Skip to content

Databases API ​

PostgreSQL and MariaDB databases. Authenticate with a Personal Access Token carrying the database:read, database:write or database:firewall scope.

Endpoints ​

MethodPathDescription
GET/v1/databasesList databases
POST/v1/databasesCreate database
GET/v1/databases/tiersList tiers
GET/v1/databases/{db_type}/{db_name}Get database
DELETE/v1/databases/{db_type}/{db_name}Delete database
GET/v1/databases/{db_type}/{db_name}/firewallList firewall rules
POST/v1/databases/{db_type}/{db_name}/firewallAdd firewall rule
DELETE/v1/databases/{db_type}/{db_name}/firewall/{rule_id}Remove firewall rule

GET /v1/databases ​

List databases

List the databases on your account. Requires the database:read scope.

Response:

FieldTypeDescription
databasesarray
totalinteger

Example:

bash
curl https://api.wayscloud.services/v1/databases \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET"

Response:

json
{
  "databases": [
    {
      "name": "webapp_prod_db",
      "technical_name": "cust_6dd1d906_pg_webapp_prod_db",
      "type": "postgresql",
      "description": "Production database",
      "tier": "standard",
      "host": "db.no.wayscloud.services",
      "created_at": "2025-10-15T14:30:00Z"
    }
  ],
  "total": 1
}

POST /v1/databases ​

Create database

Create a PostgreSQL or MariaDB database. The password is returned once, in this response. Requires the database:write scope.

Request Body:

FieldTypeDescription
db_namestringRequired. Database name: lowercase letters, digits and underscore
db_typestringRequired. Values: postgresql, mariadb
descriptionstring
tierstringencrypted runs on encrypted storage at db-secure.no.wayscloud.services Values: standard, encrypted

Example:

json
{
  "db_name": "webapp_prod_db",
  "db_type": "postgresql",
  "description": "Production database",
  "tier": "standard"
}

Response:

FieldTypeDescription
okboolean
createdboolean
friendly_namestring
technical_namestring
db_typestringValues: postgresql, mariadb
hoststring
portinteger
usernamestring
passwordstring
connection_stringstring

Example:

bash
curl -X POST https://api.wayscloud.services/v1/databases \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET" \
  -H "Content-Type: application/json" \
  -d '{
  "db_name": "webapp_prod_db",
  "db_type": "postgresql",
  "description": "Production database",
  "tier": "standard"
}'

Response:

json
{
  "ok": true,
  "created": true,
  "friendly_name": "webapp_prod_db",
  "technical_name": "cust_6dd1d906_pg_webapp_prod_db",
  "db_type": "postgresql",
  "host": "db.no.wayscloud.services",
  "port": 5432,
  "username": "cust_6dd1d906_pg_webapp_prod_db",
  "password": "Xk9mN2pQ4rS7tV3wYz",
  "connection_string": "postgresql://cust_6dd1d906_pg_webapp_prod_db:Xk9mN2pQ4rS7tV3wYz@db.no.wayscloud.services:5432/cust_6dd1d906_pg_webapp_prod_db"
}

GET /v1/databases/tiers ​

List tiers

List the tiers you can create databases in. Requires the database:read scope.

Response example:

json
[
  {
    "tier": "encrypted",
    "name": "Norway Encrypted PostgreSQL",
    "description": "Encrypted PostgreSQL node - LUKS encrypted at rest for compliance",
    "is_encrypted": true
  },
  {
    "tier": "standard",
    "name": "Norway Standard PostgreSQL",
    "description": "Standard PostgreSQL node - general purpose workloads",
    "is_encrypted": false
  }
]

Example:

bash
curl https://api.wayscloud.services/v1/databases/tiers \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET"

Response:

json
[
  {
    "tier": "encrypted",
    "name": "Norway Encrypted PostgreSQL",
    "description": "Encrypted PostgreSQL node - LUKS encrypted at rest for compliance",
    "is_encrypted": true
  },
  {
    "tier": "standard",
    "name": "Norway Standard PostgreSQL",
    "description": "Standard PostgreSQL node - general purpose workloads",
    "is_encrypted": false
  }
]

GET /v1/databases/{db_type}/ ​

Get database

Get a database with its host, port, status and size. Requires the database:read scope.

Response:

FieldTypeDescription
db_namestringTechnical name
friendly_namestringThe name you chose at creation
technical_namestring
db_typestringValues: postgresql, mariadb
hoststring
portinteger
statusstringAs the database node reports it; unknown when the node does not answer
size_mbnumber
created_atstring
descriptionstring

Example:

bash
curl https://api.wayscloud.services/v1/databases/{db_type}/{db_name} \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET"

Response:

json
{
  "db_name": "cust_6dd1d906_pg_webapp_prod_db",
  "friendly_name": "webapp_prod_db",
  "technical_name": "cust_6dd1d906_pg_webapp_prod_db",
  "db_type": "postgresql",
  "host": "db.no.wayscloud.services",
  "port": 5432,
  "status": "running",
  "size_mb": 256.5,
  "created_at": "2025-10-15T14:30:00Z",
  "description": "Production database"
}

DELETE /v1/databases/{db_type}/ ​

Delete database

Delete a database and all its data. This cannot be undone. Requires the database:write scope.

Response:

FieldTypeDescription
okboolean
deletedboolean
db_namestringTechnical name
messagestring

Example:

bash
curl -X DELETE https://api.wayscloud.services/v1/databases/{db_type}/{db_name} \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET"

Response:

json
{
  "ok": true,
  "deleted": true,
  "db_name": "cust_6dd1d906_pg_webapp_prod_db",
  "message": "Database permanently deleted"
}

GET /v1/databases/{db_type}/{db_name}/firewall ​

List firewall rules

List the IP addresses allowed to connect. Requires the database:firewall scope.

Response:

FieldTypeDescription
rulesarrayThe rules as the database node reports them: rule_id, ip_address, port, description and created_at, with the database name and type
totalinteger

Example:

bash
curl https://api.wayscloud.services/v1/databases/{db_type}/{db_name}/firewall \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET"

Response:

json
{
  "rules": [
    {
      "rule_id": "fw-a1b2c3d4-5678-90ab-cdef-123456789abc",
      "db_name": "cust_6dd1d906_pg_webapp_prod_db",
      "db_type": "postgresql",
      "ip_address": "203.0.113.50",
      "port": 5432,
      "description": "Production server",
      "created_at": "2025-10-20T09:15:00Z"
    }
  ],
  "total": 1
}

POST /v1/databases/{db_type}/{db_name}/firewall ​

Add firewall rule

Allow an IPv4 address to connect. The rule applies immediately. Requires the database:firewall scope.

Request Body:

FieldTypeDescription
ip_addressstringRequired. IPv4 address to allow
descriptionstring

Response:

FieldTypeDescription
rule_idstring
ip_addressstring
portinteger
descriptionstring
created_atstring

Example:

bash
curl -X POST https://api.wayscloud.services/v1/databases/{db_type}/{db_name}/firewall \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET" \
  -H "Content-Type: application/json" \
  -d '{
  "ip_address": "203.0.113.50",
  "description": "Production server"
}'

Response:

json
{
  "rule_id": "fw-a1b2c3d4-5678-90ab-cdef-123456789abc",
  "ip_address": "203.0.113.50",
  "port": 5432,
  "description": "Production server",
  "created_at": "2025-10-20T09:15:00Z"
}

DELETE /v1/databases/{db_type}/{db_name}/firewall/ ​

Remove firewall rule

Remove an allowed IP address. Requires the database:firewall scope.

Response:

FieldTypeDescription
okboolean
messagestring
rule_idstring

Example:

bash
curl -X DELETE https://api.wayscloud.services/v1/databases/{db_type}/{db_name}/firewall/{rule_id} \
  -H "X-API-Key: wayscloud_dbaas_abc12_YOUR_SECRET"

Response:

json
{
  "ok": true,
  "message": "Firewall rule removed",
  "rule_id": "fw-a1b2c3d4-5678-90ab-cdef-123456789abc"
}