@tbbn/sdk-js
v0.4.0
Published
JavaScript client for the TBBN Platform API — publish listings, manage offers and trade sessions, and verify webhooks. Works anywhere fetch does.
Maintainers
Readme
@tbbn/sdk-js
JavaScript client for the TBBN Platform API. Publish
listings, manage offers and trade sessions, and verify webhooks from any runtime with a global
fetch — Node 18+, Deno, Bun, Cloudflare Workers, and every modern browser.
Writing TypeScript? Use @tbbn/sdk-typescript
instead — it wraps this package with typed inputs and outputs.
Install
npm install @tbbn/sdk-jsQuick start
import { TbbnClient } from '@tbbn/sdk-js';
const client = new TbbnClient({
baseUrl: 'https://api.tbbnetwork.com',
apiKey: process.env.TBBN_API_KEY, // sk_sandbox_... or sk_live_...
});
// Publish one of your seller's items. merchantListingRef is your own id for it, so calling
// this again with the same ref updates the listing rather than duplicating it.
const listing = await client.listings.upsert({
merchantId: '...',
merchantListingRef: 'sku-1042',
sellerId: '...',
listingType: 'BOTH',
title: 'Nike Air Max 90 — size 10, lightly worn',
category: 'Apparel',
originalPrice: 150,
requestedAmount: 25,
currency: 'USD',
visibility: 'GLOBAL',
wants: [{ category: 'Electronics', subcategory: 'Tablets' }],
});
// See what other sellers have offered for it.
const offers = await client.offers.list(listing.sellerId, 'received');A complete runnable walkthrough is in example/basic.mjs.
Authentication
Pass either an API key (apiKey, issued to your merchant at
merchants.tbbnetwork.com) or a session token
(accessToken, obtained through one of the client.auth sign-in flows). Sandbox keys
(sk_sandbox_…) work against the same API and never touch live data.
Browser use
Import from the /client subpath in browser bundles. The package root also exports the webhook
verifier, which depends on Node's crypto module:
import { TbbnClient } from '@tbbn/sdk-js/client';Webhooks
Verify every inbound delivery before trusting it. Pass the raw request body exactly as received — re-serialising the JSON changes the bytes and the signature will not match.
import { verifyWebhookSignature } from '@tbbn/sdk-js';
const ok = verifyWebhookSignature(rawBody, req.headers['x-tbbn-signature'], signingSecret);Signatures are HMAC-SHA256 with a five-minute replay window. The full event catalogue is at developer.tbbnetwork.com.
Errors
Every non-2xx response throws TbbnApiError with status, code, message, and
requestId. Quote the requestId when asking for help with a specific call.
Resources
auth, merchants, apiKeys, oauthClients, oauthLink, sellers, businesses, branches,
businessMerchantLinks, listings, catalog,
media, directory, search, tradeEngine, currency, localization, matching,
recommendations, offers, tradeSessions, checkout, billing, notifications,
webhooks, auditLogs, moderation, fraud, reputation, reviews, analytics,
features, sandbox, space, waitlist, community. Each method maps one-to-one onto an
API endpoint documented in the API reference.
Support
Questions and bug reports: the developer community.
License
MIT © Trade By Barter Network, Inc.
