insforge

作者: insforge

使用此技能編寫InsForge或@insforge/sdk的應用程式碼時:資料庫CRUD、認證、儲存上傳/儲存RLS、函式、OpenRouter AI、即時功能、電子郵件、Stripe或Razorpay付款,或將S3相容工具(aws CLI、AWS SDKs、rclone、Terraform、boto3)指向InsForge Storage。在遇到新增認證、擷取資料、上傳檔案、將儲存桶設為公開、新增結帳、銷售訂閱或傳送電子郵件等請求時觸發。對於基礎設施、SQL遷移、CLI命令或付款供應商...

npx skills add https://github.com/insforge/insforge-skills --skill insforge

InsForge App Integration Skill

This skill covers client-side SDK integration using @insforge/sdk. For backend infrastructure operations (creating tables, inspecting schema, deploying functions, secrets, managing storage buckets, configuring payment provider keys/catalog, website deployments, cron job and schedules, logs, etc.), use the insforge-cli skill.

Quick Setup

1. Install the SDK

npm install @insforge/sdk@latest

2. Set up environment variables

Before using the SDK, create a .env file (or .env.local for Next.js) in your project root with your InsForge URL and anon key.

How to get your URL and anon key

  1. Ensure the project is linked. Check for .insforge/project.json in the project root.

    • Generate it with npx -y @insforge/cli link for an existing project or npx -y @insforge/cli create for a new project.
  2. Get the anon key via the CLI:

    npx -y @insforge/cli secrets get ANON_KEY
    
  3. Get the URL from the oss_host field in .insforge/project.json (e.g., https://myapp.us-east.insforge.app).

  4. Write both values to the .env file using the correct framework prefix (see table below).

Important: Use the anon key for user-scoped SDK clients, including SSR. For privileged server-only app code that needs admin/service access, use createAdminClient({ apiKey }); the API key is a full-access admin key, equivalent to a service role key on other platforms.

Use the correct environment variable prefix and access pattern for your framework:

Framework.env fileVariablesAccess Pattern
Next.js.env.localNEXT_PUBLIC_INSFORGE_URL, NEXT_PUBLIC_INSFORGE_ANON_KEYprocess.env.NEXT_PUBLIC_*
Vite (React, Vue, Svelte).envVITE_INSFORGE_URL, VITE_INSFORGE_ANON_KEYimport.meta.env.VITE_*
Astro.envPUBLIC_INSFORGE_URL, PUBLIC_INSFORGE_ANON_KEYimport.meta.env.PUBLIC_*
SvelteKit.envPUBLIC_INSFORGE_URL, PUBLIC_INSFORGE_ANON_KEYimport { env } from '$env/dynamic/public'
Create React App.envREACT_APP_INSFORGE_URL, REACT_APP_INSFORGE_ANON_KEYprocess.env.REACT_APP_*
Node.js / Server.envINSFORGE_URL, INSFORGE_ANON_KEYprocess.env.*

Example .env.local for Next.js:

NEXT_PUBLIC_INSFORGE_URL=https://your-appkey.us-east.insforge.app
NEXT_PUBLIC_INSFORGE_ANON_KEY=eyJhbGciOiJIUzI1NiIs...

Important: Keep .env files local. Add .env, .env.local, and .env*.local to your .gitignore and keep .env.example for documenting required variables.

3. Initialize the client

Next.js:

import { createClient } from '@insforge/sdk'

const insforge = createClient({
  baseUrl: process.env.NEXT_PUBLIC_INSFORGE_URL,
  anonKey: process.env.NEXT_PUBLIC_INSFORGE_ANON_KEY
})

Vite:

import { createClient } from '@insforge/sdk'

const insforge = createClient({
  baseUrl: import.meta.env.VITE_INSFORGE_URL,
  anonKey: import.meta.env.VITE_INSFORGE_ANON_KEY
})

Astro:

import { createClient } from '@insforge/sdk'

const insforge = createClient({
  baseUrl: import.meta.env.PUBLIC_INSFORGE_URL,
  anonKey: import.meta.env.PUBLIC_INSFORGE_ANON_KEY
})

For trusted server-only code that needs project-admin access:

import { createAdminClient } from "@insforge/sdk";

const admin = createAdminClient({
  baseUrl: process.env.INSFORGE_URL,
  apiKey: process.env.INSFORGE_API_KEY,
});

Module Reference

ModuleIntegration Guide
Databasedatabase/sdk-integration.md
Authauth/sdk-integration.md
Storagestorage/sdk-integration.md
Functionsfunctions/sdk-integration.md
AIai/overview.md
Real-timerealtime/sdk-integration.md
Emailemail/sdk-integration.md
Payments: Stripepayments/stripe.md
Payments: Razorpaypayments/razorpay.md

What Each Module Covers

ModuleContent
DatabaseCRUD operations, filters, pagination, RPC calls
AuthSign up/in, OAuth, sessions, profiles, password reset
StorageUpload, download, delete files; S3-compatible gateway for CI / backup tooling; write RLS policies for buckets
FunctionsInvoke edge functions
AIOpenRouter AI calls for chat, images, video, audio, embeddings, and model discovery
EmailSend custom transactional HTML emails (welcome, newsletter, notifications)
Payments: StripeStripe Checkout Sessions, subscriptions, and Billing Portal redirects
Payments: RazorpayRazorpay Orders, Subscriptions, Checkout.js, and subscription management
Real-timeConnect, subscribe, publish events, and track presence snapshots plus join/leave deltas

Guides

GuideWhen to Use
../insforge-cli/references/database/access-control.mdBackend setup for application-table access control — covers RLS, infinite recursion prevention, SECURITY DEFINER patterns, performance tips, and common InsForge patterns
storage/s3-gateway.mdFallback path when the consumer is existing S3 tooling (aws CLI, AWS SDKs, rclone, Terraform, boto3) and adopting @insforge/sdk is impractical — covers endpoint/region setup, access-key management, path-style addressing, and supported vs. not-supported S3 operations. Requires InsForge 2.0.9+. Prefer the SDK (storage/sdk-integration.md) for app code
storage/postgres-rls.mdWriting RLS policies for storage.objects — owner-only, public-read, path-scoped, team-shared, and the NULL uploaded_by caveat for mixed REST + S3 buckets
../insforge-cli/references/database/vector.mdBackend setup for semantic search, recommendations, or RAG — covers the vector extension, schema/dimensions, distance operators, HNSW/IVFFlat indexes, and RPC similarity search
ai/chat-completions.mdText generation, structured answers, and streaming chat through OpenRouter
ai/image-generation.mdImage generation/editing through OpenRouter, then durable storage in InsForge Storage
ai/video-generation.mdAsync OpenRouter video jobs, status polling, and storing generated media
ai/audio.mdSpeech-to-text, text-to-speech, and storing audio assets/transcripts with InsForge
ai/embeddings-and-rag.mdGenerating embeddings through OpenRouter, storing them in pgvector, and wiring up a basic RAG pipeline
ai/models-list.mdDiscovering OpenRouter model IDs, modalities, parameters, pricing, and embedding dimensions
paymentsConfiguring Stripe/Razorpay keys, syncing provider catalog, setting up webhooks, and writing payment RLS before app integration

Building Payments for a New App

First choose the provider. There is no generic app payments guide:

Before writing app code, check provider setup with the insforge-cli payments references:

npx -y @insforge/cli payments stripe status
npx -y @insforge/cli payments razorpay status

If the chosen provider is unconfigured, ask the developer/admin to configure that provider first.

Real-time Backend Setup

The real-time SDK is for frontend event handling and messaging. Configure channel patterns, database triggers, and channel/message RLS with the insforge-cli skill; see realtime.

Backend Configuration

Supported project config knobs are managed via the CLI — use npx -y @insforge/cli config export/plan/apply for auth redirect URLs, verification flags, password policy, auth SMTP settings, storage upload size, realtime/schedule retention, and cloud deployment subdomain. OAuth providers, external app setup, storage buckets, functions, secrets, and deployment env vars still use their dedicated dashboard or CLI flows. See the insforge-cli skill's Configuration section.

Risky backend changes? Use a branch first

When a code change in this skill depends on a schema migration, new RLS policy, OAuth provider config change, or any other backend change that affects prod behavior, create a backend branch first. Branches share JWT_SECRET (existing user JWTs keep working) but get a fresh database + EC2 + API_KEY / ANON_KEY, so you can test the SDK + backend change end-to-end in isolation.

The full branching workflow lives in the insforge-cli skill — see branch for the decision guide and lifecycle commands. Typical loop:

npx -y @insforge/cli branch create feat-x --mode schema-only
# ... apply migrations / change auth config / update RLS on the branch ...
# ... test the SDK against the branch backend ...
npx -y @insforge/cli branch merge feat-x --dry-run     # review SQL
npx -y @insforge/cli branch merge feat-x               # apply to parent

After branch create or branch switch, update the app's InsForge URL and anon-key env values, then restart your dev server (or re-source .env) so the SDK talks to the selected branch backend.

SDK Quick Reference

All SDK methods return { data, error }.

ModuleMethods
insforge.database.from().select(), .insert(), .update(), .delete(), .rpc()
insforge.auth.signUp(), .signInWithPassword(), .signInWithOtp() / .verifyOtp(), .signInWithOAuth(), .signOut(), .getCurrentUser()
insforge.storage.from().upload(), .uploadAuto(), .download(), .remove()
insforge.functions.invoke()
insforge.aiDeprecated fallback only: .chat.completions.create(), .images.generate(), .embeddings.create()
insforge.realtime.connect(), .subscribe(), .publish(), .on(), .disconnect()
insforge.emails.send({ to, subject, html, cc?, bcc?, from?, replyTo? })
insforge.payments.stripe.createCheckoutSession(), .createCustomerPortalSession()
insforge.payments.razorpay.createOrder(), .verifyOrder(), .createSubscription(), .verifySubscription(), .cancelSubscription(), .pauseSubscription(), .resumeSubscription()

Important Notes

  • Database inserts require array format: insert([{...}])
  • Bandwidth-efficient reads: Name columns and .limit() list reads; never poll unbounded select() on an interval — subscribe with realtime (paired with a realtime.publish trigger) or poll a cheap ordered probe instead. Wasteful query shapes are the top cause of projects exhausting their monthly egress allowance. Probe snippet and full rules: database/sdk-integration.md.
  • Next.js / SSR auth: Use @insforge/sdk/ssr helpers (createBrowserClient, createServerClient, createAuthActions, createRefreshAuthRouter) and import updateSession from @insforge/sdk/ssr/middleware in Proxy/Middleware. Keep the refresh token httpOnly, run auth mutations through createAuthActions() on the server, return only safe app data from Server Actions, and let the browser read the short-lived access token for Storage/Realtime. See auth/ssr-integration.md
  • Storage: Save both url AND key to database for download/delete operations
  • Functions invoke URL: Prefer insforge.functions.invoke(slug) — the SDK owns route construction. For raw HTTP: the project base URL serves the compat path /functions/{slug}, while the functions deployment host (e.g. *.function2.insforge.app) serves the slug at root /{slug}
  • Email delivery: Auth emails (signup verification, password reset, magic links, invites) ship on every plan. Custom email via insforge.emails.send() ships on every paid plan. Use the platform-managed delivery path; custom sender domain is dashboard config. See email/sdk-integration.md.
  • Payments: Configure provider keys/catalog with npx -y @insforge/cli payments <provider> ... first; frontend code uses provider-scoped SDK modules.
  • Payment RLS: Before payment UI, add app-specific RLS on provider runtime tables. Stripe uses payments.stripe_checkout_sessions and payments.stripe_customer_portal_sessions; Razorpay uses payments.razorpay_orders and payments.razorpay_subscriptions. Durable fulfillment triggers go on payments.webhook_events, not success URLs, Checkout callbacks, or payments.transactions.
  • Use Tailwind CSS v3.4
  • Always local build before deploy: Prevents wasted build resources and faster debugging
  • SDK package: Use @insforge/sdk directly for all features including authentication.
  • Deployment: Include a vercel.json in the project root for SPA routing (React, React Router apps). The download-template tool includes this automatically.
  • Branching for risky backend changes: If your SDK code depends on a new schema, RLS policy, or auth config change, create a branch via npx -y @insforge/cli branch create first — see the insforge-cli skill's branch reference. After branch create / branch switch, update the app's InsForge URL and anon-key env values, then restart the dev server.
  • Hit an InsForge-side hurdle? When the SDK, backend, docs, or a skill misbehaves — an API that should work but errors (--type bug), a capability you need that isn't supported (--type feature-request), docs that contradict actual behavior (--type bug --component docs with --doc/--expected) — report it and continue with a workaround: npx -y @insforge/cli feedback --json --type <bug|feature-request|friction> --component <backend|sdk|cli|skills|docs> --title "..." --detail "...", adding --language <lang> for SDK issues (no login required; PII is redacted locally). See the insforge-cli skill's Feedback section for the full flag set and situation→type mapping. Never file feedback for problems in the app code you are writing.

來自 insforge 的更多技能

insforge-debug
insforge
在 InsForge 專案中診斷問題時使用 — 反應式故障(SDK 錯誤物件、HTTP 4xx/5xx、閘道逾時 502/503/504、邊緣函式失敗或逾時、登入/OAuth/驗證錯誤、RLS 拒絕、即時通道問題、單一端點查詢緩慢、邊緣函式或 Vercel 部署失敗)、主動式稽核(安全性/RLS 審查、效能/索引審查、系統健康檢查、上線前準備),或當使用者遇到錯誤但不知從何著手時。
insforge
insforge
在撰寫 InsForge 或 @insforge/sdk 的應用程式碼時使用此技能:資料庫 CRUD、驗證、儲存上傳/儲存 RLS、函式、OpenRouter AI、即時功能、電子郵件、Stripe 或 Razorpay 付款,或將 S3 相容工具(aws CLI、AWS SDK、rclone、Terraform、boto3)指向 InsForge Storage。觸發於如新增驗證、擷取資料、上傳檔案、將儲存桶設為公開、新增結帳、銷售訂閱或傳送電子郵件等請求。針對基礎設施、SQL 遷移、CLI 指令或付款供應商...
developmentdatabaseaws
insforge-cli
insforge
每當有人需要後端,或任務涉及透過 InsForge CLI 操作 InsForge 後端或雲端基礎設施時,使用此技能:專案、SQL、遷移、RLS 政策、函式、儲存、部署、運算、密鑰、設定、排程、日誌、診斷、匯入/匯出、AI/OpenRouter 設定、Stripe/Razorpay 付款、Apify 網頁爬取/資料來源、PostHog 產品分析、後端分支、代理記憶(記住/回顧專案事實與決策),或 CLI 文件。若涉及應用程式碼...
developmentdatabasedevops
insforge-integrations
insforge
在將外部驗證提供者(Clerk、Auth0、WorkOS、Kinde、Stytch、Better Auth)接入 InsForge 以實現基於 JWT 的 RLS 時使用,或是在新增 OKX x402 支付中介以實現鏈上按用量計費時使用。
insforge-debug
insforge
用於診斷 InsForge 專案中的問題時使用 — 反應式故障(SDK 錯誤物件、HTTP 4xx/5xx、閘道逾時 502/503/504、邊緣函式失敗或逾時、登入/OAuth/驗證錯誤、RLS 拒絕、即時通道問題、單一端點查詢緩慢、邊緣函式或 Vercel 部署失敗)、主動式稽核(安全性/RLS 審查、效能/索引審查、系統健康檢查、上線前準備),或當使用者遇到錯誤但不知從何開始時。
insforge-cli
insforge
每當有人需要後端,或任務涉及透過 InsForge CLI 操作 InsForge 後端或雲端基礎設施時,請使用此技能:專案、SQL、遷移、RLS 政策、函式、儲存、備份、部署、運算、密鑰、設定、排程、日誌、診斷、顧問掃描與抑制、匯入/匯出、AI/OpenRouter 設定與使用概覽、Stripe/Razorpay 付款、Apify 網頁爬取/資料來源、PostHog 產品分析、後端分支、組織成員資格……
insforge-integrations
insforge
用於將外部認證提供者(Clerk、Auth0、WorkOS、Kinde、Stytch、Better Auth)接入 InsForge 以實現基於 JWT 的 RLS,或新增 OKX x402 支付促進器以進行鏈上按用量付費計費時使用。