Browser-safe client for reading experiences and refining capabilities. Carries no Cognito credential — it authenticates with the per-experience access token your server received when it created the experience.
npm install @thankly/sdk-client
import { createThanklyClient } from '@thankly/sdk-client';
const client = createThanklyClient({ apiHost: 'https://api.thankly.ai' });
// Polls until the experience is ready; onUpdate fires as widgets arrive.
const experience = await client.fetchExperience(
experienceId,
accessToken,
undefined,
(partial) => render(partial),
);
Also available: refineCapability, addCapabilities, hydrateProducts.
Regional product hydration accepts explicit shopper choices as its fourth argument while preserving the existing signal argument:
const products = await client.hydrateProducts(ids, accessToken, signal, {
country: 'GB',
postalCode: 'SW1A 1AA',
currency: 'GBP',
fulfillmentMode: 'delivery',
});
This package sends Authorization: Bearer <experience access token> — the
short-lived, per-experience JWT. That is deliberately not the same as the
X-Authorization Cognito header used by @thankly/sdk-server.
A client that reaches for the Cognito path is putting an organisation-wide
secret in the browser.
Full API reference: https://docs.thankly.ai/js
Apache-2.0
@thankly/sdk-client
Browser-safe reads against an experience your server already created.
This package authenticates with
Authorization: Bearer <experience access token>— the short-lived, per-experience JWT returned bycreateExperience. That is a different auth surface from@thankly/sdk-server, which sendsX-Authorizationwith a Cognito access token minted from yourclientSecret. The two are not interchangeable, and the distinction is the whole reason this package exists separately: it never sees the secret, so shipping it to a browser leaks nothing beyond a single experience.If you find yourself wanting Cognito credentials here, the call belongs on your server instead.