
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@offerkit/sdk
Advanced tools
Typed TypeScript client for the OfferKit API.
OfferKit is open-source promotion infrastructure for coupons, gift cards, loyalty, referrals, customer segments, and validation rules. The SDK is generated from the same oRPC contract used by the REST API, so request and response types stay in sync with your OfferKit deployment.
npm install @offerkit/sdk
pnpm add @offerkit/sdk
import { createClient } from "@offerkit/sdk";
const offerkit = createClient({
baseUrl: "https://your-offerkit-deployment",
apiKey: process.env.OFFERKIT_API_KEY,
});
const vouchers = await offerkit.vouchers.list({
limit: 20,
search: "SUMMER",
});
const validation = await offerkit.vouchers.validate({
params: { code: "SUMMER10" },
body: {
order: {
amount: 9999,
currency: "USD",
items: [],
},
},
});
const redemption = await offerkit.vouchers.redeem({
params: { code: "SUMMER10" },
body: {
order: {
amount: 9999,
currency: "USD",
items: [],
},
idempotencyKey: "order-42",
},
});
Path-bearing procedures use oRPC's detailed input shape:
params for path values, such as { code } or { id }body for request payloadsvouchers.list({ limit: 20 })import { verifyWebhook } from "@offerkit/sdk";
const valid = verifyWebhook(rawBody, request.headers.get("x-offerkit-signature")!, secret);
if (!valid) {
throw new Error("Invalid OfferKit webhook signature");
}
verifyWebhook checks the X-Offerkit-Signature header using HMAC-SHA256 and rejects stale signatures by default after 300 seconds.
Mint an API key in the OfferKit dashboard at /settings/api-keys, then pass it as apiKey or set OFFERKIT_API_KEY in your runtime environment.
FAQs
Typed client for the OfferKit promotions API.
The npm package @offerkit/sdk receives a total of 21 weekly downloads. As such, @offerkit/sdk popularity was classified as not popular.
We found that @offerkit/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.