PocketBase API Rules

Installation
SKILL.md

PocketBase API Rules & Filter Expressions

Rule Types

Each collection has 5 rule types. Each rule is a filter expression that must evaluate to true for the request to proceed.

Rule Controls Locked = Empty string =
List GET /api/collections/{name}/records superusers only everyone can list
View GET /api/collections/{name}/records/{id} superusers only everyone can view
Create POST /api/collections/{name}/records superusers only everyone can create
Update PATCH /api/collections/{name}/records/{id} superusers only everyone can update
Delete DELETE /api/collections/{name}/records/{id} superusers only everyone can delete

Critical: null/locked means only superusers can perform the action (regular users and guests are denied). Empty string "" means EVERYONE including guests. Superusers always bypass API rules entirely — see below.

Superuser Bypass

Superusers (formerly admins) always bypass API rules. Rules only apply to regular auth records and guests.

Related skills

More from davila7/claude-code-templates

Installs
GitHub Stars
27.2K
First Seen