Skip to main content

@doola/js/server

Runs on Node 18 or later, or any runtime with the web-standard fetch, Request and Response. Both helpers send your key as the raw Authorization header, pick api.doola.com or api.test.doola.com from its prefix, and time out after 10 seconds.

createSessionHandler(options)

Builds a complete session route.
  • apiKey: your dk_ secret key. A key that is set but invalid, including a pk_ key, throws when you create the handler. A missing key is refused on each request instead, so builds without the secret still pass.
  • getCustomer: return the signed-in customer, or null when nobody is signed in. null answers 401.
  • onFailure: called with the reason whenever doola does not return a session. Your own 401 for a signed-out user does not call it.
Every response carries Cache-Control: no-store. A success answers 200 with { accessToken, expiresIn }.

createCustomerSession(options)

Creates one session and returns what your route should answer, for frameworks that do not use Request and Response: status, with body as JSON, or { code } as JSON when code is set (a 409). It rejects only when the key is missing or invalid.

DoolaCustomer

Only these fields are sent to doola, whatever else the object carries.

How doola’s answers map

failure also carries doolaStatus and doolaCode, doola’s error.code, when there was one.

Partner API endpoints

An SDK integration uses five Partner API endpoints, all with your dk_ secret key: One more is optional: Everything after payment, from webhooks to documents and required actions, uses the rest of the Partner API.
Last modified on October 8, 2026