Runs what the generated APIs can not : a SQL statement as text on a SQL instance, or a database command on MongoDB, and answers what the driver returns. It is the tool of migration scripts and of the few custom APIs which need a join, a stored procedure or a DDL statement.
Method
POST
URL
/api/system-api/admin/execute-plain-query : admin is the user path of your account
Body
{ instance, database?, collection?, query }
Answer
data : the result of the driver (rows, or the result of the command)
The statement runs with the user of the connection string : it can create, alter and drop. The APIs Security Report lists this API with the sensitive system APIs ; grant it to the groups which really need it.
Values from a request must be escaped by you, or better, passed through the generated APIs. For indexes, prefer create indexes, which works the same on every database.
Over HTTP, a system API answers once its settings give it apiAccessType: TOKEN_ACCESS (the token of an API user whose group grants this system API, in x-am-authorization) or IS_PUBLIC. Without settings it is NO_ACCESS : your code calls it through g.sys, the admin panel tests it, and an HTTP call is refused.
The settings can also cache the answer or require person tokens (authProviders) ; pre and post hooks run around it like around any API.
The request headers apply : x-am-response-case, x-am-content-type-response, x-am-internationalization, x-am-tenant-username…