npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

flow9-sdk

v0.2.0

Published

Official TypeScript SDK for the Flow9 Funnel CRM API.

Downloads

154

Readme

flow9-sdk

Developer-friendly, type-safe TypeScript SDK for the Flow9 CRM Public API — generated from the OpenAPI spec, with hand-written ergonomics under flow9-sdk/extras (webhook verification, retries, pagination, idempotency). Built by Speakeasy License: MIT

Summary

Wander CRM Public API: The Wander CRM Public API enables third-party systems to integrate with Flow9 Engage CRM. Create leads, manage activities, retrieve customer profiles, and onboard new companies programmatically.

Authentication

Two credential types are accepted (see securitySchemes):

  • an API key in the x-api-key header — f9_live_<32 hex> for live traffic, f9_test_<32 hex> for the test sandbox (legacy wcrm_live_ / wcrm_test_ keys still authenticate but are no longer issued). Keys are created in Settings > API Keys or via POST /v1/api-keys.
  • an OAuth 2.1 access token in Authorization: Bearer <jwt> — what MCP clients and OAuth integrations send. Same scopes, same tenant isolation.

If both are present, x-api-key wins. A request with neither is 401 with a WWW-Authenticate: Bearer header.

These endpoints are public (no credential) — they are mounted before the auth middleware and apply their own per-IP rate limiting:

  • GET /v1/health
  • POST /v1/onboarding (tenant signup)
  • GET /v1/availability (module availability by country)

/v1/api-keys is the one exception to the two credential types above: it is authenticated by a Company_Admin session token (Bearer), because a freshly-onboarded tenant has no API key yet.

Rate limiting and quotas

Three independent controls apply; a request must pass all of them.

  • Per key — sliding windows per minute (default 60, counted per endpoint) and per hour (default 1000, across the key). The rate_limit_per_day value stored on a key is not enforced in v1; it is kept for forward compatibility only.
  • Per tenant — one ceiling across every key the company holds (default 600/minute, plus an optional daily cap derived from the plan). This is a protective backstop, not a meter.
  • Monthly quota — calls counted against the plan's api_call_cap for the billing period. Exhausted: 429 QUOTA_EXCEEDED; no subscription: 402; quota engine unreachable: 503 QUOTA_UNAVAILABLE (fails closed).

Every response carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset, describing whichever of the per-key / per-tenant windows is closest to rejecting. A 429 adds Retry-After. A monthly-quota refusal adds X-Quota-Limit, X-Quota-Used and X-Quota-Remaining. Full detail: docs/api/rate-limits.md.

Response Envelope

All responses use a consistent JSON envelope:

{
  "success": true | false,
  "data": { ... },          // present on success
  "error": { "code": "...", "message": "...", "details": ... }, // present on error
  "meta": { "request_id": "uuid", "timestamp": "ISO 8601" }
}

Table of Contents

SDK Installation

The SDK can be installed with either npm, pnpm, bun or yarn package managers.

NPM

npm add flow9-sdk

PNPM

pnpm add flow9-sdk

Bun

bun add flow9-sdk

Yarn

yarn add flow9-sdk

[!NOTE] This package is published as an ES Module (ESM) only. For applications using CommonJS, use await import("flow9-sdk") to import and use this package.

Requirements

For supported JavaScript runtimes, please consult RUNTIMES.md.

SDK Example Usage

Example

import { Flow9 } from "flow9-sdk";

const flow9 = new Flow9();

async function run() {
  const result = await flow9.health.getHealth();

  console.log(result);
}

run();

Authentication

Per-Client Security Schemes

This SDK supports the following security schemes globally:

| Name | Type | Scheme | | ------------ | ------ | ----------- | | apiKeyAuth | apiKey | API key | | bearerAuth | http | HTTP Bearer |

You can set the security parameters through the security optional parameter when initializing the SDK client instance. The selected scheme will be used by default to authenticate with the API for all operations that support it. For example:

import { Flow9 } from "flow9-sdk";

const flow9 = new Flow9({
  security: {
    apiKeyAuth: "<YOUR_API_KEY_HERE>",
  },
});

async function run() {
  const result = await flow9.health.getHealth();

  console.log(result);
}

run();

Available Resources and Operations

AccessControl

Activities

APIKeys

Attachments

Billing

Campaigns

Customers

Health

Leads

Messages

Objects

Onboarding

OrgStructure

Packages

Records

Scheduling

SearchAndReports

Settings

Suppression

TestMode

Users

Webhooks

Standalone functions

All the methods listed above are available as standalone functions. These functions are ideal for use in applications running in the browser, serverless runtimes or other environments where application bundle size is a primary concern. When using a bundler to build your application, all unused functionality will be either excluded from the final bundle or tree-shaken away.

To read more about standalone functions, check FUNCTIONS.md.

File uploads

Certain SDK methods accept files as part of a multi-part request. It is possible and typically recommended to upload files as a stream rather than reading the entire contents into memory. This avoids excessive memory consumption and potentially crashing with out-of-memory errors when working with very large files. The following example demonstrates how to attach a file stream to a request.

[!TIP]

Depending on your JavaScript runtime, there are convenient utilities that return a handle to a file without reading the entire contents into memory:

  • Node.js v20+: Since v20, Node.js comes with a native openAsBlob function in node:fs.
  • Bun: The native Bun.file function produces a file handle that can be used for streaming file uploads.
  • Browsers: All supported browsers return an instance to a File when reading the value from an <input type="file"> element.
  • Node.js v18: A file stream can be created using the fileFrom helper from fetch-blob/from.js.
import { Flow9 } from "flow9-sdk";
import { openAsBlob } from "node:fs";

const flow9 = new Flow9({
  security: {
    apiKeyAuth: "<YOUR_API_KEY_HERE>",
  },
});

async function run() {
  const result = await flow9.attachments.uploadRecordAttachment({
    object: "<value>",
    id: "013b3f02-ad24-4871-9611-2f4b59e140d4",
    body: {
      file: await openAsBlob("example.file"),
    },
  });

  console.log(result);
}

run();

Retries

Some of the endpoints in this SDK support retries. If you use the SDK without any configuration, it will fall back to the default retry strategy provided by the API. However, the default retry strategy can be overridden on a per-operation basis, or across the entire SDK.

To change the default retry strategy for a single API call, simply provide a retryConfig object to the call:

import { Flow9 } from "flow9-sdk";

const flow9 = new Flow9();

async function run() {
  const result = await flow9.health.getHealth({
    retries: {
      strategy: "backoff",
      backoff: {
        initialInterval: 1,
        maxInterval: 50,
        exponent: 1.1,
        maxElapsedTime: 100,
      },
      retryConnectionErrors: false,
    },
  });

  console.log(result);
}

run();

If you'd like to override the default retry strategy for all operations that support retries, you can provide a retryConfig at SDK initialization:

import { Flow9 } from "flow9-sdk";

const flow9 = new Flow9({
  retryConfig: {
    strategy: "backoff",
    backoff: {
      initialInterval: 1,
      maxInterval: 50,
      exponent: 1.1,
      maxElapsedTime: 100,
    },
    retryConnectionErrors: false,
  },
});

async function run() {
  const result = await flow9.health.getHealth();

  console.log(result);
}

run();

Error Handling

Flow9Error is the base class for all HTTP error responses. It has the following properties:

| Property | Type | Description | | ------------------- | ---------- | --------------------------------------------------------------------------------------- | | error.message | string | Error message | | error.statusCode | number | HTTP response status code eg 404 | | error.headers | Headers | HTTP response headers | | error.body | string | HTTP body. Can be empty string if no body is returned. | | error.rawResponse | Response | Raw HTTP response | | error.data$ | | Optional. Some errors may contain structured data. See Error Classes. |

Example

import { Flow9 } from "flow9-sdk";
import * as errors from "flow9-sdk/models/errors";

const flow9 = new Flow9({
  security: {
    apiKeyAuth: "<YOUR_API_KEY_HERE>",
  },
});

async function run() {
  try {
    const result = await flow9.onboarding.onboardCompany({
      company: {
        name: "Acme Travel",
        email: "[email protected]",
        phone: "+971501234567",
        website: "https://acmetravel.com",
        city: "Dubai",
        country: "UAE",
      },
      adminUser: {
        email: "[email protected]",
        fullName: "John Smith",
      },
      region: "middle_east",
      industry: "travel",
    });

    console.log(result);
  } catch (error) {
    // The base class for HTTP error responses
    if (error instanceof errors.Flow9Error) {
      console.log(error.message);
      console.log(error.statusCode);
      console.log(error.body);
      console.log(error.headers);

      // Depending on the method different errors may be thrown
      if (error instanceof errors.ErrorBody) {
        console.log(error.data$.success); // boolean
        console.log(error.data$.error); // models.ErrorT
        console.log(error.data$.meta); // models.Meta
      }
    }
  }
}

run();

Error Classes

Primary errors:

Network errors:

Inherit from Flow9Error:

  • ResponseValidationError: Type mismatch between the data returned from the server and the structure expected by the SDK. See error.rawValue for the raw value and error.pretty() for a nicely formatted multi-line string.

* Check the method documentation to see if the error is applicable.

Server Selection

Override Server URL Per-Client

The default server can be overridden globally by passing a URL to the serverURL: string optional parameter when initializing the SDK client instance. For example:

import { Flow9 } from "flow9-sdk";

const flow9 = new Flow9({
  serverURL: "https://mwxpyoqrtdfxubdotbmj.supabase.co/functions/v1/public-api",
});

async function run() {
  const result = await flow9.health.getHealth();

  console.log(result);
}

run();

Custom HTTP Client

The TypeScript SDK makes API calls using an HTTPClient that wraps the native Fetch API. This client is a thin wrapper around fetch and provides the ability to attach hooks around the request lifecycle that can be used to modify the request or handle errors and response.

The HTTPClient constructor takes an optional fetcher argument that can be used to integrate a third-party HTTP client or when writing tests to mock out the HTTP client and feed in fixtures.

The following example shows how to:

  • route requests through a proxy server using undici's ProxyAgent
  • use the "beforeRequest" hook to add a custom header and a timeout to requests
  • use the "requestError" hook to log errors
import { Flow9 } from "flow9-sdk";
import { ProxyAgent } from "undici";
import { HTTPClient } from "flow9-sdk/lib/http";

const dispatcher = new ProxyAgent("http://proxy.example.com:8080");

const httpClient = new HTTPClient({
  // 'fetcher' takes a function that has the same signature as native 'fetch'.
  fetcher: (input, init) =>
    // 'dispatcher' is specific to undici and not part of the standard Fetch API.
    fetch(input, { ...init, dispatcher } as RequestInit),
});

httpClient.addHook("beforeRequest", (request) => {
  const nextRequest = new Request(request, {
    signal: request.signal || AbortSignal.timeout(5000)
  });

  nextRequest.headers.set("x-custom-header", "custom value");

  return nextRequest;
});

httpClient.addHook("requestError", (error, request) => {
  console.group("Request Error");
  console.log("Reason:", `${error}`);
  console.log("Endpoint:", `${request.method} ${request.url}`);
  console.groupEnd();
});

const sdk = new Flow9({ httpClient: httpClient });

Debugging

You can setup your SDK to emit debug logs for SDK requests and responses.

You can pass a logger that matches console's interface as an SDK option.

[!WARNING] Beware that debug logging will reveal secrets, like API tokens in headers, in log messages printed to a console or files. It's recommended to use this feature only during local development and not in production.

import { Flow9 } from "flow9-sdk";

const sdk = new Flow9({ debugLogger: console });

Development

Maturity

This SDK is in beta, and there may be breaking changes between versions without a major version update. Therefore, we recommend pinning usage to a specific package version. This way, you can install the same version each time without breaking changes unless you are intentionally looking for the latest version.

Contributions

While we value open-source contributions to this SDK, this library is generated programmatically. Any manual changes added to internal files will be overwritten on the next generation. We look forward to hearing your feedback. Feel free to open a PR or an issue with a proof of concept and we'll do our best to include it in a future release.

SDK Created by Speakeasy