Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@inkeep/ai-api
Advanced tools
npm add @inkeep/ai-api
yarn add @inkeep/ai-api
For supported JavaScript runtimes, please consult RUNTIMES.md.
import { InkeepAI } from "@inkeep/ai-api";
async function run() {
const sdk = new InkeepAI({
apiKey: "<YOUR_BEARER_TOKEN_HERE>",
});
const result = await sdk.chatSession.create({
integrationId: "string",
chatSession: {
messages: [,],
},
});
if (res.chatResult == null) {
throw new Error("failed to create stream: received null value");
}
for await (const event of res.chatResult) {
// Handle the event
}
}
run();
Server-sent events are used to stream content from certain
operations. These operations will expose the stream as an async iterable that
can be consumed using a for await...of
loop. The loop will
terminate when the server no longer has any events to send and closes the
underlying connection.
import { InkeepAI } from "@inkeep/ai-api";
async function run() {
const sdk = new InkeepAI({
apiKey: "<YOUR_BEARER_TOKEN_HERE>",
});
const result = await sdk.chatSession.create({
integrationId: "string",
chatSession: {
messages: [,],
},
});
if (res.chatResult == null) {
throw new Error("failed to create stream: received null value");
}
for await (const event of res.chatResult) {
// Handle the event
}
}
run();
All SDK methods return a response object or throw an error. If Error objects are specified in your OpenAPI Spec, the SDK will throw the appropriate Error type.
Error Object | Status Code | Content Type |
---|---|---|
errors.HTTPValidationError | 422 | application/json |
errors.SDKError | 4xx-5xx | / |
Example
import { InkeepAI } from "@inkeep/ai-api";
import * as errors from "@inkeep/ai-api/models/errors";
async function run() {
const sdk = new InkeepAI({
apiKey: "<YOUR_BEARER_TOKEN_HERE>",
});
let result;
try {
result = await sdk.chatSession.create({
integrationId: "string",
chatSession: {
messages: [,],
},
});
} catch (err) {
switch (true) {
case err instanceof errors.HTTPValidationError: {
console.error(err); // handle exception
return;
}
default: {
throw err;
}
}
}
if (res.chatResult == null) {
throw new Error("failed to create stream: received null value");
}
for await (const event of res.chatResult) {
// Handle the event
}
}
run();
You can override the default server globally by passing a server index to the serverIdx
optional parameter when initializing the SDK client instance. The selected server will then be used as the default on the operations that use it. This table lists the indexes associated with the available servers:
# | Server | Variables |
---|---|---|
0 | https://api.inkeep.com | None |
import { InkeepAI } from "@inkeep/ai-api";
async function run() {
const sdk = new InkeepAI({
serverIdx: 0,
apiKey: "<YOUR_BEARER_TOKEN_HERE>",
});
const result = await sdk.chatSession.create({
integrationId: "string",
chatSession: {
messages: [,],
},
});
if (res.chatResult == null) {
throw new Error("failed to create stream: received null value");
}
for await (const event of res.chatResult) {
// Handle the event
}
}
run();
The default server can also be overridden globally by passing a URL to the serverURL
optional parameter when initializing the SDK client instance. For example:
import { InkeepAI } from "@inkeep/ai-api";
async function run() {
const sdk = new InkeepAI({
serverURL: "https://api.inkeep.com",
apiKey: "<YOUR_BEARER_TOKEN_HERE>",
});
const result = await sdk.chatSession.create({
integrationId: "string",
chatSession: {
messages: [,],
},
});
if (res.chatResult == null) {
throw new Error("failed to create stream: received null value");
}
for await (const event of res.chatResult) {
// Handle the event
}
}
run();
The TypeScript SDK makes API calls using an HTTPClient
that wraps the native
Fetch API. This
client is a thin wrapper around fetch
and provides the ability to attach hooks
around the request lifecycle that can be used to modify the request or handle
errors and response.
The HTTPClient
constructor takes an optional fetcher
argument that can be
used to integrate a third-party HTTP client or when writing tests to mock out
the HTTP client and feed in fixtures.
The following example shows how to use the "beforeRequest"
hook to to add a
custom header and a timeout to requests and how to use the "requestError"
hook
to log errors:
import { InkeepAI } from "@inkeep/ai-api";
import { HTTPClient } from "@inkeep/ai-api/lib/http";
const httpClient = new HTTPClient({
// fetcher takes a function that has the same signature as native `fetch`.
fetcher: (request) => {
return fetch(request);
}
});
httpClient.addHook("beforeRequest", (request) => {
const nextRequest = new Request(request, {
signal: request.signal || AbortSignal.timeout(5000);
});
nextRequest.headers.set("x-custom-header", "custom value");
return nextRequest;
});
httpClient.addHook("requestError", (error, request) => {
console.group("Request Error");
console.log("Reason:", `${error}`);
console.log("Endpoint:", `${request.method} ${request.url}`);
console.groupEnd();
});
const sdk = new InkeepAI({ httpClient });
This SDK supports the following security scheme globally:
Name | Type | Scheme |
---|---|---|
apiKey | http | HTTP Bearer |
To authenticate with the API the apiKey
parameter must be set when initializing the SDK client instance. For example:
import { InkeepAI } from "@inkeep/ai-api";
async function run() {
const sdk = new InkeepAI({
apiKey: "<YOUR_BEARER_TOKEN_HERE>",
});
const result = await sdk.chatSession.create({
integrationId: "string",
chatSession: {
messages: [,],
},
});
if (res.chatResult == null) {
throw new Error("failed to create stream: received null value");
}
for await (const event of res.chatResult) {
// Handle the event
}
}
run();
This SDK is in beta, and there may be breaking changes between versions without a major version update. Therefore, we recommend pinning usage to a specific package version. This way, you can install the same version each time without breaking changes unless you are intentionally looking for the latest version.
While we value open-source contributions to this SDK, this library is generated programmatically. Feel free to open a PR or a Github issue as a proof of concept and we'll do our best to include it in a future release!
FAQs
Inkeep Chat API TS SDK <img src="https://custom-icon-badges.dem
The npm package @inkeep/ai-api receives a total of 3,383 weekly downloads. As such, @inkeep/ai-api popularity was classified as popular.
We found that @inkeep/ai-api demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.