
Security News
Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.
@offerkit/sdk
Advanced tools
Typed TypeScript client for the OfferKit API.
OfferKit is open-source promotion infrastructure for coupons, gift cards, loyalty, referrals, customer segments, and validation rules. The SDK is generated from the same oRPC contract used by the REST API, so request and response types stay in sync with your OfferKit deployment.
npm install @offerkit/sdk
pnpm add @offerkit/sdk
import { createClient } from "@offerkit/sdk";
const offerkit = createClient({
baseUrl: "https://your-offerkit-deployment",
apiKey: process.env.OFFERKIT_API_KEY,
});
const vouchers = await offerkit.vouchers.list({
limit: 20,
search: "SUMMER",
});
const validation = await offerkit.vouchers.validate({
params: { code: "SUMMER10" },
body: {
order: {
amount: 9999,
currency: "USD",
items: [],
},
},
});
const redemption = await offerkit.vouchers.redeem({
params: { code: "SUMMER10" },
body: {
order: {
amount: 9999,
currency: "USD",
items: [],
},
idempotencyKey: "order-42",
},
});
Path-bearing procedures use oRPC's detailed input shape:
params for path values, such as { code } or { id }body for request payloadsvouchers.list({ limit: 20 })import { verifyWebhook } from "@offerkit/sdk";
const valid = verifyWebhook(rawBody, request.headers.get("x-offerkit-signature")!, secret);
if (!valid) {
throw new Error("Invalid OfferKit webhook signature");
}
verifyWebhook checks the X-Offerkit-Signature header using HMAC-SHA256 and rejects stale signatures by default after 300 seconds.
Mint an API key in the OfferKit dashboard at /settings/api-keys, then pass it as apiKey or set OFFERKIT_API_KEY in your runtime environment.
FAQs
Typed client for the OfferKit promotions API.
We found that @offerkit/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.