API configuration
Page summary:
/config/apicentralizes response privacy, REST defaults (prefix, pagination limits, max request size), and strict parameter validation for both the REST Content API and the Document Service.
General settings for API calls can be set in the ./config/api.js (or ./config/api.ts) file. Both rest and documents options live in this single config file.
| Property | Description | Type | Default |
|---|---|---|---|
responses | Global API response configuration | Object | - |
responses.privateAttributes | Set of globally defined attributes to be treated as private. | String array | [] |
rest | REST API configuration | Object | - |
rest.prefix | The API prefix | String | /api |
rest.defaultLimit | Default limit parameter used in API calls (see REST API documentation). Setting it to -1 removes the limit (see note below). | Integer | 25 |
rest.maxLimit | Maximum allowed number that can be requested as limit (see REST API documentation). | Integer | 100 |
rest.withCount | Whether list responses include the total number of entries and pages in meta.pagination by default. Can be overridden per request with the pagination[withCount] parameter. | Boolean | true |
rest.strictParams | When true, only allowed query and body parameters are accepted on Content API routes; unknown top-level keys are rejected. Add allowed parameters via Custom Content API parameters in register. | Boolean | - |
documents | Document Service configuration | Object | - |
documents.strictParams | When true, Document Service methods reject parameters with unrecognized root-level keys (e.g., invalid status, locale). When false or unset, unknown parameters are ignored. See Document Service API. | Boolean | - |
rest.defaultLimit and rest.maxLimit interact in 2 ways:
- If the
rest.maxLimitvalue is less than therest.defaultLimitvalue,maxLimitwill be the limit used. - Setting
rest.defaultLimitto-1removes the limit for requests that don't explicitly pass apaginationparameter: every matching entry is returned in a single response, andrest.maxLimitdoes not cap it. This differs from explicitly passingpagination[limit]=-1on a request, which is still capped byrest.maxLimit(see REST API documentation).
rest.strictParams applies to incoming REST Content API requests (query and body). documents.strictParams applies to parameters passed to strapi.documents() in server-side code. You can enable one or both in the same config file.
Apps scaffolded with create-strapi-app have both rest.strictParams and documents.strictParams set to true by default in the generated config/api.* file.
Example:
- JavaScript
- TypeScript
module.exports = ({ env }) => ({
responses: {
privateAttributes: ['_v', 'id', 'created_at'],
},
rest: {
prefix: '/v1',
defaultLimit: 100,
maxLimit: 250,
strictParams: true, // only allow parameters defined on routes or added via contentAPI.addQueryParams/addInputParams
},
documents: {
strictParams: true, // reject unrecognized root-level parameters in strapi.documents() calls
},
});
export default ({ env }) => ({
responses: {
privateAttributes: ['_v', 'id', 'created_at'],
},
rest: {
prefix: '/v1',
defaultLimit: 100,
maxLimit: 250,
strictParams: true, // only allow parameters defined on routes or added via contentAPI.addQueryParams/addInputParams
},
documents: {
strictParams: true, // reject unrecognized root-level parameters in strapi.documents() calls
},
});