Cognito token management for server-side Thankly API calls. Handles refresh, caches the token through a storage adapter, and coalesces concurrent refreshes so a burst of calls makes one token request.
npm install @thankly/sdk-auth
import { createThanklyAuth } from '@thankly/sdk-auth';
const auth = createThanklyAuth({
apiHost: 'https://api.thankly.ai',
secretTokenKey: 'thankly.token',
clientId: process.env.THANKLY_CLIENT_ID!,
clientSecret: process.env.THANKLY_CLIENT_SECRET!,
});
await auth.ensureToken();
const token = await auth.getToken();
Server-side only. This package takes a clientSecret and exchanges it for a
Cognito access token — putting it in code that ships to a browser or a mobile app
leaks a credential that authenticates as your whole organisation. If you need to
call Thankly from a browser, use @thankly/sdk-client,
which takes a per-experience token and never sees the secret.
The header this produces is X-Authorization, not Authorization — see
getCognitoAuthorizationHeader(). The two are different auth surfaces and are
not interchangeable.
Full API reference: https://docs.thankly.ai/js
Apache-2.0