SDK Reference
@proveanything/smartlinks
Namespaces
auth
Admin authentication and account ops: login/logout, tokens, account info.
requestAdminJWT
Requests an admin JWT for the current user and a specific collection Returns JWT if valid.
requestAdminJWT(collectionId: string) → Promise<string>requestPublicJWT
Requests a JWT for the current user and a specific collection/product/proof Validates if the user has access to the resource, and returns a JWT
requestPublicJWT(collectionId: string, productId: string, proofId: string) → Promise<string>registerUser
Tries to register a new user account. Can return a bearer token, or a Firebase token
registerUser(user: ) → Promise<>getUserToken
Admin: Get a user bearer token (impersonation/automation). POST /admin/auth/userToken All fields are optional; at least one identifier should be provided.
getUserToken(opts?: {
email?: string
collectionId?: string
userId?: string
expiry?: string
}) → Promise<getLocation
Gets a best-effort coarse location for the current anonymous caller. This endpoint is typically IP-derived and is useful when the user is not logged in but you still want country/location context for content rules, analytics enrichment, or regional defaults. Returns fields such as country, latitude, longitude, and area when available. By default the result is cached in session storage for 30 minutes so apps can reuse coarse location context without repeatedly hitting the endpoint.
getLocation(options: = {}) → Promise<>clearCachedLocation
Clears the cached anonymous auth location, if present.
clearCachedLocation(storageKey: string = DEFAULT_AUTH_LOCATION_CACHE_KEY) → voidgetAccount
Gets current account information for the logged in user. Returns user, owner, account, and location objects. When the caller is authenticated, prefer account.location from this response. For anonymous callers, use auth.getLocation() instead. Short-circuits immediately (no network request) when the SDK has no bearer token or API key set — the server would return 401 anyway. Throws a SmartlinksApiError with statusCode 401 and details.local = true so callers can distinguish "never authenticated" from an actual server-side token rejection. This short-circuit is skipped when proxy mode is enabled, because in that case credentials are held by the parent frame and the local SDK may have no token set yet — the request must be forwarded to the parent to determine whether the user is authenticated.
getAccount() → Promise<>login
Login with email and password. Sets the bearerToken for subsequent API calls.
login(email: string, password: string) → Promise<>logout
Logout (clears bearerToken for future API calls).
logout() → voidverifyToken
Verifies the current bearerToken (or a provided token). Returns user/account info if valid.
verifyToken(token?: string) → Promise<>