DecodeLabs · Full Stack Project 2
One flow.
Many routes.
Manifold is a developer API platform: issue API keys, run validated CRUD against a live REST API, and watch every request measured in real time. Built with Node.js and Express — no frameworks on the frontend, just the platform speaking for itself.
- 10 endpoints
- Dual-layer validation
- Per-key rate limits
- Nanosecond telemetry
Interactive
API sandbox
Fire real requests at the live API. Pick a preset or craft your own —
every response shows its HTTP status, round-trip time and the
X-Response-Time header the server measured.
Request builder
Try POST /projects with {"name":"x"} — the gatekeeper rejects it with a structured 400.
Response
No request yet.
Dispatch one to see the raw response.
Telemetry
Live metrics
The server measures every request with nanosecond precision and aggregates it here. This dashboard refreshes itself — dispatch a few requests in the sandbox and watch it move.
–
Total requests
–
Avg latency
–
p95 latency
–
Error rate
Latency over time
Status codes
Recent requests
| Time | Method | Path | Status | Latency |
|---|---|---|---|---|
| No requests yet. | ||||
Authentication
API keys
Keys gate the /projects resource. Issue one, copy it once —
the secret is never shown again — then paste it into the sandbox.
Issue a key
Your new key (copy now — shown once)
Issued keys
| Name | Key | Requests | Status | |
|---|---|---|---|---|
| No keys yet. | ||||
Reference
Endpoints
Everything the platform exposes. Auth column: key means the x-api-key header is required.
| Method | Path | Auth | Description |
|---|---|---|---|
| GET | /api/health | open | Service status and uptime |
| POST | /api/keys | open · 10/min per IP | Issue an API key (secret shown once) |
| GET | /api/keys | open | List issued keys (secrets masked) |
| DELETE | /api/keys/:id | open | Revoke an API key |
| GET | /api/projects | key | List projects — filter by status, tag, q; paginate with page/limit |
| POST | /api/projects | key | Create a project — dual-layer validation, 400 on violation |
| GET | /api/projects/:id | key | Fetch one project |
| PUT | /api/projects/:id | key | Partial update — merged document re-validated |
| DELETE | /api/projects/:id | key | Delete a project |
| GET | /api/metrics | open | Live telemetry: totals, latency, status breakdown |
The gatekeeper rule
"Never trust the client." Every write passes two layers before it touches data:
- Syntactic — types, lengths, enums, formats.
{"name": "x"}dies here. - Semantic — domain rules, e.g. project names must be unique. Duplicates die here.
Violations return HTTP 400 with the failing layer named per field. Hammer an endpoint and the sliding-window limiter answers HTTP 429 with a Retry-After header.