RESTHeart v9 Documentation
RESTHeart CloudWelcome to RESTHeart v9! This documentation is organized to help you learn progressively and find information quickly.
|
Tip
|
Questions, ideas, a bug to report? Join our community on Discord. |
🚀 Quick Start
New to RESTHeart? Start here:
Get RESTHeart running in 5 minutes.
|
Note
|
Upgrading from RESTHeart v8 or earlier?
📦 RESTHeart v9 brings major improvements! Java 25, OAuth 2.0 authentication, enhanced security, custom metrics, and more. 👉 Read the Upgrade Guide for migration instructions and breaking changes. |
📚 Learning Paths
Choose the path that matches what you are building. The first four cover what RESTHeart gives you without writing backend code; the last three are for extending and running it.
Path 1: Build on MongoDB, No Backend Code
Goal: Read, write, aggregate and validate data through RESTHeart’s APIs, with rules enforced by the server.
Time: ~4 hours | Difficulty: Beginner
| Step | Topic |
|---|---|
1 |
What is RESTHeart? (10 min) |
2 |
Quick Start (15 min) |
3 |
Security Fundamentals (20 min) |
4 |
REST API Tutorial (30 min) |
5 |
Reading Data (30 min) |
6 |
Writing Data (30 min) |
7 |
Aggregations (20 min) |
8 |
Data Constraints (20 min) |
9 |
Change Streams (15 min) |
10 |
Permissions (30 min) |
11 |
Configuration (20 min) |
✓ You can now run a production API on MongoDB.
Next steps: Transactions, File Storage, Schema Validation
Path 2: Users, Sign-up and Teams
Goal: Give your application sign-up, login, social sign-in, password reset, teams and invitations — with the restheart-accounts plugin, not with code of yours.
Time: ~2 hours | Difficulty: Beginner
| Step | Topic |
|---|---|
1 |
Sign-up Management Overview (10 min) |
2 |
Tutorial: Set Up Registration (30 min) |
3 |
User Registration and Verification (15 min) |
4 |
Password Reset (10 min) |
5 |
Email Templates (15 min) |
6 |
Sign in with Google and GitHub (20 min) |
7 |
Teams and Invitations (15 min) |
8 |
Multi-tenancy (15 min) |
9 |
Terms and Consents (10 min) |
✓ Your users can register, sign in and work in teams.
Path 3: AI Agents and Semantic Search
Goal: Let an AI agent use your data over MCP, and search it by meaning with vector search — the restheart-ai plugin.
Time: ~2 hours | Difficulty: Intermediate
| Step | Topic |
|---|---|
1 |
AI Features Overview (10 min) |
2 |
The MCP Server (20 min) |
3 |
|
4 |
Connect Claude Desktop (10 min) |
5 |
API Keys: a Credential for an Agent (15 min) |
6 |
Vector Search (20 min) |
7 |
✓ An agent answers questions on your data, and your search understands meaning.
Path 4: Subscriptions and Billing with Stripe
Goal: Sell plans and seats, gate features by plan, and keep subscriptions in step with Stripe — the restheart-stripe plugin.
Time: ~2 hours | Difficulty: Intermediate
| Step | Topic |
|---|---|
1 |
Stripe Integration Overview (10 min) |
2 |
Tutorial: Set Up Stripe (30 min) |
3 |
Products and Prices (15 min) |
4 |
Plans and Seats (20 min) |
5 |
Plan Gates (15 min) |
6 |
Subscription Lifecycle (15 min) |
7 |
Webhooks (15 min) |
8 |
Multi-tenancy (10 min) |
✓ Your application charges, and knows who paid for what.
Next steps: Subscription Owner Provider, Teams and Invitations
Path 5: Plugin Developer
Goal: Extend RESTHeart with custom services, interceptors and providers, in Java, Kotlin, JavaScript or TypeScript.
Time: ~3 hours | Difficulty: Intermediate
| Step | Topic |
|---|---|
1 |
What is RESTHeart? (10 min) |
2 |
Quick Start (15 min) |
3 |
Core Concepts (30 min) |
4 |
Framework Overview (20 min) |
5 |
Plugin Tutorial (45 min) |
6 |
Developing Services (30 min) |
7 |
Developing Interceptors (20 min) |
8 |
Providers & Dependency Injection (15 min) |
9 |
Deploying Plugins (20 min) |
✓ You can now build and deploy custom plugins.
Next steps: JavaScript Plugins, Initializers, Sending email from a plugin
Path 6: DevOps / Site Reliability Engineer
Goal: Deploy and operate RESTHeart in production.
Time: ~2 hours | Difficulty: Intermediate
| Step | Topic |
|---|---|
1 |
What is RESTHeart? (10 min) |
2 |
Installation (20 min) |
3 |
Docker Setup (20 min) |
4 |
Configuration (30 min) |
5 |
Security Hardening (20 min) |
6 |
TLS Configuration (15 min) |
7 |
Logging (10 min) |
8 |
Monitoring (15 min) |
9 |
Clustering & Load Balancing (20 min) |
✓ You’re ready to run RESTHeart in production.
Next steps: GraalVM Native Image, Auditing, Reverse Proxy
Path 7: GraphQL Developer
Goal: Build GraphQL APIs on top of MongoDB.
Time: ~2 hours | Difficulty: Intermediate
| Step | Topic |
|---|---|
1 |
What is RESTHeart? (10 min) |
2 |
Quick Start (15 min) |
3 |
GraphQL Tutorial (30 min) |
4 |
Getting Started (20 min) |
5 |
GraphQL Apps (20 min) |
6 |
Schema Design (20 min) |
7 |
Mappings (20 min) |
8 |
Resolvers (20 min) |
✓ You can now build GraphQL APIs with RESTHeart.
Next steps: Performance Optimization, Advanced Example, Best Practices
📖 Browse Documentation by Topic
Prefer to explore on your own? These are the sections of the sidebar, in the same order.
Foundations
Introduction, installation, core concepts and security fundamentals.
Start here if you are new to RESTHeart.
REST API
CRUD, queries, aggregations, transactions, files, schema validation and data constraints.
Use RESTHeart’s MongoDB API without writing backend code.
GraphQL API
GraphQL apps on MongoDB: schema, mappings, resolvers and performance.
When clients want to say exactly what shape of data they need.
WebSocket and SSE
Real-time streams backed by MongoDB change streams, over WebSocket or Server-Sent Events.
When clients have to know about a change as it happens.
AI and MCP
The MCP server that publishes your data to AI agents, and vector search for semantic queries.
Let an agent read your data, and search it by meaning.
Security
Authentication mechanisms, API keys, JWT, authorization, permissions, TLS and hardening.
Essential for any API that is not local.
Sign-up, OAuth and Invitations
Registration, verification, password reset, Google and GitHub sign-in, teams, invitations, consents and multi-tenancy — the restheart-accounts plugin.
Everything an application needs around its users, without code.
Subscriptions and Billing
Plans, seats, plan gates, subscription lifecycle and webhooks with Stripe — the restheart-stripe plugin.
When your application charges for what it does.
Configuration and Deployment
Configuration options, GraalVM native image, logging, monitoring, auditing, clustering and reverse proxies.
Run RESTHeart in production.
Framework
Services, interceptors, providers, initializers, JavaScript plugins, security plugins, sending email and making a plugin MCP-aware.
Extend RESTHeart with your own code.
RESTHeart Cloud
The managed service: console, plans, users, permissions, webhooks, MCP, API keys, the Kit and the rhc CLI.
Use RESTHeart without running it.
Sophia
The AI assistant: setup, user and administrator guides, API and MCP.
Chat with your documentation, or let an agent do it.
Reference
Performance, example applications, blog posts and the enterprise license.
Facts and resources.
🔗 Quick Links
Get running in 5 minutes
What RESTHeart is, and how it fits
Real applications on RESTHeart Cloud, and what they use
React, Angular, Ecommerce on RESTHeart Cloud: clone, point at a service, run
🎓 Tutorials
Hands-on guides, one per feature, each from a blank service to something working:
-
REST API Tutorial — the REST API through examples
-
GraphQL Tutorial — build a GraphQL API
-
WebSocket Tutorial — real-time data with WebSockets
-
SSE Tutorial — server-push streams over plain HTTP
-
Security Tutorial — set up authentication and authorization
-
Registration Tutorial — sign-up, verification and password reset with
restheart-accounts -
MCP Tutorial — publish your data to an AI agent, then connect Claude Desktop
-
Vector Search Tutorial — semantic search on your own documents
-
Stripe Tutorial — subscriptions and payments with
restheart-stripe -
Webhook Tutorials — notify Slack, Discord or your own endpoint from RESTHeart Cloud
-
Plugin Development Tutorial — build your first plugin
🌟 Why RESTHeart?
-
Zero Code Required - Use MongoDB APIs out of the box
-
Instant APIs - REST, GraphQL, WebSocket, and SSE for MongoDB
-
Secure by Default - Built-in authentication and authorization
-
Highly Extensible - Simple plugin system in Java, Kotlin, or JavaScript
-
High Performance - Virtual threads for massive scalability
-
Cloud Ready - Docker, Kubernetes, GraalVM native images
💬 Community & Support
-
GitHub: SoftInstigate/restheart
-
Examples: Plugin examples on GitHub
-
Enterprise Support: Enterprise License and Support
📰 Stay Updated
-
Blog Posts - Technical articles and announcements
-
Roadmap - Upcoming features
Ready to dive in? Choose a learning path or jump straight to the Quick Start!