Backend API. Server-side code: this runs in a Codename One backend, not in the app on the device.

Codename One Backend API

778 documented types across 45 packages. Search the API from the site search, or download the whole backend reference as a zip.

Packages marked shared are the same classes the client uses, compiled into the server as well.

com.codename1.annotations sharedCodename One specific Java annotations used by the build pipeline and the ParparVM bytecode translator to mark methods and classes for special treatment – e.g. opting individual call sites out of debug info or null/array-bounds checks, declaring asynchronous methods, or forcing a class to be treated as concrete during devirtualization.
com.codename1.annotations.db sharedMapping annotations for managed database persistence.
com.codename1.backendThe Codename One backend runtime: the server side of an application, written in the same Java as the app and compiled to a native server binary.
com.codename1.backend.annotationsAnnotations that turn an ordinary class into an HTTP or websocket endpoint.
com.codename1.backend.awsAmazon Web Services from a backend: request signing, credentials, and S3.
com.codename1.backend.metricsMetrics for a backend: counters, gauges and histograms named after the OpenTelemetry semantic conventions.
com.codename1.backend.ormThe build-time ORM on the server: entity classes in, typed data access objects out.
com.codename1.backend.otelOpenTelemetry tracing and metrics for a backend, exported over OTLP/HTTP without an OpenTelemetry library.
com.codename1.backend.securityAuthentication and authorization for the routes of a backend, in the shape of Spring Security: an application declares one or more SecurityFilterChain beans, each built from the HttpSecurity its method is handed, and every request the server does not answer on its own behalf is put to them.
com.codename1.backend.security.apikeyAPI keys: long-lived secrets a program presents instead of signing in.
com.codename1.backend.security.core.userdetailsUsers as the security layer sees them: UserDetails, the UserDetailsService a chain authenticates against, and an in-memory store.
com.codename1.backend.security.cryptoPassword hashing: the PasswordEncoder contract, the delegating encoder that reads the {id} in front of a stored password, and the encoders behind it.
com.codename1.backend.security.mfaA second factor at sign-in: one-time codes from an authenticator app, and the recovery codes that stand in for a lost phone.
com.codename1.backend.security.oauth2.clientSigning users in through another identity provider, with OAuth2 or OpenID Connect: this server as a client of Google, GitHub, Microsoft, Apple or any provider described by a ClientRegistration.
com.codename1.backend.security.oauth2.coreWhat the OAuth 2.0 parts of the security layer share: the error a token or a request is refused with, and the validators a token is put to.
com.codename1.backend.security.oauth2.jose.jwsThe names of the algorithms a JSON Web Signature is made with (RFC 7518 3), for the ones this runtime signs and verifies.
com.codename1.backend.security.oauth2.jwtJSON Web Tokens signed with a public key algorithm or a shared secret: JwtDecoder verifies one and reads its claims, JwtEncoder makes one.
com.codename1.backend.security.oauth2.server.authorizationAn OAuth2 authorization server and OpenID Connect provider: the server that signs users in on behalf of clients and issues them tokens.
com.codename1.backend.security.oauth2.server.resourceA server whose routes are reached with a bearer token (RFC 6750): finding the token in a request, verifying it as a JWT, turning its claims into who is calling and what they may do, and answering a request whose token is missing, bad or not enough.
com.codename1.backend.security.ratelimitLimits on how often a client may ask: a RateLimiter counts requests under a key, and a RateLimitKeyResolver says which key a request counts under – its client’s address, who it is signed in as, its session, its API key.
com.codename1.backend.security.remembermeRemember-me: recognizing a returning user by a cookie, so that closing the browser does not sign them out.
com.codename1.backend.security.webauthnPasskeys: signing in with a credential an authenticator holds, as the Web Authentication specification defines it.
com.codename1.backend.sqlThe database engines a backend talks to, and what they spell differently.
com.codename1.backend.testTesting a backend the way Spring Boot tests are written, on the JVM and as a compiled native test.
com.codename1.io.gzip sharedgzip support based on https://github.com/ymnk/jzlib
com.codename1.migration sharedVersioned database migrations, shared by applications and the Codename One backend.
com.codename1.orm.session sharedManaged persistence contexts and queries for the client and backend ORMs.
com.codename1.security sharedThe part of the client’s cryptography a server shares with it: the portable Java digests and message authentication codes, and the one-time passwords built on them.
java.io shared
java.lang shared
java.lang.annotation shared
java.lang.invoke shared
java.lang.ref shared
java.lang.reflect shared
java.net shared
java.nio.charset shared
java.text shared
java.time shared
java.time.format shared
java.time.temporal shared
java.util
java.util.concurrent
java.util.concurrent.atomic shared
java.util.function shared
java.util.stream shared