A clear distinction between available capabilities, controlled features, and planned connectors. MIAO prioritizes least privilege, reproducibility, and self-hosting. An unlisted service is not a compatibility claim.
AVAILABLE NOW
Available now
Implemented in source
External HTTP(S) reads
Server-side read
Data flow
External HTTP(S) → Agent / collection flow
Authentication
Credential-free HTTP(S) URLs only. General OAuth and source credential references are not supported; never put secrets in URLs.
Access / writes
Reads URL content only; does not write to external services.
Limits
Up to 2 MiB per response, a 15-second timeout, and at most 2 followed redirects; collection also has page, item, and request budgets.
Audit / deployment
Server-side requests have budgets and timeouts; run receipts record response status. Private-address and redirect protection is pending (issue #93); operators must restrict egress.
Declarative collection scripts
Controlled collection
Data flow
External HTTP(S) → specified MIAO table
Authentication
Credential-free HTTP(S) sources with declared extraction and mapping; not arbitrary code, authenticated SaaS access, or a credential vault.
Access / writes
Declares the target table and field mapping; writes MIAO business data with deduplication and run receipts.
Limits
Up to 20 pages and 1,000 items; pagination and detail fetching each have a request budget of up to 30. Response, timeout, and run limits also apply.
Audit / deployment
Configure and inspect run status / receipts in the app. Requires a self-hosted MIAO server; collection does not run in a visitor's browser.
Internal PocketBase data
Embedded storage
Data flow
Read / write MIAO workspaces, apps, business tables, and records
Authentication
MIAO member identity; administrator credentials are not exposed to the browser.
Access / writes
API enforces workspace and app permissions. Declared business actions can write; public data reads have separate publication allowlists.
Limits
Depends on the specific API; this does not mean unlimited data or uploads.
Audit / deployment
Business changes and background runs have records / receipts. PocketBase is embedded in the self-hosted MIAO Go server.
DECLARED AND PERMISSIONED
Controlled capabilities
Declared and permissioned
Workflows and declared Agent actions
In-app operations
Data flow
Read / write within MIAO business tables; Agent external reads have separate HTTP(S) limits.
Authentication
Workspace membership and server-side configuration; model credentials stay on the server.
Access / writes
Only declared workflow transitions and business actions in the app; writes enforce app permissions and field validation.
Limits
Bound by declared steps, task run budgets, and timeouts; arbitrary writes to external systems are not promised.
Audit / deployment
Actions and background tasks retain run status, steps, or write receipts; a self-hosted MIAO server is required.
Public releases
Anonymous read-only
Data flow
Explicitly authorized fields in a published app → public visitors
Authentication
Visitors need no login; publishers authenticate with MIAO and explicitly configure the public scope.
Access / writes
Only pages, records, and fields allowed by the public policy; this entry covers anonymous GET data APIs, which omit business actions, raw attachments, and relations. Separate public form submissions are not general-purpose write-back.
Limits
Bound by published field allowlists and public API limits; not a full database export or arbitrary public write access.
Audit / deployment
Published versions can be rolled back; per-visitor access auditing is not promised. Requires an accessible MIAO deployment.
ROADMAP — NOT AVAILABLE YET
Planned capabilities
Not available as integrations
Connector directory, credential references, and external writes
Planned · unavailable
Data flow
Controlled connections to external services are being considered; specific directions and services are not committed.
Authentication
A secure credential-reference model is still to be designed; this page does not imply an existing OAuth or secrets vault.
Access / writes
Writing to external systems is not currently an available capability. Do not rely on it in production workflows.
Limits
To be defined; unlimited calls or arbitrary writes are not promised.
Audit / deployment
Scope, auditing, and deployment requirements must be confirmed by a future public design / issue.