Skip to main content

Configure a client

The SDK does not read environment variables itself. In these examples, your application passes the credential from process.env.

OAuth access tokens

For an application acting on behalf of a user, supply accessToken instead of apiKey. A callback can retrieve the current token before a request:
This example reads a token already supplied to the server. For a production integration, replace that lookup with your server’s token store and refresh logic. The SDK does not run the OAuth consent flow or refresh tokens for you. See OAuth client requirements. OAuth requests follow the user’s current workspace membership, role and approved scopes. API keys follow their own workspace, status and scopes. API Access is required for both. Do not supply both credential options.

Timeouts and cancellation

Client defaults apply to every operation. Pass timeoutMs, maxRetries or signal in the last argument, after the method’s inputs, to override one request. For generated client.api methods, this is the second argument; resource shortcuts can place it first, second or third. See Request option examples. The timeout covers the whole request, including token resolution, retries, retry delays and response reads. An AbortSignal lets your application cancel it earlier.
Cancelling a request stops waiting for its response. It does not undo an API action already accepted by the server.

Retry behavior

Eligible GET and HEAD requests can be retried after a network failure or HTTP 429, 502, 503 or 504. The SDK honors Retry-After when present and uses bounded backoff otherwise. Write requests are never retried automatically, including after a rate limit. Raising maxRetries does not enable write retries. This protects actions such as placing calls, sending messages and purchasing resources from accidental duplication.
A timeout or lost connection after a write can leave its outcome unknown. Check the resource state, call history or webhook before deciding to repeat the action. An arbitrary idempotency header does not make every operation safe to repeat.

Handle errors

Do not log credentials or whole sensitive request bodies. A request ID, when available, helps support locate the failed request.

Troubleshooting

Check the same credential independently with the CLI:
For HTTP behavior and scope requirements, consult the REST API reference. For AI tool connections, use the MCP guide.