Choose an SDK
Sudomimus offers two SDK layers. Framework SDKs handle Connect callbacks, server routes, cookies, redirects, and session rotation for supported web frameworks. API SDKs provide typed clients and token helpers for applications that manage those flows directly. API SDK clients derive from the public OpenAPI 3.1 contracts; framework SDKs build on the API SDKs.
Choose an integration
Section titled “Choose an integration”- Use a framework SDK for Next.js, React Router, Nuxt, or Django server applications.
- Use an API SDK for another runtime or when your application manages Connect, Session, Device, or Native flows directly. Choose a language below.
- Use the API reference for the exact wire contract, unsupported languages, or your own generated client.
API SDK coverage
Section titled “API SDK coverage”| API | SDK responsibility |
|---|---|
| Connect API | Start browser login inquiries, status-poll them, redeem them for tokens, and fetch application metadata. |
| Session API | Rotate refresh tokens, introspect sessions, log out one session, or revoke all sessions for a subject. |
| Device API | Start device-code authorization and exchange the device code after user approval. |
| Native API | Exchange Steam tickets or AccessKey credentials for ordinary Sudomimus tokens. |
| Token helpers | Parse and verify Sudomimus access and refresh JWTs. |
API SDKs by language
Section titled “API SDKs by language”Framework SDKs
Section titled “Framework SDKs”The framework SDK guide compares the supported frameworks and links to each package guide. The framework SDK handles the web login and session lifecycle; the API SDK remains available for lower-level operations.
API SDK package model
Section titled “API SDK package model”Each API SDK package corresponds to one Sudomimus API. Install the package for the flow you start with, then add the Session package for refresh-token lifecycle work after tokens are issued.
- Connect is the usual web-application login flow. It needs your application’s client-auth private key because
/establishrequires client-auth signing. - Device is for public clients such as CLIs, launchers, TV apps, and terminals. It does not require a client secret.
- Native is for native credentials such as Steam Web API auth tickets and Sudomimus AccessKeys.
- Session is for everything that happens after initial issue: refresh, introspection, logout, and revoke-all.
- Token is for services that only verify access or refresh tokens and do not call an API.
The API walkthroughs still explain the underlying protocol: