Install any skill in seconds. Free to start, no credit card required.
Get Started Free →API rules and filter expressions for PocketBase access control. Use when setting permissions, writing filter expressions, configuring who can access what, or debugging 403/404 responses. Covers all 5 rule types, filter syntax, operators, request/collection macros, and field modifiers.
.claude/skills/davila7-pocketbase-api-rules/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 43% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 73% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 74% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 45% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 42% | 0% |
Each collection has 5 rule types. Each rule is a filter expression that must evaluate to true for the request to proceed.
| Rule | Controls | Locked = | Empty string = | |------|----------|----------|----------------| | List | GET /api/collections/{name}/records | superusers only | everyone can list | | View | GET /api/collections/{name}/records/{id} | superusers only | everyone can view | | Create | POST /api/collections/{name}/records | superusers only | everyone can create | | Update | PATCH /api/collections/{name}/records/{id} | superusers only | everyone can update | | Delete | DELETE /api/collections/{name}/records/{id} | superusers only | everyone can delete |
Critical: null/locked means only superusers can perform the action (regular users and guests are denied). Empty string "" means EVERYONE including guests. Superusers always bypass API rules entirely — see below.
Superusers (formerly admins) always bypass API rules. Rules only apply to regular auth records and guests.
| Operator | Meaning | Example | |----------|---------|---------| | = | Equal | status = "active" | | != | Not equal | status != "draft" | | > | Greater than | count > 5 | | >= | Greater or equal | count >= 5 | | < | Less than | count < 10 | | <= | Less or equal | count <= 10 | | ~ | LIKE (contains) | title ~ "hello" | | !~ | NOT LIKE | title !~ "spam" | | ?= | Any/has (array contains) | tags ?= "TAG_ID" | | ?!= | None (array not contains) | tags ?!= "TAG_ID" | | ?> | Any greater than | scores ?> 90 | | ?>= | Any greater or equal | scores ?>= 90 | | ?< | Any less than | scores ?< 10 | | ?<= | Any less or equal | scores ?<= 10 | | ?~ | Any LIKE | emails ?~ "@gmail.com" | | ?!~ | Any NOT LIKE | emails ?!~ "@test.com" |
Critical: use ?= (not =) for multi-valued fields (multi-select, multi-relation, multi-file). = checks the raw JSON string, ?= checks individual values.
status = "active" && author = @request.auth.id
status = "active" || status = "featured"Parentheses for grouping: (a = 1 || b = 2) && c = 3
"value" or 'value'123, 45.67true, falsenull — empty/missing value@request.*)Access the current request context in rules:
| Macro | Type | Description | |-------|------|-------------| | @request.auth.id | string | Current auth record ID (empty if guest) | | @request.auth.email | string | Current auth record email | | @request.auth.verified | bool | Whether email is verified | | @request.auth.collectionId | string | Auth collection ID | | @request.auth.collectionName | string | Auth collection name | | @request.auth.* | any | Any field from the auth record | | @request.body.fieldName | any | Field value from request body | | @request.query.paramName | string | URL query parameter | | @request.headers.name | string | Request header (lowercase key) | | @request.method | string | HTTP method (GET/POST/PATCH/DELETE) |
You can traverse relations on the auth record:
@request.auth.team.owner = @request.auth.id@collection.*)Cross-collection lookups without explicit joins:
@collection.memberships.user ?= @request.auth.id &&
@collection.memberships.team ?= teamThis checks if a record exists in the memberships collection where the user matches the current auth user and the team matches the current record's team field.
Note: @collection.* performs an implicit EXISTS subquery. It's powerful but can be slow on large datasets — add indexes.
Use in create/update rules to validate specific field behaviors:
| Modifier | Works on | Description | |----------|----------|-------------| | :isset | @request.body.* | True if the field was sent in the request (even if empty) | | :changed | record field | True if the field value differs from current stored value (update only) | | :length | string/array | Returns the length | | :each | array | Applies the condition to each element | | :lower | string | Lowercased value |
// Only allow changing status if user is owner
status:changed = false || author = @request.auth.id
// Prevent setting role on create
@request.body.role:isset = false
// Require at least 2 tags
@request.body.tags:length >= 2
// Check each tag is from allowed list
@request.body.tags:each ?= @collection.allowed_tags.id| Macro | Example output | |-------|----------------| | @now | 2024-01-15 10:30:00.000Z | | @second | 2024-01-15 10:30:00.000Z | | @minute | 2024-01-15 10:30:00.000Z | | @hour | 2024-01-15 10:00:00.000Z | | @day | 2024-01-15 00:00:00.000Z | | @month | 2024-01-01 00:00:00.000Z | | @year | 2024-01-01 00:00:00.000Z | | @todayStart | 2024-01-15 00:00:00.000Z | | @todayEnd | 2024-01-15 23:59:59.999Z | | @monthStart | 2024-01-01 00:00:00.000Z | | @monthEnd | 2024-01-31 23:59:59.999Z | | @yearStart | 2024-01-01 00:00:00.000Z | | @yearEnd | 2024-12-31 23:59:59.999Z |
Arithmetic: @now - 7d, @now + 1h, @now - 30m
geoDistance()For location-based filtering:
geoDistance(lat, lon, 40.7128, -74.0060) <= 10000Arguments: geoDistance(latField, lonField, targetLat, targetLon) — returns meters.
// View/Update/Delete rule:
author = @request.auth.id@request.auth.id != ""@request.auth.verified = true@request.auth.role = "admin" || author = @request.auth.id@collection.team_members.user ?= @request.auth.id &&
@collection.team_members.team ?= team// List/View: "" (empty = everyone)
// Create: @request.auth.id != ""
// Update/Delete: author = @request.auth.id// Update rule: prevent changing `owner` after creation
owner:changed = falseexpires > @now| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 12,107 | 8,827 | -27% | 1 | 1 | 0% | 2,382 | 3,839 | +61% | 0 | 0 | — |
case-02 | fail→pass | 15,039 | 10,243 | -32% | 1 | 1 | 0% | 2,805 | 4,005 | +43% | 0 | 0 | — |
case-03 | fail→pass | 12,981 | 11,515 | -11% | 1 | 1 | 0% | 2,518 | 4,351 | +73% | 0 | 0 | — |
case-04 | fail→pass | 8,392 | 2,943 | -65% | 1 | 1 | 0% | 1,489 | 2,596 | +74% | 0 | 0 | — |
case-05 | pass→pass | 6,570 | 3,325 | -49% | 1 | 1 | 0% | 927 | 2,675 | +189% | 0 | 0 | — |
case-06 | fail→pass | 9,759 | 3,009 | -69% | 1 | 1 | 0% | 1,810 | 2,631 | +45% | 0 | 0 | — |
case-07 | fail→pass | 11,027 | 2,984 | -73% | 1 | 1 | 0% | 1,869 | 2,650 | +42% | 0 | 0 | — |
case-08 | pass→pass | 17,835 | 4,210 | -76% | 1 | 1 | 0% | 2,975 | 2,887 | -3% | 0 | 0 | — |
case-09 | fail→pass | 12,964 | 3,421 | -74% | 1 | 1 | 0% | 2,467 | 2,744 | +11% | 0 | 0 | — |
case-10 | pass→pass | 3,951 | 2,797 | -29% | 1 | 1 | 0% | 671 | 2,627 | +292% | 0 | 0 | — |
case-11 | fail→pass | 9,634 | 4,909 | -49% | 1 | 1 | 0% | 1,624 | 2,999 | +85% | 0 | 0 | — |
case-12 | fail→pass | 10,696 | 2,766 | -74% | 1 | 1 | 0% | 1,853 | 2,588 | +40% | 0 | 0 | — |
case-13 | pass→pass | 7,613 | 2,950 | -61% | 1 | 1 | 0% | 1,290 | 2,573 | +99% | 0 | 0 | — |
case-14 | fail→pass | 10,826 | 2,945 | -73% | 1 | 1 | 0% | 2,057 | 2,682 | +30% | 0 | 0 | — |
case-15 | pass→pass | 8,729 | 4,342 | -50% | 1 | 1 | 0% | 1,595 | 2,977 | +87% | 0 | 0 | — |
case-16 | fail→pass | 9,946 | 2,753 | -72% | 1 | 1 | 0% | 1,678 | 2,542 | +51% | 0 | 0 | — |
case-17 | pass→pass | 4,339 | 2,750 | -37% | 1 | 1 | 0% | 672 | 2,536 | +277% | 0 | 0 | — |
case-18 | pass→pass | 4,239 | 3,119 | -26% | 1 | 1 | 0% | 768 | 2,667 | +247% | 0 | 0 | — |
case-19 | pass→pass | 6,791 | 3,684 | -46% | 1 | 1 | 0% | 1,233 | 2,721 | +121% | 0 | 0 | — |
case-20 | pass→pass | 5,912 | 4,906 | -17% | 1 | 1 | 0% | 1,120 | 3,025 | +170% | 0 | 0 | — |
case-21 | pass→pass | 10,381 | 8,713 | -16% | 1 | 1 | 0% | 1,885 | 3,819 | +103% | 0 | 0 | — |
case-22 | pass→pass | 10,394 | 6,722 | -35% | 1 | 1 | 0% | 1,937 | 3,466 | +79% | 0 | 0 | — |
case-23 | pass→pass | 13,371 | 11,301 | -15% | 1 | 1 | 0% | 2,616 | 4,239 | +62% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +43 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.