@gol/sdk/server holds everything that carries a project credential: the API clients, the polling helpers, and webhook verification. Import it from your server only. Its requests send your API key or your developer session token, so bundling it into a web page or a mobile app publishes that credential.
The root @gol/sdk entry point is the one for browser code. The split is deliberate: a reader can tell from the import path alone whether a module can touch a secret.
Create a client
GolApiClient authenticates with a project API key.
GolManagementClient authenticates with a developer session token and covers the console management routes: projects, API keys, audit history, and the session lifecycle.
revokeSession on sign-out.
startEmailChallenge, verifyEmailChallenge, createGoogleSession, renewSession, and revokeSession exist for a server that implements developer sign-in itself. GOL’s own console at console.gol.network is a first-party client, not a dependency of yours: build your own sign-in and UI with your own product’s conventions. Google sign-in is disabled on the hosted console pending provider setup and a verified round trip.Base URL rules
The client validates its configuration at construction, so a mistake fails immediately instead of at the first request.
Each violation throws
GolTransportError from the constructor.
Pass your own fetch
fetch is injectable, which is what makes the client testable without a network.
GET, POST, or DELETE with Accept: application/json, cache: no-store, and a bearer Authorization header when a credential is present.
Read configuration at runtime
getGasConfiguration returns the deployed core, relayer, attester, recipient, asset, and limits for your project and environment. Read it at startup and pass the values into any request, rather than hard-coding an address from the docs.
Scope the key
The key’s scopes decide which methods succeed.GolApiClient does not pre-check them, so a missing scope surfaces as a GolApiError with code authorization_denied. The scopes each method needs are listed in create a project and API key.
Handle errors
Every client method rejects withGolApiError when the API returns a non-2xx status, and with GolTransportError when the request cannot be made or the response is not JSON. See errors for the shape and the retry rules.
correlationId is the value to quote in a bug report. Do not log the API key or the full Authorization header alongside it.
Polling helpers
Six helpers wrap a confirm-or-retry loop. Each polls until the API answers, then returns:waitForGasPolicyConfirmation, waitForGasPolicySafetyAction, waitForGasPolicyRevocation, waitForGasExecution, waitForEip7702Setup (until confirmed or failed), and waitForChildMandate (until the child leaves pending).
signal, so you can stop waiting when a request is aborted. A timeout throws GolTransportError. The underlying confirmGasPolicy, confirmGasPolicySafetyAction, confirmGasPolicyRevocation, getGasExecution, getEip7702Setup, and listChildMandates methods are public if you would rather own the loop, and waitForGasExecution accepts until to change the state you are waiting for.
Webhook verification
verifyWebhook is in this entry point because it needs the Node.js crypto module and your endpoint secret. See webhooks.