Getting Started
Tutorial: Building with CleaveDB
Session Context (SET)
When clients interact with CleaveDB over TCP sockets or WebSockets, each connection maintains an isolated session state. The SET command injects arbitrary key-value variables into this active session context.
Injecting session variables
Assign strings, numbers, or identifiers directly to session variables:
CleaveQLExample · Define session variables
SET role = "viewer"
SET tenant_id = "acme_corp"
SET max_retries = 5These variables persist in memory for the duration of the client connection and are instantly available to all security policies and rate limits.
Referencing context in policies
In ENFORCE SECURITY and MASK statements, session variables can be referenced using either my <var> or @<var>:
CleaveQLExample · Evaluate session context in policies
-- Evaluates 'my role':
MASK "salary" ON staff IF my role = "viewer"
-- Evaluates '@tenant_id':
ENFORCE SECURITY "tenant_isolation" ON orders TO ALLOW read IF tenant = @tenant_idBecause context is evaluated dynamically per query, changing a session variable with SET immediately alters which rows and fields the client is permitted to view.
