(Re)Introducing JXP, the opinionated API framework with batteries included

(Re)Introducing JXP, the opinionated API framework with batteries included
Prompt: I want an image for a blog post titled: "JXP, the opinionated API framework with batteries included". Be creative! Be mysterious!

I've been working on my RESTful API framework, JXP, for over 10 years, and I think it's a total sleeper – an open sourced beast of a system just waiting to be discovered by the general population.

Since version 6 just dropped, I thought I better write about it.

It makes building a back-end for an enterprise application stupidly simple and fast. It comes with authentication, permissions, groups, and security baked in.

It scales – I have had production tables of one billion with a motherfucking B – running just fine. I have had over 3 million hits an hour. It's currently used by over 10 million individual users a month.

And for developers with difficult clients, it's a dream. This was really its first use-case: a difficult client who would tell me in the morning what new features he'd like deployed that afternoon. I would deploy to production anywhere from three to 10 times a day, for years.

Managing your data structure in this type of environment is typically a nightmare. I would have either murdered the client or gone insane if it hadn't been for JXP. Its secret is that you can change the data structure on-the-fly, no database changes required.

It's backed by Mongo, the NoSql database that gave me the flexibility I needed for the shifting sand beneath my feet. I added Mongoose, a great schema framework to give structure to the structureless Mongo. Then I built on that for JXP, adding permissions, soft-deletion, and clever linking to Mongoose.

JXP is a classic RESTful API, with your usual verb-like actions to add, delete, or update data. But the endpoints automagically appear when you create a new schema. There's no faffing with databases or tables, no creating new files for a new type, it just is there, ready to use.

I built in a permissioning system similar to Linux CRUD (Create, Read, Update, Delete). You have baked-in anonymous, user, and admin roles, and you can go wild with groups too. For each type you define, you can give exactly the permissions you want.

Some basic collections come for free, including users, tokens, api keys, etc. (You can always override them of course.) The opinionated part comes in with user management – passwords are always encrypted; sensitive data never shown. Other "opinionated" stuff is limiting on large datasets, watching for very large responses, and limiting the more advanced actions you can take in Mongo to ensure you don't jailbreak or do something destructive.

It solves some of the REST limitations on joins, allowing you to hydrate your data with their linked items, making it more GraphQL-like. You can also write full-on Mongo pipelines and do wild things with the data.

JXP is becoming more AI-ready, with an MCP server baked in. There's also a websocket you can subscribe to for changes. And more of that is on the roadmap.

Version 6 introduces a ton of security improvements, including API keys where you can limit capabilities. I also shut off api keys on url queries and basic auth, they're just too insecure for modern computing. This is a breaking change, but if you've been using the companion SDK, "jxp-helper", upgrading that will keep everything working seamlessly.

There's also a cool front-end that includes all the documentation, including documenting your own API, always showing you your latest definitions.

There's tons of more features – bulk operations, baked-in CSV, Topt 2FA, Webauthn, an index monitor... 10 years of development tends to add up.

If you'd like to check it out, it's on NPM, and if you'd like help implementing it, please reach out.