---
title: "Change many rows with SQL, as the builder"
description: "One UPDATE or DELETE; each row is written through the ordinary path, and the statement is one changeset (changesetId), undone by one revert."
canonical: "https://gtable.app/docs/builder-api/data/sql-execute"
updated: "2026-10-05"
---

# Change many rows with SQL, as the builder

`POST https://studio.gtable.app/v1/apps/{appId}/sql/execute`

One UPDATE or DELETE; each row is written through the ordinary path, and the statement is one changeset (changesetId), undone by one revert.

Up to 500 rows per statement; without a WHERE it needs confirm: true; dryRun counts first. The dialect: SELECT \<columns or aggregates> FROM \<table> \[WHERE …] \[GROUP BY …] \[ORDER BY …] \[LIMIT n OFFSET m]; UPDATE \<table> SET col = expr \[WHERE …]; DELETE FROM \<table> \[WHERE …]. One table per statement; field names or ids (double-quote names with spaces); 'text', numbers, TRUE, FALSE, NULL, CURRENT\_DATE; AND OR NOT, = \<> \< \<= > >=, \[NOT] LIKE, \[NOT] IN (…), IS \[NOT] NULL, \[NOT] BETWEEN, CASE WHEN cond THEN v … \[ELSE v] END and CASE expr WHEN value THEN v … \[ELSE v] END; a select takes its choice's label (any case) or id; functions LENGTH LOWER UPPER TRIM ABS ROUND COALESCE SUBSTR DATE STRFTIME IFNULL INSTR REPLACE; link columns: col HAS ANY ('id', …), col HAS ALL (…), col IS EMPTY. Your text is never executed: it is compiled against your own permissions, and a column you may not read is simply an unknown column.

Requires the `records:write` scope. Operation `apps.sql.execute`. MCP tool `apps_sql_execute`. CLI, once published: `gtable apps sql execute`.

## Path parameters

| Name    | Type   | Required | Description |
| ------- | ------ | -------- | ----------- |
| `appId` | string | yes      |             |

## Headers

| Name              | Type   | Required | Description                                                                                                                                                                                                                                                        |
| ----------------- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `Idempotency-Key` | string | no       | Any unique string. Sending the same key with the same request again returns the first response (marked `Idempotency-Replayed: true`) instead of running it twice. Reusing it for a different request is refused with 409. Kept for 24 hours. Up to 255 characters. |

## Request body

| Field     | Type    | Required | Description             |
| --------- | ------- | -------- | ----------------------- |
| `sql`     | string  | yes      | Up to 20000 characters. |
| `confirm` | boolean | no       |                         |
| `dryRun`  | boolean | no       |                         |
