How apps work
An app is a collection of entities declared usingdefineEntity() functions from the twenty-sdk package. The SDK detects these declarations via AST analysis at build time and produces a manifest — a complete description of what your app adds to a workspace. These functions validate your configuration at build time and provide IDE autocompletion and type safety.
File organization is up to you. Entity detection is AST-based — the SDK finds
export default defineEntity(...) calls regardless of where the file lives. The folder structure above is a convention, not a requirement.Entity types
Sandboxing
- Logic functions run in isolated Node.js processes on the server. They only access data through the typed API client, scoped to the app’s role permissions.
- Front components run in Web Workers using Remote DOM — sandboxed from the main page but rendering native DOM elements (not iframes). They communicate with Twenty via a message-passing host API.
- Permissions are enforced at the API level. The runtime token (
TWENTY_APP_ACCESS_TOKEN) is derived from the role defined indefineApplication().
App lifecycle
yarn twenty dev— watches your source files and live-syncs changes to a connected Twenty server. The typed API client is regenerated automatically when the schema changes.yarn twenty dev:build— compiles TypeScript, bundles logic functions and front components with esbuild, and produces a manifest.- Pre/post-install and uninstall hooks — optional functions that run during installation or right before removal. See Install Hooks for details.
Next steps
Config
Application identity, default role, and install and uninstall hooks.
Data
Objects, fields, and bidirectional relations.
Logic
Logic functions, skills, agents, and OAuth connections.
Layout
Views, navigation, page layouts, front components.
Operations
CLI, testing, remotes, CI, and publishing your app.