SQLite / libsql: 7 data plane verbs, one client
A SQLite database file, or a Turso libsql database. No server and no user — a file connection is as private as the disk it sits on. Every call below is available over HTTP, through the SDK and as a tool for a coding agent, with the same arguments and the same meter.
What SQLite / libsql can do here
SQLite / libsql is not an HTTP API. Browsed as tables or collections rather than called as endpoints — the schema is read from the server and is what makes a caller-supplied table name safe. It answers introspect, read, count, insert, update, remove and raw. A SQLite database file, or a Turso libsql database. No server and no user — a file connection is as private as the disk it sits on.
How it authenticates
SQLite / libsql authenticates with a authToken and a encryptionKey, supplied per request or stored once against your account and sealed at rest.
Called by name, not by capability
SQLite / libsql does not currently map onto a vendor-neutral capability, so you call its operations by name. That is the right shape when you genuinely mean this provider — which, for a service with its own model of the world, is most of the time.
- introspect — data plane
- read — data plane
- count — data plane
- insert — data plane
- update — data plane
- remove — data plane
- raw — data plane
Questions
Do I have to bring my own API keys?
You can, and that lane is free for ever — pass your key on the request or store it against your account, and we are one proxy hop. The paid lane is the other direction: we call 228 providers with our credentials so you never register anywhere. Both go through the same client and the same operation names.
What happens to a key I store here?
It is sealed with AES-256-GCM before it reaches the database and is only ever opened to make the call you asked for. It is scoped to your account, it is never logged, and deleting the connection deletes it. For an OAuth provider we hold a refresh token instead, and revoking the link at the provider stops the calls here immediately.
What happens when a provider changes its API?
The operation contract is declared, so a response that no longer matches is a refusal rather than a silently wrong answer. The contract does not coerce types — a field declared a number that arrives as a string is rejected at the edge, on the way in and on the way out.