Skip to content

Choose an SDK

View as Markdown

Sudomimus offers two SDK layers. Framework SDKs handle Connect callbacks, server routes, cookies, redirects, and session rotation for supported web frameworks. API SDKs provide typed clients and token helpers for applications that manage those flows directly. API SDK clients derive from the public OpenAPI 3.1 contracts; framework SDKs build on the API SDKs.

  • Use a framework SDK for Next.js, React Router, Nuxt, or Django server applications.
  • Use an API SDK for another runtime or when your application manages Connect, Session, Device, or Native flows directly. Choose a language below.
  • Use the API reference for the exact wire contract, unsupported languages, or your own generated client.
API SDK responsibility
Connect API Start browser login inquiries, status-poll them, redeem them for tokens, and fetch application metadata.
Session API Rotate refresh tokens, introspect sessions, log out one session, or revoke all sessions for a subject.
Device API Start device-code authorization and exchange the device code after user approval.
Native API Exchange Steam tickets or AccessKey credentials for ordinary Sudomimus tokens.
Token helpers Parse and verify Sudomimus access and refresh JWTs.

The framework SDK guide compares the supported frameworks and links to each package guide. The framework SDK handles the web login and session lifecycle; the API SDK remains available for lower-level operations.

Each API SDK package corresponds to one Sudomimus API. Install the package for the flow you start with, then add the Session package for refresh-token lifecycle work after tokens are issued.

  • Connect is the usual web-application login flow. It needs your application’s client-auth private key because /establish requires client-auth signing.
  • Device is for public clients such as CLIs, launchers, TV apps, and terminals. It does not require a client secret.
  • Native is for native credentials such as Steam Web API auth tickets and Sudomimus AccessKeys.
  • Session is for everything that happens after initial issue: refresh, introspection, logout, and revoke-all.
  • Token is for services that only verify access or refresh tokens and do not call an API.

The API walkthroughs still explain the underlying protocol: