Skip to main content
POST
Run read-only SQL

Authorizations

Authorization
string
header
required

Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for machines and MCP clients), a WorkOS AuthKit session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.

Headers

X-Organization-Id
string

Active WorkOS organization (property group). Optional cross-check for session (JWT) auth: when sent it must equal the token's verified org_id claim, else 403. The org is taken from the claim, not this header. Ignored for API keys and static tokens.

X-Property-Id
string<uuid>

Optional single-property drill-down. When set, narrows the request to this property; it must belong to the caller's group, else 403. A property-pinned API key is already narrowed and ignores this header.

Body

application/json
sql
string
required
Example:

"SELECT first_name, surname FROM guest_profiles ORDER BY created_at DESC LIMIT 10"

Response

Query results.

columns
string[]
required
rows
object[]
required
truncated
boolean
required
rowCount
integer
required