
Security News
Open Source CAI Framework Handles Pen Testing Tasks up to 3,600× Faster Than Humans
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.
@gr4vy/sdk
Advanced tools
Developer-friendly & type-safe TypeScript SDK specifically catered to leverage the **Gr4vy** API.
Developer-friendly & type-safe TypeScript SDK specifically catered to leverage the Gr4vy API.
The official Gr4vy SDK for TypeScript provides a convenient way to interact with the Gr4vy API from your server-side application. This SDK allows you to seamlessly integrate Gr4vy's powerful payment orchestration capabilities, including:
This SDK is designed to simplify development, reduce boilerplate code, and help you get up and running with Gr4vy quickly and efficiently. It handles authentication, request signing, and provides easy-to-use methods for most API endpoints.
yarn add @gr4vy/sdk
yarn add @gr4vy/sdk
For supported JavaScript runtimes, please consult RUNTIMES.md.
import fs from "fs";
import { Gr4vy, withToken } from "@gr4vy/sdk";
async function run() {
const gr4vy = new Gr4vy({
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
const result = await gr4vy.transactions.list({});
// Handle the result
console.log(result);
}
run();
Alternatively, you can create a token for use with the SDK or with your own client library.
import { getToken } from "@gr4vy/sdk";
async function run() {
const token = await getToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
});
console.log(token);
}
run();
Note: This will only create a token once. Use
withToken
to dynamically generate a token for every request.
Alternatively, you can create a token for use with Embed as follows.
import { Gr4vy, getEmbedToken } from "@gr4vy/sdk";
async function run() {
const privateKey = fs.readFileSync("private_key.pem", "utf8")
const gr4vy = new Gr4vy({
server: "sandbox",
id: "example",
bearerAuth: withToken({ privateKey }),
});
const checkoutSession = await gr4vy.checkoutSessions.create()
const token = await getEmbedToken({
privateKey,
checkoutSessionId: checkoutSession.id,
embedParams: {
amount: 1299,
currency: 'USD',
buyerExternalIdentifier: 'user-1234',
}
});
console.log(token);
}
run();
Note: This will only create a token once. Use
withToken
to dynamically generate a token for every request.
Depending on the key used, you might need to explicitly define a merchant account ID to use. In our API,
this uses the X-GR4VY-MERCHANT-ACCOUNT-ID
header. When using the SDK, you can set the merchantAccountId
on every request.
const result = await gr4vy.transactions.list({
merchantAccountId: 'merchant-12345'
})
Alternatively, the merchant account ID can also be set when initializing the SDK.
const gr4vy = new Gr4vy({
server: "sandbox",
id: "example",
merchantAccountId: 'merchant-12345',
bearerAuth: withToken({ privateKey }),
});
The SDK provides a verifyWebhook
method to validate incoming webhook requests from Gr4vy. This ensures that the webhook payload is authentic and has not been tampered with.
import { verifyWebhook } from "@gr4vy/sdk";
const payload = 'your-webhook-payload'
const secret = 'your-webhook-secret'
const signatureHeader = 'signatures-from-header'
const timestampHeader = 'timestamp-from-header'
const timestampTolerance = 300 // optional, in seconds (default: 0)
try {
verifyWebhook(
payload,
secret,
signatureHeader,
timestampHeader,
timestampTolerance
)
console.log('Webhook verified successfully!')
} catch (error) {
console.error('Webhook verification failed:', error.message)
}
payload
: The raw payload string received in the webhook request.secret
: The secret used to sign the webhook. This is provided in your Gr4vy dashboard.signatureHeader
: The X-Gr4vy-Signature
header from the webhook request.timestampHeader
: The X-Gr4vy-Timestamp
header from the webhook request.timestampTolerance
: (Optional) The maximum allowed difference (in seconds) between the current time and the timestamp in the webhook. Defaults to 0
(no tolerance).Gr4vyError
is the base class for all HTTP error responses. It has the following properties:
Property | Type | Description |
---|---|---|
error.message | string | Error message |
error.statusCode | number | HTTP response status code eg 404 |
error.headers | Headers | HTTP response headers |
error.body | string | HTTP body. Can be empty string if no body is returned. |
error.rawResponse | Response | Raw HTTP response |
error.data$ | Optional. Some errors may contain structured data. See Error Classes. |
import { Gr4vy } from "@gr4vy/sdk";
import * as errors from "@gr4vy/sdk/models/errors";
const gr4vy = new Gr4vy({
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
try {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
});
console.log(result);
} catch (error) {
// The base class for HTTP error responses
if (error instanceof errors.Gr4vyError) {
console.log(error.message);
console.log(error.statusCode);
console.log(error.body);
console.log(error.headers);
// Depending on the method different errors may be thrown
if (error instanceof errors.Error400) {
console.log(error.data$.type); // string
console.log(error.data$.code); // string
console.log(error.data$.status); // number
console.log(error.data$.message); // string
console.log(error.data$.details); // ErrorDetail[]
}
}
}
}
run();
Primary errors:
Gr4vyError
: The base class for HTTP error responses.
Error400
: The request was invalid. Status code 400
.Error401
: The request was unauthorized. Status code 401
.Error403
: The credentials were invalid or the caller did not have permission to act on the resource. Status code 403
.Error404
: The resource was not found. Status code 404
.Error405
: The request method was not allowed. Status code 405
.Error409
: A duplicate record was found. Status code 409
.Error425
: The request was too early. Status code 425
.Error429
: Too many requests were made. Status code 429
.Error500
: The server encountered an error. Status code 500
.Error502
: The server encountered an error. Status code 502
.Error504
: The server encountered an error. Status code 504
.HTTPValidationError
: Validation Error. Status code 422
. *Network errors:
ConnectionError
: HTTP client was unable to make a request to a server.RequestTimeoutError
: HTTP request timed out due to an AbortSignal signal.RequestAbortedError
: HTTP request was aborted by the client.InvalidRequestError
: Any input used to create a request is invalid.UnexpectedClientError
: Unrecognised or unexpected error.Inherit from Gr4vyError
:
ResponseValidationError
: Type mismatch between the data returned from the server and the structure expected by the SDK. See error.rawValue
for the raw value and error.pretty()
for a nicely formatted multi-line string.* Check the method documentation to see if the error is applicable.
You can override the default server globally by passing a server name to the server: keyof typeof ServerList
optional parameter when initializing the SDK client instance. The selected server will then be used as the default on the operations that use it. This table lists the names associated with the available servers:
Name | Server | Variables | Description |
---|---|---|---|
sandbox | https://api.sandbox.{id}.gr4vy.app | id | |
production | https://api.{id}.gr4vy.app | id |
If the selected server has variables, you may override its default values through the additional parameters made available in the SDK constructor:
Variable | Parameter | Default | Description |
---|---|---|---|
id | id: string | "example" | The subdomain for your Gr4vy instance. |
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
server: "production",
id: "<id>",
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
});
console.log(result);
}
run();
The default server can also be overridden globally by passing a URL to the serverURL: string
optional parameter when initializing the SDK client instance. For example:
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
serverURL: "https://api.sandbox.example.gr4vy.app",
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
});
console.log(result);
}
run();
The TypeScript SDK makes API calls using an HTTPClient
that wraps the native
Fetch API. This
client is a thin wrapper around fetch
and provides the ability to attach hooks
around the request lifecycle that can be used to modify the request or handle
errors and response.
The HTTPClient
constructor takes an optional fetcher
argument that can be
used to integrate a third-party HTTP client or when writing tests to mock out
the HTTP client and feed in fixtures.
The following example shows how to use the "beforeRequest"
hook to to add a
custom header and a timeout to requests and how to use the "requestError"
hook
to log errors:
import { Gr4vy } from "@gr4vy/sdk";
import { HTTPClient } from "@gr4vy/sdk/lib/http";
const httpClient = new HTTPClient({
// fetcher takes a function that has the same signature as native `fetch`.
fetcher: (request) => {
return fetch(request);
}
});
httpClient.addHook("beforeRequest", (request) => {
const nextRequest = new Request(request, {
signal: request.signal || AbortSignal.timeout(5000)
});
nextRequest.headers.set("x-custom-header", "custom value");
return nextRequest;
});
httpClient.addHook("requestError", (error, request) => {
console.group("Request Error");
console.log("Reason:", `${error}`);
console.log("Endpoint:", `${request.method} ${request.url}`);
console.groupEnd();
});
const sdk = new Gr4vy({ httpClient });
This SDK supports the following security scheme globally:
Name | Type | Scheme | Environment Variable |
---|---|---|---|
bearerAuth | http | HTTP Bearer | GR4VY_BEARER_AUTH |
To authenticate with the API the bearerAuth
parameter must be set when initializing the SDK client instance. For example:
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
merchantAccountId: "<id>",
});
async function run() {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
});
console.log(result);
}
run();
The SDK can be installed with either npm, pnpm, bun or yarn package managers.
npm add @gr4vy/sdk
pnpm add @gr4vy/sdk
bun add @gr4vy/sdk
yarn add @gr4vy/sdk zod
# Note that Yarn does not install peer dependencies automatically. You will need
# to install zod as shown above.
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
});
console.log(result);
}
run();
Some of the endpoints in this SDK support pagination. To use pagination, you
make your SDK calls as usual, but the returned response object will also be an
async iterable that can be consumed using the for await...of
syntax.
Here's an example of one such pagination call:
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
const result = await gr4vy.buyers.list();
for await (const page of result) {
console.log(page);
}
}
run();
Some of the endpoints in this SDK support retries. If you use the SDK without any configuration, it will fall back to the default retry strategy provided by the API. However, the default retry strategy can be overridden on a per-operation basis, or across the entire SDK.
To change the default retry strategy for a single API call, simply provide a retryConfig object to the call:
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
}, {
retries: {
strategy: "backoff",
backoff: {
initialInterval: 1,
maxInterval: 50,
exponent: 1.1,
maxElapsedTime: 100,
},
retryConnectionErrors: false,
},
});
console.log(result);
}
run();
If you'd like to override the default retry strategy for all operations that support retries, you can provide a retryConfig at SDK initialization:
import { Gr4vy } from "@gr4vy/sdk";
const gr4vy = new Gr4vy({
retryConfig: {
strategy: "backoff",
backoff: {
initialInterval: 1,
maxInterval: 50,
exponent: 1.1,
maxElapsedTime: 100,
},
retryConnectionErrors: false,
},
merchantAccountId: "<id>",
server: "sandbox",
id: "example",
bearerAuth: withToken({
privateKey: fs.readFileSync("private_key.pem", "utf8"),
}),
});
async function run() {
const result = await gr4vy.accountUpdater.jobs.create({
paymentMethodIds: [
"ef9496d8-53a5-4aad-8ca2-00eb68334389",
"f29e886e-93cc-4714-b4a3-12b7a718e595",
],
});
console.log(result);
}
run();
Gr4vy: The Gr4vy API.
All the methods listed above are available as standalone functions. These functions are ideal for use in applications running in the browser, serverless runtimes or other environments where application bundle size is a primary concern. When using a bundler to build your application, all unused functionality will be either excluded from the final bundle or tree-shaken away.
To read more about standalone functions, check FUNCTIONS.md.
accountUpdaterJobsCreate
- Create account updater jobauditLogsList
- List audit log entriesbuyersCreate
- Add a buyerbuyersDelete
- Delete a buyerbuyersGet
- Get a buyerbuyersGiftCardsList
- List gift cards for a buyerbuyersList
- List all buyersbuyersPaymentMethodsList
- List payment methods for a buyerbuyersShippingDetailsCreate
- Add buyer shipping detailsbuyersShippingDetailsDelete
- Delete a buyer's shipping detailsbuyersShippingDetailsGet
- Get buyer shipping detailsbuyersShippingDetailsList
- List a buyer's shipping detailsbuyersShippingDetailsUpdate
- Update a buyer's shipping detailsbuyersUpdate
- Update a buyercardSchemeDefinitionsList
- List card scheme definitionscheckoutSessionsCreate
- Create checkout sessioncheckoutSessionsDelete
- Delete checkout sessioncheckoutSessionsGet
- Get checkout sessioncheckoutSessionsUpdate
- Update checkout sessiondigitalWalletsCreate
- Register digital walletdigitalWalletsDelete
- Delete digital walletdigitalWalletsDomainsCreate
- Register a digital wallet domaindigitalWalletsDomainsDelete
- Remove a digital wallet domaindigitalWalletsGet
- Get digital walletdigitalWalletsList
- List digital walletsdigitalWalletsSessionsApplePay
- Create a Apple Pay sessiondigitalWalletsSessionsClickToPay
- Create a Click to Pay sessiondigitalWalletsSessionsGooglePay
- Create a Google Pay sessiondigitalWalletsUpdate
- Update digital walletgiftCardsBalancesList
- List gift card balancesgiftCardsCreate
- Create gift cardgiftCardsDelete
- Delete a gift cardgiftCardsGet
- Get gift cardgiftCardsList
- List gift cardsmerchantAccountsCreate
- Create a merchant accountmerchantAccountsGet
- Get a merchant accountmerchantAccountsList
- List all merchant accountsmerchantAccountsUpdate
- Update a merchant accountpaymentLinksCreate
- Add a payment linkpaymentLinksExpire
- Expire a payment linkpaymentLinksGet
- Get payment linkpaymentLinksList
- List all payment linkspaymentMethodsCreate
- Create payment methodpaymentMethodsDelete
- Delete payment methodpaymentMethodsGet
- Get payment methodpaymentMethodsList
- List all payment methodspaymentMethodsNetworkTokensCreate
- Provision network tokenpaymentMethodsNetworkTokensCryptogramCreate
- Provision network token cryptogrampaymentMethodsNetworkTokensDelete
- Delete network tokenpaymentMethodsNetworkTokensList
- List network tokenspaymentMethodsNetworkTokensResume
- Resume network tokenpaymentMethodsNetworkTokensSuspend
- Suspend network tokenpaymentMethodsPaymentServiceTokensCreate
- Create payment service tokenpaymentMethodsPaymentServiceTokensDelete
- Delete payment service tokenpaymentMethodsPaymentServiceTokensList
- List payment service tokenspaymentOptionsList
- List payment optionspaymentServiceDefinitionsGet
- Get a payment service definitionpaymentServiceDefinitionsList
- List payment service definitionspaymentServiceDefinitionsSession
- Create a session for apayment service definitionpaymentServicesCreate
- Update a configured payment servicepaymentServicesDelete
- Delete a configured payment servicepaymentServicesGet
- Get payment servicepaymentServicesList
- List payment servicespaymentServicesSession
- Create a session for apayment service definitionpaymentServicesUpdate
- Configure a payment servicepaymentServicesVerify
- Verify payment service credentialspayoutsCreate
- Create a payout.payoutsGet
- Get a payout.payoutsList
- List payouts created.refundsGet
- Get refundreportExecutionsList
- List executed reportsreportsCreate
- Add a reportreportsExecutionsGet
- Get executed reportreportsExecutionsList
- List executions for reportreportsExecutionsUrl
- Create URL for executed reportreportsGet
- Get a reportreportsList
- List configured reportsreportsPut
- Update a reporttransactionsCapture
- Capture transactiontransactionsCreate
- Create transactiontransactionsEventsList
- List transaction eventstransactionsGet
- Get transactiontransactionsList
- List transactionstransactionsRefundsAllCreate
- Create batch transaction refundtransactionsRefundsCreate
- Create transaction refundtransactionsRefundsGet
- Get transaction refundtransactionsRefundsList
- List transaction refundstransactionsSettlementsGet
- Get transaction settlementtransactionsSettlementsList
- List transaction settlementstransactionsSync
- Sync transactiontransactionsVoid
- Void transactionYou can setup your SDK to emit debug logs for SDK requests and responses.
You can pass a logger that matches console
's interface as an SDK option.
[!WARNING] Beware that debug logging will reveal secrets, like API tokens in headers, in log messages printed to a console or files. It's recommended to use this feature only during local development and not in production.
import { Gr4vy } from "@gr4vy/sdk";
const sdk = new Gr4vy({ debugLogger: console });
You can also enable a default debug logger by setting an environment variable GR4VY_DEBUG
to true.
To run the tests, install NPM, ensure to download the private_key.pem
for the test environment, and run the following.
npm install
npx vitest --testTimeout 8000
While we value open-source contributions to this SDK, this library is generated programmatically. Feel free to open a PR or a Github issue as a proof of concept and we'll do our best to include it in a future release!
FAQs
Developer-friendly & type-safe TypeScript SDK specifically catered to leverage the **Gr4vy** API.
The npm package @gr4vy/sdk receives a total of 397 weekly downloads. As such, @gr4vy/sdk popularity was classified as not popular.
We found that @gr4vy/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.
Security News
Deno 2.4 brings back bundling, improves dependency updates and telemetry, and makes the runtime more practical for real-world JavaScript projects.
Security News
CVEForecast.org uses machine learning to project a record-breaking surge in vulnerability disclosures in 2025.