Server-side Thankly client: create experiences, read catalogs, upload assets, and drive the lifecycle surface (signals, engagement decisions, outcomes, brand config, playbooks).
npm install @thankly/sdk-server
import { createThanklyServer } from '@thankly/sdk-server';
const thankly = createThanklyServer({
apiHost: 'https://api.thankly.ai',
clientId: process.env.THANKLY_CLIENT_ID!,
clientSecret: process.env.THANKLY_CLIENT_SECRET!,
secretTokenKey: 'thankly.token',
});
const experience = await thankly.createExperience({ /* context + capabilities */ });
// Hand experience.accessToken to the browser; keep the clientSecret here.
Catalog product reads accept the same explicit regional context as product hydration:
const products = await thankly.fetchProducts('uk-store', {
category: 'shoes',
purchaseContext: {
country: 'GB',
postalCode: 'SW1A 1AA',
currency: 'GBP',
fulfillmentMode: 'delivery',
},
});
const product = await thankly.fetchProduct('uk-store', 'sku-1', {
country: 'GB',
currency: 'GBP',
fulfillmentMode: 'delivery',
});
This package holds your clientSecret and authenticates with
X-Authorization: Bearer <Cognito access token>. It must not ship to a browser
or a mobile app. Pass the per-experience accessToken to the client instead and
use @thankly/sdk-client
there.
invokeEngagementDecision resolves when the decision is made — enrichment
widgets are spawned afterwards and arrive on subsequent reads. That gap is why
waitForEngagementDecision exists; a consumer that renders once on the decision
response and never polls again will silently miss the enrichment content.
Full API reference: https://docs.thankly.ai/js
Apache-2.0
@thankly/sdk-server
Privileged calls against the Thankly API — experiences, catalog, uploads, and the lifecycle surface.
Server-side only. This package takes a
clientSecretand exchanges it for a Cognito access token, sent asX-Authorization: Bearer <token>. That credential authenticates as your whole organisation, so it must not reach a browser, a mobile app, or anything else a user can read — bundling it is not a configuration mistake, it is a credential disclosure.For browser code, hand the per-experience
accessTokenfrom ThanklyServerApi.createExperience to@thankly/sdk-client, which sends the plainAuthorizationheader and never sees the secret. Two headers, two trust levels; picking the wrong one is the mistake this split exists to prevent.