> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List entity records

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the records held in one of the app's entities. Deleted records are left out.

Row-level security applies, so you only get the records the entity's `rls` read rule lets your credential see. An entity with no `rls` rules returns every record.

Filter records with the `q` parameter, or by passing one of the entity's own field names directly as a query parameter for an exact match. For example, `?status=paid` is equivalent to `q={"status": "paid"}`. Only `q` supports comparisons like `$gt`. An unrecognized parameter name is still treated as a filter, so a misspelled field name matches nothing rather than returning an error.

Returns at most 5000 records per call, whether you leave `limit` out or ask for more. The response doesn't indicate when it was cut short, so use `skip` to page through a larger entity.

<Note>This endpoint accepts a personal API key belonging to a user with access to the app, including a read-only key. Workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json get /api/apps/{app_id}/entities/{entity_name}
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - ApiKeyAuth: []
paths:
  /api/apps/{app_id}/entities/{entity_name}:
    get:
      summary: List entity records
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Returns the records held in one of the app's entities. Deleted records
        are left out.


        Row-level security applies, so you only get the records the entity's
        `rls` read rule lets your credential see. An entity with no `rls` rules
        returns every record.


        Filter records with the `q` parameter, or by passing one of the entity's
        own field names directly as a query parameter for an exact match. For
        example, `?status=paid` is equivalent to `q={"status": "paid"}`. Only
        `q` supports comparisons like `$gt`. An unrecognized parameter name is
        still treated as a filter, so a misspelled field name matches nothing
        rather than returning an error.


        Returns at most 5000 records per call, whether you leave `limit` out or
        ask for more. The response doesn't indicate when it was cut short, so
        use `skip` to page through a larger entity.


        <Note>This endpoint accepts a personal API key belonging to a user with
        access to the app, including a read-only key. Workspace API keys are not
        accepted.</Note>
      operationId: list_entities_api_apps__app_id__entities__entity_name__get
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app that owns the entity.
            title: App Id
          description: ID of the app that owns the entity.
          example: 6820f3a4e7b91d003c45a1f2
        - name: entity_name
          in: path
          required: true
          schema:
            type: string
            description: >-
              Name of the entity, exactly as [List entity
              schemas](/api-reference/list-entity-schemas) reports it. Don't
              pass `User` here. It doesn't fail, but it reads and writes a
              separate, disconnected set of records stored under that name, not
              the app's real user accounts, which are managed through their own
              endpoints.
            title: Entity Name
          description: >-
            Name of the entity, exactly as [List entity
            schemas](/api-reference/list-entity-schemas) reports it. Don't pass
            `User` here. It doesn't fail, but it reads and writes a separate,
            disconnected set of records stored under that name, not the app's
            real user accounts, which are managed through their own endpoints.
          example: Invoice
        - name: q
          in: query
          required: false
          description: >-
            Filter as a JSON object of field names and values, for example
            `{"status": "paid"}` for an exact match, or using an operator such
            as `$gt` for a comparison. See [Filtering, sorting, and
            paging](/developers/references/apps-api/sections/entities#filtering-sorting-and-paging)
            for a full list of operators.
          example: '{"status": "paid"}'
          schema:
            type: string
        - name: limit
          in: query
          required: false
          description: >-
            Maximum number of records to return, from 1 to 5000. Defaults to
            5000, and Base44 returns at most 5000 records however high you set
            this.
          example: 100
          schema:
            type: integer
            default: 5000
        - name: skip
          in: query
          required: false
          description: >-
            Number of records to skip before the ones you get back, 0 or more.
            Defaults to 0. Use it with `limit` to page through an entity.
          example: 100
          schema:
            type: integer
            default: 0
        - name: sort
          in: query
          required: false
          description: >-
            Single field to sort by, prefixed with `-` for descending. For
            example, `-created_date` returns newest first. Sorting by more than
            one field isn't supported.
          example: '-created_date'
          schema:
            type: string
        - name: fields
          in: query
          required: false
          description: >-
            Comma-separated list of fields to return, which reduces the response
            size on a wide entity. Reach a field inside an object with dots, as
            in `customer.email`. Each record still carries its `id` whether you
            ask for it or not.
          example: status,amount
          schema:
            type: string
      responses:
        '200':
          description: The entity's records.
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
                  additionalProperties: true
                  description: One record in one of an app's entities.
                  properties:
                    id:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: >-
                        ID of the record. Pass it as `entity_id` to [Get entity
                        record](/api-reference/get-entity-record), [Update
                        entity record](/api-reference/update-entity-record) or
                        [Delete entity
                        record](/api-reference/delete-entity-record).
                      example: 6886b8d390dc7e2f4a2c91b3
                      title: Id
                    created_date:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: >-
                        When the record was created, as a UTC timestamp in ISO
                        8601 format. A record Base44 has just created carries a
                        `Z` suffix, and a record read back from storage does
                        not.
                      example: '2026-06-01T09:23:41.481000'
                      title: Created Date
                    updated_date:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: >-
                        When the record last changed, as a UTC timestamp in ISO
                        8601 format. A record Base44 has just created carries a
                        `Z` suffix, and a record read back from storage does
                        not.
                      example: '2026-06-04T14:07:02.115000'
                      title: Updated Date
                    created_by:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: >-
                        Email of the app user who created the record, or
                        `anonymous` when a visitor created it on an app that
                        needs no login. Apps that hide record authorship leave
                        this field out of the response.
                      example: jane@acme.com
                      title: Created By
                    created_by_id:
                      anyOf:
                        - type: string
                        - type: 'null'
                      description: >-
                        ID of the app user who created the record, or
                        `anonymous` when a visitor created it on an app that
                        needs no login.
                      example: 6874b0c2e1a94d0031bb77de
                      title: Created By Id
                    is_sample:
                      anyOf:
                        - type: boolean
                        - type: 'null'
                      description: >-
                        Whether Base44 stored the record as sample data while
                        the app was being built. A record you create reports
                        `false`.
                      example: false
                      title: Is Sample
                  title: EntityRecord
                title: EntityRecords
        '400':
          description: '`sort` names more than one field.'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: You don't have access to this app.
        '404':
          description: App not found, or the app has no entity with this name.
        '422':
          description: >-
            A filter you passed as its own query parameter doesn't match the
            type the entity's schema declares for that field, for example text
            where the field holds a number. Values inside `q` aren't
            type-checked.
        '429':
          description: >-
            Rate limit exceeded. The base limit is 100 requests per minute, and
            this endpoint shares it with [Count entity
            records](/api-reference/count-entity-records). See [Rate
            limits](/developers/references/apps-api/get-started/rate-limits) for
            the multiplier your plan gets.
components:
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: api_key
      description: Personal API key.

````