Thankly developer documentation

Reference documentation for the Thankly platform and its SDKs, with a short getting-started for each.

REST API

Two tokens, two headers — the distinction most integrations get wrong first.

# 1 — exchange client credentials for an org access token
curl -sS https://api.thankly.ai/auth/token \
  -H 'Content-Type: application/json' \
  -d '{"clientId":"$THANKLY_CLIENT_ID","clientSecret":"$THANKLY_CLIENT_SECRET"}'
# → { "accessToken": "…", "tokenType": "bearer", "expiresIn": 3600 }

# 2 — create an experience, server-side, with X-Authorization
curl -sS https://api.thankly.ai/experiences \
  -H 'Content-Type: application/json' \
  -H "X-Authorization: Bearer $ORG_ACCESS_TOKEN" \
  -d '{
        "tag_id": "your-tag",
        "context": { "topic": { "topic": "weekend in Lisbon",
                                 "questions": ["Where should we eat?"] } },
        "capabilities": [ { "type": "restaurants" } ]
      }'
# → { "experienceId": "…", "accessToken": "…" }

# 3 — poll until ready, with the per-experience token and plain Authorization
curl -sS "https://api.thankly.ai/experiences/$EXPERIENCE_ID" \
  -H "Authorization: Bearer $EXPERIENCE_ACCESS_TOKEN"
The two headers are not interchangeable. X-Authorization carries the org access token minted from your clientSecret and belongs on your server only — it authenticates as your whole organisation. Authorization carries the short-lived per-experience token returned by step 2, and is the one safe to hand to a browser or app.

Full REST reference →

JavaScript SDK

The same flow, with token refresh and polling handled for you.

// Server-side — holds the clientSecret, sends X-Authorization
import { createThanklyServer } from '@thankly/sdk-server'

const thankly = createThanklyServer({
  apiHost: 'https://api.thankly.ai',
  clientId: process.env.THANKLY_CLIENT_ID,
  clientSecret: process.env.THANKLY_CLIENT_SECRET,
  secretTokenKey: 'thankly.token',
})

const { experienceId, accessToken } = await thankly.createExperience({
  tag_id: 'your-tag',
  context: { topic: { topic: 'weekend in Lisbon', questions: ['Where should we eat?'] } },
  capabilities: [{ type: 'restaurants' }],
})

// Browser — receives only the per-experience token, never the secret
import { createThanklyClient } from '@thankly/sdk-client'

const client = createThanklyClient({ apiHost: 'https://api.thankly.ai' })
const experience = await client.fetchExperience(experienceId, accessToken)

Full JavaScript reference →

JVM SDK

Kotlin, coroutines throughout. recommend creates and awaits in one call.

import ai.thankly.sdk.*
import kotlinx.coroutines.runBlocking

// Backends only: clientCredentials holds the secret. On Android, take a token
// your own backend vends instead — see the reference.
val config = ThanklyConfig(
    apiHost = "https://api.thankly.ai",
    tokenProvider = TokenProvider.clientCredentials(
        clientId = System.getenv("THANKLY_CLIENT_ID"),
        clientSecret = System.getenv("THANKLY_CLIENT_SECRET"),
        apiHost = "https://api.thankly.ai",
    ),
)

val result = runBlocking {
    ThanklyClient(config).recommend(
        context = Topic(
            topic = "weekend in Lisbon",
            questions = listOf("Where should we eat?"),
        ),
        capabilities = listOf(CapabilityRequest(type = "restaurants")),
        tagId = "your-tag",
    )
}

Full JVM reference →

Installing

The SDK packages are not on npm or Maven Central yet. The references above document the surface as it will ship, and the REST API is live today — it needs no SDK. Talk to us if you want early access to either SDK before the first release.