Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

A dashboard for managing Parse Server

License

NotificationsYou must be signed in to change notification settings

parse-community/parse-dashboard

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

parse-repository-header-dashboard


Build StatusBuild StatusSnyk Badge

Node Versionauto-release

npm latest versionnpm alpha version

Backers on Open CollectiveSponsors on Open CollectiveLicenseForumTwitter


Parse Dashboard is a standalone dashboard for managing yourParse Server apps.


Getting Started

Install the dashboard fromnpm.

npm install -g parse-dashboard

You can launch the dashboard for an app with a single command by supplying an app ID, master key, URL, and name like this:

parse-dashboard --dev --appId yourAppId --masterKey yourMasterKey --serverURL "https://example.com/parse" --appName optionalName

You may set the host, port and mount path by supplying the--host,--port and--mountPath options to parse-dashboard. You can use anything you want as the app name, or leave it out in which case the app ID will be used.

The--dev parameter disables production-ready security features. This parameter is useful when running Parse Dashboard on Docker. Using this parameter will:

  • allow insecure http connections from anywhere, bypassing the optionallowInsecureHTTP
  • allow the Parse ServermasterKey to be transmitted in cleartext without encryption
  • allow dashboard access without user authentication

⚠️ Do not use this parameter when deploying Parse Dashboard in a production environment.

After starting the dashboard, you can visithttp://localhost:4040 in your browser:

Parse Dashboard

Compatibility

Parse Server

Parse Dashboard is compatible with the following versions of Parse Server.

Parse DashboardParse Server
>= 1.0.0>= 2.1.4 < 7.0.0
>= 8.0.0>= 7.0.0

Parse Dashboard automatically checks the Parse Server version when connecting and displays a warning if the server version does not meet the minimum required version. The required Parse Server version is defined in thesupportedParseServerVersion field inpackage.json.

Node.js

Parse Dashboard is continuously tested with the most recent releases of Node.js to ensure compatibility. We follow theNode.js Long Term Support plan and only test against versions that are officially supported and have not reached their end-of-life date.

VersionMinimum versionEnd-of-LifeCompatible
Node.js 1818.20.4May 2025✅ Yes
Node.js 2020.18.0April 2026✅ Yes
Node.js 2222.9.0April 2027✅ Yes
Node.js 2424.0.0April 2028✅ Yes

Configuring Parse Dashboard

Options

This section provides a comprehensive reference for all Parse Dashboard configuration options that can be used in the configuration file, via CLI arguments, or as environment variables.

Root Options

KeyTypeRequiredDefaultCLIEnv VariableExampleDescriptionLinks to Details
appsArray<Object>Yes--PARSE_DASHBOARD_CONFIG[{...}]Array of Parse Server apps to manageApp Options
usersArray<Object>No---[{...}]User accounts for dashboard authenticationUser Configuration
useEncryptedPasswordsBooleanNofalse--trueUse bcrypt hashes instead of plain text passwords-
trustProxyBoolean | NumberNofalse--trustProxyPARSE_DASHBOARD_TRUST_PROXY1Trust X-Forwarded-* headers when behind proxy-
iconsFolderStringNo---"icons"Folder for app icons (relative or absolute path)-
agentObjectNo--PARSE_DASHBOARD_AGENT (JSON){...}AI agent configurationAI Agent Configuration
enableResourceCacheBooleanNofalse--trueEnable browser caching of dashboard resources-
App Options
ParameterTypeOptionalDefaultCLIEnv VariableExampleDescription
appIdStringno---appIdPARSE_DASHBOARD_APP_ID"myAppId"The Application ID for your Parse Server instance.
masterKeyString | Functionno---masterKeyPARSE_DASHBOARD_MASTER_KEY"key" or() => "key"Master key for full access. Can be a String or Function returning a String.
serverURLStringno---serverURLPARSE_DASHBOARD_SERVER_URL"http://localhost:1337/parse"The URL where your Parse Server is running.
appNameStringyesappId--appNamePARSE_DASHBOARD_APP_NAME"MyApp"Display name of the app.
masterKeyTtlNumberyes---masterKeyTtl-3600TTL for master key cache in seconds (only when masterKey is a function).
readOnlyMasterKeyStringyes---"myReadOnlyKey"Read-only master key that prevents mutations.
clientKeyStringyes---"myClientKey"Client key for Parse SDK (legacy, mostly unused).
javascriptKeyStringyes---"myJsKey"JavaScript key for Parse SDK (legacy, mostly unused).
restKeyStringyes---"myRestKey"REST API key for server-side REST applications.
windowsKeyStringyes---"myWindowsKey"Windows SDK key (legacy, mostly unused).
webhookKeyStringyes---"myWebhookKey"Webhook key for Cloud Code Webhooks.
fileKeyStringyes---"myFileKey"File key used for file migrations.
graphQLServerURLStringyes---graphQLServerURLPARSE_DASHBOARD_GRAPHQL_SERVER_URL"http://localhost:1337/graphql"The URL where your Parse GraphQL Server is running.
appNameForURLStringyesappName--"my-app"URL-friendly name used in dashboard URLs.
productionBooleanyesfalse--trueMark as production environment.
iconNameStringyes---"icon.png"Filename of app icon (requires globaliconsFolder).
primaryBackgroundColorStringyes---"#FFA500"Primary background color (CSS value).
secondaryBackgroundColorStringyes---"#FF4500"Secondary background color (CSS value).
supportedPushLocalesArray<String>yes---["en","fr"]Supported locales for push notifications.
preventSchemaEditsBooleanyesfalse--truePrevent schema modifications through the dashboard.
columnPreferenceObjectyes---{"_User":[...]}Column visibility/sorting/filtering preferences. Seecolumn preferences details.
classPreferenceObjectyes---{"_Role":{...}}Persistent filters for all users. Seepersistent filters details.
enableSecurityChecksBooleanyesfalse--trueEnable security checks under App Settings > Security.
cloudConfigHistoryLimitIntegeryes100--200Number of historic Cloud Config values (0 to Number.MAX_SAFE_INTEGER).
configObjectyes---{...}Settings for storing dashboard config on server.
config.classNameStringyes---"DashboardConfig"Table name for dashboard configuration.
scriptsArray<Object>yes[]--[{...}]Scripts for this app. Seescripts table below.
infoPanelArray<Object>yes---[{...}]Info panel config. Seeinfo panel table below.
Column Options

Each class incolumnPreference can have an array of column configurations:

ParameterTypeOptionalDefaultExampleDescription
nameStringno-"createdAt"Column/field name.
visibleBooleanyestruefalseWhether the column is visible in the data browser.
preventSortBooleanyesfalsetruePrevent this column from being sortable.
filterSortToTopBooleanyesfalsetrueSort this column to the top in filter popup.
Script Options
ParameterTypeOptionalDefaultExampleDescription
titleStringno-"Delete User"Title in context menu and confirmation dialog.
classesArray<String> | Array<Object>no-["_User"]Classes for which script can run.
cloudCodeFunctionStringno-"deleteUser"Parse Cloud Function name to execute.
executionBatchSizeIntegeryes110Batch size for multiple objects (runs in serial).
showConfirmationDialogBooleanyesfalsetrueShow confirmation dialog before execution.
confirmationDialogStyleStringyesinfocriticalDialog style:info (blue) orcritical (red).
Info Panel Options
ParameterTypeOptionalDefaultExampleDescription
titleStringno-"User Details"Panel title.
classesArray<String>no-["_User"]Classes for which panel is displayed.
cloudCodeFunctionStringno-"getUserDetails"Cloud Function receiving selected object.
prefetchObjectsNumberyes02Number of next rows to prefetch.
prefetchStaleNumberyes010Seconds after which prefetched data is stale.
prefetchImageBooleanyestruefalseWhether to prefetch image content.
prefetchVideoBooleanyestruefalseWhether to prefetch video content.
prefetchAudioBooleanyestruefalseWhether to prefetch audio content.
User Options
ParameterTypeOptionalDefaultCLIEnv VariableExampleDescription
userStringno---userIdPARSE_DASHBOARD_USER_ID"admin"Username for authentication.
passStringno---userPasswordPARSE_DASHBOARD_USER_PASSWORD"pass"Password (plain or bcrypt hash).
mfaStringyes---"JBSWY3DPEHPK3PXP"MFA secret for TOTP.
mfaAlgorithmStringyes"SHA1"--"SHA256"TOTP algorithm for MFA.
mfaDigitsNumberyes6--8Number of digits in MFA code.
mfaPeriodNumberyes30--60MFA code validity period in seconds.
readOnlyBooleanyesfalse--trueRead-only access to all their apps.
appsArray<Object>yes---[{...}]Apps user can access (all if omitted).
apps[].appIdStringno---"myAppId"App ID user can access.
apps[].readOnlyBooleanyesfalse--trueRead-only access to this specific app.

CLI & Server Options

ParameterTypeOptionalDefaultCLIEnv VariableExampleDescription
hostStringyes"0.0.0.0"--hostHOST"127.0.0.1"Host address to bind server.
portNumberyes4040--portPORT8080Port for dashboard server.
mountPathStringyes"/"--mountPathMOUNT_PATH"/dashboard"Mount path for application.
allowInsecureHTTPBooleanyesfalse--allowInsecureHTTPPARSE_DASHBOARD_ALLOW_INSECURE_HTTPtrueAllow HTTP (use behind HTTPS proxy).
sslKeyStringyes---sslKeyPARSE_DASHBOARD_SSL_KEY"/path/key"Path to SSL private key for HTTPS.
sslCertStringyes---sslCertPARSE_DASHBOARD_SSL_CERT"/path/cert"Path to SSL certificate for HTTPS.
cookieSessionSecretStringyesRandom--cookieSessionSecretPARSE_DASHBOARD_COOKIE_SESSION_SECRET"secret"Secret for session cookies (for multi-server).
cookieSessionMaxAgeNumberyesSession-only--cookieSessionMaxAgePARSE_DASHBOARD_COOKIE_SESSION_MAX_AGE3600Session cookie expiration (seconds).
devBooleanyesfalse--dev--Development mode (DO NOT use in production).
configStringyes---config-"config.json"Path to JSON configuration file.

Helper CLI Commands

CommandDescription
--createUserInteractive tool to generate secure user passwords and MFA secrets.
--createMFAInteractive tool to generate MFA secrets for existing users.

File

You can also start the dashboard from the command line with a config file. To do this, create a new file calledparse-dashboard-config.json inside your local Parse Dashboard directory hierarchy. The file should match the following format:

{"apps": [    {"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"MyApp"    }  ]}

You can then start the dashboard usingparse-dashboard --config parse-dashboard-config.json.

Environment variables

This only works when starting the app using theparse-dashboard command

There are also two methods you can use to configure the dashboard using environment variables.

Multiple apps

Provide the entire JSON configuration inPARSE_DASHBOARD_CONFIG and it will be parsed just like the config file.

Single app

You can also define each configuration option individually.

HOST: "0.0.0.0"PORT: "4040"MOUNT_PATH: "/"PARSE_DASHBOARD_TRUST_PROXY: undefined // Or "1" to trust connection info from a proxy's X-Forwarded-* headersPARSE_DASHBOARD_SERVER_URL: "http://localhost:1337/parse"PARSE_DASHBOARD_MASTER_KEY: "myMasterKey"PARSE_DASHBOARD_APP_ID: "myAppId"PARSE_DASHBOARD_APP_NAME: "MyApp"PARSE_DASHBOARD_USER_ID: "user1"PARSE_DASHBOARD_USER_PASSWORD: "pass"PARSE_DASHBOARD_SSL_KEY: "sslKey"PARSE_DASHBOARD_SSL_CERT: "sslCert"PARSE_DASHBOARD_CONFIG: undefined // Only for reference, it must not existPARSE_DASHBOARD_COOKIE_SESSION_SECRET: undefined // set the cookie session secret, defaults to a random string. Use this option if you want sessions to work across multiple servers, or across restartsPARSE_DASHBOARD_AGENT: undefined // JSON string containing the full agent configuration with models array

Managing Multiple Apps

Managing multiple apps from the same dashboard is also possible. Simply add additional entries into theparse-dashboard-config.json file's"apps" array:

{"apps": [    {"serverURL":"http://localhost:1337/parse",// Self-hosted Parse Server"appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App"    },    {"serverURL":"http://localhost:1337/parse2",// Self-hosted Parse Server"appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App 2"    }  ]}

GraphQL Playground

Parse Dashboard has a built-in GraphQL Playground to play with the auto-generatedParse GraphQL API.

You can setup the GraphQL Playground by passing the--graphQLServerURL option to theparse-dashboard CLI:

parse-dashboard --dev --appId yourAppId --masterKey yourMasterKey --serverURL "https://example.com/parse" --graphQLServerURL "https://example.com/graphql" --appName optionalName

ThegraphQLServerURL option is also available through an environment variable calledPARSE_DASHBOARD_GRAPHQL_SERVER_URL:

HOST: "0.0.0.0"PORT: "4040"MOUNT_PATH: "/"PARSE_DASHBOARD_SERVER_URL: "http://localhost:1337/parse"PARSE_DASHBOARD_GRAPHQL_SERVER_URL: "http://localhost:1337/graphql"PARSE_DASHBOARD_MASTER_KEY: "myMasterKey"PARSE_DASHBOARD_APP_ID: "myAppId"PARSE_DASHBOARD_APP_NAME: "MyApp"

You can also setup the GraphQL Playground in yourparse-dashboard-config.json file:

{"apps": [    {"serverURL":"http://localhost:1337/parse","graphQLServerURL":"http://localhost:1337/graphql","appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App"    },    {"serverURL":"http://localhost:1337/parse2","graphQLServerURL":"http://localhost:1337/graphql2","appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App 2"    }  ]}

After starting the dashboard, you can visithttp://0.0.0.0:4040/apps/MyTestApp/api_console/graphql in your browser:

Parse Dashboard GraphQL Playground

App Icon Configuration

Parse Dashboard supports adding an optional icon for each app, so you can identify them easier in the list. To do so, youmust use the configuration file, define aniconsFolder in it, and define theiconName parameter for each app (including the extension). The path of theiconsFolder is relative to the configuration file. If you have installed ParseDashboard globally you need to use the full path as value for theiconsFolder. To visualize what it means, in the following exampleicons is a directory located under the same directory as the configuration file:

{"apps": [    {"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App","iconName":"MyAppIcon.png",    }  ],"iconsFolder":"icons"}

App Background Color Configuration

Parse Dashboard supports adding an optional background color for each app, so you can identify them easier in the list. To do so, youmust use the configuration file, define anprimaryBackgroundColor andsecondaryBackgroundColor in it, parameter for each app. It isCSS style. To visualize what it means, in the following examplebackgroundColor is a configuration file:

{"apps": [    {"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App","primaryBackgroundColor":"#FFA500",// Orange"secondaryBackgroundColor":"#FF4500"// OrangeRed    },    {"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App [2]","primaryBackgroundColor":"rgb(255, 0, 0)",// Red"secondaryBackgroundColor":"rgb(204, 0, 0)"// DarkRed    }  ]}

Other Configuration Options

You can setappNameForURL in the config file for each app to control the url of your app within the dashboard. This can make it easier to use bookmarks or share links on your dashboard.

To change the app to production, simply setproduction totrue in your config file. The default value is false if not specified.

Prevent columns sorting

You can prevent some columns to be sortable by addingpreventSort to columnPreference options in each app configuration

"apps": [  {"appId":"local_app_id","columnPreference": {"_User": [          {"name":"createdAt","visible":true,"preventSort":true          },          {"name":"updatedAt","visible":true,"preventSort":false          },        ]      }    }]

Custom order in the filter popup

If you have classes with a lot of columns and you filter them often with the same columns you can sort those to the top by extending thecolumnPreference setting with thefilterSortToTop option:

"apps": [  {"columnPreference": {"_User": [          {"name":"objectId","filterSortToTop":true          },          {"name":"email","filterSortToTop":true          }        ]      }    }]

Persistent Filters

The filters you save in the data browser of Parse Dashboard are only available for the current dashboard user in the current browser session. To make filters permanently available for all dashboard users of an app, you can define filters in theclassPreference setting.

For example:

"apps": [{"classPreference": {"_Role": {"filters": [{"name":"Filter Name","filter": [          {"field":"objectId","constraint":"exists"          }        ]      }]    }  }}]

You can conveniently create a filter definition without having to write it by hand by first saving a filter in the data browser, then exporting the filter definition underApp Settings > Export Class Preferences.

Keyboard Shortcuts

Configure custom keyboard shortcuts for dashboard actions inApp Settings > Keyboard Shortcuts.

Delete a shortcut key to disable the shortcut.

Scripts

You can specify scripts to execute Cloud Functions with thescripts option:

"apps": [  {"scripts": [      {"title":"Delete Account","classes": ["_User"],"cloudCodeFunction":"deleteAccount","showConfirmationDialog":true,"confirmationDialogStyle":"critical"      }    ]  }]

You can also specify custom fields with thescrips option:

"apps": [  {"scripts": [      {"title":"Delete account","classes": [          {"name":"_User","fields": [              {"name":"createdAt","validator":"value => value > new Date(\"2025\")" }            ]          }        ],"cloudCodeFunction":"deleteAccount"      }    ]  }]

Next, define the Cloud Function in Parse Server that will be called. The object that has been selected in the data browser will be made available as a request parameter:

Parse.Cloud.define('deleteAccount',async(req)=>{req.params.object.set('deleted',true);awaitreq.params.object.save(null,{useMasterKey:true});},{requireMaster:true});

The field which the script was invoked on can be accessed byselectedField:

Parse.Cloud.define('deleteAccount',async(req)=>{if(req.params.selectedField!=='objectId'){thrownewParse.Error(Parse.Error.SCRIPT_FAILED,'Deleting accounts is only available on the objectId field.');}req.params.object.set('deleted',true);awaitreq.params.object.save(null,{useMasterKey:true});},{requireMaster:true});

⚠️ Depending on your Parse Server version you may need to set the Parse Server optionencodeParseObjectInCloudFunction totrue so that the selected object in the data browser is made available in the Cloud Function as an instance ofParse.Object. If the option is not set, is set tofalse, or you are using an older version of Parse Server, the object is made available as a plain JavaScript object and needs to be converted from a JSON object to aParse.Object instance withreq.params.object = Parse.Object.fromJSON(req.params.object);, before you can call anyParse.Object properties and methods on it.

For older versions of Parse Server:

Parse Server >=4.4.0 <6.2.0
Parse.Cloud.define('deleteAccount',async(req)=>{req.params.object=Parse.Object.fromJSON(req.params.object);req.params.object.set('deleted',true);awaitreq.params.object.save(null,{useMasterKey:true});},{requireMaster:true});
Parse Server >=2.1.4 <4.4.0
Parse.Cloud.define('deleteAccount',async(req)=>{if(!req.master||!req.params.object){throw'Unauthorized';}req.params.object=Parse.Object.fromJSON(req.params.object);req.params.object.set('deleted',true);awaitreq.params.object.save(null,{useMasterKey:true});});

Resource Cache

Parse Dashboard can cache its resources such as bundles in the browser, so that opening the dashboard in another tab does not reload the dashboard resources from the server but from the local browser cache. Caching only starts after login in the dashboard.

ParameterTypeOptionalDefaultExampleDescription
enableResourceCacheBooleanyesfalsetrueEnables caching of dashboard resources in the browser for faster dashboard loading in additional browser tabs.

Example configuration:

constdashboard=newParseDashboard({enableResourceCache:true,apps:[{serverURL:'http://localhost:1337/parse',appId:'myAppId',masterKey:'myMasterKey',appName:'MyApp'}]});

Warning

This feature can make it more difficult to push dashboard updates to users. Enabling the resource cache will start a browser service worker that caches dashboard resources locally only once. As long as the service worker is running, it will prevent loading any dashboard updates from the server, even if the user reloads the browser tab. The service worker is automatically stopped, once the last dashboard browser tab is closed. On the opening of the first dashboard browser tab, a new service worker is started and the dashboard resources are loaded from the server.

Note

For developers: during dashboard development, the resource cache should be disabled to ensure reloading the dashboard tab in the browser loads the new dashboard bundle with any changes you made in the source code. You can inspect the service worker in the developer tools of most browsers. For example in Google Chrome, go toDeveloper Tools > Application tab > Service workers to see whether the dashboard service worker is currently running and to debug it.

Running as Express Middleware

Instead of starting Parse Dashboard with the CLI, you can also run it as anexpress middleware.

varexpress=require('express');varParseDashboard=require('parse-dashboard');vardashboard=newParseDashboard({"apps":[{"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"MyApp"}]});varapp=express();// make the Parse Dashboard available at /dashboardapp.use('/dashboard',dashboard);varhttpServer=require('http').createServer(app);httpServer.listen(4040);

If you want to run bothParse Server and Parse Dashboard on the same server/port, you can run them both as express middleware:

varexpress=require('express');varParseServer=require('parse-server').ParseServer;varParseDashboard=require('parse-dashboard');varapi=newParseServer({// Parse Server settings});varoptions={allowInsecureHTTP:false};vardashboard=newParseDashboard({// Parse Dashboard settings},options);varapp=express();// make the Parse Server available at /parseapp.use('/parse',api);// make the Parse Dashboard available at /dashboardapp.use('/dashboard',dashboard);varhttpServer=require('http').createServer(app);httpServer.listen(4040);

Deploying Parse Dashboard

Preparing for Deployment

Make sure the server URLs for your apps can be accessed by your browser. If you are deploying the dashboard, thenlocalhost urls will not work.

Security Considerations

In order to securely deploy the dashboard without leaking your apps master key, you will need to use HTTPS and Basic Authentication.

The deployed dashboard detects if you are using a secure connection. If you are deploying the dashboard behind a load balancer or front-facing proxy, then the app won't be able to detect that the connection is secure. In this case, you can start the dashboard with the--trustProxy=1 option (or set the PARSE_DASHBOARD_TRUST_PROXY config var to 1) to rely on the X-Forwarded-* headers for the client's connection security. This is useful for hosting on services like Heroku, where you can trust the provided proxy headers to correctly determine whether you're using HTTP or HTTPS. You can also turn on this setting when using the dashboard asexpress middleware:

vartrustProxy=true;vardashboard=newParseDashboard({"apps":[{"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"MyApp"}],"trustProxy":1});

Security Checks

You can view the security status of your Parse Server by enabling the dashboard optionenableSecurityChecks, and visiting App Settings > Security.

constdashboard=newParseDashboard({"apps":[{"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"MyApp""enableSecurityChecks":true}],});

Configuring Basic Authentication

You can configure your dashboard for Basic Authentication by adding usernames and passwords yourparse-dashboard-config.json configuration file:

{"apps": [{"...":"..."}],"users": [    {"user":"user1","pass":"pass"    },    {"user":"user2","pass":"pass"    }  ],"useEncryptedPasswords":true| false}

You can store the password in eitherplain text orbcrypt formats. To use thebcrypt format, you must set the configuseEncryptedPasswords parameter totrue.You can generate encrypted passwords by usingparse-dashboard --createUser, and pasting the result in your users config.

Multi-Factor Authentication (One-Time Password)

You can add an additional layer of security for a user account by requiring multi-factor authentication (MFA) for the user to login.

With MFA enabled, a user must provide a one-time password that is typically bound to a physical device, in addition to their login password. This means in addition to knowing the login password, the user needs to have physical access to a device to generate the one-time password. This one-time password is time-based (TOTP) and only valid for a short amount of time, typically 30 seconds, until it expires.

The user requires an authenticator app to generate the one-time password. These apps are provided by many 3rd parties and mostly for free.

If you create a new user by runningparse-dashboard --createUser, you will be asked whether you want to enable MFA for the new user. To enable MFA for an existing user, runparse-dashboard --createMFA to generate amfa secret that you then add to the existing user configuration, for example:

{"apps": [{"...":"..."}],"users": [    {"user":"user1","pass":"pass","mfa":"lmvmOIZGMTQklhOIhveqkumss"    }  ]}

Parse Dashboard follows the industry standard and supports the common OTP algorithmSHA-1 by default, to be compatible with most authenticator apps. If you have specific security requirements regarding TOTP characteristics (algorithm, digit length, time period) you can customize them by using the guided configuration mentioned above.

Running Multiple Dashboard Replicas

When deploying Parse Dashboard with multiple replicas behind a load balancer, you need to use a shared session store to ensure that CSRF tokens and user sessions work correctly across all replicas. Without a shared session store, login attempts may fail with "CSRF token validation failed" errors when requests are distributed across different replicas.

Using a Custom Session Store

Parse Dashboard supports using any session store compatible withexpress-session. ThesessionStore option must be configured programmatically when initializing the dashboard.

Suggested Session Stores:

Example using connect-redis:

constexpress=require('express');constParseDashboard=require('parse-dashboard');const{ createClient}=require('redis');constRedisStore=require('connect-redis').default;// Instantiate Redis clientconstredisClient=createClient({url:'redis://localhost:6379'});redisClient.connect();// Instantiate Redis session storeconstcookieSessionStore=newRedisStore({client:redisClient});// Configure dashboard with session storeconstdashboard=newParseDashboard({apps:[...],users:[...],},{  cookieSessionStore,cookieSessionSecret:'your-secret-key',});**ImportantNotes:**-The`cookieSessionSecret`optionmustbesettothesamevalueacrossallreplicastoensuresessioncookiesworkcorrectly.-If`cookieSessionStore`isnotprovided,ParseDashboardwillusethedefaultin-memorysessionstore,whichonlyworksforsingle-instancedeployments.-Forproductiondeploymentswithmultiplereplicas,alwaysconfigureasharedsessionstore.####Alternative:UsingStickySessionsIfyoucannotuseasharedsessionstore,youcanconfigureyourloadbalancertousestickysessions(sessionaffinity),whichensuresthatrequestsfromthesameuserarealwaysroutedtothesamereplica.However,usingasharedsessionstoreistherecommendedapproachasitprovidesbetterreliabilityandscalability.###SeparatingAppAccessBasedonUserIdentityIfyouhaveconfiguredyourdashboardtomanagemultipleapplications,youcanrestrictthemanagementofappsbasedonuseridentity.Todoso,updateyour`parse-dashboard-config.json`configurationfiletomatchthefollowingformat:```json{"apps":[{"...":"..."}],"users":[{"user":"user1","pass":"pass1","apps":[{"appId":"myAppId1"},{"appId":"myAppId2"}]},{"user":"user2","pass":"pass2","apps":[{"appId":"myAppId1"}]}]}

The effect of such a configuration is as follows:

Whenuser1 logs in, he/she will be able to managemyAppId1 andmyAppId2 from the dashboard.

Whenuser2 logs in, he/she will only be able to managemyAppId1 from the dashboard.

Use Read-Only masterKey

Starting parse-server 2.6.5, it is possible to provide areadOnlyMasterKey to parse-server to prevent mutations on objects from a client.If you want to protect your dashboard with this feature, just use thereadOnlyMasterKey instead of themasterKey. All write calls will fail.

Making an app read-only for all users

Start yourparse-server with

{"masterKey":"YOUR_MASTER_KEY_HERE","readOnlyMasterKey":"YOUR_READ_ONLY_MASTER_KEY",}

Then in your dashboard configuration:

vartrustProxy=true;vardashboard=newParseDashboard({"apps":[{"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"YOUR_READ_ONLY_MASTER_KEY","appName":"MyApp"}],"trustProxy":1});

Makings users read-only

Make sure you specify thereadOnlyMasterKey for the apps that you want to use read-only feature in "apps" configuration.You can mark a user as a read-only user:

{"apps": [    {"appId":"myAppId1","masterKey":"myMasterKey1","readOnlyMasterKey":"myReadOnlyMasterKey1","serverURL":"myURL1","port":4040,"production":true    },    {"appId":"myAppId2","masterKey":"myMasterKey2","readOnlyMasterKey":"myReadOnlyMasterKey2","serverURL":"myURL2","port":4041,"production":true    }  ],"users": [    {"user":"user1","pass":"pass1","readOnly":true,"apps": [{"appId":"myAppId1"}, {"appId":"myAppId2"}]    },    {"user":"user2","pass":"pass2","apps": [{"appId":"myAppId1"}]    }  ]}

This wayuser1 will have a readOnly access tomyAppId1 andmyAppId2

Making user's apps readOnly

Make sure you specify thereadOnlyMasterKey for the apps that you want to use read-only feature in "apps" configuration.You can give read only access to a user on a per-app basis:

{"apps": [    {"appId":"myAppId1","masterKey":"myMasterKey1","readOnlyMasterKey":"myReadOnlyMasterKey1","serverURL":"myURL","port":4040,"production":true    },    {"...":"..."}  ],"users": [    {"user":"user","pass":"pass","apps": [{"appId":"myAppId","readOnly":true}, {"appId":"myAppId2"}]    }  ]}

With this configuration, user1 will have read only access tomyAppId1 and read/write access tomyAppId2.

Configuring Localized Push Notifications

With the latest version of thedashboard, it is possible to send localized messages for push notifications.You can provide a list of locales or languages you want to support for your dashboard users.

{"apps": [    {"serverURL":"http://localhost:1337/parse","appId":"myAppId","masterKey":"myMasterKey","appName":"My Parse Server App","iconName":"MyAppIcon.png","supportedPushLocales": ["en","ru","fr"]    }  ],"iconsFolder":"icons"}

Run with Docker

The official docker image is published ondocker hub

Run the image with yourconfig.json mounted as a volume

docker run -d -p 8080:4040 -v host/path/to/config.json:/src/Parse-Dashboard/parse-dashboard-config.json parseplatform/parse-dashboard --dev

You can also pass the appId, masterKey and serverURL as arguments:

docker run -d -p 4040:4040 parseplatform/parse-dashboard --dev --appId $APP_ID --masterKey $MASTER_KEY --serverURL $SERVER_URL

By default, the container will start the app at port 4040 inside the container. However, you can run custom command as well (seeDeploying in production for custom setup).

In this example, we want to run the application in production mode at port 80 of the host machine.

docker run -d -p 80:8080 -v host/path/to/config.json:/src/Parse-Dashboard/parse-dashboard-config.json parse-dashboard --port 8080 --dev

If you are not familiar with Docker,--port 8080 will be passed in as argument to the entrypoint to form the full commandnpm start -- --port 8080. The application will start at port 8080 inside the container and port8080 will be mounted to port80 on your host machine.

Features

(The following is not a complete list of features but a work in progress to build a comprehensive feature list.)

Data Browser

Filters

▶️Core > Browser > Filter

The filter dialog allows to add relational filter conditions based on other classes that have a pointer to the current class.

For example, users in the_User class may have:

  • purchases in aPurchase class with a_User pointer field
  • transactions in aPayment class with a_User pointer field

A relational filter allows you filter all users who:

  • purchased a specific item (inPurchase class)
  • payed with a specific payment method (inPayment class)

To apply such a filter, simply go to the_User class and add the two required filter conditions with thePurchase andPayment classes.

Info Panel

▶️Core > Browser > Show Panel / Hide Panel

The data browser offers an info panel that can display information related to the currently selected object in the data browser table. The info panel is made visible by clicking on the menu buttonShow Panel in the top right corner when browsing a class for which the info panel is configured in the dashboard options.

The following example dashboard configuration shows an info panel for the_User class with the titleUser Details, by calling the Cloud Code FunctiongetUserDetails and displaying the returned response.

"apps": [  {"infoPanel": [      {"title":"User Details","classes": ["_User"],"cloudCodeFunction":"getUserDetails","prefetchObjects":2,"prefetchStale":10,"prefetchImage":true,"prefetchVideo":true,"prefetchAudio":true      }    ]  }]

The Cloud Code Function receives the selected object in the payload and returns a response that can include various items.

Response

Segments

The info panel can contain multiple segments to display different groups of information.

ParameterValueOptionalDescription
segmentsArrayNoAn ordered array of segments, where each segment represents a distinct group of items to display.
segments[i].titleStringNoThe title of the segment that will be displayed.
segments[i].itemsArrayNoAn ordered array of items within the segment. Each item can be of different types, such as text, key-value pairs, tables, images, etc.
segments[i].styleObjectYesThe CSS style definition for the segment.
segments[i].titleStyleObjectYesThe CSS style definition for the segment title.

Example:

{"panel": {"segments": [      {"title":"Purchases","style": {"backgroundColor":"lightgray","font-size":"10px" },"titleStyle": {"backgroundColor":"orange","color":"white" },"items": [          {"type":"text","text":"This user has a high churn risk!"          }        ]      }    ]  }}

The items array can include various types of content such as text, key-value pairs, tables, images, videos, audios, and buttons. Each type offers a different way to display information within the info panel, allowing for a customizable and rich user experience. Below is a detailed explanation of each type.

Text Item

A simple text field.

ParameterValueOptionalDescription
typeStringNoMust be"text".
textStringNoThe text to display.
styleObjectYesThe CSS style definition.

Example:

{"type":"text","text":"This user has a high churn risk!","style": {"backgroundColor":"red" },}
Key-Value Item

A text item that consists of a key and a value. The value can optionally be linked to a URL.

ParameterValueDefaultOptionalDescription
typeString-NoMust be"keyValue".
keyString-NoThe key text to display.
valueString-NoThe value text to display.
urlStringundefinedYesThe URL that will be opened in a new browser tab when clicking on the value text. It can be set to an absolute URL or a relative URL in which case the base URL is<PROTOCOL>://<HOST>/<MOUNT_PATH>/.
isRelativeUrlBooleanfalseYesSet this totrue when linking to another dashboard page, in which case the base URL for the relative URL will be<PROTOCOL>://<HOST>/<MOUNT_PATH>/apps/<APP_NAME>/.
valuesArray-YesAdditional values to display aftervalue. Each item is an object withvalue, optionalurl andisRelativeUrl.
styleObject-YesThe CSS style definition.

Examples:

{"type":"keyValue","key":"Lifetime purchase value","value":"$10k","style": {"backgroundColor":"green" },}
{"type":"keyValue","key":"Last purchase ID","value":"123","url":"https://example.com/purchaseDetails?purchaseId=123"}
{"type":"keyValue","key":"Purchase","value":"123","url":"browser/Purchase","isRelativeUrl":true}
{"type":"keyValue","key":"Purchase Value","value":"123","url":"browser/Purchase","isRelativeUrl":true,"values": [{"value":"456" }]}

To navigate to a specific object using a relative URL, the query parameters must be URL encoded:

constobjectId='abc123';constclassName='Purchase';constquery=[{field:'objectId',constraint:'eq',compareTo:objectId}];consturl=`browser/Purchase?filters=${JSON.stringify(query)}`;constitem={type:'keyValue',key:'Purchase',value:objectId,  url,isRelativeUrl:true}
Table Item

A table with columns and rows to display data in a structured format.

ParameterValueOptionalDescription
typeStringNoMust be"table".
columnsArrayNoThe column definitions, including names and types.
columns[*].nameStringNoThe name of the column to display.
columns[*].typeStringNoThe type of the column value (e.g.,"string","number").
rowsArrayNoThe rows of data, where each row is an object containing values for each column.
styleObjectYesThe CSS style definition.

Example:

{"type":"table","columns": [    {"name":"Name","type":"string"    },    {"name":"Age","type":"number"    }  ],"rows": [    {"Name":"Alice","Age":30    },    {"Name":"Bob","Age":40    }  ],"style": {"backgroundColor":"lightGray" }}
Image Item

An image to be displayed in the panel.

ParameterValueOptionalDescription
typeStringNoMust be"image".
urlStringNoThe URL of the image to display.
styleObjectYesThe CSS style definition.

Example:

{"type":"image","url":"https://example.com/images?purchaseId=012345","style": {"backgroundColor":"white" }}
Video Item

A video to be displayed in the panel.

ParameterValueOptionalDescription
typeStringNoMust be"video".
urlStringNoThe URL of the video to display.
styleObjectYesThe CSS style definition.

Example:

{"type":"video","url":"https://example.com/video.mp4","style": {"backgroundColor":"white" }}
Audio Item

An audio file to be played in the panel.

ParameterValueOptionalDescription
typeStringNoMust be"audio".
urlStringNoThe URL of the audio to play.
styleObjectYesThe CSS style definition.

Example:

{"type":"audio","url":"https://example.com/audio.mp3","style": {"backgroundColor":"white" }}
Button Item

A button that triggers an action when clicked.

ParameterValueOptionalDescription
typeStringNoMust be"button".
textStringNoThe text to display on the button.
actionObjectNoThe action to be performed when the button is clicked.
action.urlStringNoThe URL to which the request should be sent.
action.methodStringNoThe HTTP method to use for the action (e.g.,"POST").
action.headersObjectYesOptional headers to include in the request.
action.bodyObjectYesThe body of the request in JSON format.
styleObjectYesThe CSS style definition.

Example:

{"type":"button","text":"Click me!","action": {"url":"https://api.example.com/click","method":"POST","headers": {"Content-Type":"application/json"    },"body": {"key":"value"    }  },"style": {"backgroundColor":"pink","color":"white" }}
Panel Item

A sub-panel whose data is loaded on-demand by expanding the item.

ParameterValueOptionalDescription
typeStringNoMust be"infoPanel".
titleStringNoThe title to display in the expandable headline.
cloudCodeFunctionStringNoThe Cloud Code Function to call which receives the selected object in the data browser and returns the response to be displayed in the sub-panel.
styleObjectYesThe CSS style definition.

Example:

{"type":"panel","title":"Purchase History","cloudCodeFunction":"getUserPurchaseHistory","style": {"backgroundColor":"lightGray" },}

Prefetching

To reduce the time for info panel data to appear, data can be prefetched.

ParameterTypeOptionalDefaultExampleDescription
infoPanel[*].prefetchObjectsNumberyes02Number of navigation steps to prefetch ahead when browsing sequential rows. For example,2 means data for the next 2 navigation steps will be fetched in advance. When using multi-panel mode with batch navigation enabled, each navigation step corresponds to a full batch of panels, so the total number of prefetched objects will beprefetchObjects × panelCount.
infoPanel[*].prefetchStaleNumberyes010Duration in seconds after which prefetched data is discarded as stale.
infoPanel[*].prefetchImageBooleanyestruefalseWhether to prefetch image content when prefetching objects. Only applies whenprefetchObjects is enabled.
infoPanel[*].prefetchVideoBooleanyestruefalseWhether to prefetch video content when prefetching objects. Only applies whenprefetchObjects is enabled.
infoPanel[*].prefetchAudioBooleanyestruefalseWhether to prefetch audio content when prefetching objects. Only applies whenprefetchObjects is enabled.

Prefetching is particularly useful when navigating through lists of objects. To optimize performance and avoid unnecessary data loading, prefetching is triggered only after the user has moved through 3 consecutive rows using the keyboard down-arrow key or by mouse click.

WhenprefetchObjects is enabled, media content (images, videos, and audio) in the info panel can also be prefetched to improve loading performance. By default, all media types are prefetched, but you can selectively disable prefetching for specific media types using theprefetchImage,prefetchVideo, andprefetchAudio options.

Freeze Columns

▶️Core > Browser > Freeze column

Right-click on a table column header to freeze columns from the left up to the clicked column in the data browser. When scrolling horizontally, the frozen columns remain visible while the other columns scroll underneath.

Browse as User

▶️Core > Browser > Browse

This feature allows you to use the data browser as another user, respecting that user's data permissions. For example, you will only see records and fields the user has permission to see.

⚠️ Logging in as another user will trigger the same Cloud Triggers as if the user logged in themselves using any other login method. Logging in as another user requires to enter that user's password.

Change Pointer Key

▶️Core > Browser > Edit > Change pointer key

This feature allows you to change how a pointer is represented in the browser. By default, a pointer is represented by theobjectId of the linked object. You can change this to any other column of the object class. For example, if classInstallation has a field that contains a pointer to classUser, the pointer will show theobjectId of the user by default. You can change this to display the fieldemail of the user, so that a pointer displays the user's email address instead.

Limitations

  • This does not work for an array of pointers; the pointer will always display theobjectId.
  • System columns likecreatedAt,updatedAt,ACL cannot be set as pointer key.
  • This feature uses browser storage; switching to a different browser resets the pointer key toobjectId.

⚠️ For each custom pointer key in each row, a server request is triggered to resolve the custom pointer key. For example, if the browser shows a class with 50 rows and each row contains 3 custom pointer keys, a total of 150 separate server requests are triggered.

CSV Export

▶️Core > Browser > Export

This feature will take either selected rows or all rows of an individual class and saves them to a CSV file, which is then downloaded. CSV headers are added to the top of the file matching the column names.

⚠️ There is currently a 10,000 row limit when exporting all data. If more than 10,000 rows are present in the class, the CSV file will only contain 10,000 rows.

AI Agent

The Parse Dashboard includes an AI agent that can help manage your Parse Server data through natural language commands. The agent can perform operations like creating classes, adding data, querying records, and more.

Caution

The AI agent has full access to your database using the master key. It can read, modify, and delete any data. This feature is highly recommended for development environments only. Always back up important data before using the AI agent.

Configuration

To configure the AI agent for your dashboard, you need to add theagent configuration to your Parse Dashboard config:

{"apps": [// ...  ],"agent": {"models": [      {"name":"ChatGPT 4.1","provider":"openai","model":"gpt-4.1","apiKey":"YOUR_OPENAI_API_KEY"      },    ]  }}
ParameterTypeRequiredDescription
agentObjectYesThe AI agent configuration object. When using the environment variable, provide the complete agent configuration as a JSON string.
agent.modelsArrayYesArray of AI model configurations available to the agent.
agent.models[*].nameStringYesThe display name for the model (e.g.,ChatGPT 4.1).
agent.models[*].providerStringYesThe AI provider identifier (e.g., "openai").
agent.models[*].modelStringYesThe specific model name from the provider (e.g.,gpt-4.1).
agent.models[*].apiKeyStringYesThe API key for authenticating with the AI provider.

The agent will use the configured models to process natural language commands and perform database operations using the master key from your app configuration.

Providers

Note

Currently, only OpenAI models are supported. Support for additional providers may be added in future releases.

OpenAI

To get an OpenAI API key for use with the AI agent:

  1. Create an OpenAI account: Visitplatform.openai.com and sign up for an account if you don't already have one.

  2. Access the API section: Once logged in, navigate to the API section of your OpenAI dashboard.

  3. Create a new project:

    • Go to the "Projects" section
    • Click "Create project"
    • Name your project "Parse-Dashboard" (or any descriptive name)
    • Complete the project setup
  4. Configure model access:

    • In your project, navigate to "Limits > Model Usage"
    • Select the AI models you want to use (e.g.,gpt-4,gpt-3.5-turbo)
    • These model names will be used as theagent.models[*].model parameter in your dashboard configuration
  5. Generate an API key:

    • Go to the "API Keys" page in your project settings
    • Click "Create new secret key"
    • Give your key a descriptive name (e.g., "Parse Dashboard Agent")
    • Copy the generated API key immediately (you won't be able to see it again)
  6. Set up billing: Make sure you have a valid payment method added to your OpenAI account, as API usage incurs charges.

  7. Configure the dashboard: Add the API key to your Parse Dashboard configuration as shown in the example above.

Important

Keep your API key secure and never commit it to version control. Consider using environment variables or secure configuration management for production deployments.

Views

▶️Core > Views

Views are saved queries that display data in a table format. Saved views appear in the sidebar, where you can select, edit, or delete them. Optionally you can enable the object counter to show in the sidebar how many items match the view.

Caution

Values are generally rendered without sanitization in the resulting data table. If rendered values come from user input or untrusted data, make sure to remove potentially dangerous HTML or JavaScript, to prevent an attacker from injecting malicious code, to exploit vulnerabilities like Cross-Site Scripting (XSS).

Data Sources

Views can pull their data from the following data sources.

Aggregation Pipeline

Display aggregated data from your classes using a MongoDB aggregation pipeline. Create a view by selecting a class and defining an aggregation pipeline.

Cloud Function

Display data returned by a Parse Cloud Function. Create a view specifying a Cloud Function that returns an array of objects. Cloud Functions enable custom business logic, computed fields, and complex data transformations.

Cloud Function views can prompt users for text input and/or file upload when opened. Enable "Require text input" or "Require file upload" checkboxes when creating the view. The user provided data will then be available in the Cloud Function as parameters.

Cloud Function example:

Parse.Cloud.define("myViewFunction",request=>{consttext=request.params.text;constfileData=request.params.fileData;returnprocessDataWithTextAndFile(text,fileData);});

Note

Text and file data are ephemeral and only available to the Cloud Function during that request. Files are base64 encoded, increasing the data during transfer by ~33%.

View Table

When designing the aggregation pipeline, consider that some values are rendered specially in the output table.

Pointer

Parse Object pointers are automatically displayed as links to the target object.

Example:

{"__type":"Pointer","className":"_User","objectId":"xWMyZ4YEGZ" }

Link

Links are rendered as hyperlinks that open in a new browser tab.

Example:

{"__type":"Link","url":"https://example.com","text":"Link"}

SetisRelativeUrl: true when linking to another dashboard page, in which case the base URL for the relative URL will be<PROTOCOL>://<HOST>/<MOUNT_PATH>/apps/<APP_NAME>/. The keyisRelativeUrl is optional andfalse by default.

Example:

{"__type":"Link","url":"browser/_Installation","isRelativeUrl":true,"text":"Link"}

A query part of the URL can be easily added using theurlQuery key which will automatically escape the query string.

Example:

{"__type":"Link","url":"browser/_Installation","urlQuery":"filters=[{\"field\":\"objectId\",\"constraint\":\"eq\",\"compareTo\":\"xWMyZ4YEGZ\",\"class\":\"_Installation\"}]","isRelativeUrl":true,"text":"Link"}

In the example above, the query string will be escaped and added to the url, resulting in the complete URL:

"browser/_Installation?filters=%5B%7B%22field%22%3A%22objectId%22%2C%22constraint%22%3A%22eq%22%2C%22compareTo%22%3A%22xWMyZ4YEGZ%22%2C%22class%22%3A%22_Installation%22%7D%5D"

Tip

For guidance on how to create the URL query for a dashboard data browser filter, open the data browser and set the filter. Then copy the browser URL and unescape it. The query constraints in?filters=[...] will give you an idea of the constraint syntax.

Note

For security reasons, the link<a> tag contains therel="noreferrer" attribute, which prevents the target website to know the referring website which in this case is the Parse Dashboard URL. That attribute is widely supported across modern browsers, but if in doubt check your browser's compatibility.

Image

Images are rendered directly in the output table with an<img> tag. The content mode is always "scale to fit", meaning that if the image file is 100x50px and the specified dimensions are 50x50px, it would display as 50x25px, since it's scaled maintaining aspect ratio.

Example:

{"__type":"Image","url":"https://example.com/image.png","width":"50","height":"50","alt":"Image"}

Warning

The URL will be directly invoked by the browser when trying to display the image. For security reasons, make sure you either control the full URL, including the image file name, or sanitize the URL before returning it to the dashboard. URLs containing#"auto">

Video

Videos are rendered directly in the output table with a<video> tag that includes playback controls. The content mode is always "scale to fit", meaning that the video maintains its aspect ratio within the specified dimensions.

Example:

{"__type":"Video","url":"https://example.com/video.mp4","width":"320","height":"240"}

Warning

The URL will be directly invoked by the browser when trying to display the video. For security reasons, make sure you either control the full URL, including the video file name, or sanitize the URL before returning it to the dashboard. URLs containing#"auto">

Contributing

We really want Parse to be yours, to see it grow and thrive in the open source community. Please see theContributing to Parse Dashboard guide.


As of April 5, 2017, Parse, LLC has transferred this code to the parse-community organization, and will no longer be contributing to or distributing this code.


[8]ページ先頭

©2009-2025 Movatter.jp