@sentralbee/app-sdk
v0.2.2
Published
Build a Sentralbee marketplace app: platform-token verification, install lifecycle, public API client, webhooks, and the embed bridge — the security-critical protocol, done for you.
Maintainers
Readme
@sentralbee/app-sdk
The security-critical protocol for a Sentralbee marketplace app — platform-token verification, the install lifecycle, encryption-at-rest, webhook signatures, and the public API client — so you never reimplement crypto. Your app logic + UI stay in your own code.
bun add @sentralbee/app-sdkServer (@sentralbee/app-sdk)
import {
createTokenVerifier, // Ed25519 platform-token verify (session + one-time provision)
createSessionAuth, // Hono middleware: workspace/scopes from the verified token
mountInstall, // wires /install/provision · /install/uninstall · /install/connect
createCypher, // AES-256-GCM encrypt/decrypt at rest (fail-closed)
verifyWebhookSignature,// Standard-Webhooks (Svix) signature verify
signWebhook, // compute a signature (tests/fixtures)
sentralbeeClient, // typed public-API client (markOrderPaid + request() escape hatch)
validateManifest, // validate sentralbee.app.json
manifestAudience,
} from "@sentralbee/app-sdk";createTokenVerifier({ publicKeyPem, audience, issuer? })→{ verifySession(token), verifyProvision(token) }.verifyProvisionvalidates only (does not consume the jti —mountInstallconsumes it after your work succeeds).mountInstall(app, { verifier, consumeJti, releaseJti?, onProvision, onUninstall, onConnect? })— you supply what to store; the SDK owns the token checks + retry-safe jti handling.createSessionAuth(verifier)— gate embed routes; readc.get('workspace').createCypher(secretKey)→{ encryptSecret, decryptSecret }.verifyWebhookSignature(rawBody, { id, timestamp, signature }, secret, { toleranceSeconds? })— over the RAW body.sentralbeeClient({ apiKey, baseUrl? })→.markOrderPaid(...),.request(method, path, body).
React embed (@sentralbee/app-sdk/react)
import { useHostTheme, useSafeArea, useSessionToken, ready } from "@sentralbee/app-sdk/react";useSessionToken() → { token, loading, error, workspace }. See the embed guide.
Docs
Concepts, lifecycle, quickstart, manifest reference, and guides live in the
app-kit docs. Scaffold a working app from
templates/starter and run it locally with sentralbee dev (no Sentralbee stack required).
Security posture
Every crypto path fails closed (no key → refuse). The workspace is always derived from a verified token, never the request body. Provision tokens are one-time; the SDK consumes the jti only after provisioning succeeds and rolls it back on failure.
