DecodeLabs · Full Stack Project 2

One flow.
Many routes.

Manifold is a developer API platform: issue API keys, run validated CRUD against a live REST API, and watch every request measured in real time. Built with Node.js and Express — no frameworks on the frontend, just the platform speaking for itself.

  • 10 endpoints
  • Dual-layer validation
  • Per-key rate limits
  • Nanosecond telemetry

Interactive

API sandbox

Fire real requests at the live API. Pick a preset or craft your own — every response shows its HTTP status, round-trip time and the X-Response-Time header the server measured.

Request builder

Try POST /projects with {"name":"x"} — the gatekeeper rejects it with a structured 400.

Response

No request yet.
Dispatch one to see the raw response.

Telemetry

Live metrics

The server measures every request with nanosecond precision and aggregates it here. This dashboard refreshes itself — dispatch a few requests in the sandbox and watch it move.

–

Total requests

–

Avg latency

–

p95 latency

–

Error rate

Latency over time

avg p95

Status codes

Waiting for traffic…

Recent requests

TimeMethodPathStatusLatency
No requests yet.

Authentication

API keys

Keys gate the /projects resource. Issue one, copy it once — the secret is never shown again — then paste it into the sandbox.

Issue a key

Issued keys

NameKeyRequestsStatus
No keys yet.

Reference

Endpoints

Everything the platform exposes. Auth column: key means the x-api-key header is required.

MethodPathAuthDescription
GET/api/healthopenService status and uptime
POST/api/keysopen · 10/min per IPIssue an API key (secret shown once)
GET/api/keysopenList issued keys (secrets masked)
DELETE/api/keys/:idopenRevoke an API key
GET/api/projectskeyList projects — filter by status, tag, q; paginate with page/limit
POST/api/projectskeyCreate a project — dual-layer validation, 400 on violation
GET/api/projects/:idkeyFetch one project
PUT/api/projects/:idkeyPartial update — merged document re-validated
DELETE/api/projects/:idkeyDelete a project
GET/api/metricsopenLive telemetry: totals, latency, status breakdown

The gatekeeper rule

"Never trust the client." Every write passes two layers before it touches data:

  1. Syntactic — types, lengths, enums, formats. {"name": "x"} dies here.
  2. Semantic — domain rules, e.g. project names must be unique. Duplicates die here.

Violations return HTTP 400 with the failing layer named per field. Hammer an endpoint and the sliding-window limiter answers HTTP 429 with a Retry-After header.