@eshal-bot/server
v0.1.20
Published
Server-side proxy for the eshal chat widget — keeps your secret key out of the browser
Readme
@eshal-bot/server
Server-side proxy for the eshal chat widget — keeps your secret key out of the browser.
Why
The widget can talk to the eshal API directly using a public key, but any
flow that needs a secret key (sk_live_...) must not run that key in
browser code. @eshal-bot/server runs a lightweight HMAC-signed proxy on
your own infrastructure: the widget's apiBaseUrl points at your server,
and your server signs and forwards every request to the eshal API.
Install
npm install @eshal-bot/serverQuick start
// Express — mount at /api/v1: the widget requests {apiBaseUrl}/api/v1/*
// and the proxy forwards the full original path to the eshal API.
const proxy = await createEshalProxy({ secretKey: process.env.ESHAL_SECRET_KEY! });
app.use('/api/v1', proxy.express());
// Next.js App Router
const proxy = await createEshalProxy({ secretKey: process.env.ESHAL_SECRET_KEY! });
export const GET = proxy.nextAppRouter();
export const POST = proxy.nextAppRouter();
// Next.js Pages Router (set bodyParser: false)
export const config = { api: { bodyParser: false } };
export default proxy.nextPagesRouter();
// Vercel / Netlify
export default proxy.vercel(); // or proxy.netlify()Widget config (frontend)
ChatWidget.init({ apiBaseUrl: 'https://myapp.com' });
// No key, no orgId — the proxy handles bothOptions
| Option | Required | Default | Description |
| ------------- | -------- | ------------------------- | -------------------------------------------------------- |
| secretKey | yes | — | Your eshal secret key. Never expose this in browser code. |
| eshalApiUrl | no | https://app.eshal.ai | Base URL of the eshal API. |
createEshalProxy validates the secret key against the eshal API on
startup and resolves your orgId once, so every subsequent request can be
HMAC-signed without an extra round-trip. Call it once at module load and
reuse the returned proxy.
