUp datasets and bundles are another starting point.
The standard MCP Apps result resource provides a shared UI in supported hosts. Text and structured results are available in every supported client. Manage saved secrets and secret-bound Functions in MiniUp.
For paid wallet-owned work, use the [separate x402 connection](https://www.miniup.io/docs/ai/x402).
## Related guides
- [AI connection overview](https://www.miniup.io/docs/ai)
- [Sites and publishing](https://www.miniup.io/docs/sites)
---
Source: https://www.miniup.io/docs/ai/x402
Description: Discover prices, pay for wallet-owned MiniUp operations, and retry safely through HTTP or MCP.
# MiniUp for paid x402 agents
## Get started
An autonomous agent can create and manage Sites, files, Tables, records, datasets, ArcGIS publications, and approved Dataset Bundles owned by its wallet. This connection does not grant access to a person's MiniUp account.
- [Free API discovery](https://www.miniup.io/api/x402)
- [Current action prices and network](https://www.miniup.io/api/x402/pricing)
- [Machine-readable agent guide](https://www.miniup.io/.well-known/SKILL.md)
- Paid MCP: `https://www.miniup.io/api/x402/mcp`
Use an official x402-compatible HTTP or MCP client. Discover the current currency, network, and price before spending. Set your agent's transaction and total spending limits in its wallet or payment client; MiniUp cannot enforce the client's overall budget.
HTTP paid actions issue a `402` challenge with `PAYMENT-REQUIRED`; the client supplies `PAYMENT-SIGNATURE`. Successful settlement returns `PAYMENT-RESPONSE` and a receipt. Paid MCP uses the official x402 MCP payment metadata and challenge format.
For mutations, send a stable `Idempotency-Key` over HTTP or `requestId` over paid MCP. Reuse the same inputs and signed payment on a retry. A changed request with a reused identity is rejected. If MiniUp reports a pending payment or request, do not send a second payment: retain the transaction hash and request identity for reconciliation.
Free public discovery requires no wallet. Wallet-owned actions priced at zero and allowlisted wallets still require an official, recent Sign-In-With-X signature bound to the exact request URL and network. An address header alone does not prove ownership.
Functions, saved secrets, private credentials, PDF Knowledge Packs, and account member administration are not available to paid agents. Use a MiniUp account and its secure management pages for those workflows.
See [all AI connections](https://www.miniup.io/docs/ai) or the [agent overview](https://www.miniup.io/x402agent).
## Related guides
- [AI connection overview](https://www.miniup.io/docs/ai)
- [Sites and publishing](https://www.miniup.io/docs/sites)
---
Source: https://www.miniup.io/docs/authenticated-apps/authorization
Description: Protect private data and operations in a Site Members Function using trusted roles and record-level checks.
# Enforce Backend Authorization
Frontend controls what users SEE. Backend controls what users MAY DO. Every protected operation must enforce authorization in the Function, regardless of which buttons or JavaScript modules the frontend displays.
## Protect a role-restricted operation
1. Read the trusted identity from `env.MINIUP_USER`.
2. Verify the member's role before loading private data or making a change.
3. Verify any record-specific rule, such as whether a record belongs to that member.
4. Validate the submitted fields independently of the permission check.
5. Return only the fields the authorized caller needs.
```javascript
const user = env.MINIUP_USER;
if (!user) {
return Response.json({ error: "Sign in required" }, { status: 401 });
}
if (user.role !== "owner" && user.role !== "admin") {
return Response.json({ error: "Forbidden" }, { status: 403 });
}
// Perform the administrative operation only after these checks.
```
## Understand why hiding UI is insufficient
A user can call an endpoint directly even if the page hides its Admin button. Loading `admin.js` conditionally is useful for navigation and performance, but it does not protect data. A browser-supplied record owner or role must not override the trusted member identity.
For a “My requests” page, filter records using the trusted `user.id` in the backend. Do not return every user's records to the browser and rely on client-side filtering.
## Protect credentials and persistent data
Keep private records in Tables or private services and access them through a Function with [Secrets](https://www.miniup.io/docs/functions/secrets). Check the underlying Table's own access policy too: protecting a Function does not protect a separate publicly readable Table API.
## Test authorization explicitly
Test the same administrative request as Owner, Admin, Editor, Viewer, and while signed out. Lower-privilege users should receive a denied response without private data or side effects. Retest after changing roles or removing a member.
## Related guides
- [Site Access and members](https://www.miniup.io/docs/access/members)
- [Use env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user)
- [Bootstrap pattern](https://www.miniup.io/docs/authenticated-apps/bootstrap)
- [Table permissions](https://www.miniup.io/docs/tables/permissions)
---
Source: https://www.miniup.io/docs/authenticated-apps/bootstrap
Description: Implement a recommended bootstrap endpoint that returns safe identity, feature flags, and navigation settings to a MiniUp app.
# Bootstrap an Authenticated App
`/bootstrap` is a recommended app design pattern: an endpoint you implement in a Site Members Function to return safe startup information. It is not a required MiniUp route, login endpoint, internal MiniUp API, automatic authorization, or special runtime syntax.
## Implement a bootstrap endpoint
1. Create a Site Members Function linked to your Site.
2. Add a GET handler for a path ending in `/bootstrap`.
3. Read the member from `env.MINIUP_USER` and return safe identity and feature flags.
4. Test and publish the Function.
5. Call the endpoint from the linked Site and use the result to initialize the UI.
```javascript
export default {
async fetch(request, env) {
const url = new URL(request.url);
if (request.method === "GET" && url.pathname.endsWith("/bootstrap")) {
const user = env.MINIUP_USER;
if (!user) return Response.json({ error: "Sign in required" }, { status: 401 });
return Response.json({
user: { id: user.id, name: user.name, role: user.role },
features: {
dashboard: true,
reports: user.role !== "viewer",
administration: user.role === "owner" || user.role === "admin"
}
});
}
return Response.json({ error: "Not found" }, { status: 404 });
}
};
```
The example returns a subset of identity fields to avoid exposing unnecessary email information. An app may return more user-safe fields when needed.
## Load the frontend from bootstrap data
```javascript
const status = document.querySelector("#status");
try {
status.textContent = "Loading your app…";
const response = await fetch("/api/functions/my-app-api/bootstrap");
if (!response.ok) throw new Error(`Unable to load app (${response.status})`);
const app = await response.json();
if (app.features.dashboard) {
const dashboard = await import("./components/dashboard.js");
dashboard.render(app);
}
status.textContent = "";
} catch (error) {
status.textContent = error.message;
}
```
Create the referenced component file with an exported `render` function. The [complete example](https://www.miniup.io/docs/examples/member-dashboard) includes the frontend files and a backend permission check.
## Choose safe bootstrap contents
Typical contents include user-safe identity, role, feature availability, navigation flags, and browser-safe application configuration. Never include API keys, Function Secrets, private credentials, or data the member is not authorized to receive.
## Enforce authorization after bootstrap
A bootstrap response helps the UI decide what to show. It does not authorize later requests. Each backend operation must check current trusted permissions again. Importing `admin.js` only for Admins does not secure the API that `admin.js` calls.
## Related guides
- [Use env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user)
- [Frontend versus backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
- [Complete member dashboard](https://www.miniup.io/docs/examples/member-dashboard)
---
Source: https://www.miniup.io/docs/authenticated-apps
Description: Combine Site files, Site Access, members, roles, a Site Members Function, Tables, and Secrets into an authenticated application.
# Build an Authenticated MiniUp App
An authenticated MiniUp app combines a Site frontend with Site Access and a Site Members Function. MiniUp provides trusted member identity; your Function decides which application operations each member may perform.
## Understand the application pieces
| Piece | Responsibility |
| --- | --- |
| MiniUp Site | HTML, CSS, JavaScript, and static assets |
| Site Access | Login requirements, members, and roles |
| Site Members Function | Trusted backend logic and authorization |
| MiniUp Tables / APIs | Application records and data |
| Function Secrets | Private credentials used by Function code |
```text
Browser
↓
MiniUp Site
↓
/api/functions/my-api/...
↓
Site Members Function
↓
private data / external APIs
```
## Build the app step by step
1. [Publish frontend files](https://www.miniup.io/docs/sites/publish) in a MiniUp Site.
2. Choose [Invite-only or Private Site Access](https://www.miniup.io/docs/access) if the frontend itself should be protected.
3. [Invite members and assign roles](https://www.miniup.io/docs/access/members).
4. [Create a Site Members Function](https://www.miniup.io/docs/functions/site-members) linked to that Site.
5. Use [env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user) for trusted identity and check permissions inside every protected backend operation.
6. Add private credentials through [Function Secrets](https://www.miniup.io/docs/functions/secrets), then publish the Function.
7. Optionally implement [a bootstrap endpoint](https://www.miniup.io/docs/authenticated-apps/bootstrap) to tell the frontend which features to display.
8. Test the complete app as Owner, as Viewer, and while signed out.
## Example: a staff reports portal
Everyone in the Site can see a dashboard. Editors can view reports. Owners and Admins can perform administrative actions. The frontend uses feature flags to show appropriate navigation, while each corresponding backend route enforces the same permission before returning data or making changes.
**Frontend controls what users SEE. Backend controls what users MAY DO.** Hiding an Admin button is a convenience for users, not API protection.
## Related guides
- [Complete member dashboard example](https://www.miniup.io/docs/examples/member-dashboard)
- [Bootstrap an authenticated app](https://www.miniup.io/docs/authenticated-apps/bootstrap)
- [Enforce backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
---
Source: https://www.miniup.io/docs/authenticated-apps/miniup-user
Description: Use the trusted current Site member identity and role in a Site Members Function for personalization and authorization.
# Use env.MINIUP_USER
`env.MINIUP_USER` represents the trusted current Site member inside a Site Members Function. Use this public Function runtime contract for authorization and personalization instead of trusting user or role values sent by the browser.
## Read MINIUP_USER identity fields
| Field | Meaning |
| --- | --- |
| `id` | The current member's user identifier |
| `email` | The member's email information, when available |
| `name` | The member's display name, when available |
| `role` | The member's Site role: owner, admin, editor, or viewer |
| `siteId` | The linked MiniUp Site identifier |
The identity is supplied for Site Members Functions. Do not assume a Public or API Key Function receives a member identity. Display names and email addresses should not be treated as durable business authorization keys.
## Use identity in a Function
1. Link the Function to your Site with **Site Members** access.
2. Read `env.MINIUP_USER` inside the request handler.
3. Check the role and, where necessary, the record's relationship to `user.id`.
4. Return only the user information the frontend needs.
```javascript
export default {
async fetch(request, env) {
const user = env.MINIUP_USER;
if (!user) return Response.json({ error: "Sign in required" }, { status: 401 });
return Response.json({
user: { id: user.id, name: user.name || "Member", role: user.role }
});
}
};
```
## Do not trust browser-supplied identity
A request body such as `{"role":"owner"}` is just user input. It does not change `env.MINIUP_USER.role` or grant permission. Use the trusted identity for every protected operation, even when the frontend previously loaded a bootstrap response.
## Related guides
- [Bootstrap an app](https://www.miniup.io/docs/authenticated-apps/bootstrap)
- [Backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
- [Site roles](https://www.miniup.io/docs/access/members)
- [Site Members Functions](https://www.miniup.io/docs/functions/site-members)
---
Source: https://www.miniup.io/docs/chatgpt/agent
Description: Discover the public Agent API, inspect current pricing, authorize a paid operation, and use the returned receipt to manage a Site.
# Use the MiniUp Agent x402 API
The MiniUp Agent x402 API lets compatible agents perform published app and data operations through a public paid API. Use it for an agent workflow that explicitly supports x402 payments and user-authorized spending.
## Start with public discovery
1. Open **Agent** in MiniUp's navigation.
2. Use [Open API JSON](https://www.miniup.io/api/x402) to discover the current supported actions and request shapes.
3. Read [Current Pricing](https://www.miniup.io/api/x402/pricing) before authorizing any paid action.
4. Configure your compatible agent's wallet and spending controls outside public app code.
5. Choose the intended action, follow the x402 payment challenge, and retain the returned receipt and resource URL.
6. Open the result and verify that the requested operation completed.
## Understand the request pattern
An unpaid request for a paid action may return **402 Payment Required** with the payment requirements. A compatible x402 client handles that challenge using authorized funds and retries appropriately. A payment challenge is not a successful publish result.
The public discovery document is the current reference for request fields, payment requirements, upload helpers, and supported lifecycle actions. Do not hardcode a price from an old example.
## Example agent task
Ask an agent to inspect current pricing, create one static report app within an explicit spending cap, upload its files, publish it, and return the receipt plus the working URL. Use the receipt's resource information for later supported updates, data operations, or unpublishing.
## Protect credentials and avoid duplicate actions
Keep wallet credentials out of Site files, Function documentation, and shared prompts. If an action's outcome is uncertain, inspect its receipt and resource state before repeating a chargeable operation. User authorization for one operation is not permission for unlimited future spending.
## Related guides
- [Agent product page](https://www.miniup.io/x402agent)
- [Publish a Site](https://www.miniup.io/docs/sites/publish)
- [Table API usage](https://www.miniup.io/docs/tables/api)
- [Security principles](https://www.miniup.io/docs/security)
---
Source: https://www.miniup.io/docs/chatgpt/ai-studio
Description: Use MiniUp Agent Ask, Edit, and Goal workflows, review staged changes, preview the app, and apply or discard the result.
# Edit a Site with AI Studio
AI Studio is the Site workspace for MiniUp Agent. Use Ask to understand the Site, Edit for targeted changes, or Goal for a larger multi-step task with planning and validation.
## Choose an AI Studio mode
1. Open **Dashboard → your Site → AI Studio**.
2. Choose the available model and mode, and review the shown usage or credit availability.
3. Use **Ask** for explanations, **Edit** for a focused file change, or **Goal** for a larger build.
4. Describe the expected result and attach relevant supported files when needed.
A question entered in Edit may be routed to Ask; a multi-step generation request may be routed to Goal. Read the routing notice before starting. Viewers can ask questions but cannot generate or apply edits.
## Review and apply an Edit
Request a concrete change such as “Add a date filter to the existing sales table and preserve its data access.” Inspect the changed files and draft preview. Use **Approve & Apply** or the displayed apply control when the result is ready. Use **Discard** to reject staged work.
After applying, open the published Site and test the changed behavior. A draft preview is not proof that live files have been updated.
## Work through a Goal
Describe the app's purpose, data, audience, and acceptance criteria. Review the plan and use **Approve plan** when offered. Inspect progress and staged changes. Use **Run one step** where available, **Fix error** with a concrete preview problem, or **Cancel goal** if the work should stop. Apply the completed result only after checking the preview and diff.
## Troubleshoot AI Studio
Check account credits, model availability, role, and any error shown by the run. If the preview is blank, inspect the preview error and provide it to **Fix error**. Keep source data and access requirements explicit; do not accept placeholder data as a working connection.
## Related guides
- [Prompt patterns](https://www.miniup.io/docs/chatgpt/prompts)
- [Update Site files](https://www.miniup.io/docs/sites/files)
- [Revision rollback](https://www.miniup.io/docs/sites/revisions)
- [Limits and usage](https://www.miniup.io/docs/limits-plans)
---
Source: https://www.miniup.io/docs/chatgpt
Description: Connect MiniUp, build from uploaded files or approved hosted datasets, and publish or update a working application from chat.
# Use MiniUp with ChatGPT
MiniUp in ChatGPT lets you create, publish, and update MiniUp Sites using uploaded files or approved hosted data. Connect your MiniUp account, describe the app, and review the actual published result.
## Connect MiniUp in ChatGPT
1. Open ChatGPT's **Plugins** or its app directory. Some clients may label integrations as plugins or connectors.
2. Find MiniUp, choose **Connect**, and sign in to your MiniUp account when prompted.
3. Review and approve the requested access.
4. Select or invoke MiniUp in a conversation and describe what you want to build.
Availability depends on the ChatGPT account, plan, region, workspace controls, and current directory availability. For custom connection options, use MiniUp's current [ChatGPT connection page](https://www.miniup.io/chatgptapp). It also includes the intentionally public Claude connector workflow. OpenAI's [connection guidance](https://developers.openai.com/plugins/deploy/connect-chatgpt) describes developer testing where supported.
## Build from uploaded files
1. Attach the source CSV, spreadsheet, spatial file, PDF, or HTML content supported by the chosen MiniUp workflow.
2. Explain the audience, purpose, required fields, and desired access.
3. Ask MiniUp to inspect the source and build a no-build static app connected to the uploaded data.
4. Review any requested action approval and publish the result.
5. Open the resulting URL and verify the app uses the actual uploaded data.
## Build from existing hosted data
Ask MiniUp to find a dataset you own in the [Data Catalog](https://www.miniup.io/docs/data/catalog), inspect its schema and sample, and propose an app using its real fields. For multiple datasets, create or choose a [Dataset Bundle](https://www.miniup.io/docs/data/bundles) and explicitly approve the intended context.
```text
Use MiniUp to build a regional sales dashboard from my approved
Sales Overview Dataset Bundle. Inspect the schema first. Use actual
field names, show region totals and a paginated table, preserve dataset
access, and include loading, empty, and error states. Publish the app
and give me the URL and a summary of what changed.
```
## Review publishing and updates
Specify whether the request should create a new Site or update an existing named Site. Review the published link, data connection, mobile layout, and access. A generated code block is not the same as a published app. Use Dashboard to inspect the files and settings after creation.
## Keep AI data access intentional
Do not paste Function Secrets or private API keys into a conversation. Approve only data appropriate to the task. A bundle does not make a private dataset public, and an AI should not weaken access to fix a failed request. Manage or disconnect the MiniUp integration through the client's integration settings when needed.
## Related guides
- [Useful MiniUp prompts](https://www.miniup.io/docs/chatgpt/prompts)
- [Use AI Studio](https://www.miniup.io/docs/chatgpt/ai-studio)
- [Dataset Bundles](https://www.miniup.io/docs/data/bundles)
- [PDF Knowledge Packs](https://www.miniup.io/docs/pdf)
---
Source: https://www.miniup.io/docs/chatgpt/prompts
Description: Give an AI a clear audience, data source, access policy, and acceptance criteria for publishing or editing a MiniUp app.
# Write Useful MiniUp Prompts
A useful MiniUp prompt states the audience, task, actual data, access requirements, and how the finished app will be checked. Include whether the AI should create a new Site or update an existing Site.
## Prepare a prompt
1. Name the workflow: new Site, existing Site edit, Table app, dataset dashboard, or member portal.
2. Identify the uploaded file, hosted dataset, or approved Dataset Bundle.
3. Ask the AI to inspect schema and sample values before choosing fields.
4. Describe required behavior and who may see or change data.
5. Require a published URL, changed-files summary, and verification results.
## Build from an uploaded spreadsheet
```text
Use MiniUp to build a mobile-friendly request tracker from my uploaded
spreadsheet. Inspect the columns first. Use a Table for editable records,
preserve private reads, and route protected operations through a Site
Members Function. Include search, loading, empty, and error states.
Do not invent rows or place private keys in browser files.
```
## Reuse approved hosted data
```text
Use my approved Parks Dataset Bundle in MiniUp. Verify geometry and
field names, then build a map and a paginated list. Show only bounded
results and preserve the dataset's access settings. Publish a new Site
and return its URL. Explain any source-data gaps.
```
## Build from a PDF Knowledge Pack
```text
Use this MiniUp PDF App Prompt to build a searchable reference guide.
Keep source citations visible. If the PDF does not support an answer,
say so. Use the pack's actual access instructions, avoid invented facts,
and test the result on a phone.
```
## Improve an existing app safely
```text
Update my MiniUp Site named my-site. Add an accessible filter to the
existing dashboard. Keep the current API connection and access policy.
Show the file diff and preview, validate the filter, and summarize the
published change.
```
## Review AI output
Open the actual result and test its primary action. Check that the app uses real data and retains permissions. A realistic screenshot or example response does not prove the live API works.
## Related guides
- [MiniUp in ChatGPT](https://www.miniup.io/docs/chatgpt)
- [AI Studio](https://www.miniup.io/docs/chatgpt/ai-studio)
- [Dataset Bundles](https://www.miniup.io/docs/data/bundles)
- [Authenticated apps](https://www.miniup.io/docs/authenticated-apps)
---
Source: https://www.miniup.io/docs/data/access
Description: Choose Private to this app, selected MiniUp apps, or Public link access for Tables and hosted data files.
# Control Dataset Access and Cross-Site Sharing
Dataset access is configured separately from Site Access. Use it to keep data with its source app, share read access with selected MiniUp apps, or intentionally publish a public data link.
## Choose a dataset access mode
| UI choice | Outcome |
| --- | --- |
| Private to this app | Keeps dataset use within its source app's permitted access |
| Share with selected MiniUp apps | Adds explicit read access for selected target Sites |
| Public link | Makes the dataset publicly readable under its current availability and key requirements |
A Table may also require a read key or enforce action-specific permissions. Inspect both dataset access and Table API settings. A public frontend should not contain a credential intended to bypass private dataset access.
## Share a dataset with another Site
1. Open **Dashboard → source Site → API** for a Table, or **Parquet** for a data file.
2. Open the dataset's **Access settings** or dataset access panel.
3. Choose **Share with selected MiniUp apps**.
4. Select the intended target Site and add the read grant.
5. Open the target app and verify that data loads for the intended visitor.
6. Remove or disable a grant when the target app should no longer use the dataset.
## Example: reuse a reference dataset
A reference Table can remain in its original Site while two approved MiniUp apps read it. Select those target apps explicitly. If you instead choose Public link, anyone with access to that public URL may read the data; Gallery visibility is irrelevant.
## Troubleshoot denied dataset access
Check the source Site, target Site, dataset access mode, enabled grant, and read-key requirement. A bundle may report a dataset as ineligible if it is owner-only, requires a private read key, is unavailable, or is incompatible with the target. Fix the dataset policy intentionally rather than embedding credentials in the app.
## Related guides
- [Site Access](https://www.miniup.io/docs/access)
- [Table permissions](https://www.miniup.io/docs/tables/permissions)
- [Dataset Bundles](https://www.miniup.io/docs/data/bundles)
---
Source: https://www.miniup.io/docs/data/arcgis
Description: Import a queryable ArcGIS layer, configure fields and geometry, preview the result, and refresh a MiniUp snapshot.
# Connect an ArcGIS Data Source
An ArcGIS Data Source imports records from a supported FeatureServer or queryable MapServer layer into a refreshable MiniUp dataset. Use it for maps and dashboards based on GIS services you are allowed to access.
## Connect an ArcGIS layer
1. Open **Dashboard → Data Sources → New source** and select ArcGIS.
2. Enter a name, destination Site, and **ArcGIS FeatureServer/MapServer layer URL**. Use a specific layer URL ending in its layer number, such as `https://example.com/arcgis/rest/services/Parks/FeatureServer/0`.
3. Select **Public** authentication or enter an **ArcGIS token** in its dedicated field. Set the optional token expiration when known.
4. Configure **Where clause**, **Out fields (comma-separated)**, and **Return geometry**.
5. Run **Save and test**, then **Preview source** to confirm fields, sample records, and geometry.
6. Create a snapshot and inspect the result before building a map.
## Choose filters and geometry
Use a where clause such as `STATUS = 'Open'` only if that field and value exist in the layer. Use `1=1` when you intend to include all eligible records. Select only the fields your app needs. Enable Return geometry for maps; a table-only report may not need it.
## Refresh and diagnose an ArcGIS source
Refresh from the source detail page when you need updated records. Check row counts, warnings, and connection history. An expired token, unsupported layer, source query limit, or mismatched field can cause a failed refresh. Update the credentials or query, test again, and verify the latest successful snapshot.
A MiniUp snapshot does not edit the original ArcGIS service. A map built from that snapshot reflects the snapshot's data and access settings.
## Related guides
- [Data Source snapshot behavior](https://www.miniup.io/docs/data/sources)
- [GeoParquet and maps](https://www.miniup.io/docs/parquet/geoparquet)
- [Data Catalog](https://www.miniup.io/docs/data/catalog)
- [Dataset access](https://www.miniup.io/docs/data/access)
---
Source: https://www.miniup.io/docs/data/bundles
Description: Approve datasets for one app, choose their roles, inspect the safe manifest, and pass the bundle to an AI creation workflow.
# Create and Use a Dataset Bundle
A Dataset Bundle is an explicit group of datasets approved for one app. Use a bundle when an AI-built application needs several related datasets and should have clear, limited data context.
## Create a Dataset Bundle
1. Open **Dashboard → Data Catalog → New bundle**, or choose **Add to bundle** on a dataset.
2. Set the bundle name, description, and target Site or new-app target.
3. Select eligible datasets and assign their dataset roles from the choices shown. These describe each dataset's purpose; they are not member authorization roles.
4. Review compatibility warnings and create the bundle.
5. Open the bundle and inspect **Selected datasets** and **Safe manifest preview**.
6. Select **Build app with this bundle** and use the copied context or prompt in your AI workflow.
## Review the bundle manifest
The manifest describes approved datasets, schemas, access context, and intended roles without supplying private credentials. A bundle is not a copy of all the dataset rows and does not invent relationships between them. Explain valid join fields and business rules in your prompt.
## Edit and manage a bundle
Use **Edit bundle** to rename or describe it. **Browse datasets** adds eligible datasets with roles; **Remove** removes a selected item. Use **Disable** and **Enable** to control bundle availability, or **Delete** when it is no longer needed.
Disabling or deleting a bundle is not a substitute for changing the underlying dataset access or unpublishing an app that already uses the data.
## Example: a parks and inspections app
Bundle a parks geometry dataset and an inspections Table. Describe `park_id` as the join field and ask the AI to verify matching values before building a map and inspection list. Require loading, empty, and error states and preservation of the dataset access settings.
## Resolve ineligible datasets
Owner-only, private read-key-protected, unavailable, or target-incompatible datasets may be blocked. Review **Access settings** on the dataset and grant only the intended access. Do not put private keys into the bundle or make sensitive data public merely to clear a warning.
## Related guides
- [Data Catalog](https://www.miniup.io/docs/data/catalog)
- [Dataset sharing](https://www.miniup.io/docs/data/access)
- [ChatGPT workflows](https://www.miniup.io/docs/chatgpt)
- [AI prompt patterns](https://www.miniup.io/docs/chatgpt/prompts)
---
Source: https://www.miniup.io/docs/data/catalog
Description: Search datasets you own across Sites, inspect schema, samples, profiles, and access, then choose data for an app.
# Find and Inspect Data in the Data Catalog
The Data Catalog is an owner-only view of MiniUp datasets across your Sites. Use it to find existing Table APIs, Parquet, GeoParquet, and ArcGIS-compatible layers before creating or uploading duplicate data.
## Find a dataset
1. Open **Dashboard → Data Catalog**.
2. Search by name, slug, Site, or type.
3. Filter by dataset type, access, or geometry availability.
4. Review the dataset's parent Site, row count, fields, update information, and access summary.
5. Select **Preview / Schema / Profile** to inspect the dataset.
## Understand schema, samples, and profiles
The schema lists the actual field names and types to use in queries. A sample shows a bounded selection of rows; it is not the complete dataset. A profile summarizes available shape and quality information. Verify the exact fields and values before asking an AI to generate charts or join datasets.
## Build from an existing dataset
Choose **Build app with this dataset** or **Add to bundle** to begin creating explicit approved context. Use **Access settings** to inspect or change the underlying dataset's sharing policy. Refresh the catalog after publishing new data if it is not yet visible.
## Example: reuse a sales Table
Search for `sales`, inspect its schema to confirm `region` and `revenue`, then select it for a Dataset Bundle. Tell the AI to use those exact fields rather than inventing columns.
## Access and troubleshooting
Catalog visibility does not make data public. Owner-only, key-protected, or unavailable datasets may be unsuitable for a public app. An empty search can mean there are no matching owned datasets or that filters are too narrow. Clear filters and check the source Site.
## Related guides
- [Create a Dataset Bundle](https://www.miniup.io/docs/data/bundles)
- [Dataset access](https://www.miniup.io/docs/data/access)
- [Build with ChatGPT](https://www.miniup.io/docs/chatgpt)
---
Source: https://www.miniup.io/docs/data
Description: Choose Tables, hosted Parquet files, Data Sources, Data Catalog, or Dataset Bundles for your application.
# Choose and Use MiniUp Data Features
MiniUp data features let you host records and files, refresh data from supported sources, inspect existing datasets, and reuse approved data in applications.
## Choose the right data feature
| Need | Use |
| --- | --- |
| Editable records and CRUD | [MiniUp Tables](https://www.miniup.io/docs/tables) |
| Analytical data or spatial files | [Parquet & GeoParquet](https://www.miniup.io/docs/parquet) |
| Repeatable imports from a web source | [Data Sources](https://www.miniup.io/docs/data/sources) |
| Find and inspect datasets you own | [Data Catalog](https://www.miniup.io/docs/data/catalog) |
| Approve several datasets for one AI-built app | [Dataset Bundles](https://www.miniup.io/docs/data/bundles) |
| Source-backed content from PDFs | [PDF Knowledge Packs](https://www.miniup.io/docs/pdf) |
## Start a data-backed app
1. Choose or create a destination MiniUp Site.
2. Import a Table, publish a hosted data file, or create a Data Source snapshot.
3. Inspect the schema and sample values before writing queries.
4. Set the dataset access appropriate to the app's audience.
5. Copy the public usage example or create a Dataset Bundle for AI-assisted building.
6. Test the published app as its intended audience.
## Example: a city service map
Create an ArcGIS Data Source, select the layer and relevant fields, and publish a snapshot into a Site. Inspect its geometry in the catalog, then build a map using the hosted dataset. Refresh the snapshot when you need updated source data.
## Keep data access explicit
A dataset has a source Site and its own access policy. A catalog entry or bundle does not automatically grant public access. Review [dataset sharing](https://www.miniup.io/docs/data/access) when using data across Sites.
## Related guides
- [Connect HTTP Data Sources](https://www.miniup.io/docs/data/sources)
- [Connect ArcGIS](https://www.miniup.io/docs/data/arcgis)
- [Browse the Data Catalog](https://www.miniup.io/docs/data/catalog)
- [Use datasets in a browser](https://www.miniup.io/docs/parquet/browser)
---
Source: https://www.miniup.io/docs/data/sources
Description: Create a Data Source from a supported web file, test credentials, preview records, publish a snapshot, and refresh it.
# Connect an HTTP or HTTPS Data Source
A Data Source saves a connection to a supported external dataset and creates a refreshable MiniUp snapshot. Use it when an app needs a reusable copy of a web dataset instead of uploading a new file by hand each time.
## Create an HTTP Data Source
1. Open **Dashboard → Data Sources → New source** and select the HTTP/HTTPS source type.
2. Enter **Source name** and choose the **Destination MiniUp site**.
3. Enter the direct **HTTP/HTTPS file URL**, not a webpage containing a download button.
4. Choose **Format**: auto, CSV, JSON, JSONL, NDJSON, GeoJSON, Parquet, or GeoParquet.
5. Choose **Authentication**: None, Bearer token, or API key header. Enter credentials in the dedicated fields. Supported API-key header choices are shown in the form.
6. Continue to **Test connection** and select **Save and test**.
7. Use **Preview source** to inspect schema and sample records without creating an output dataset.
8. Choose **Create snapshot** after selecting the destination Site.
## Refresh and inspect a Data Source
Open the source detail page to test, preview, or refresh it. Inspect **Refresh and connection history**, the latest result, row/byte counts, warnings, and inferred schema. Update connection settings when the source URL or credentials change. Use the available disable/delete controls when a source is no longer needed; review the confirmation before deleting. Deleting a Data Source leaves its latest output dataset available; remove or restrict that dataset separately if it should no longer be used.
## Understand snapshot behavior
A snapshot represents the data from a completed import, not a continuous live connection. Refresh it when you need updated data. A failed refresh leaves the last successful snapshot available. Check the latest successful run before claiming an app shows current upstream data. Do not assume automatic scheduled refresh unless the product explicitly provides that setting.
## Example and common problems
Use `https://example.com/operations.csv` as a direct source URL for an operations dashboard. If preview fails, verify the URL returns a supported file, credentials are valid, and the file fits the current import limits. URLs containing credential-bearing query parameters are not supported; use the dedicated authentication fields.
## Related guides
- [Connect an ArcGIS source](https://www.miniup.io/docs/data/arcgis)
- [Inspect hosted data](https://www.miniup.io/docs/data/catalog)
- [Dataset access](https://www.miniup.io/docs/data/access)
- [Supported formats](https://www.miniup.io/docs/reference/formats)
---
Source: https://www.miniup.io/docs/examples
Description: Choose practical examples for static publishing, Table APIs, Functions, authenticated dashboards, maps, and PDF apps.
# MiniUp App Examples
Build a MiniUp app by starting with the smallest example that matches the task, then connect it to real data and verify its permissions.
## Choose an example
| Outcome | Guide | Prerequisites |
| --- | --- | --- |
| First static page | [Publish HTML](https://www.miniup.io/docs/sites/publish) | Browser-ready HTML |
| Records in an app | [Table API requests](https://www.miniup.io/docs/tables/api) | A Table and enabled methods |
| Public utility API | [Function handler](https://www.miniup.io/docs/functions/create) | Function availability |
| Member dashboard | [Complete authenticated example](https://www.miniup.io/docs/examples/member-dashboard) | Site, members, Function, private Table |
| Geometry utility | [Trusted ESM example](https://www.miniup.io/docs/functions/trusted-esm) | Approved import source |
| Data analysis | [DuckDB browser example](https://www.miniup.io/docs/parquet/browser) | Hosted Parquet dataset |
| Map application | [GeoParquet and layers](https://www.miniup.io/docs/parquet/geoparquet) | Spatial dataset |
| Source-backed reference app | [PDF app workflow](https://www.miniup.io/docs/pdf/apps) | Completed Knowledge Pack |
## Adapt an example
1. Create the prerequisites and inspect their actual URLs and schemas.
2. Replace placeholders with your public resource names and safe configuration.
3. Store private credentials in Function Secrets.
4. Test success, empty data, invalid input, and denied access where applicable.
5. Publish and verify the real app on desktop and mobile.
## Important example limits
Example data and resource names are illustrative. A copied API URL will not work until the resource exists and permits the request. Do not remove authentication to make an example succeed with private data.
## Related guides
- [Get Started](https://www.miniup.io/docs/getting-started)
- [Security principles](https://www.miniup.io/docs/security)
- [Troubleshooting](https://www.miniup.io/docs/troubleshooting)
---
Source: https://www.miniup.io/docs/examples/member-dashboard
Description: Create a static member frontend and a Site Members Function that bootstraps roles and reads a private Table only for authorized members.
# Build a Complete Member Dashboard
This example builds a member dashboard with a static frontend and a Site Members Function. Every member receives safe startup information; only Owners and Admins can request the private report records.
## Create the resources
1. Publish a Site named `my-site` or another available name. Choose Invite-only or Private Site Access and invite a Viewer for testing.
2. Create a Table in the **API** tab named Reports with a Text field `title`. Add a sample record such as “September overview”.
3. Configure the Table as **Developer API** and create a server key with read permission. Keep the Table's reads private to that credential.
4. Create a Site Members Function linked to the Site. Use `my-app-api` or another available slug; update the frontend URL if you choose a different slug.
5. Add Function Secrets `TABLE_API_URL` (the Table's copied base URL) and `TABLE_API_KEY` (the private server key).
6. Paste the Function code below, enable GET, Test `/bootstrap`, and Publish.
## Function: authorize before reading private data
```javascript
export default {
async fetch(request, env) {
const user = env.MINIUP_USER;
if (!user) return Response.json({ error: "Sign in required" }, { status: 401 });
const url = new URL(request.url);
if (request.method !== "GET") {
return Response.json({ error: "Method not allowed" }, { status: 405 });
}
const canReadReports = user.role === "owner" || user.role === "admin";
if (url.pathname.endsWith("/bootstrap")) {
return Response.json({
user: { name: user.name || "Member", role: user.role },
features: { dashboard: true, reports: canReadReports }
});
}
if (url.pathname.endsWith("/reports")) {
if (!canReadReports) {
return Response.json({ error: "Forbidden" }, { status: 403 });
}
if (!env.TABLE_API_URL || !env.TABLE_API_KEY) {
return Response.json({ error: "Reports not configured" }, { status: 503 });
}
try {
const source = new URL(env.TABLE_API_URL);
source.searchParams.set("limit", "25");
const response = await fetch(source, {
headers: { "x-miniup-api-key": env.TABLE_API_KEY }
});
if (!response.ok) throw new Error("Report source failed");
const data = await response.json();
if (!Array.isArray(data.records)) throw new Error("Invalid report data");
return Response.json({
reports: data.records.map(record => ({
id: record.id, title: String(record.fields.title || "Untitled report")
}))
});
} catch {
return Response.json({ error: "Reports unavailable" }, { status: 502 });
}
}
return Response.json({ error: "Not found" }, { status: 404 });
}
};
```
The report route checks the trusted role on every request and returns only `id` and `title`. It does not pass the member's browser-supplied URL or role to the private data source.
## Frontend: index.html
Upload these three frontend files to the Site. The main page uses a responsive layout, accessible status, a retry action, and a component loaded after bootstrap.
```html
Member dashboard
Member dashboard
Loading your app…
```
## Frontend: app.js
```javascript
const status = document.querySelector("#status");
const retry = document.querySelector("#retry");
const dashboard = document.querySelector("#dashboard");
const base = "/api/functions/my-app-api";
async function load() {
retry.hidden = true;
dashboard.hidden = true;
status.textContent = "Loading your app…";
try {
const response = await fetch(`${base}/bootstrap`);
if (!response.ok) throw new Error(`Unable to load your app (${response.status}). Check Site membership.`);
const app = await response.json();
if (!app.features.dashboard) throw new Error("Dashboard unavailable.");
const component = await import("./components/dashboard.js");
await component.render(app, base, dashboard);
dashboard.hidden = false;
status.textContent = "";
} catch (error) {
status.textContent = error.message;
retry.hidden = false;
}
}
retry.addEventListener("click", load);
load();
```
## Frontend: components/dashboard.js
```javascript
export async function render(app, base, container) {
container.replaceChildren();
const greeting = document.createElement("h2");
greeting.textContent = `Welcome, ${app.user.name}`;
container.append(greeting);
if (!app.features.reports) {
const note = document.createElement("p");
note.textContent = "Your membership does not include report access.";
container.append(note);
return;
}
const response = await fetch(`${base}/reports`);
if (!response.ok) throw new Error(`Reports could not load (${response.status}).`);
const { reports } = await response.json();
if (!reports.length) {
const empty = document.createElement("p");
empty.textContent = "No reports yet.";
container.append(empty);
return;
}
const list = document.createElement("ul");
for (const report of reports) {
const item = document.createElement("li");
item.textContent = report.title;
list.append(item);
}
container.append(list);
}
```
## Validate the complete app
1. As Owner, open the published Site. Expect the greeting and up to 25 real report records.
2. With an empty Reports Table, expect “No reports yet.”
3. As Viewer, expect the greeting and the no-report-access message.
4. As Viewer, call `/api/functions/my-app-api/reports` directly. Expect 403 even if someone modifies frontend flags.
5. While signed out, verify protected Site access and denied Function access.
6. Temporarily use invalid test credentials in the Function preview to check the safe 502 error. Restore valid Secrets and publish before sharing.
This example intentionally provides a bounded read-only report list. Add pagination and record-specific rules before extending it to a larger business workflow. Do not assume a role check alone gives per-record isolation.
## Related guides
- [Bootstrap pattern](https://www.miniup.io/docs/authenticated-apps/bootstrap)
- [env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
- [Table permissions](https://www.miniup.io/docs/tables/permissions)
- [Backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
---
Source: https://www.miniup.io/docs/functions/access
Description: Configure Public, API Key, or Site Members access with optional x402 payments, rotate keys, select HTTP methods, and set Allowed Web Origins.
# Choose Function Access, API Keys, and Web Origins
Function access determines who may call a MiniUp Function. Allowed methods determine which HTTP actions it accepts. Allowed Web Origins controls browser access and is not a replacement for authentication.
## Compare Function access modes
| Mode | Best for | Browser secret needed |
| --- | --- | --- |
| Public | Open APIs | No |
| API Key | Trusted external/server calls | Yes — caller needs a key; keep it out of browsers |
| Site Members | Authenticated MiniUp apps | No |
| x402 Paid | Optional payment per successful request | No Function key; an x402-compatible client satisfies payment |
For API Key mode, the caller needs a secret, but it belongs in trusted server code. Do not embed the Function API key in browser JavaScript. Site Members mode avoids this browser secret by using the linked Site's authenticated membership.
## Configure Public or API Key access
1. Open **Functions → your Function → API**.
2. Choose **Public** or **API Key** under **Access** and select **Save access**.
3. For API Key mode, select **Generate key** and copy the revealed value immediately. MiniUp shows the full key only once.
4. Choose allowed methods: GET, POST, PUT, PATCH, or DELETE. Save API settings.
5. Call the copied endpoint with a method your handler implements.
```bash
curl 'https://functions.miniup.app/my-api/health' -H 'x-miniup-api-key: YOUR_API_KEY'
```
Replace the example endpoint with the endpoint shown in your Function editor. The public Function API accepts `x-miniup-api-key` for API-key authentication.
## Rotate a Function API key
Select **Rotate key**, review the confirmation, and securely copy the replacement. There is one active key per Function. The old key stops working when the replacement becomes active; update all trusted callers and test them. Key and access updates are separate from editing and publishing a new code draft.
## Configure Allowed Web Origins
For Public and API Key Functions, enter exact origins in **Allowed Web Origins (CORS)**, separated by semicolons:
```text
https://my-site.miniup.app; https://example.com
```
Use a scheme and hostname, with a port if needed. Do not include a path, trailing slash, or wildcard. Leaving the list empty allows all websites to make browser requests. Non-browser callers are not restricted by this browser setting; use API Key access to restrict callers.
## Configure Site Members access
Choose **Site Members**, select the **Linked MiniUp Site** you own, and save access. Alternatively create the Function directly from that Site's **Functions** tab. Same-origin calls from the linked Site do not require Web Origin configuration or a browser Function key.
## Configure optional x402 payments
Under **x402 Monetization**, select **Enable x402 payments** to add a payment fallback to any access setting. Valid API keys and verified Site Members bypass payment. External callers pay positive route prices; $0 routes require no payment proof or settlement. Enter a decimal USD price and payout wallet, choose directory listing and external discovery independently, and save access. [Follow the paid Function guide](https://www.miniup.io/docs/functions/paid-x402) for payment behavior and preview. Public, API Key, and Site Members Functions do not need payment configuration.
## Related guides
- [Paid Functions with x402](https://www.miniup.io/docs/functions/paid-x402)
- [Create a Site Members Function](https://www.miniup.io/docs/functions/site-members)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
- [Diagnose 401, 403, and browser errors](https://www.miniup.io/docs/functions/troubleshooting)
---
Source: https://www.miniup.io/docs/functions/create
Description: Write a Function handler, save a draft, preview HTTP requests, publish a stable endpoint, and manage endpoint status.
# Test and Publish a MiniUp Function
The Function editor separates your draft from the live endpoint. **Save draft** preserves work, **Test** runs a preview of the draft, and **Publish** makes the code live.
## Create and test a Function
1. Open **Functions → New Function**. Enter a **Display name** and **Stable slug**, then select **Create**.
2. Open **Code** and replace the starter with a handler like the example below.
3. Save the draft. Saving alone does not change production.
4. Open **Test**, set the method to GET and the path to `/health`, and run the preview. Headers must be a JSON object; request bodies must match what your handler expects.
5. Inspect the response status and body. Fix any error and repeat Test.
6. Set the intended access and allowed methods in **API**. Add any required [Function Secrets](https://www.miniup.io/docs/functions/secrets).
7. Select **Publish**, wait for the live confirmation, and copy the Function endpoint.
## Minimal Function handler
```javascript
export default {
async fetch(request, env) {
const url = new URL(request.url);
if (request.method === "GET" && url.pathname.endsWith("/health")) {
return Response.json({ ok: true, service: "my-api" });
}
return Response.json({ error: "Not found" }, { status: 404 });
}
};
```
For a standalone Function, append `/health` to the endpoint copied from MiniUp. For a Site Members Function, call `/api/functions/my-api/health` from the linked Site as an authorized member.
## Understand Test, Preview, and Publish
Test runs the current saved draft in a preview and does not replace live code. A passing preview proves only the request tested: verify the published endpoint, its access requirements, and any external service calls too. Preview code may still call external services, so use test data for operations with side effects.
Trusted ESM imports are resolved during Test/Preview and Publish. Secret additions, updates, and removals require another Publish before the live Function uses the current Secret set.
## Change settings or endpoint status
In **Settings**, change the display name or description. The slug locks after the first deployment. Use **Disable endpoint** to make the endpoint unavailable while retaining deployed code, then **Enable endpoint** to restore that deployed code. **Delete Function** is permanent; review the confirmation carefully.
The editor shows draft changes and last-deployed status. It does not currently expose a revision rollback browser. To restore older Function logic, paste your saved copy, test it, and publish again.
## Related guides
- [Paid Functions with x402](https://www.miniup.io/docs/functions/paid-x402)
- [Access, API keys, methods, and origins](https://www.miniup.io/docs/functions/access)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
- [Troubleshoot Functions](https://www.miniup.io/docs/functions/troubleshooting)
---
Source: https://www.miniup.io/docs/functions/directory
Description: Add public Function documentation, request and response examples, tags, and an optional API directory listing.
# Document and Share a Function API
A deployed standalone MiniUp Function can have public API documentation and a directory listing. Use this to help intended callers understand your API without exposing its code or credentials.
## Publish Function documentation
1. Open **Functions → your Function → Documentation**.
2. Set the **Public name**, **Description**, and comma-separated **Tags**.
3. Describe the API's purpose, methods, inputs, output, and access requirement in **Documentation text**.
4. Add safe **Example request** and **Example response** values using placeholders.
5. Choose **Listed in the public API directory** if you want discovery, then **Save documentation**.
6. Use **Preview public docs** when available and verify that no private values are included.
## Understand public documentation access
A Public or x402-enabled Function may keep an unlisted documentation link. An API Key Function without x402 must be listed before its documentation is publicly reachable. Listing describes the API; access rules still apply. Site Members Functions without x402 use the Site workflow. With x402 enabled, external callers can use the standalone payment endpoint.
The public [MiniUp Function Explorer](https://functions.miniup.app/) lets callers search listed APIs, filter by access type, HTTP method, or tag, and sort by useful directory metadata. x402 listings may also show their settled paid-call count. MiniUp does not present account-wide Function quota usage as per-API traffic.
For example, document an open coordinate utility with its accepted JSON fields and a sample response.
## Paid Function listings
An x402 Paid listing shows **x402 Paid** and the exact price per request alongside the endpoint, methods, description, and tags. MiniUp Directory listing does not enable external x402 discovery or remove the payment requirement. Configure external discovery separately in **API → x402 Monetization**.
## Important publishing notes
Do not include real API keys, private business records, or Function Secrets in descriptions or examples. Review the public documentation again after changing your handler's request or response shape.
## Related guides
- [Paid Functions with x402](https://www.miniup.io/docs/functions/paid-x402)
- [Function access modes](https://www.miniup.io/docs/functions/access)
- [Function publishing](https://www.miniup.io/docs/functions/create)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
---
Source: https://www.miniup.io/docs/functions
Description: Create, test, publish, secure, and call JavaScript Functions for open APIs, trusted integrations, and member applications.
# Create and Use MiniUp Functions
A MiniUp Function runs server-side JavaScript when an HTTP request arrives. Use a Function to validate input, enforce member permissions, transform data, or call services using private credentials.
## Choose a Function workflow
- **Open API:** publish a Public Function for data or logic that anyone may call.
- **Trusted integration:** protect a Function with an API Key and call it from a trusted server.
- **Paid API (optional):** enable x402 payments alongside any access setting and charge compatible callers per successful request.
- **Authenticated app:** link a Site Members Function to one MiniUp Site and use the Site's members and roles.
| Mode | Best for | Browser secret needed |
| --- | --- | --- |
| Public | Open APIs | No |
| API Key | Trusted external/server calls | Yes — caller needs a key; keep it out of browsers |
| Site Members | Authenticated MiniUp apps | No |
| x402 Paid | Optional payment per successful request | No Function key; an x402-compatible client satisfies payment |
## Create your first Function
1. Open **Functions** in the main navigation and choose **New Function**.
2. Enter a display name and globally unique stable slug.
3. Write a JavaScript request handler in **Code** and save the draft.
4. Use **Test** to run a preview request, inspect the result, and repair errors.
5. Configure access, methods, and any Secrets.
6. Select **Publish** and test the resulting endpoint in its intended calling context.
Start with the [step-by-step Function guide](https://www.miniup.io/docs/functions/create) and its minimal handler.
## What belongs in a Function?
Functions handle requests and return responses. Keep frontend files in the Site and persistent application records in a Table or service. Do not treat a Function's in-memory variables as a persistent database. Use browser-safe code for the frontend and a standard JavaScript `fetch` handler for Function code.
## Review availability and usage
Open Functions to see your Function count, API calls this month, remaining calls, and reset date. Account allowances and feature availability can differ. Check Plans and your signed-in usage before depending on a particular limit.
## Related guides
- [Paid Functions with x402](https://www.miniup.io/docs/functions/paid-x402)
- [Document and list a Function API](https://www.miniup.io/docs/functions/directory)
- [Test and publish a Function](https://www.miniup.io/docs/functions/create)
- [Function access modes](https://www.miniup.io/docs/functions/access)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
- [Trusted ESM dependencies](https://www.miniup.io/docs/functions/trusted-esm)
- [Authenticated apps](https://www.miniup.io/docs/authenticated-apps)
---
Source: https://www.miniup.io/docs/functions/paid-x402
Description: Optionally charge per successful MiniUp Function request, receive payment directly, preview without payment, and choose how callers discover your API.
# Paid Functions with x402
Write an API. Set a price. Publish it. x402-compatible agents can pay and call it.
Choose Public, API Key, or Site Members for access, then optionally enable x402 payments. x402 is a monetization fallback, independent of authentication. Valid API keys and Site Members call normally without payment; external callers can use x402. Public + x402 requires payment on positive-priced routes. $0 routes are genuinely free: no HTTP 402, payment proof, or settlement.
## Create a paid API
1. Create a normal [MiniUp Function](https://www.miniup.io/docs/functions/create) and write its request handler.
2. In **API → Access**, choose your authentication setting. Under **x402 Monetization**, select **Enable x402 payments**.
3. Enter the **Price per successful request (USD)**, with the default $0.001, an amount from $0.001 to $1.00, or $0 for free requests. Use a decimal value with up to six decimal places, such as `0.01`.
4. Enter a valid **Payout wallet** that you control and that can receive the payment described in your endpoint's payment requirement.
5. Optionally select **List in MiniUp Function Explorer**.
6. Independently, optionally select **Enable external x402 discovery**.
7. Select **Save access**. Add a clear description, tags, documentation, and safe request and response examples under **Documentation**.
8. Use **Test** to preview, then **Save & Publish** to publish your handler.
9. Copy the endpoint and call it with an x402-compatible client.
The endpoint follows the same stable Function URL pattern. Changing access on an already published Function updates its live access requirement when you save. Verify the price and recipient before sharing the endpoint.
## Optional route pricing
In **API**, expand **Advanced route pricing** to override the default for specific methods and paths. For example:
| Method | Path | Price |
| --- | --- | --- |
| GET | `/summary` | $0 (free) |
| POST | `/items` | $0.005 |
| POST | `/items/:id/adjust` | $0.002 |
Paths begin after your Function slug. `/items/abc123/adjust` matches `/items/:id/adjust`. GET and POST are different routes. A literal segment takes priority over a parameter at the first differing segment. Trailing slashes match the same route. Query strings do not affect pricing.
Routes without an override inherit the default. Remove an override and select **Save access** to restore that behavior. Saving access updates pricing for an already live Function. Setting either the default or an override to **$0** allows calls without a wallet or payment. Free requests still use the normal Function request allowance.
## View usage
The Functions page shows **Calls this month** and **Last call**. Search by name, slug, or endpoint, filter by status, access, or listing, and sort by activity. Open **Manage → Usage** for total recorded calls, paid calls, revenue, and the last paid call.
Per-Function tracking starts on the date shown in the dashboard. Earlier account usage cannot be assigned to individual Functions. Calls count production requests admitted to run, including requests that return errors; previews are excluded. Paid calls count only completed positive payments for successful requests. Revenue keeps the actual amount paid, even after prices change. Free requests do not add paid calls or revenue.
## Call a paid Function
An unpaid request to a positive-price route receives HTTP 402 with a payment requirement. An x402-compatible client can satisfy that requirement and call the Function. An ordinary curl or browser fetch request does not automatically make a payment. With API Key access, a valid Function API key bypasses payment. With Site Members access, verified members bypass payment and keep their normal identity; external payment callers do not receive a member identity.
Payment is verified before the Function runs. Successful payments settle directly to the configured payout wallet; MiniUp does not hold a creator balance or require withdrawals. The caller receives the Function's response with payment confirmation headers. Functions can return text, JSON, or other supported response content.
## Understand successful and failed requests
Responses with a 2xx or 3xx status are eligible for settlement. Responses with a 4xx or 5xx status, thrown errors, runtime failures, and quota rejections are not settled. On positive-price routes, an invalid or missing payment cannot execute the Function. Paid calls still use the owner's normal Function request allowance and remain subject to request limits.
A Function may perform an external operation before it fails; a failed request does not undo that operation. If settlement cannot be confirmed, MiniUp returns an error rather than a payment success. Do not repeat a pending operation with a new payment. Reuse the original payment and request when retrying; changed input or payment settings can cause a conflict.
## Preview without payment
**Preview bypasses payment and does not create an x402 transaction.** It uses your authenticated owner preview access and creates no paid receipt. Preview may still call external services, so use test data for operations with side effects. Unauthenticated production calls require payment only when the matching route price is greater than $0.
## Set prices and documentation for each route
Open **Advanced route pricing** to review routes detected from your saved source. MiniUp scans when you create, save, publish, or enable payments. **Rescan routes** scans the saved draft again. Detection is best effort: review the method and path, and add a manual route when needed.
Detected routes use the default price until you choose **Override**. For example, with a $0.05 default, you can price `POST /extract` at $0.005 while `POST /company` stays at $0.05. Changing the default to $0.08 updates `/company`; `/extract` stays at $0.005. **Return to default** removes the explicit price. Save access & monetization to apply your changes.
MiniUp may suggest `GET /`, `/health`, `/status`, and `/ping` as free routes. **Apply suggestions** selects $0 overrides; nothing becomes free until you apply and save them. An override for a route missing from a later scan stays visible as **No longer detected** until you remove it.
Under **Public documentation**, edit each route's description, JSON request and response examples, and input/output schemas. These are public descriptions of your API, so never include credentials. Saving or rescanning source preserves your edits. Function-wide documentation remains the overview.
Public docs and Function Explorer show effective route prices. With external discovery enabled, a payment requirement uses the documentation matching the requested method and path, so two POST routes can describe different inputs. Older Functions without route documentation continue using their Function-wide examples.
## Choose discovery separately
These settings are independent:
| Setting | Effect |
| --- | --- |
| Enable x402 payments | Applies the default or matching route price to callers using the payment fallback. |
| List in MiniUp Function Explorer | Shows the Function's description, methods, endpoint, tags, and exact price in MiniUp's directory. |
| Enable external x402 discovery | Adds compatible discovery metadata to the unpaid payment requirement. |
A paid API can be unlisted, listed only in MiniUp, or eligible for compatible external x402 discovery. Enabling paid access does not automatically enable either listing option. An unlisted paid Function can still share its documentation link.
For external discovery, describe the API and keep its example request and response accurate. For GET requests, use an object with example query parameters. For JSON request bodies, use an example object. Examples help describe input fields; they do not replace validation in your handler.
After publishing with external discovery enabled, select **Validate external discovery**. A passed result means the endpoint and its discovery metadata passed the current eligibility check. It does not confirm listing on Coinbase, Agentic.Market, or another directory. If the result needs attention, check the published endpoint, description, and examples and try again.
## Related guides
- [Choose Function access](https://www.miniup.io/docs/functions/access)
- [Test and publish a Function](https://www.miniup.io/docs/functions/create)
- [Document and share a Function API](https://www.miniup.io/docs/functions/directory)
- [Function Secrets](https://www.miniup.io/docs/functions/secrets)
## Check Coinbase Bazaar manually
These are four independent settings or observations:
- **Enable x402 payments** adds payment fallback to the selected access setting.
- **List in MiniUp Function Explorer** controls MiniUp's own directory listing.
- **Enable external x402 discovery** publishes compatible discovery metadata. **Validate external discovery** checks protocol eligibility, not indexing.
- **Check Coinbase Bazaar** looks for the exact Function endpoint in Coinbase's catalog. Another Function using the same payout wallet does not count.
Enable external discovery, publish, and complete a compatible successful paid request. External indexing may take time. Press **Check Coinbase Bazaar** when ready; listing and timing are not guaranteed. Coinbase describes this process in its [discovery guide](https://docs.cdp.coinbase.com/x402/seller/get-discovered).
MiniUp never continuously queries Coinbase. Opening or reloading the editor only displays the last saved observation and its **Last checked** time. **Check again** makes a new manual lookup.
**Indexed** means Coinbase returned this exact endpoint. **Not found yet** is a neutral result: allow time after a recent payment and check again. **Check unavailable** means the lookup could not establish a reliable result; it does not mean the resource is absent. Configuration changes make the previous observation historical. Disabling discovery does not remove an external listing.
Coinbase also makes discovery available to people browsing Agentic.Market. MiniUp does not independently verify that marketplace. Coinbase's current discovery response does not provide a public API detail-page link, so MiniUp shows the observed status without inventing an external link.
When Bazaar reports **Indexed**, select **View Bazaar details** to inspect the saved resource information inside MiniUp. The viewer uses a modal on desktop and a bottom sheet on mobile. It shows available service and payment details, copy actions, and a collapsed **Bazaar extension** section. Amounts are shown in the asset's base units.
Details come from the latest manual check. Opening, closing, or reopening them makes no Coinbase request. **Check again** refreshes the saved observation and the open viewer. Older observations may have no detailed metadata until you run another manual check.
## Usage and payments
Normal Function Usage counts authorized production executions across Public, API Key, Site Members, and x402 access, including free routes and executions that return errors. Payment challenges and rejected payments do not run the Function and do not count. A saved response replay does not count again. Preview bypasses production usage.
Paid calls and revenue remain separate: they count successful settled payments. A free execution adds one normal call and no paid call or revenue. Failed Function responses are not settled.
---
Source: https://www.miniup.io/docs/functions/secrets
Description: Save private credentials for Function code, keep them out of the browser, and publish changes to the live Function.
# Configure Function Secrets
Function Secrets store private credentials and make them available to your Function without exposing them in browser code. Use Secrets for Table write keys, server API keys, and credentials for external services.
## Save a Function Secret
1. Open **Functions → your Function → Secrets**.
2. Enter a **Secret name** such as `TABLE_API_URL`, `TABLE_WRITE_KEY`, or `EXTERNAL_API_KEY`.
3. Enter the value and choose **Add / Update**. Copying the value into a public code example is not necessary.
4. Reference the Secret by name from the Function's `env` argument.
5. Test the Function, then **Publish** again when the live Function should use the new Secret set.
Saved Secret values are not displayed back to users. The list shows names and update information. Store a recoverable copy in your own secure credential manager when appropriate.
## Use Secrets in Function code
```javascript
export default {
async fetch(request, env) {
if (request.method !== "GET") {
return Response.json({ error: "Method not allowed" }, { status: 405 });
}
// Add member/role authorization here if this is private data.
const response = await fetch(env.TABLE_API_URL + "?limit=25", {
headers: { "x-miniup-write-key": env.TABLE_WRITE_KEY }
});
if (!response.ok) {
return Response.json({ error: "Data unavailable" }, { status: 502 });
}
const data = await response.json();
return Response.json({ count: data.records.length });
}
};
```
This example returns only a count. Decide whether that result is public before choosing Public access. For a Developer API Table key, use the Table's `x-miniup-api-key` contract instead.
## Update or remove a Function Secret
Use **Add / Update** with the existing name to replace its value. Use **Delete** to remove a Secret. Publish again to update live behavior; saving or deleting a Secret alone does not update the live Function's Secret set. Test all callers after a credential rotation.
## Keep private data private
```text
Browser → Function → Secret-backed private service
```
Never return Secrets in a response, bootstrap configuration, error message, or log you expose to users. Do not place Secrets in Site HTML, JavaScript, public Function documentation, or AI prompts.
## Related guides
- [Function publishing lifecycle](https://www.miniup.io/docs/functions/create)
- [Backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
- [Complete member dashboard example](https://www.miniup.io/docs/examples/member-dashboard)
---
Source: https://www.miniup.io/docs/functions/site-members
Description: Link a Function to one MiniUp Site and use trusted member identity without putting a Function API key in browser code.
# Create a Site Members Function
A Site Members Function is a MiniUp Function linked to one MiniUp Site. It uses the Site's authenticated members and roles so browser code can call a secure backend without embedding a Function API key.
## Create a Site Members Function
1. Sign in as the Site owner and open **Dashboard → your Site → Functions**.
2. Create a Function and choose its name and slug, such as `my-app-api`.
3. Write the handler and use `env.MINIUP_USER` for trusted member identity.
4. Test a request in the editor, then **Publish**.
5. Open the actual linked Site as a member and call the Function with a relative URL.
```javascript
const response = await fetch("/api/functions/my-app-api/bootstrap");
if (!response.ok) throw new Error(`App request failed: ${response.status}`);
const app = await response.json();
```
Implement `/bootstrap` in your Function before calling it. It is an [application design pattern](https://www.miniup.io/docs/authenticated-apps/bootstrap), not an automatic endpoint.
## Understand the linked Site boundary
A Site Members Function is linked to one Site. A copied URL on another Site is not a substitute for that link. If a Function is no longer linked or the linked Site is unavailable, inspect its access settings and restore an appropriate owned Site link.
Site Access and Function access serve different purposes. A Public Site can show a public landing page while its Site Members Function still requires authenticated membership. A Password Site's shared password does not create a member identity. Use Invite-only or Private when the frontend files themselves should require membership.
## Test member authorization
Test from the published Site as Owner, as a lower-privilege member, and while signed out. The editor's preview does not replace this test. Each protected operation must check the trusted role and any record-specific permission in the Function.
## Related guides
- [Build an authenticated app](https://www.miniup.io/docs/authenticated-apps)
- [Use env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user)
- [Bootstrap an app](https://www.miniup.io/docs/authenticated-apps/bootstrap)
- [Backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
- [Site members and roles](https://www.miniup.io/docs/access/members)
---
Source: https://www.miniup.io/docs/functions/troubleshooting
Description: Diagnose Function 401, 403, method, origin, preview, dependency, quota, and publishing errors.
# Troubleshoot MiniUp Functions
Diagnose a Function failure by checking the request status, access mode, method, path, and whether the intended code has been published. A draft change does not change the live endpoint.
## Match the symptom to the next check
| Symptom | What to check |
| --- | --- |
| 401 Unauthorized | Required API key, or signed-in membership for a Site Members Function |
| 403 Forbidden | Member role, linked Site, and the Function's own authorization rules |
| 404 Not found | Copied endpoint, slug, linked Site, and route implemented by your handler |
| 405 Method not allowed | Allowed methods and the handler's method check |
| 429 or quota message | Function call usage, remaining allowance, and reset date |
| Browser-only failure | Allowed Web Origins; use same-origin URLs for Site Members Functions |
| Preview succeeds but live code differs | Publish the current draft and retest the live endpoint |
| Secret change has no live effect | Publish again to apply the current Secret set |
| Dependency error | Approved Trusted ESM source, import syntax, version, and supported module |
| Function error / 500 | Input parsing, handler exceptions, and external service failures |
## Debug one request at a time
1. Open the Function and confirm its status and last deployed information.
2. Reproduce the failing method, path, query, headers, and body in **Test** using safe test data.
3. Check whether the handler returns an error or the request fails before it reaches your app logic.
4. Correct the relevant setting or code. Test again, then publish code changes.
5. Verify from the intended caller: trusted server, public browser, or signed-in linked Site.
## Example: /bootstrap returns 404
`/bootstrap` only exists if your Function implements it. Check `url.pathname.endsWith("/bootstrap")` and confirm the handler was published. Then call `/api/functions/my-app-api/bootstrap` from the correct linked Site.
## Avoid hiding failures
A failed data call should show a visible error and retry option. Do not show an empty successful dashboard for an authorization failure. Keep credentials and private service responses out of browser error messages.
## Related guides
- [Function access](https://www.miniup.io/docs/functions/access)
- [Bootstrap pattern](https://www.miniup.io/docs/authenticated-apps/bootstrap)
- [Usage and limits](https://www.miniup.io/docs/limits-plans)
- [General troubleshooting](https://www.miniup.io/docs/troubleshooting)
---
Source: https://www.miniup.io/docs/functions/trusted-esm
Description: Use approved static HTTPS imports in MiniUp Functions and resolve dependencies during Test and Publish without an installation workflow.
# Use Trusted ESM in a Function
Trusted ESM lets a MiniUp Function use static HTTPS imports from approved sources. Use it when a small library provides useful functionality such as geometry helpers or data transformations.
## Add an approved import
1. Open **Functions → your Function → Code** and review the **Trusted ESM sources** shown in the editor.
2. Choose a browser-compatible ESM module from an approved HTTPS source. Pin an explicit version for predictable behavior.
3. Add a static import at the top of the Function code.
4. Run **Test** with a request that exercises the imported functionality.
5. Publish after the preview succeeds and test the live endpoint.
## Example using an approved geometry helper
Use this import only when `https://esm.sh/` appears in the editor's approved list.
```javascript
import { point } from "https://esm.sh/@turf/helpers@7.2.0";
export default {
async fetch(request) {
if (request.method !== "POST") {
return Response.json({ error: "Use POST" }, { status: 405 });
}
let input;
try { input = await request.json(); }
catch { return Response.json({ error: "Invalid JSON" }, { status: 400 }); }
const { lng, lat } = input;
if (!Number.isFinite(lng) || !Number.isFinite(lat) ||
Math.abs(lng) > 180 || Math.abs(lat) > 90) {
return Response.json({ error: "Valid lng and lat required" }, { status: 400 });
}
return Response.json(point([lng, lat]));
}
};
```
Test with POST and body `{"lng":-97.74,"lat":30.27}`. Enable POST in the Function's allowed methods.
## Understand dependency behavior
Imports are resolved during Test/Preview and Publish. Production execution does not need to fetch each imported dependency from a third-party source on every request. There is no `npm install` or `package.json` workflow for a MiniUp Function.
The approved list can change. Unsupported sources, unsupported import forms, incompatible modules, or dependency limits should produce a test/publish error. Resolve the error before publishing; do not assume every package available on an approved source can run in a Function. MiniUp shows the approved sources; ordinary Function users do not configure the global source policy.
## Related guides
- [Test and publish a Function](https://www.miniup.io/docs/functions/create)
- [Function troubleshooting](https://www.miniup.io/docs/functions/troubleshooting)
- [Supported runtime contracts](https://www.miniup.io/docs/reference/public-contracts)
---
Source: https://www.miniup.io/docs/getting-started/dashboard
Description: Locate Sites, API tables, Parquet, PDF Packs, Data Sources, Data Catalog, Functions, usage, and account settings.
# Find Features in the MiniUp Dashboard
The MiniUp Dashboard is your workspace for managing published Sites, data, Functions, and account usage. Sign in with the account that owns the content or has been invited to it.
## Navigate the Dashboard
1. Open **Dashboard** in the main navigation.
2. Use the section tabs to find **Pages**, **API**, **Parquet**, and **PDF Packs**. On smaller screens, related data choices appear in the Data menu.
3. Open **Data Sources**, **Data Catalog**, or **Functions** for those workspaces.
4. Search or sort the current list to find an existing resource. Open a Site to work with its files and data.
## Find features inside a Site
| Site tab or control | What you can do |
| --- | --- |
| Page | Edit files, add assets, preview, save changes |
| Settings → Access → Manage | Choose Site Access and manage invitations and members |
| Settings → Gallery | Set a listing, card title, description, thumbnail |
| Settings → Custom Domain | Connect and verify a domain |
| Settings → Revisions | Inspect and restore saved file snapshots |
| API | Import and manage MiniUp Tables and records |
| Functions | Create and manage the Site's member backend |
| Parquet | Upload, inspect, publish, and use datasets |
| PDF | Create and inspect PDF Knowledge Packs |
| AI Studio | Ask questions, edit, or run a Goal |
## Example: find the backend for a member app
Open **Dashboard → your Site → Functions**. The Site owner manages linked Functions. Other members may see an owner-managed explanation instead of editing controls. Having an Admin role inside an app does not automatically make someone the Function owner.
## Understand missing controls and empty lists
A new account starts with empty lists. Create a Site before adding Site data. A missing or disabled control may reflect your role, account availability, or a reached limit. Check **Current Usage** and [Plans](https://www.miniup.io/plans), then check the [member roles](https://www.miniup.io/docs/access/members) for shared Sites.
## Related guides
- [Manage account settings](https://www.miniup.io/docs/limits-plans/account)
- [Understand limits and usage](https://www.miniup.io/docs/limits-plans)
- [Use AI Studio](https://www.miniup.io/docs/chatgpt/ai-studio)
---
Source: https://www.miniup.io/docs/getting-started
Description: Understand MiniUp Sites, Tables, Functions, members, and the steps from a first page to a working application.
# Get Started with MiniUp
MiniUp turns HTML and data into shareable websites and lightweight applications. You can start without a build tool: publish HTML, CSS, JavaScript, and static assets, then add data or server-side logic when needed.
## What can you build with MiniUp?
Use MiniUp for reports, portfolios, event pages, dashboards, searchable directories, maps, forms, and member portals. A simple report may need only a Site. A booking form needs a Table. A member dashboard can combine Site Access, a Site Members Function, and private data.
## Understand the core MiniUp concepts
| Product concept | Purpose | Example |
| --- | --- | --- |
| MiniUp Site | Frontend files and content | A dashboard with HTML, CSS, and JavaScript |
| MiniUp Table | Editable records and a Table API | Bookings or customer requests |
| Hosted dataset | Reusable data for analysis and maps | A Parquet sales dataset |
| Site Access | Who can open a Site, plus members and roles | Invite-only team portal |
| MiniUp Function | Server-side application logic | Validate a submission or call a private service |
| ChatGPT / AI Studio | A creation and editing workflow | Generate an app from approved data |
## Publish and grow your first app
1. [Sign in and publish your first Site](https://www.miniup.io/docs/sites/publish). Signing in lets you manage it from Dashboard.
2. Open the published link and check it on a phone.
3. Visit [Dashboard](https://www.miniup.io/docs/getting-started/dashboard) to edit files and configure access.
4. Add a [Table](https://www.miniup.io/docs/tables) for records, or a [hosted dataset](https://www.miniup.io/docs/data) for analysis.
5. Add a [Function](https://www.miniup.io/docs/functions) when an operation needs private credentials or trusted authorization.
## Know what belongs in a Site
MiniUp Sites run browser-ready files. A project that requires a package installation, a build command, or a server process is not directly publishable as a Site. Export its static output first, or ask an AI to produce a no-build HTML/CSS/JavaScript app. Use MiniUp Functions for server-side request handling.
## Related guides
- [MiniUp Documentation home](https://www.miniup.io/docs)
- [Publish a MiniUp Site](https://www.miniup.io/docs/sites/publish)
- [Find features in Dashboard](https://www.miniup.io/docs/getting-started/dashboard)
- [Build an authenticated app](https://www.miniup.io/docs/authenticated-apps)
---
Source: https://www.miniup.io/docs
Description: Build, publish, connect data, and create authenticated applications with MiniUp.
# MiniUp Documentation
MiniUp lets you publish websites, host reusable data, build APIs, and create authenticated applications. Start with one HTML file, then add the capabilities your app needs.
New to MiniUp? Publish something small, then build on it.
[Start learning MiniUp →](https://www.miniup.io/docs/getting-started)[Publish your first site →](https://www.miniup.io/docs/sites/publish)
## Find your next step
See the documentation index for all learning paths: https://www.miniup.io/docs/index.json
## Choose a learning path
1. **Share content:** [publish a site](https://www.miniup.io/docs/sites/publish), [update files](https://www.miniup.io/docs/sites/files), and [share the result](https://www.miniup.io/docs/sites/sharing).
2. **Build a data app:** [create a Table](https://www.miniup.io/docs/tables), [call its API](https://www.miniup.io/docs/tables/api), or [reuse hosted datasets](https://www.miniup.io/docs/data/catalog).
3. **Build a member app:** configure [Site Access](https://www.miniup.io/docs/access), add a [Site Members Function](https://www.miniup.io/docs/functions/site-members), and follow the [complete example](https://www.miniup.io/docs/examples/member-dashboard).
4. **Create with AI:** [connect MiniUp in ChatGPT](https://www.miniup.io/docs/chatgpt), select a [Dataset Bundle](https://www.miniup.io/docs/data/bundles), and review the published app.
Browse all [app examples](https://www.miniup.io/docs/examples) when you are ready to build.
## Search and reference
Use the documentation search for feature names, tasks, or errors such as `401`, `403`, `bootstrap`, and `MINIUP_USER`. Search works on phones as well as desktop. [Troubleshooting](https://www.miniup.io/docs/troubleshooting) helps diagnose failed actions. The [glossary](https://www.miniup.io/docs/reference/glossary) explains product terminology.
For AI tools, use the [documentation index](https://www.miniup.io/docs/index.json), [llms.txt](https://www.miniup.io/llms.txt), or [full public documentation](https://www.miniup.io/llms-full.txt).
---
Source: https://www.miniup.io/docs/limits-plans/account
Description: Update your display name, change an enabled password login, and understand account identity and sign-in troubleshooting.
# Manage Your MiniUp Account Settings
Account Settings lets you review your MiniUp account identity and update your display name or an enabled password login. Site membership and Function API keys are managed separately.
## Update account settings
1. Sign in and open **Dashboard → Account Settings**.
2. Review the displayed email, username, and password-login status.
3. Edit **Display name** and save the change.
4. To change an enabled password login, enter **Current password**, **New password**, and **Confirm new password**, then save.
5. Leave password fields blank when you only want to change the display name.
## Understand password availability
The account panel indicates whether password login is enabled. If it says an administrator reset is required, the ordinary password-change form cannot enable that login method for you. Use your available sign-in method and the product's account recovery/support path.
Changing a display name does not transfer Site ownership or change a member's role. Use the [Site members panel](https://www.miniup.io/docs/access/members) for membership changes and the relevant API settings for key management.
## Troubleshoot missing Sites
Confirm you signed in to the same account that created the Site or accepted the invitation. A different email/account can show a different Dashboard. Review the invitation account if a shared Site is missing.
## Related guides
- [Dashboard overview](https://www.miniup.io/docs/getting-started/dashboard)
- [Site members and roles](https://www.miniup.io/docs/access/members)
- [Limits and Plans](https://www.miniup.io/docs/limits-plans)
---
Source: https://www.miniup.io/docs/limits-plans
Description: Find current feature availability, upload and data limits, Function calls, PDF usage, AI credits, and reset information.
# Understand MiniUp Limits and Plans
MiniUp limits depend on the account and enabled features. Use [Plans](https://www.miniup.io/plans) for the current public offering and the signed-in Dashboard's usage controls for the allowances that apply to you.
## Find your current limits
1. Open **Plans** to compare current feature availability and allowances.
2. Sign in and open **Dashboard → Current Usage** for your actual consumption and limits.
3. Check the feature's own panel before starting a large operation: Publish for uploads, Functions for calls, PDF for pack usage, and AI Studio for model/credit availability.
4. Read any displayed reset date or remaining allowance instead of assuming every quota resets on the same schedule.
## Understand the main usage categories
| Category | What to check |
| --- | --- |
| Publishing | HTML/file size, folder file count, Site count and storage |
| Revisions | Whether enabled and retained revision count |
| Tables | Table count, records per Table, import and API allowances |
| Notifications | Emails used and the daily allowance |
| Parquet / data | Import size, dataset size, rows, and storage |
| Functions | Function count, production calls this month, remaining calls, reset date |
| PDF Knowledge Packs | File/page and processing allowances shown for the workflow |
| AI Studio | Enabled models, credits, and run availability |
| Custom domains | Whether available for the account |
## Handle a reached limit
For example, if Function calls are exhausted, inspect the remaining count and reset information before retrying. For an oversized upload, reduce the actual file or split the data into a workflow the product supports. Removing unused resources may help count/storage limits, but should not be assumed to refund already consumed calls or processing usage.
Use the current plan controls if you need a different allowance. Confirm the change in your signed-in usage before depending on it. The docs intentionally avoid repeating numerical quotas that can differ by account or change over time.
## Related guides
- [Account settings](https://www.miniup.io/docs/limits-plans/account)
- [Function usage](https://www.miniup.io/docs/functions)
- [Supported formats](https://www.miniup.io/docs/reference/formats)
- [Troubleshooting](https://www.miniup.io/docs/troubleshooting)
---
Source: https://www.miniup.io/docs/parquet/browser
Description: Load hosted Parquet using the copied access instructions and query bounded results with DuckDB or DuckDB-Wasm.
# Use Parquet in a Browser or DuckDB
Use the dataset's copied access instructions to read hosted Parquet. MiniUp provides a stable access URL for tools and a browser grant URL for browser apps; browser code should obtain a fresh download URL on each load.
## Find the correct dataset URLs
1. Open **Dashboard → your Site → Parquet** and select the published dataset.
2. Open **Use this data** and its data/API or advanced usage instructions.
3. Copy the exact **Stable access endpoint** or **Browser grant endpoint** for your workflow.
4. Verify dataset access for the intended caller. Do not guess endpoints or reuse an expired download URL.
The following examples use placeholders for values copied from that UI. The access and browser grant URLs are public usage contracts; temporary download URLs should not be saved in app code.
## Read Parquet with DuckDB
For a publicly readable dataset, replace the URL below with its stable access endpoint:
```sql
INSTALL httpfs;
LOAD httpfs;
SELECT *
FROM read_parquet('https://example.com/COPIED_STABLE_ACCESS_URL')
LIMIT 25;
```
Use exact schema names. For example, after confirming `region` and `revenue` exist, select `region, sum(revenue)` and group by `region` instead of downloading all rows into a chart.
## Load a dataset with DuckDB-Wasm
This browser example uses the setup shown by MiniUp. Replace `COPIED_BROWSER_GRANT_URL` with the dataset's browser grant URL, add `
Loading…
` to your HTML, and run this as a module script.
```javascript
import * as duckdb from "https://cdn.jsdelivr.net/npm/@duckdb/duckdb-wasm/+esm";
const status = document.querySelector("#status");
let db, connection, workerUrl;
try {
const bundle = await duckdb.selectBundle(duckdb.getJsDelivrBundles());
workerUrl = URL.createObjectURL(new Blob(
[`importScripts(${JSON.stringify(bundle.mainWorker)});`],
{ type: "text/javascript" }
));
db = new duckdb.AsyncDuckDB(new duckdb.ConsoleLogger(), new Worker(workerUrl));
await db.instantiate(bundle.mainModule, bundle.pthreadWorker);
await db.open({ path: ":memory:" });
connection = await db.connect();
const grant = await fetch("COPIED_BROWSER_GRANT_URL", {
method: "POST", cache: "no-store"
});
if (!grant.ok) throw new Error(`Dataset access failed (${grant.status})`);
const { url } = await grant.json();
const response = await fetch(url, { cache: "no-store" });
if (!response.ok) throw new Error(`Download failed (${response.status})`);
await db.registerFileBuffer("data.parquet", new Uint8Array(await response.arrayBuffer()));
const result = await connection.query("SELECT * FROM read_parquet('data.parquet') LIMIT 25");
status.textContent = result.numRows ? result.toString() : "No records found.";
} catch (error) {
status.textContent = error.message;
} finally {
await connection?.close();
await db?.terminate();
if (workerUrl) URL.revokeObjectURL(workerUrl);
}
```
## Understand size and access limitations
This example downloads the file into browser memory before querying it. A bounded SQL result does not make that initial download smaller. Use appropriately sized datasets, precomputed summaries, or the supported layer/query workflow for larger maps. Avoid rendering every record at once.
A 401 or 403 requires reviewing dataset access and the calling Site. If a temporary URL expires, request a fresh grant. Never add private credentials to frontend code to work around a denied request.
## Related guides
- [Publish Parquet](https://www.miniup.io/docs/parquet)
- [GeoParquet geometry and maps](https://www.miniup.io/docs/parquet/geoparquet)
- [Dataset access](https://www.miniup.io/docs/data/access)
---
Source: https://www.miniup.io/docs/parquet/geoparquet
Description: Review geometry, build maps from GeoParquet, publish read-only ArcGIS-compatible layers, or create an editable MiniUp layer.
# Use GeoParquet and Map Layers
GeoParquet combines tabular data with geometry for maps and spatial analysis. MiniUp can publish spatial data as a hosted dataset and offers map/layer workflows from the dataset detail view.
## Prepare geometry correctly
1. Open the dataset's **Parquet** detail or upload preview.
2. Review its geometry information and coordinate fields.
3. If using latitude and longitude, select the correct fields before publishing.
4. Preview the map and confirm that features appear in the expected location.
GeoParquet geometry may appear as WKB binary or a hex value beginning with `0x`. That is not GeoJSON text. Decode it with a compatible geometry library or use the supplied map/layer workflow. Do not pass raw WKB directly to a map library expecting GeoJSON.
## Publish a read-only layer
From **Use this data**, open the ArcGIS/map sharing workflow and publish the read-only ArcGIS-compatible layer when available. Copy the resulting service URL and use it in the supported map client, such as ArcGIS Online. Check the read-only status and dataset access before sharing it.
A read-only layer is useful for distributing a published spatial dataset. It does not make the original external ArcGIS source editable.
## Create an editable MiniUp layer
If the app needs spatial record edits, use the dataset detail's option to create a separate editable MiniUp layer. Choose its name, slug, and access preset, then review its records and API. The editable layer is a separate resource; do not assume edits synchronize back to the source Parquet file or external service.
## Example: parks and service requests
Publish park boundaries as a read-only layer and keep incoming service requests in an editable Table/layer. Load only features relevant to the current map area and only the fields needed by the UI.
## Troubleshoot map placement and size
Check longitude versus latitude order, coordinate values, geometry encoding, and the dataset's spatial metadata. A map with thousands of complex features may need bounded queries or simplified data. Test on a phone before sharing it.
## Related guides
- [Connect ArcGIS Data Sources](https://www.miniup.io/docs/data/arcgis)
- [Parquet browser usage](https://www.miniup.io/docs/parquet/browser)
- [Dataset access](https://www.miniup.io/docs/data/access)
- [Tables and APIs](https://www.miniup.io/docs/tables)
---
Source: https://www.miniup.io/docs/parquet
Description: Upload tabular or spatial files, review schema and coordinates, and publish reusable Parquet or GeoParquet data.
# Publish Parquet and GeoParquet Datasets
Parquet is a column-oriented data format suited to analytical queries. GeoParquet adds geometry information for spatial datasets. MiniUp lets you convert supported files into hosted datasets for dashboards, maps, and other apps.
## Publish a dataset
1. Open **Dashboard → your Site → Parquet**.
2. Under **Upload data**, choose a source file: CSV, XLSX, XLS, ZIP shapefile, GeoJSON, JSON, Parquet, or GeoParquet.
3. Set the dataset name and slug, and review the detected schema and sample rows.
4. For spatial data, verify the geometry or select the correct latitude and longitude fields. If detection is ambiguous, choose both columns explicitly.
5. Complete the conversion/publish action and wait for a successful result.
6. Open the published dataset's detail view, inspect its format, row count, size, and access.
7. Use **Use this data** to copy the relevant app, map, or data usage instructions.
## Choose Parquet instead of a Table
Use Parquet for analytical reads and larger data files that do not need individual record editing. Use a [MiniUp Table](https://www.miniup.io/docs/tables) or [editable layer](https://www.miniup.io/docs/parquet/geoparquet) when users must create or update records. Replacing or refreshing a dataset is different from editing a single Table record.
## Keep large-data apps responsive
Select only the columns needed, aggregate before charting, and page through rows. Avoid turning the entire dataset into JavaScript objects just to display a small table. Browser memory still matters; a compact file can require more memory after loading and processing.
## Example: a regional sales dashboard
Upload a sales CSV, inspect the exact region and amount field names, publish Parquet, then use [DuckDB in the browser](https://www.miniup.io/docs/parquet/browser) to calculate regional totals and display one page of records at a time.
## Related guides
- [Use Parquet with DuckDB and browsers](https://www.miniup.io/docs/parquet/browser)
- [GeoParquet and map layers](https://www.miniup.io/docs/parquet/geoparquet)
- [Dataset access](https://www.miniup.io/docs/data/access)
- [Limits and usage](https://www.miniup.io/docs/limits-plans)
---
Source: https://www.miniup.io/docs/pdf/apps
Description: Use the PDF App Prompt, improve app data with AI, and create source-backed action applications from a completed pack.
# Build Apps from PDF Knowledge Packs
A completed PDF Knowledge Pack can supply an app preview, an AI App Builder Prompt, and source-backed action-app workflows. Start from a completed pack and verify its extracted content before generating an application.
## Use the App Prompt
1. Open **Dashboard → your Site → PDF** and select a completed pack.
2. Select **Copy AI App Builder Prompt**.
3. Give the prompt to your coding AI and describe the intended audience and task.
4. Ask for a static MiniUp app with clear source references, loading, empty, and error states.
5. Use **Publish App** for the available publishing workflow, then verify the resulting Site and its source access as the intended visitor.
## Improve App Data with AI
Choose **Improve App Data with AI** when the control is available. Review the selected options and usage implications, run the improvement, and wait for completion. Use the **AI enhanced** comparison view to inspect changes against the original app data. AI enhancement should be reviewed, especially for formulas, numerical values, or instructions extracted from a source.
## Create an Action App
Select **Create Action App** when the required source artifacts are available. Follow the dialog to choose the app/table workflow and review the proposed structure and source-backed fields. Confirm the destination and access, then inspect the generated records and app before sharing.
For example, a maintenance manual can become a checklist application. Check that each generated action is supported by the source and that missing or ambiguous instructions remain visible as gaps.
## Important access and quality notes
AI output is not proof of source accuracy. Preserve source references and verify representative results. Public app content and copied artifacts can expose the underlying document information. Choose access intentionally and avoid copying private credentials into prompts or generated files.
## Related guides
- [Create a PDF Knowledge Pack](https://www.miniup.io/docs/pdf)
- [Use MiniUp with ChatGPT](https://www.miniup.io/docs/chatgpt)
- [Table permissions](https://www.miniup.io/docs/tables/permissions)
- [Security principles](https://www.miniup.io/docs/security)
---
Source: https://www.miniup.io/docs/pdf
Description: Turn a PDF upload, URL, or Site file into source-backed artifacts, an App Prompt, and app-ready knowledge.
# Create a PDF Knowledge Pack
A PDF Knowledge Pack turns a PDF into source-backed content and app-ready artifacts. Use it to build a manual viewer, reference tool, study app, or other application grounded in a source document.
## Create a PDF Knowledge Pack
1. Open **Dashboard → your Site → PDF**.
2. Choose a PDF upload, supported PDF URL import, or existing PDF from the Site. You can also use the PDF conversion action beside a PDF in the Page tab.
3. Set **Save as** and decide whether to **Replace existing pack at this path**.
4. Select **Create PDF Pack** and wait for the job to finish.
5. Select the job to inspect status, progress, errors, and completed artifacts.
6. Preview important extracted text, tables, definitions, formulas, or examples against the original PDF before using them.
## Use the completed pack
Use **Open App** to inspect the app-ready result. **Copy AI App Builder Prompt** provides the App Prompt for a coding AI. The prompt gives the AI source-backed content and usage instructions so it can build from the pack rather than inventing the PDF's contents.
Artifact controls let you **Preview**, **Copy**, or open the available formats. Use source references when presenting extracted facts in an app. Not every PDF contains every artifact type, and extraction may need review for scanned pages, complex tables, or unusual layouts.
## Example: a product manual app
Import the manual, inspect its sections and source references, and copy the App Prompt. Ask the AI to build a searchable guide that links answers back to the relevant source, displays a “not found in source” state, and avoids inventing missing specifications.
## Understand access and sharing
The pack belongs to its Site. Review Site and artifact access before sharing a generated app or copied artifact. Do not assume an owner preview proves that an unauthenticated visitor can load the same content. Copying extracted text into a Public Site makes that copy public; changing the source pack's access cannot retract copies already shared.
## Troubleshoot a PDF job
Check the PDF file or direct source URL, current size/page allowance, and the job's error. A failed job is not a usable completed pack. Retry after fixing the cause. Use **Delete** only when you intend to remove the selected job/pack and have reviewed its downstream use.
## Related guides
- [Build apps from PDF Packs](https://www.miniup.io/docs/pdf/apps)
- [AI prompt patterns](https://www.miniup.io/docs/chatgpt/prompts)
- [Site Access](https://www.miniup.io/docs/access)
- [Usage and limits](https://www.miniup.io/docs/limits-plans)
---
Source: https://www.miniup.io/docs/reference/formats
Description: Match HTML, CSV, Excel, spatial data, Parquet, or PDF files to the appropriate MiniUp publishing and import workflow.
# Choose a Supported MiniUp File Format
MiniUp supports different formats for Site publishing, Table import, hosted data conversion, and PDF Knowledge Packs. Choose the workflow based on how the app will use the content.
## Supported formats by workflow
| Workflow | Supported formats |
| --- | --- |
| Site | HTML, CSS, JavaScript, and static assets; upload HTML, a folder, or a ZIP |
| Table import | CSV and XLSX |
| Parquet conversion | CSV, XLSX, XLS, ZIP shapefile, GeoJSON, JSON, Parquet, GeoParquet |
| HTTP Data Source | CSV, JSON, JSONL, NDJSON, GeoJSON, Parquet, GeoParquet |
| ArcGIS Data Source | FeatureServer or queryable MapServer layer URL |
| PDF Knowledge Pack | PDF upload, supported PDF URL, or an existing Site PDF |
## Choose the correct upload tool
1. Use **Publish** for a browser-ready Site and its assets.
2. Use the Site's **API** tab for CSV/XLSX data that needs editable records.
3. Use **Parquet** for larger analytical or spatial datasets. A ZIP in this workflow means a supported shapefile package, not a static Site project.
4. Use **PDF** for source-backed document knowledge.
5. Use **Data Sources** for a repeatable supported web-file or ArcGIS connection.
## Prepare source files
Give columns meaningful names and consistent value types. Include the required companion files in a shapefile ZIP. Put a Site's main HTML at `index.html` and include its referenced assets. A filename extension alone does not make incompatible content valid.
## Example format choice
Use XLSX → Table for a small editable request list. Use CSV → Parquet for an analytical dashboard. Use GeoJSON → GeoParquet or a layer workflow for maps. Use PDF → Knowledge Pack for a source-backed reference app.
## Important limits
Accepted format does not mean unlimited file size or row count. Review the upload panel and [current usage](https://www.miniup.io/docs/limits-plans). If an unsupported file arrives, export it to a supported format before importing.
## Related guides
- [Publish a Site](https://www.miniup.io/docs/sites/publish)
- [Create a Table](https://www.miniup.io/docs/tables)
- [Publish Parquet](https://www.miniup.io/docs/parquet)
- [Create a PDF Pack](https://www.miniup.io/docs/pdf)
---
Source: https://www.miniup.io/docs/reference/glossary
Description: Understand MiniUp Sites, Tables, Functions, Site Access, members, Secrets, Trusted ESM, data features, and AI workflows.
# MiniUp Glossary
The MiniUp glossary defines the product terms used in Dashboard, APIs, and documentation. Follow a linked term for its setup and usage guide.
## Sites and access
- **[MiniUp Site](https://www.miniup.io/docs/sites):** a published collection of HTML, CSS, JavaScript, and static assets with a Site URL.
- **[Site Access](https://www.miniup.io/docs/access):** the Public, Password, Invite-only, or Private setting that controls who can open a Site.
- **[Site member](https://www.miniup.io/docs/access/members):** a signed-in person with a current role on a Site.
- **[Role](https://www.miniup.io/docs/access/members):** Owner, Admin, Editor, or Viewer permissions associated with Site membership.
- **[Gallery](https://www.miniup.io/docs/sites/sharing):** public discovery listings for Sites; listing is separate from access.
- **[Custom domain](https://www.miniup.io/docs/sites/custom-domains):** a hostname you own and connect to a Site.
- **[Revision](https://www.miniup.io/docs/sites/revisions):** a retained Site-file snapshot that can be restored.
## Tables and Functions
- **[MiniUp Table](https://www.miniup.io/docs/tables):** editable records with a schema and Table API.
- **[Schema](https://www.miniup.io/docs/tables):** the field names and data types expected in a dataset or Table.
- **[Table API](https://www.miniup.io/docs/tables/api):** the public HTTP interface for allowed Table record operations.
- **[Write key / server key](https://www.miniup.io/docs/tables/permissions):** a credential for the Table actions authorized by its current settings.
- **[MiniUp Function](https://www.miniup.io/docs/functions):** server-side JavaScript that receives a request and returns a response.
- **[Site Members Function](https://www.miniup.io/docs/functions/site-members):** a Function linked to one MiniUp Site that uses trusted current member identity.
- **[env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user):** the trusted member's id, email, name, role, and siteId inside a Site Members Function.
- **[Function Secrets](https://www.miniup.io/docs/functions/secrets):** private named values available to Function code and not displayed after saving.
- **[Trusted ESM](https://www.miniup.io/docs/functions/trusted-esm):** approved static HTTPS module imports for Functions, resolved during Test/Publish.
- **[Allowed Web Origins](https://www.miniup.io/docs/functions/access):** the websites permitted to call a standalone Function from browser code.
- **[Bootstrap](https://www.miniup.io/docs/authenticated-apps/bootstrap):** an optional app-defined endpoint returning safe startup identity and UI configuration.
## Data and AI
- **[Data Source](https://www.miniup.io/docs/data/sources):** a saved supported external data connection used to create or refresh snapshots.
- **[Snapshot](https://www.miniup.io/docs/data/sources):** the dataset produced by a successful import at a particular time.
- **[Data Catalog](https://www.miniup.io/docs/data/catalog):** the owner's searchable inventory of hosted datasets across Sites.
- **[Dataset Bundle](https://www.miniup.io/docs/data/bundles):** an explicit approved selection of datasets for one app, with a safe descriptive manifest.
- **[Dataset access](https://www.miniup.io/docs/data/access):** the per-dataset policy governing source-app, selected-app, or public reading.
- **[Parquet](https://www.miniup.io/docs/parquet):** a column-oriented format for analytical data.
- **[GeoParquet](https://www.miniup.io/docs/parquet/geoparquet):** Parquet with geometry information for spatial data.
- **[PDF Knowledge Pack](https://www.miniup.io/docs/pdf):** source-backed artifacts and app-ready knowledge produced from a PDF.
- **[App Prompt](https://www.miniup.io/docs/pdf/apps):** instructions and source context from a Knowledge Pack for an AI app-building workflow.
- **[AI Studio](https://www.miniup.io/docs/chatgpt/ai-studio):** the Site workspace for MiniUp Agent's Ask, Edit, and Goal workflows.
- **[x402 Agent API](https://www.miniup.io/docs/chatgpt/agent):** the public API for compatible agents using authorized per-action payments.
## Use the glossary
For example, if an app needs trusted role checks, start with Site Members Function, then env.MINIUP_USER and backend authorization. If it needs several existing datasets, start with Data Catalog and Dataset Bundle.
## Related guides
- [Get Started](https://www.miniup.io/docs/getting-started)
- [Public contracts](https://www.miniup.io/docs/reference/public-contracts)
- [Reference home](https://www.miniup.io/docs/reference)
---
Source: https://www.miniup.io/docs/reference
Description: Look up public API contracts, supported file formats, product terms, and the documentation index.
# MiniUp Product Reference
The MiniUp product reference defines the public concepts, formats, and request contracts used throughout the guides. Use it when you know the feature and need a precise term or supported workflow.
## Find the right reference
1. Use the [glossary](https://www.miniup.io/docs/reference/glossary) to identify an unfamiliar product term.
2. Check [supported formats](https://www.miniup.io/docs/reference/formats) before choosing an import workflow.
3. Read [public contracts](https://www.miniup.io/docs/reference/public-contracts) for Table, Function, dataset, and agent usage.
4. Use [limits and usage](https://www.miniup.io/docs/limits-plans) to find current account allowances.
## Example lookup
If a guide asks for a “Site Members Function,” the glossary explains the concept, the public contract reference lists its browser call pattern, and the [Site Members guide](https://www.miniup.io/docs/functions/site-members) gives the setup steps.
## Use Docs with AI and agents
The [public JSON index](https://www.miniup.io/docs/index.json) contains page titles, descriptions, URLs, sections, and keywords. [llms.txt](https://www.miniup.io/llms.txt) lists primary learning paths. [llms-full.txt](https://www.miniup.io/llms-full.txt) provides public documentation text generated from the same content as these pages.
## Related guides
- [Glossary](https://www.miniup.io/docs/reference/glossary)
- [Supported formats](https://www.miniup.io/docs/reference/formats)
- [Public contracts](https://www.miniup.io/docs/reference/public-contracts)
---
Source: https://www.miniup.io/docs/reference/public-contracts
Description: Find intentional public Table APIs, Function calls, member identity fields, dataset usage links, and Agent API discovery.
# MiniUp Public API and Runtime Contracts
MiniUp's public contracts are the URLs, headers, formats, and runtime values intentionally provided for customers to build applications. Copy resource-specific URLs from the product instead of guessing paths.
## Public application contracts
| Contract | Usage |
| --- | --- |
| MiniUp Site URL | Open and share a published Site; commonly `https://my-site.miniup.app` |
| Table base URL | Commonly `https://my-site.miniup.app/api/data/my-site/my-table` |
| Table schema URL | Table base URL plus `/schema` |
| Table record URL | Table base URL plus `/RECORD_ID` |
| `x-miniup-write-key` | Table write/read credential where specified by that Table |
| `x-miniup-api-key` | Server Table key or Function API key, scoped to the corresponding resource |
| Function endpoint | Copy the standalone endpoint from the Function editor |
| `/api/functions/my-api/...` | Browser call from the linked MiniUp Site to a Site Members Function |
| `env.MINIUP_USER` | Trusted member identity inside a Site Members Function |
| Function Secrets | Named values read through the Function's `env` argument |
| Dataset access/grant URLs | Copy the stable or browser usage URL from the dataset's instructions |
| Agent discovery | [Public Agent API](https://www.miniup.io/api/x402) and [current pricing](https://www.miniup.io/api/x402/pricing) |
## Make a public request
1. Create the resource and copy its public URL.
2. Verify allowed methods, access, and any required public credential header.
3. Use the request/response example for that resource type.
4. Check HTTP status before treating a response as successful.
For example, a member frontend calls `/api/functions/my-api/bootstrap` only after you have implemented and published that path. `/bootstrap` is an [app design pattern](https://www.miniup.io/docs/authenticated-apps/bootstrap), not an automatic MiniUp endpoint.
## Understand common statuses
- **400:** invalid input; inspect the request format and field values.
- **401:** required authentication or credential is missing or invalid.
- **403:** access or operation is forbidden for this caller.
- **404:** resource or application path is not found.
- **405:** method is not allowed.
- **429:** request allowance or rate limit reached; inspect current usage.
- **5xx:** operation failed; inspect the relevant product error and retry only when appropriate.
An app's own Function may return additional statuses. Use the response body and product context rather than assuming every error has one cause.
## Related guides
- [Table API requests](https://www.miniup.io/docs/tables/api)
- [Function access](https://www.miniup.io/docs/functions/access)
- [env.MINIUP_USER](https://www.miniup.io/docs/authenticated-apps/miniup-user)
- [Parquet browser usage](https://www.miniup.io/docs/parquet/browser)
---
Source: https://www.miniup.io/docs/security
Description: Choose appropriate access, keep credentials out of browser code, authorize backend operations, and review data sharing.
# Secure Your MiniUp App
Secure a MiniUp app by choosing Site and dataset access intentionally, keeping private credentials in Function Secrets, and authorizing every protected backend operation.
## Configure an app's security boundaries
1. Choose [Site Access](https://www.miniup.io/docs/access) for the intended audience.
2. Invite only the needed members and assign the least powerful useful role.
3. Review each Table and file's [dataset access](https://www.miniup.io/docs/data/access), including public links and cross-site grants.
4. Put private service credentials in [Function Secrets](https://www.miniup.io/docs/functions/secrets).
5. Enforce roles and record ownership in the [Site Members Function](https://www.miniup.io/docs/authenticated-apps/authorization).
6. Test with a lower-privilege account and while signed out before sharing.
## Example: private applications with a public landing page
A Public Site can show general information while a Site Members Function requires membership for private operations. Do not put private records in the public HTML or download them before authorization. If even the frontend files should be restricted, use Invite-only or Private Site Access.
## Protect browser-visible information
Anything returned to browser code can be inspected by the visitor. Bootstrap responses should contain only safe identity and configuration. Hiding an Admin button, JavaScript module, Gallery listing, or link does not protect an API or dataset.
Allowed Web Origins controls which websites can make browser requests; it does not authenticate non-browser callers. An API Key Function should be called from trusted code when a private key is required.
## Respond to a shared credential
Replace or revoke the affected key using its product controls, update trusted callers, and publish again when Function Secrets changed. Remove exposed values from public files and examples. Changing a key does not remove copies of data already disclosed.
## Related guides
- [Function API key rotation](https://www.miniup.io/docs/functions/access)
- [Table permissions and keys](https://www.miniup.io/docs/tables/permissions)
- [Backend authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
- [Members and roles](https://www.miniup.io/docs/access/members)
---
Source: https://www.miniup.io/docs/sites/custom-domains
Description: Connect your own hostname to a MiniUp Site, add the displayed DNS records, and verify the public address.
# Connect a Custom Domain
A custom domain lets visitors open a MiniUp Site at a hostname you own. Configure it in the Site's **Page settings → Custom Domain** panel when the feature is enabled for your account.
## Before connecting a domain
You need a published Site, permission to manage its settings, and access to the domain's DNS records. Choose the exact hostname, such as `portal.example.com`. Check [Plans](https://www.miniup.io/plans) and the panel for current availability.
## Add and verify a custom domain
1. Open **Dashboard → your Site → Page → Page settings → Custom Domain**.
2. Enter the hostname in **Domain** and save it.
3. Copy the DNS record type, host, and value displayed by MiniUp into your domain's DNS settings. Use the panel's current values rather than values from an old guide.
4. Remove conflicting records for that same hostname if necessary. Do not change unrelated domain records.
5. Return to MiniUp and use the verification or status check control after DNS changes have taken effect.
6. Open the hostname over HTTPS and test the Site's pages, assets, and data.
## Example: a branded member portal
Connect `portal.example.com` to your existing MiniUp Site. Keep Invite-only access enabled. Test a member sign-in on the new hostname and ensure application requests use relative Site Function URLs such as `/api/functions/my-api/bootstrap`.
## Troubleshoot domain verification
Check spelling, the exact hostname, and the record values shown in the panel. A root domain and `www` are different hostnames; configure the one you intend to use. DNS updates may take time. If a domain was connected elsewhere, remove the old conflicting assignment before retrying.
Use the domain panel to remove a connection when it is no longer needed, and update shared links and DNS accordingly. A custom domain changes the address, not who is authorized to use the Site or its datasets.
## Related guides
- [Site Access](https://www.miniup.io/docs/access)
- [Share a Site](https://www.miniup.io/docs/sites/sharing)
- [Call Site Members Functions](https://www.miniup.io/docs/functions/site-members)
---
Source: https://www.miniup.io/docs/sites/files
Description: Edit HTML, CSS, and JavaScript, add or replace assets, and validate changes while keeping the Site URL.
# Update Files in a MiniUp Site
Update an existing MiniUp Site in **Dashboard → your Site → Page**. Editing or replacing files at their existing paths updates the Site without creating a new Site URL.
## Before editing Site files
Use an account with editing access. Download a copy of important files or check [revision availability](https://www.miniup.io/docs/sites/revisions) before large changes. Site files must remain browser-ready; private credentials belong in Function Secrets.
## Edit and save a file
1. Open the Site's **Page** tab.
2. Select the file to edit. Use the code editor for text such as HTML, CSS, and JavaScript.
3. Make the change and save it with the editor's save control.
4. Open or refresh the Site preview, then check the actual published URL.
5. Test the feature you changed, including its loading, empty, and error states when it uses data.
## Add, replace, download, or delete files
Use the file upload controls to add individual assets or multiple project files. Review the destination path before replacing an existing file. Use the file actions to download a copy or delete an unwanted file. Deleting a referenced file can break the published page; update the references as part of the change.
For example, add `components/reports.js` and import it with `import("./components/reports.js")` from `app.js`. The file path is part of your application, so keep it consistent across uploads and imports.
## Troubleshoot a change that seems missing
Confirm you saved the correct file in the correct Site. Check the published URL rather than an old preview. Reload the browser and verify the path and case of any updated asset. If the change breaks the Site, [restore a revision](https://www.miniup.io/docs/sites/revisions) or upload your saved copy.
## Related guides
- [Revision history and rollback](https://www.miniup.io/docs/sites/revisions)
- [Use AI Studio to edit a Site](https://www.miniup.io/docs/chatgpt/ai-studio)
- [Frontend visibility and authorization](https://www.miniup.io/docs/authenticated-apps/authorization)
---
Source: https://www.miniup.io/docs/sites
Description: Choose HTML, file, folder, or ZIP publishing and learn how to maintain and share a MiniUp Site.
# Sites and Publishing
A MiniUp Site is a published collection of frontend files with a shareable URL. Use a Site for a standalone page or a multi-file application with data and a linked Function.
## Choose a publishing workflow
| Starting point | Workflow |
| --- | --- |
| HTML copied from an AI or editor | Paste HTML on Publish |
| One HTML document | Upload the HTML file |
| HTML plus styles, scripts, images, or documents | Upload a folder |
| A packaged static project | Upload a ZIP |
| An existing MiniUp Site | Edit or add files in Dashboard |
## Publish and maintain a Site
1. Prepare browser-ready files and put the main page in `index.html`.
2. [Publish the Site](https://www.miniup.io/docs/sites/publish) with an available name.
3. [Set Site Access](https://www.miniup.io/docs/access) before sharing sensitive content.
4. [Update files](https://www.miniup.io/docs/sites/files), check the live result, and use [revision history](https://www.miniup.io/docs/sites/revisions) when you need to roll back.
5. Share the URL, create a QR code, or add a [Gallery listing](https://www.miniup.io/docs/sites/sharing).
## Example project
```text
index.html
styles.css
app.js
images/logo.svg
```
Reference `./styles.css`, `./app.js`, and `./images/logo.svg` from the HTML. Keep spelling and letter case consistent. A saved change at the same file path keeps the existing link useful.
## Related guides
- [Publish a MiniUp Site](https://www.miniup.io/docs/sites/publish)
- [Connect a custom domain](https://www.miniup.io/docs/sites/custom-domains)
- [Build an authenticated app](https://www.miniup.io/docs/authenticated-apps)
---
Source: https://www.miniup.io/docs/sites/publish
Description: Publish pasted HTML, an HTML file, a folder, or a ZIP project and get a shareable MiniUp Site URL.
# Publish a MiniUp Site
Publish a MiniUp Site from the **Publish** page by pasting HTML or uploading an HTML file, folder, or ZIP. MiniUp gives the Site a URL you can open and share.
## Prepare your Site
Sign in first if you want to manage the Site from Dashboard. Prepare a no-build static project with a main `index.html`. Check the upload limits shown on Publish; folder file counts and per-file limits apply even when files arrive in a ZIP.
## Publish HTML or a project
1. Open [Publish](https://www.miniup.io/).
2. Choose the HTML input, HTML file upload, folder upload, or ZIP upload for your content.
3. For pasted HTML, supply a complete document. For a folder or ZIP, include the main page and all local assets with their relative paths.
4. Enter the Site name and resolve any availability or naming error. Names are 3–64 characters using letters, numbers, hyphens, or underscores; reserved names cannot be used.
5. Review the preview and access choice, then publish. Wait for the successful result before leaving.
6. Open the returned URL. Test images, navigation, forms, and data loading on the published Site.
## Copy a minimal HTML page
```html
My first MiniUp Site
Hello from MiniUp
My first published page.
```
## Understand the Site URL and index.html
A Site URL typically looks like `https://my-site.miniup.app`. Copy the actual URL shown by MiniUp, especially when using a custom domain. The root opens the Site's main page. Put `index.html` at the project root and keep links relative so the folder structure works after upload. Do not assume a source project folder is its publishable output.
## Fix common publishing problems
- **Name unavailable:** choose another name; do not repeatedly submit a reserved name.
- **Blank page:** inspect the main HTML file and browser errors; remove dependencies on a local development server.
- **Missing styles or images:** check relative paths and include the referenced files in the folder or ZIP.
- **Upload rejected:** check format, file count, and size limits. Remove unrelated project files before retrying.
## Related guides
- [Supported file formats](https://www.miniup.io/docs/reference/formats)
- [Update Site files](https://www.miniup.io/docs/sites/files)
- [Control Site Access](https://www.miniup.io/docs/access)
---
Source: https://www.miniup.io/docs/sites/revisions
Description: Review saved Site file snapshots and restore an earlier revision when a published change needs to be rolled back.
# Restore a Site Revision
Site revision history lets you restore an earlier saved version of Site files. Use it to recover from an unwanted edit or a broken publishing change.
## Restore a saved revision
1. Sign in with editing access and open **Dashboard → your Site → Page → Page settings → Revisions**.
2. Review the saved snapshots and timestamps. MiniUp shows whether revisions are enabled and how many are retained for your account.
3. Choose the revision that contains the version you need.
4. Select **Restore** and review the confirmation: restoring replaces the current page files with the selected snapshot.
5. Open the published Site and verify its assets and application behavior.
## Example: undo a broken dashboard edit
If yesterday's dashboard worked and today's file changes broke the chart, choose yesterday's snapshot, restore it, and verify the chart and navigation. Keep a copy of any newer work you may still need before restoring.
## Understand revision limits
History is subject to account limits and retained snapshots. An empty list does not mean every previous edit is recoverable. Site file rollback is not a rollback of Table records, Function code, or external service data. Make separate copies of data before destructive edits.
The current Function editor exposes draft and deployed code workflows, not a Site-style revision restore browser. Keep your own copy of Function code before replacing it.
## Related guides
- [Update Site files](https://www.miniup.io/docs/sites/files)
- [Function publishing lifecycle](https://www.miniup.io/docs/functions/create)
- [Limits and usage](https://www.miniup.io/docs/limits-plans)
---
Source: https://www.miniup.io/docs/sites/sharing
Description: Share MiniUp Site links, customize a QR code, and control public Gallery discovery with a title, description, and thumbnail.
# Share a Site, Create a QR Code, and Use Gallery
Share a MiniUp Site by copying its published URL, generating a QR code, or listing it in Gallery. Sharing a link does not override the Site's access restrictions.
## Share a Site URL or QR code
1. Open **Dashboard** and find the Site.
2. Use the Site's link or copy action to copy its published URL.
3. Open the **QR** action to create a QR code. Use the available appearance controls, then download it.
4. Scan the downloaded code on another device and check the destination before printing it.
A QR code for an Invite-only Site still takes visitors through the required member access. Use a normal link alongside a QR code so people who cannot scan it can still open the Site.
## List a Site in Gallery
1. Open **Dashboard → your Site → Page → Page settings → Gallery**.
2. Add a **Card Title**, **Short Description**, and **Thumbnail** that describe the public content.
3. Enable **Show in Gallery** and save the settings.
4. Check [Gallery](https://www.miniup.io/gallery) to see the listing when Gallery is available.
You can also use **Show in Gallery** or **Hide from Gallery** on the Dashboard Site card. A listing may be unavailable or hidden by product moderation. Keep sensitive names and images out of Gallery metadata.
## Understand discovery versus access
An unlisted Public Site can still be opened by anyone with its URL. Gallery is a discovery choice, not an access control. Set [Site Access](https://www.miniup.io/docs/access) separately. For example, share a public event landing page in Gallery, but keep the volunteer portal Invite-only.
## Related guides
- [Site Access modes](https://www.miniup.io/docs/access)
- [Connect a custom domain](https://www.miniup.io/docs/sites/custom-domains)
- [Publish a Site](https://www.miniup.io/docs/sites/publish)
---
Source: https://www.miniup.io/docs/tables/api
Description: Read, filter, create, update, and delete Table records using public URLs, request headers, and JavaScript or curl examples.
# Use a MiniUp Table API
A MiniUp Table API lets an application read and change Table records over HTTP. Copy the public API URL from the Table's API information and use the allowed methods and credentials shown for that Table.
## Find the public Table API URL
1. Open **Dashboard → your Site → API** and select the Table.
2. Open its API information or **OpenAPI Quick Doc** and copy the base URL.
3. Review the schema, current access permissions, and generated request examples.
For a Site named `my-site` and Table slug `customer-leads`, a typical base URL is:
```text
https://my-site.miniup.app/api/data/my-site/customer-leads
```
Use the actual copied URL if your Site uses a different hostname. The schema URL is the base URL plus `/schema`. A record URL is the base URL plus `/RECORD_ID`.
## Read records from a browser
This example requires a Table with public GET access. Render values as text, not untrusted HTML.
```javascript
const response = await fetch(
"https://my-site.miniup.app/api/data/my-site/customer-leads?limit=25&offset=0"
);
if (!response.ok) throw new Error(`Table request failed: ${response.status}`);
const data = await response.json();
const rows = data.records.map(record => ({ id: record.id, ...record.fields }));
console.log(rows);
```
List responses contain `records`, with each record exposing `id` and `fields`. An empty array is a valid empty result. Request another page with a larger offset rather than loading the entire Table at once.
## Create, update, and delete from trusted code
These examples use the write-key contract. Enable the relevant method and use the credential shown for your Table. For a Developer API server key, replace the key header with `x-miniup-api-key: YOUR_API_KEY`.
```bash
# Create one record
curl -X POST 'https://my-site.miniup.app/api/data/my-site/customer-leads' -H 'Content-Type: application/json' -H 'x-miniup-write-key: YOUR_WRITE_KEY' --data '{"record":{"name":"Avery","email":"avery@example.com"}}'
# Update the specified record
curl -X PATCH 'https://my-site.miniup.app/api/data/my-site/customer-leads/RECORD_ID' -H 'Content-Type: application/json' -H 'x-miniup-write-key: YOUR_WRITE_KEY' --data '{"fields":{"name":"Avery Chen"}}'
# Delete the specified record
curl -X DELETE 'https://my-site.miniup.app/api/data/my-site/customer-leads/RECORD_ID' -H 'x-miniup-write-key: YOUR_WRITE_KEY'
```
For public insert Tables, the authorized POST workflow does not require a private browser key. Public insert does not authorize GET, PATCH, or DELETE.
## Filter, sort, and summarize a Table
| Public query parameter | Purpose |
| --- | --- |
| `limit`, `offset`, `includeTotal` | Page through results and request a total |
| `field`, `value` or `filterField`, `filterValue` | Match a field value |
| `sortField`, `sortDir` | Sort with `asc` or `desc` |
| `q`, `searchFields` | Search selected fields |
| `dateField`, `dateFrom`, `dateTo` | Restrict a date range |
| `fields` or `columns`, `compact` | Select a smaller response shape |
| `aggregate`, `aggregateField`, `groupBy` | Request count, sum, avg, min, or max summaries |
| `bbox`, `longitudeField`, `latitudeField` | Restrict coordinate records to a map area |
Use exact schema field names and URL-encode values with `URLSearchParams`. Start with the default record shape before opting into compact or aggregate responses, which have different shapes. For example, `?field=status&value=open&limit=25` fetches a bounded page of open records.
## Handle Table API errors
Check `response.ok` before parsing success data. Show an error rather than an empty successful table when access fails. Review [permissions and keys](https://www.miniup.io/docs/tables/permissions) for 401, 403, or 405. Reduce request size for limit errors and retry transient failures without blindly repeating a create request that may already have succeeded.
## Related guides
- [Table permissions and keys](https://www.miniup.io/docs/tables/permissions)
- [Use Power Query](https://www.miniup.io/docs/tables/power-query)
- [Complete member dashboard example](https://www.miniup.io/docs/examples/member-dashboard)
---
Source: https://www.miniup.io/docs/tables
Description: Design a Table or import CSV and Excel, review its schema, and add, edit, delete, or export records.
# Create and Manage a MiniUp Table
A MiniUp Table stores editable records and provides a Table API for applications. Use Tables for forms, bookings, directories, and other data that changes one record at a time. Use [Parquet](https://www.miniup.io/docs/parquet) for larger analytical datasets.
## Create a MiniUp Table
Sign in and create or choose a destination Site first.
1. Open **Dashboard → API** and choose **Design Table**, or open **Dashboard → your Site → API** to import a file.
2. Give the Table a descriptive name and a stable slug such as `customer-leads`.
3. In Design Table, add columns with names and types: **Text**, **Number**, **True / False**, or **Date**. Choose the access preset appropriate to the app.
4. For import, choose a **CSV** or **XLSX** file, set **First row is header**, and review inferred names, types, and sample rows. Clean blank headers and mixed types in the source before importing.
5. Review **Require API key for reads** and the Table's action permissions. Finish creating or importing the Table.
6. Open the Table and check its records and generated API information.
## Add, edit, and delete records
Use the Table's record viewer to add values matching the schema. Select a record to edit its fields, save it, and verify the result. Use the delete action only for records you intend to remove. The record ID identifies the record for API updates; it is not the row's current position in a sorted view.
Use sorting and pagination or lazy loading to inspect records. Use the available export action to download data before bulk changes. Empty Tables show no records until you add or import them.
## Example: a customer request Table
Create `customer-requests` with Text columns `name`, `email`, and `message`. Choose **Form / Booking / RSVP** if visitors should submit requests but should not read everyone else's submissions. Use an [authenticated app](https://www.miniup.io/docs/authenticated-apps) when the business workflow requires individual member permissions.
## Important Table access notes
The Table's API methods and access requirements both matter. A key does not enable a disabled method. A Public Site does not automatically make every Table public. Never put a server key or private write key into public JavaScript.
## Related guides
- [Configure Table permissions and keys](https://www.miniup.io/docs/tables/permissions)
- [Use a Table API](https://www.miniup.io/docs/tables/api)
- [Configure Table notifications](https://www.miniup.io/docs/tables/notifications)
---
Source: https://www.miniup.io/docs/tables/notifications
Description: Notify the Table owner when new rows arrive, customize the email template, and send a test notification.
# Configure Table Email Notifications
Table notifications send the Table owner an email when a new row is added. Use them for a form, booking request, or RSVP workflow that needs attention without repeatedly checking the Table.
## Enable a Table notification
1. Open the Table's record/API viewer and the notification control.
2. Enable **Enable email notification when a new row is added**.
3. Set the subject and message. Use the variable selector to insert supported values such as the Table name, row summary, page URL, and creation time.
4. Review the template preview and select **Save notification**.
5. Select **Send test email** and check the Table owner's inbox.
## Example notification template
```text
Subject: New row added to {{table_name}}
A new request arrived.
{{row_summary}}
Open: {{page_url}}
Submitted: {{created_at}}
```
Use the UI's variable list when inserting record fields. Keep sensitive values out of email if email is not an appropriate destination for that data.
## Understand delivery and limits
Notifications depend on feature availability, a usable owner email address, and the daily email allowance shown in usage. A successful record insert and successful email delivery are separate outcomes. If notifications stop, check that the setting is saved, review the daily allowance, and use a test email before resubmitting real records.
## Related guides
- [Create a Table](https://www.miniup.io/docs/tables)
- [Form access permissions](https://www.miniup.io/docs/tables/permissions)
- [Limits and usage](https://www.miniup.io/docs/limits-plans)
---
Source: https://www.miniup.io/docs/tables/permissions
Description: Choose Table access presets, allowed methods, public inserts, read access, server API keys, and write keys.
# Configure Table Permissions and Keys
Table permissions control who can read, create, update, or delete records. Choose an access preset, then inspect the enabled actions and any additional key requirement before connecting an app.
## Choose a Table access preset
Open **Dashboard → API**, find the Table, and review its **Access preset** and allowed-action summary.
| Preset | Reads | Writes | Use it for |
| --- | --- | --- | --- |
| Public Dataset | Public | Disabled | Open directories and reference data |
| Form / Booking / RSVP | Private | Public insert only | Collect submissions without exposing them |
| Internal Admin Table | Same-Site access | Editors | Management tools for Site collaborators |
| Developer API | Server API key | Server API key | Trusted server or Function integrations |
Custom access settings may differ from these presets. Read the current Read, Insert, Update, and Delete summary rather than inferring access from the Table name.
## Configure methods and keys
1. Open the Table's API settings and enable only the required actions: **GET**, **POST**, **PATCH**, and **DELETE**. Update examples may also use PUT where the update action is enabled.
2. Choose read and write access appropriate to your audience. **Insert access** can distinguish disabled, editor-only, public insert, and API-key access.
3. For **Developer API**, use **Server key** to create a key with the needed Table/action scope. Copy it when shown and store it privately.
4. If the Table's generated example uses a write key, send it in `x-miniup-write-key`. A server API key uses `x-miniup-api-key`. Follow the example for that Table; these are not interchangeable credentials.
5. Test an allowed request and a request without the required key. Disabled actions must remain unavailable.
## Revoke Table server keys
Open **Server key → Revoke all keys** and review the confirmation. Revoking all server keys stops trusted callers using those keys immediately. Create a replacement key only for the required actions, update the affected Function Secret or trusted caller, and publish the Function again when its Secret changed. Table server-key revocation is separate from the legacy write-key contract.
## Keep credentials out of browser files
Put a private Table credential in [Function Secrets](https://www.miniup.io/docs/functions/secrets) and let the Function call the Table. A key included in HTML, JavaScript, a public URL, or an AI prompt can be copied by others. Use public insert only when anonymous submissions are intentional.
For read-key-protected Tables, reads and schema requests require the configured credential. Selected-site dataset sharing still needs an explicit compatible grant; knowing a dataset URL does not grant access.
## Troubleshoot a rejected Table request
A **401** suggests a missing or invalid required credential. A **403** suggests the caller lacks permission. A **405** indicates an unavailable method. Check both the action switch and access mode, and confirm the key is scoped to the correct Table and operation.
## Related guides
- [Use a Table API](https://www.miniup.io/docs/tables/api)
- [Share datasets across Sites](https://www.miniup.io/docs/data/access)
- [Build an authenticated app](https://www.miniup.io/docs/authenticated-apps)
---
Source: https://www.miniup.io/docs/tables/power-query
Description: Load a public MiniUp Table into Excel or Power BI with Power Query and expand record fields.
# Read a Table API with Power Query
Power Query can read a MiniUp Table API and turn its records into a worksheet or report. Use this workflow when you want a refreshable view in Excel or Power BI.
## Before connecting Power Query
Copy the Table's public API URL and confirm GET is enabled. The example below uses public read access and returns the first 100 records. For private data, use an appropriately secured credential workflow rather than distributing a workbook containing a private key.
## Add a Power Query
1. In Excel or Power BI, create a blank query and open its Advanced Editor.
2. Paste the query below and replace the URL with the Table URL shown by MiniUp.
3. Run the query and inspect the returned columns.
4. Load the result into your worksheet or model. Refresh it when you need current records.
```text
let
Source = Json.Document(Web.Contents(
"https://my-site.miniup.app/api/data/my-site/customer-leads",
[Query = [limit = "100", offset = "0"]]
)),
Rows = List.Transform(Source[records], each [fields]),
Result = Table.FromRecords(Rows)
in
Result
```
## Fetch more than one page
The example is intentionally bounded. For a larger Table, create a pagination query that advances `offset` and combines returned pages until no records remain. Do not assume one response contains all records. A Table export is useful when you need a one-time full copy rather than a refreshable connection.
## Troubleshoot Power Query
A 401 or 403 requires checking Table access and credentials. A missing column may reflect the Table's actual schema or an empty response. If the source data changed, refresh the query and review downstream transformations.
## Related guides
- [Public Table API reference](https://www.miniup.io/docs/tables/api)
- [Table permissions](https://www.miniup.io/docs/tables/permissions)
- [Parquet and DuckDB](https://www.miniup.io/docs/parquet/browser)
---
Source: https://www.miniup.io/docs/troubleshooting
Description: Diagnose publishing, access, data, Function, PDF, AI, and custom-domain problems using visible product information.
# Troubleshoot MiniUp Publishing and Apps
Start troubleshooting with the exact Site or resource, the action attempted, and the visible error. Check whether the failure is in a draft preview, a published app, or an account management screen.
## Diagnose common symptoms
| Symptom | Next step |
| --- | --- |
| Site upload fails | Check file format, name availability, file count, and current upload size limits |
| Blank published Site | Confirm root index.html, referenced assets, and browser-ready JavaScript |
| Update not visible | Confirm the right Site/file was saved and the intended version was published |
| Member cannot enter | Check signed-in account, invitation acceptance, current role, and Site Access |
| Data returns 401 or 403 | Check Table key/access settings and cross-site dataset grants |
| Function returns 404 or 405 | Check slug, implemented route, and allowed HTTP method |
| Function call quota reached | Read current Function usage, remaining allowance, and reset date |
| Data Source refresh fails | Test URL, credentials, schema, source availability, and import limits |
| Map is empty or misplaced | Verify geometry, coordinates, query area, and data access |
| PDF Pack fails | Review the job error and source PDF before retrying |
| AI result is incomplete | Review staged files, preview errors, model availability, and credits |
| Domain does not verify | Compare exact hostname and DNS records with the current domain panel |
## Debug a published app
1. Copy the actual published URL and reproduce the problem in the intended account.
2. Check Site Access, dataset access, Function access, and published status for the affected resources.
3. Inspect the browser's visible request status or the Function Test result without sharing private credentials.
4. Repair the relevant setting or file and rerun the same action.
5. Test on another browser or phone when the issue concerns layout or browser access.
## Example: an empty table after deployment
Distinguish a successful API response containing no records from a failed request. A 403 should produce an access error, not a “No records” message. Check the dataset grant and Table permissions before changing UI code.
## When to request help
If the visible controls and linked guides do not resolve the issue, provide the public Site URL, feature name, action, time, and sanitized error. Do not send keys, passwords, private records, or Function Secrets. MiniUp's [FAQ](https://www.miniup.io/faqs) includes its support contact.
## Related guides
- [Function troubleshooting](https://www.miniup.io/docs/functions/troubleshooting)
- [Site publishing](https://www.miniup.io/docs/sites/publish)
- [Dataset access](https://www.miniup.io/docs/data/access)
- [Limits and Plans](https://www.miniup.io/docs/limits-plans)