Skip to main content
P2HS backend capabilities are exposed through controlled project and runtime contracts. Depending on the admitted composition, an application can use authentication, records/entities, forms, files, workflows, notifications, payments, and integrations. P2HS decides whether a workspace and project may use a capability. Managed runtime services provide execution and record operations. Generated applications should use approved BFF/SSR or trusted-client flows instead of embedding provider credentials. The backend surface is project-scoped and authorization remains server-side. Client-side visibility checks are UX only, not a security boundary.