Skip to main content
Version: 25.03

DB Viewer - Collection Query

Endpoint​

/o/db?db=countly&collection=members

Overview​

Queries documents from a MongoDB collection, with filtering, projection, sorting, and pagination.

Authentication​

Pass api_key or auth_token as a query parameter, or send countly-token as a header. See Authentication.

Permissions​

Requires DB Viewer access (dbviewer read right for app-scoped users).

Request Parameters​

ParameterTypeRequiredDescription
api_keyStringConditionalRequired if auth_token is not provided.
auth_tokenStringConditionalRequired if api_key is not provided.
db / dbsStringYesDatabase name (countly, countly_drill, countly_out, or countly_fs).
collectionStringYesCollection name.
limitNumberNoPage size. Default 20, capped at 10000.
skipNumberNoOffset. Default 0.
filter / queryJSON StringNoQuery filter object.
projection / projectJSON StringNoField projection object.
sortJSON StringNoSort object.
sSearchStringNo_id regex shortcut.

Examples​

Query collection​

/o/db?api_key=YOUR_API_KEY&db=countly&collection=members&limit=20&skip=0&sort={"_id":-1}

Response​

Success Response​

{
"limit": 20,
"start": 1,
"end": 20,
"total": 138,
"pages": 7,
"curPage": 1,
"collections": [
{
"_id": "ObjectId(507f1f77bcf86cd799439011)",
"name": "Test User",
"email": "user@example.com"
}
]
}

Response Fields​

FieldTypeDescription
limitNumberPage size.
startNumberStart row index (1-based in this response contract).
endNumberEnd row index.
totalNumberTotal matching rows.
pagesNumberTotal pages.
curPageNumberCurrent page number.
collectionsArrayCollection documents.

Error Responses​

  • 400
{
"result": "Failed to parse query. ..."
}
  • 400
{
"result": "Invalid collection name: Collection names can not contain '$' or other invalid characters"
}
  • 401
{
"result": "User does not have right to view this collection"
}
  • 404
{
"result": "Database not found."
}

Behavior​

  • Parses filter/query, projection/project, and sort as EJSON.
  • Invalid filter/query JSON returns 400; invalid projection/sort falls back to {}.
  • For non-admin users, app-level base filters are merged into the query.
  • For members collection, password and api_key are removed.
  • For auth_tokens collection, _id is redacted to ***redacted***.
Implementation details

Configuration Impact

SettingDefaultAffectsUser-visible impact
security.api_additional_headersEmptyHTTP response headersAdditional configured headers are appended to streamed MongoDB collection responses.

Database Collections

This endpoint reads from the collection specified by db and collection.