Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.
Codename One Backend API
780 documented types across 45 packages. Search the API from the Javadoc search, or download the whole backend reference as a zip.
Packages marked shared are the same classes the client uses, compiled into the server as well.
com.codename1.annotations shared | Codename One specific Java annotations used by the build pipeline and the ParparVM bytecode translator to mark methods and classes for special treatment – e.g. opting individual call sites out of debug info or null/array-bounds checks, declaring asynchronous methods, or forcing a class to be treated as concrete during devirtualization. |
com.codename1.annotations.db shared | Mapping annotations for managed database persistence. |
com.codename1.backend | The Codename One backend runtime: the server side of an application, written in the same Java as the app and compiled to a native server binary. |
com.codename1.backend.annotations | Annotations that turn an ordinary class into an HTTP or websocket endpoint. |
com.codename1.backend.aws | Amazon Web Services from a backend: request signing, credentials, and S3. |
com.codename1.backend.metrics | Metrics for a backend: counters, gauges and histograms named after the OpenTelemetry semantic conventions. |
com.codename1.backend.orm | The build-time ORM on the server: entity classes in, typed data access objects out. |
com.codename1.backend.otel | OpenTelemetry tracing and metrics for a backend, exported over OTLP/HTTP without an OpenTelemetry library. |
com.codename1.backend.security | Authentication and authorization for the routes of a backend, in the shape of Spring Security: an application declares one or more SecurityFilterChain beans, each built from the HttpSecurity its method is handed, and every request the server does not answer on its own behalf is put to them. |
com.codename1.backend.security.apikey | API keys: long-lived secrets a program presents instead of signing in. |
com.codename1.backend.security.core.userdetails | Users as the security layer sees them: UserDetails, the UserDetailsService a chain authenticates against, and an in-memory store. |
com.codename1.backend.security.crypto | Password hashing: the PasswordEncoder contract, the delegating encoder that reads the {id} in front of a stored password, and the encoders behind it. |
com.codename1.backend.security.mfa | A second factor at sign-in: one-time codes from an authenticator app, and the recovery codes that stand in for a lost phone. |
com.codename1.backend.security.oauth2.client | Signing users in through another identity provider, with OAuth2 or OpenID Connect: this server as a client of Google, GitHub, Microsoft, Apple or any provider described by a ClientRegistration. |
com.codename1.backend.security.oauth2.core | What the OAuth 2.0 parts of the security layer share: the error a token or a request is refused with, and the validators a token is put to. |
com.codename1.backend.security.oauth2.jose.jws | The names of the algorithms a JSON Web Signature is made with (RFC 7518 3), for the ones this runtime signs and verifies. |
com.codename1.backend.security.oauth2.jwt | JSON Web Tokens signed with a public key algorithm or a shared secret: JwtDecoder verifies one and reads its claims, JwtEncoder makes one. |
com.codename1.backend.security.oauth2.server.authorization | An OAuth2 authorization server and OpenID Connect provider: the server that signs users in on behalf of clients and issues them tokens. |
com.codename1.backend.security.oauth2.server.resource | A server whose routes are reached with a bearer token (RFC 6750): finding the token in a request, verifying it as a JWT, turning its claims into who is calling and what they may do, and answering a request whose token is missing, bad or not enough. |
com.codename1.backend.security.ratelimit | Limits on how often a client may ask: a RateLimiter counts requests under a key, and a RateLimitKeyResolver says which key a request counts under – its client’s address, who it is signed in as, its session, its API key. |
com.codename1.backend.security.rememberme | Remember-me: recognizing a returning user by a cookie, so that closing the browser does not sign them out. |
com.codename1.backend.security.webauthn | Passkeys: signing in with a credential an authenticator holds, as the Web Authentication specification defines it. |
com.codename1.backend.sql | The database engines a backend talks to, and what they spell differently. |
com.codename1.backend.test | Testing a backend the way Spring Boot tests are written, on the JVM and as a compiled native test. |
com.codename1.io.gzip shared | gzip support based on https://github.com/ymnk/jzlib |
com.codename1.migration shared | Versioned database migrations, shared by applications and the Codename One backend. |
com.codename1.orm.session shared | Managed persistence contexts and queries for the client and backend ORMs. |
com.codename1.security shared | The part of the client’s cryptography a server shares with it: the portable Java digests and message authentication codes, and the one-time passwords built on them. |
java.io shared | |
java.lang shared | |
java.lang.annotation shared | |
java.lang.invoke shared | |
java.lang.ref shared | |
java.lang.reflect shared | |
java.net shared | |
java.nio.charset shared | |
java.text shared | |
java.time shared | |
java.time.format shared | |
java.time.temporal shared | |
java.util | |
java.util.concurrent | |
java.util.concurrent.atomic shared | |
java.util.function shared | |
java.util.stream shared |