@casecore/intake-client
v0.7.0
Published
Server-only client for CaseCore external intake
Readme
@casecore/intake-client
Server-only TypeScript client for the CaseCore support intake API. Keep the source credential in the product backend and expose an authenticated same-origin endpoint to the browser.
Installation
pnpm add @casecore/intake-clientThe package requires Node.js 22.14 or newer and is intentionally blocked by its browser export.
import { createCaseCoreIntakeClient } from '@casecore/intake-client';
const client = createCaseCoreIntakeClient({
baseUrl: process.env.CASECORE_URL,
credential: process.env.CASECORE_INTAKE_KEY,
cloudflareAccess:
process.env.CASECORE_ACCESS_CLIENT_ID && process.env.CASECORE_ACCESS_CLIENT_SECRET
? {
clientId: process.env.CASECORE_ACCESS_CLIENT_ID,
clientSecret: process.env.CASECORE_ACCESS_CLIENT_SECRET,
}
: undefined,
});cloudflareAccess is optional, but when supplied both values must be non-empty. The client adds
the service-token headers to ticket and attachment requests, applies timeouts, and returns
structured credential-free errors.
For a newly created user-reporter support ticket, createTicket() returns portalUrl alongside
the case and receipt metadata. The URL is returned only once; application-reporter tickets and
idempotent replays return portalUrl: null. Pass it through the authenticated BFF response
without logging or persisting the embedded bearer token.
Public website leads
createLead(input, idempotencyKey) sends a typed sales lead to
POST /api/v1/intake/sales. Call it only from the marketing site's backend/BFF.
The input includes consent, turnstileToken, and the optional website bot-trap
field; none of these weaken the server-only credential boundary.
