MongoDB retired the Atlas Data API and the HTTPS Endpoints of App Services at the end of September 2025. If your app called data.mongodb-api.com, those calls now fail, and MongoDB's own advice is to write a backend.
You don't have to. Ulabase is a hosted service that does what the Data API did, over HTTPS, with no backend code, on your MongoDB or on one it provides. This article is the migration, one call at a time.
What the Data API was, and what replaces it
The Data API was one endpoint per action. You sent POST /action/find with the collection and a filter in the body, and an api-key header. Ulabase is one endpoint per collection: the collection is in the URL, the action is the HTTP method, the filter is a query parameter. Same MongoDB underneath, same documents.
| You called | Now you call |
|---|---|
POST /action/find with { "filter": {...} } |
GET /orders?filter={...} |
POST /action/findOne |
GET /orders/<id> or GET /orders?filter={...}&pagesize=1 |
POST /action/insertOne with { "document": {...} } |
POST /orders with the document as the body |
POST /action/insertMany with { "documents": [...] } |
POST /orders with an array as the body |
POST /action/updateOne with { "filter", "update" } |
PATCH /orders/<id> with the fields to change |
POST /action/updateMany |
PATCH /orders/*?filter={...} |
POST /action/replaceOne |
PUT /orders/<id> with the whole document |
POST /action/deleteOne |
DELETE /orders/<id> |
POST /action/deleteMany |
DELETE /orders/*?filter={...} |
POST /action/aggregate with a pipeline in the body |
GET /orders/_aggrs/<name> — the pipeline is defined once on the server, the client calls it by name |
Two things change on purpose:
- The client sends no pipeline. On the Data API any client could run any aggregation. On Ulabase you define the pipelines you want to expose, with parameters, and the client calls them by name. It is safer, and it is also faster to write: the pipeline editor in the console runs it against your data before you save.
dataSourceanddatabaseare gone from the body. A service is bound to one database on the Free and Shared tiers; on Dedicated, the database is the first segment of the path.
A find, before and after
Before:
const res = await fetch('https://data.mongodb-api.com/app/<app-id>/endpoint/data/v1/action/find', {
method: 'POST',
headers: { 'Content-Type': 'application/json', 'api-key': API_KEY },
body: JSON.stringify({
dataSource: 'Cluster0', database: 'shop', collection: 'orders',
filter: { status: 'pending' }, sort: { createdAt: -1 }, limit: 20
})
});
const { documents } = await res.json();
After:
const filter = encodeURIComponent(JSON.stringify({ status: 'pending' }));
const sort = encodeURIComponent(JSON.stringify({ createdAt: -1 }));
const res = await fetch(`https://c0ffee.ulabase.app/orders?filter=${filter}&sort=${sort}&pagesize=20`, {
headers: { Authorization: `Bearer ${token}` }
});
const documents = await res.json();
The documents come back as they are stored, in MongoDB's extended JSON: an ObjectId is {"$oid": "..."}, a date is {"$date": ...}, the same encoding the Data API used. Your parsing code stays.
Authentication: from one API key to your users
The Data API gave you one api-key for everything, and your app had to hide it. Ulabase authenticates users, each with roles, and permissions decide what each role may read and write, down to the document: a rule like readFilter: { owner: "@user._id" } means a user only ever sees their own orders, and the client cannot ask for more.
Three ways to send credentials:
- From a browser or a mobile app, the user signs in and gets a JWT; every request carries
Authorization: Bearer <token>. The Cloud Kit does this for React, Angular and Vue, session included. - From a server or a script, Basic Auth with a user of the service:
-u alice:secret. - For an agent or an integration that must stay connected, an API key issued by a user, revocable on its own. This is the closest thing to what you had, with the difference that it carries a role you chose, not the keys to everything.
If you were using Atlas App Services for email/password authentication, sign-up management covers registration, email verification, password reset and login with Google.
The migration, step by step
- Create a service at ulabase.com. The free tier needs no card. On Free and Shared, MongoDB is included and you import your data; on Dedicated, you give it the connection string of your Atlas cluster and it works on your data in place. Getting Started takes five minutes.
- Create the users and the permissions your app needs, in the console or with
ulabasefrom a file in your repo. Start with one role that can read and write the collections your app uses; refine later. - Define the aggregations your app ran, one named endpoint each. Paste the pipeline, give it a name, run it in the editor.
- Change the calls with the table above. In most apps this is one module: the base URL, the method, and the filter moving from the body to the query string.
- Test with the interactive tutorial in the console, which runs real requests against your service, then point your app at it.
A typical app moves in an afternoon. The part that takes longest is deciding the roles, which is time you get back the first time a client tries to read what it should not.
What you gain over the Data API
- GraphQL over the same collections, with no resolvers to write.
- Change streams over WebSocket, so a UI updates when the data does. The Data API had no equivalent.
- Webhooks, JSON Schema validation, constraints across a collection, transactional email, and Stripe subscriptions and checkout, all from the console.
- An MCP server that publishes your collections and aggregations to AI agents, under the same permissions.
- Open source underneath. Ulabase runs RESTHeart, which you can run yourself if you ever want to leave.
Pricing
Free to build and test. Shared at €19.90 a month for an app in production, with backups and email support. Dedicated from €49.90 a month, on your own MongoDB, in the AWS region you choose. Plans has the numbers.
Need a hand?
Write to support@ulabase.com with what your app calls today. We have moved several teams off the Data API and can tell you in a day what yours takes.
Ready to Build Something Great?
Focus on what makes your app unique. Your backend is ready in minutes. Start with our free tier - no credit card required.