Edit Page

RESTHeart v9 Documentation

RESTHeart Cloud
Prefer not to run it yourself? RESTHeart Cloud is this, hosted, with sign-up, payments and an MCP server already on. Free to start. Get started →

Welcome to RESTHeart v9! This documentation is organized to help you learn progressively and find information quickly.

Tip
Questions, ideas, a bug to report? Join our community on Discord.

🚀 Quick Start

New to RESTHeart? Start here:

Get RESTHeart running in 5 minutes.

Note
Upgrading from RESTHeart v8 or earlier?

📦 RESTHeart v9 brings major improvements! Java 25, OAuth 2.0 authentication, enhanced security, custom metrics, and more.

👉 Read the Upgrade Guide for migration instructions and breaking changes.

📚 Learning Paths

Choose the path that matches what you are building. The first four cover what RESTHeart gives you without writing backend code; the last three are for extending and running it.

Path 1: Build on MongoDB, No Backend Code

Goal: Read, write, aggregate and validate data through RESTHeart’s APIs, with rules enforced by the server.

Time: ~4 hours | Difficulty: Beginner

Step Topic

1

What is RESTHeart? (10 min)

2

Quick Start (15 min)

3

Security Fundamentals (20 min)

4

REST API Tutorial (30 min)

5

Reading Data (30 min)

6

Writing Data (30 min)

7

Aggregations (20 min)

8

Data Constraints (20 min)

9

Change Streams (15 min)

10

Permissions (30 min)

11

Configuration (20 min)

✓ You can now run a production API on MongoDB.


Path 2: Users, Sign-up and Teams

Goal: Give your application sign-up, login, social sign-in, password reset, teams and invitations — with the restheart-accounts plugin, not with code of yours.

Time: ~2 hours | Difficulty: Beginner

Step Topic

1

Sign-up Management Overview (10 min)

2

Tutorial: Set Up Registration (30 min)

3

User Registration and Verification (15 min)

4

Password Reset (10 min)

5

Email Templates (15 min)

6

Sign in with Google and GitHub (20 min)

7

Teams and Invitations (15 min)

8

Multi-tenancy (15 min)

9

Terms and Consents (10 min)

✓ Your users can register, sign in and work in teams.


Path 3: AI Agents and Semantic Search

Goal: Let an AI agent use your data over MCP, and search it by meaning with vector search — the restheart-ai plugin.

Time: ~2 hours | Difficulty: Intermediate

Step Topic

1

AI Features Overview (10 min)

2

The MCP Server (20 min)

3

Tutorial: Publish Your Data to an Agent (30 min)

4

Connect Claude Desktop (10 min)

5

API Keys: a Credential for an Agent (15 min)

6

Vector Search (20 min)

7

Tutorial: Semantic Search on Your Documents (30 min)

✓ An agent answers questions on your data, and your search understands meaning.


Path 4: Subscriptions and Billing with Stripe

Goal: Sell plans and seats, gate features by plan, and keep subscriptions in step with Stripe — the restheart-stripe plugin.

Time: ~2 hours | Difficulty: Intermediate

Step Topic

1

Stripe Integration Overview (10 min)

2

Tutorial: Set Up Stripe (30 min)

3

Products and Prices (15 min)

4

Plans and Seats (20 min)

5

Plan Gates (15 min)

6

Subscription Lifecycle (15 min)

7

Webhooks (15 min)

8

Multi-tenancy (10 min)

✓ Your application charges, and knows who paid for what.


Path 5: Plugin Developer

Goal: Extend RESTHeart with custom services, interceptors and providers, in Java, Kotlin, JavaScript or TypeScript.

Time: ~3 hours | Difficulty: Intermediate

Step Topic

1

What is RESTHeart? (10 min)

2

Quick Start (15 min)

3

Core Concepts (30 min)

4

Framework Overview (20 min)

5

Plugin Tutorial (45 min)

6

Developing Services (30 min)

7

Developing Interceptors (20 min)

8

Providers & Dependency Injection (15 min)

9

Deploying Plugins (20 min)

✓ You can now build and deploy custom plugins.


Path 6: DevOps / Site Reliability Engineer

Goal: Deploy and operate RESTHeart in production.

Time: ~2 hours | Difficulty: Intermediate

Step Topic

1

What is RESTHeart? (10 min)

2

Installation (20 min)

3

Docker Setup (20 min)

4

Configuration (30 min)

5

Security Hardening (20 min)

6

TLS Configuration (15 min)

7

Logging (10 min)

8

Monitoring (15 min)

9

Clustering & Load Balancing (20 min)

✓ You’re ready to run RESTHeart in production.


Path 7: GraphQL Developer

Goal: Build GraphQL APIs on top of MongoDB.

Time: ~2 hours | Difficulty: Intermediate

Step Topic

1

What is RESTHeart? (10 min)

2

Quick Start (15 min)

3

GraphQL Tutorial (30 min)

4

Getting Started (20 min)

5

GraphQL Apps (20 min)

6

Schema Design (20 min)

7

Mappings (20 min)

8

Resolvers (20 min)

✓ You can now build GraphQL APIs with RESTHeart.


📖 Browse Documentation by Topic

Prefer to explore on your own? These are the sections of the sidebar, in the same order.

Foundations

Introduction, installation, core concepts and security fundamentals.

Start here if you are new to RESTHeart.

REST API

CRUD, queries, aggregations, transactions, files, schema validation and data constraints.

Use RESTHeart’s MongoDB API without writing backend code.

GraphQL API

GraphQL apps on MongoDB: schema, mappings, resolvers and performance.

When clients want to say exactly what shape of data they need.

WebSocket and SSE

Real-time streams backed by MongoDB change streams, over WebSocket or Server-Sent Events.

When clients have to know about a change as it happens.

AI and MCP

The MCP server that publishes your data to AI agents, and vector search for semantic queries.

Let an agent read your data, and search it by meaning.

Security

Authentication mechanisms, API keys, JWT, authorization, permissions, TLS and hardening.

Essential for any API that is not local.

Sign-up, OAuth and Invitations

Registration, verification, password reset, Google and GitHub sign-in, teams, invitations, consents and multi-tenancy — the restheart-accounts plugin.

Everything an application needs around its users, without code.

Subscriptions and Billing

Plans, seats, plan gates, subscription lifecycle and webhooks with Stripe — the restheart-stripe plugin.

When your application charges for what it does.

Configuration and Deployment

Configuration options, GraalVM native image, logging, monitoring, auditing, clustering and reverse proxies.

Run RESTHeart in production.

Framework

Services, interceptors, providers, initializers, JavaScript plugins, security plugins, sending email and making a plugin MCP-aware.

Extend RESTHeart with your own code.

RESTHeart Cloud

The managed service: console, plans, users, permissions, webhooks, MCP, API keys, the Kit and the rhc CLI.

Use RESTHeart without running it.

Sophia

The AI assistant: setup, user and administrator guides, API and MCP.

Chat with your documentation, or let an agent do it.

Reference

Performance, example applications, blog posts and the enterprise license.

Facts and resources.

âš¡ Quick Start

Get running in 5 minutes

📖 Introduction

What RESTHeart is, and how it fits

💡 Examples

Real applications on RESTHeart Cloud, and what they use

🧩 Starter Apps

React, Angular, Ecommerce on RESTHeart Cloud: clone, point at a service, run

🎓 Tutorials

Hands-on guides, one per feature, each from a blank service to something working:

🌟 Why RESTHeart?

  • Zero Code Required - Use MongoDB APIs out of the box

  • Instant APIs - REST, GraphQL, WebSocket, and SSE for MongoDB

  • Secure by Default - Built-in authentication and authorization

  • Highly Extensible - Simple plugin system in Java, Kotlin, or JavaScript

  • High Performance - Virtual threads for massive scalability

  • Cloud Ready - Docker, Kubernetes, GraalVM native images

💬 Community & Support

📰 Stay Updated


Ready to dive in? Choose a learning path or jump straight to the Quick Start!