Outside APIs
An app reaches its own database and nothing else, unless it names an outside
service in spryloom.yaml:
egress:
- slack.com
- api.stripe.com
Each host has to be one of the services below. It is shown on the app's page before anyone signs in, in the words in the last column, so a coworker knows where their data can go.
Put the service's key in a secret, never in the code:
spry secrets office-requests set SLACK_BOT_TOKEN=xoxb-...
Then call the service as you normally would, over HTTPS. Spryloom sets
HTTPS_PROXY and NODE_USE_ENV_PROXY for the app, so Node's own fetch
goes through Spryloom's gateway without any change to your code. The gateway
lets the app reach the hosts it declared and nothing else.
The services an app can reach
| Host | Service | Key | Shown on the app's page as |
|---|---|---|---|
api.openai.com |
OpenAI | API key | Sends data to OpenAI for AI processing |
api.anthropic.com |
Anthropic | API key | Sends data to Anthropic for AI processing |
generativelanguage.googleapis.com |
Google Gemini API | API key | Sends data to Google for AI processing |
api.stripe.com |
Stripe | Secret key, restricted where you can | Sends payment data to Stripe |
slack.com |
Slack Web API | Bot token | Reads from and posts to Slack |
api.github.com |
GitHub REST API | Fine-grained token | Reads from and writes to GitHub |
api.linear.app |
Linear | API key | Reads from and writes to Linear |
api.notion.com |
Notion | Integration token | Reads from and writes to Notion |
api.airtable.com |
Airtable | Personal access token | Reads from and writes to Airtable |
api.hubapi.com |
HubSpot | Private app token | Reads from and writes to HubSpot |
sheets.googleapis.com, oauth2.googleapis.com |
Google Sheets, through a service account | Service-account key | Reads from and writes to Google Sheets |
For Google Sheets, declare both hosts, and share the sheet with the service account's address.
Not on the list yet: services that send email or SMS to anyone, places
where anyone can receive data under a name they choose, webhook addresses
anyone can create, such as Slack's incoming webhooks and Discord's (use Slack's
bot API at slack.com with a bot token instead), and services where
each company has its own address, such as a Jira or Zendesk site. Services
that need a person to click "Allow", like Gmail or Google Drive, come later.
To ask for a host, email hello@spryloom.com with the host and what your app needs it for. The answer comes within a working day.
What the beta allows
- HTTPS on port 443 only, to the hosts named. An address instead of a name is refused.
- If a service redirects to another host, that host has to be declared too.
- At most 500 MB sent and received a day per app. You are emailed at 80% and at the limit, and new connections are refused until midnight UTC.
- At most 20 connections open at once per app.
A request to a host the app did not declare is refused with:
403 Spryloom: this app does not declare api.stripe.com in egress.
Add it to spryloom.yaml and publish again.