Docs menu

Outside APIs

An app reaches its own database and nothing else, unless it names an outside service in spryloom.yaml:

egress:
  - slack.com
  - api.stripe.com

Each host has to be one of the services below. It is shown on the app's page before anyone signs in, in the words in the last column, so a coworker knows where their data can go.

Put the service's key in a secret, never in the code:

spry secrets office-requests set SLACK_BOT_TOKEN=xoxb-...

Then call the service as you normally would, over HTTPS. Spryloom sets HTTPS_PROXY and NODE_USE_ENV_PROXY for the app, so Node's own fetch goes through Spryloom's gateway without any change to your code. The gateway lets the app reach the hosts it declared and nothing else.


The services an app can reach

Host Service Key Shown on the app's page as
api.openai.com OpenAI API key Sends data to OpenAI for AI processing
api.anthropic.com Anthropic API key Sends data to Anthropic for AI processing
generativelanguage.googleapis.com Google Gemini API API key Sends data to Google for AI processing
api.stripe.com Stripe Secret key, restricted where you can Sends payment data to Stripe
slack.com Slack Web API Bot token Reads from and posts to Slack
api.github.com GitHub REST API Fine-grained token Reads from and writes to GitHub
api.linear.app Linear API key Reads from and writes to Linear
api.notion.com Notion Integration token Reads from and writes to Notion
api.airtable.com Airtable Personal access token Reads from and writes to Airtable
api.hubapi.com HubSpot Private app token Reads from and writes to HubSpot
sheets.googleapis.com, oauth2.googleapis.com Google Sheets, through a service account Service-account key Reads from and writes to Google Sheets

For Google Sheets, declare both hosts, and share the sheet with the service account's address.

Not on the list yet: services that send email or SMS to anyone, places where anyone can receive data under a name they choose, webhook addresses anyone can create, such as Slack's incoming webhooks and Discord's (use Slack's bot API at slack.com with a bot token instead), and services where each company has its own address, such as a Jira or Zendesk site. Services that need a person to click "Allow", like Gmail or Google Drive, come later.

To ask for a host, email hello@spryloom.com with the host and what your app needs it for. The answer comes within a working day.


What the beta allows

  • HTTPS on port 443 only, to the hosts named. An address instead of a name is refused.
  • If a service redirects to another host, that host has to be declared too.
  • At most 500 MB sent and received a day per app. You are emailed at 80% and at the limit, and new connections are refused until midnight UTC.
  • At most 20 connections open at once per app.

A request to a host the app did not declare is refused with:

403 Spryloom: this app does not declare api.stripe.com in egress.
Add it to spryloom.yaml and publish again.