Skip to main content
@gol/sdk/server exposes two typed clients. GolApiClient authenticates with a project API key and covers the project routes. GolManagementClient authenticates with a developer session token and covers the console management and session routes. Both inherit the same read-only project methods, so a project listing looks identical from either. Every method is a thin, typed wrapper over one documented route. There is no hidden behavior and no chain transaction behind a method: where a method changes authority, the authority is an owner signature you obtain separately. See owner signing.

Create a client

The constructor validates its arguments before any request, so a malformed key or a plain-HTTP base URL fails at startup rather than on the first call. See server entry point for the exact rules.

GolApiClient methods

Grouped by what they do. Scopes come from create a project and API key.

Identity and configuration

getAccountStatus is the first call for any account. A family of null means the account is not one of the supported configurations, and the flow stops there.

Owner gas policies

prepareGasPolicy returns a plain summary in review: recipients, caps, gas caps, which outcomes the owner pays gas for, expiry, and the GOL attester and reimbursement recipient. Show it to the owner as part of your own review screen before they sign. The confirm methods answer with a discriminated union, so the retry case is explicit rather than a null check.
getGasPolicy reports unavailable when the on-chain state is unknown or conflicting, rather than guessing. Treat that as unresolved and retry later, not as revoked.

Actions

See execution and observation for the action lifecycle and the idempotency rule.

Webhooks

See webhooks.

GolManagementClient methods

Use this client for developer sign-in and for the management routes a console needs. It is not on the agent action path. Methods that need a session throw GolTransportError when the client has no sessionToken, so a misconfigured client fails before the request.
Keep the session token in an HTTP-only cookie and out of client JavaScript. A token in browser storage is readable by any script on the page, and it identifies a developer account rather than one project.

Read values, do not hard-code them

Addresses, limits, and asset identifiers belong in your configuration, read from the API. The values in current availability are a record of a deployment; getGasConfiguration is that deployment as it is now.

Pagination

List methods take PageOptions and return a data array with a cursor. limit, cursor, and environment are all optional.

Transport behavior

Each request sends Accept: application/json, cache: no-store, and Authorization: Bearer <credential> when a credential is present. A 204 response is treated as an empty body, which is what revokeSession returns. Anything other than a 2xx becomes a GolApiError carrying the API’s own code, the HTTP status, and a correlationId. A transport failure, a non-JSON body, or an invalid baseUrl becomes a GolTransportError. See errors.