Oracle is where ledgers, claims systems, manufacturing execution, and decades of business logic actually live. Most auto-API tools either don't support it, support it on a feature-trailing connector, or assume you'll migrate to Postgres first. None of those are realistic answers.
FastCRUD treats Oracle as a peer. We connect, introspect the schema and the PL/SQL packages, and give you a documented REST and GraphQL API in about a minute. VPD and Label Security policies stay in force. Audit logs are emitted on every call — your DBA's logs and ours line up.
how it works
# 1. Connect Oracle (on-prem, OCI, AWS RDS for Oracle, Exadata)
host ledger-prod.corp.internal:1521
service FINPROD.corp.internal
schema FIN_API
auth oracle (or kerberos / wallet on enterprise)
# 2. Introspection
✓ 218 tables, 47 views cataloged
✓ 12 packages discovered (FIN_API.PKG_INVOICES, ...)
✓ VPD policies detected — preserved
# 3. Scoped access key
scope read FIN_API.INVOICES, FIN_API.ORDERS
call FIN_API.PKG_INVOICES.SP_CLOSE_MONTH
row filter TENANT_ID.eq.acme
ip allowlist 10.30.0.0/16
# 4. Query — every call logged with actor + outcome
GET /crud/FIN_API.INVOICES?filter=STATUS.eq.UNPAID&limit=20
Authorization: Bearer eyJ...
→ 200 37 rows 53ms audit_id=ax_3a...
# 5. Call a package procedure
POST /rpc/FIN_API.PKG_INVOICES.SP_CLOSE_MONTH
{ "P_PERIOD": "2026-04", "P_ACTOR_ID": 193 }oracle specifics
thin client, no oracle instant client
Connections use a maintained native driver. You don't install Oracle Instant Client anywhere in our stack, and you don't ship it to whatever's calling our API.
schema as project
A FastCRUD project maps cleanly onto one Oracle schema (user). Separate schemas can be separate projects with separate access keys, separate audit trails, and separate row-level rules.
pl/sql packages, exposed
Packages discovered during introspection can be promoted to typed endpoints. Procedure and function arguments are validated against the catalog before the call is made.
rowid, sysdate, sequences
Oracle's native types and quirks are preserved in REST and GraphQL responses. ROWIDs are stable identifiers; CLOB/BLOB streaming is supported; sequence-driven inserts return the assigned values.
vpd & label security, respected
If the connection user has VPD (Virtual Private Database) or Oracle Label Security policies, they apply transparently — FastCRUD calls run as that user, so your existing policies are not bypassed.
transparent data encryption
TDE-at-rest in your database keeps doing its job. FastCRUD never sees raw data files; it only sees the decrypted result your database returns to a connected client.
topologies we support
not a fit if
20-minute call. We'll connect to a representative Oracle schema (or yours under NDA), expose a table and a package, scope an access key, and walk through the audit log.