Your logic stays yours

Fóir does not host your code. You write a function, host it anywhere that serves HTTP and register its URL as an operation, and Fóir calls it, retries it when a retry could help and keeps a record of every run.

An HTTP contract

A call to an operation is an HTTP POST with a JSON body, so any language that can serve HTTP and verify a signed token will do. The published SDK helpers are JavaScript and TypeScript. In another language you implement the request and the token check yourself. The endpoint has to be publicly routable, and loopback, private and cloud-metadata addresses are refused when you save and again at call time. For local work, foir operations dev forwards the project's dispatches to your machine without exposing it.

The token each call carries

Every call carries a signed, short-lived token in the X-Foir-Token header, scoped to that one dispatch. Your function verifies it against Fóir's published keys. It carries exactly the capabilities the operation declared, such as reading one model's records or writing another's. Your function holds no API key. It builds its client from the token and calls Fóir as the operation.

Reading secrets

The same token lets your function read the project's secrets. It fetches one with getSecret when it needs it, and nothing is substituted into the request Fóir sends. The exception is a templated operation, where Fóir calls a third-party API itself and none of your code runs. There Fóir fills the secret into the outgoing request from the vault.

Retries and the run record

A failure that another attempt could fix, such as an unreachable endpoint or a server error, is retried, three times by default. A client error or a refusal is not. A run that exhausts its retries goes to a dead-letter queue, where you can inspect, retry or dismiss it. Every execution is stored with its status, duration, result or error, trigger and retry count. The same payload can arrive more than once, so write the handler to be idempotent.

Read the detail

The operations guide covers the request and token contract, triggers, sync and async modes, retries and the execution record.