@doola/js/server
fetch, Request and Response. Both helpers send your key as the raw Authorization header, pick api.doola.com or api.test.doola.com from its prefix, and time out after 10 seconds.
createSessionHandler(options)
apiKey: yourdk_secret key. A key that is set but invalid, including apk_key, throws when you create the handler. A missing key is refused on each request instead, so builds without the secret still pass.getCustomer: return the signed-in customer, ornullwhen nobody is signed in.nullanswers 401.onFailure: called with the reason whenever doola does not return a session. Your own 401 for a signed-out user does not call it.
Cache-Control: no-store. A success answers 200 with { accessToken, expiresIn }.
createCustomerSession(options)
Request and Response: status, with body as JSON, or { code } as JSON when code is set (a 409). It rejects only when the key is missing or invalid.
DoolaCustomer
Only these fields are sent to doola, whatever else the object carries.
How doola’s answers map
failure also carries doolaStatus and doolaCode, doola’s error.code, when there was one.
Partner API endpoints
An SDK integration uses five Partner API endpoints, all with yourdk_ secret key:
One more is optional:
Everything after payment, from webhooks to documents and required actions, uses the rest of the Partner API.