
Security News
Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
@tuya/tuya-connector-nodejs
Advanced tools
tuya-connector
?Tuya Open Platform—API User Guide
Tuya provides a set of HTTP APIs and signature verification logic. You need to implement the logic during when you integrate the APIs.
tuya-connector
provides capabilities to sign a request, refresh, store, and renew a token, and encapsulate common APIs. You can quickly connect to Tuya open platform.
npm install @tuya/tuya-connector-nodejs
# or
yarn add @tuya/tuya-connector-nodejs
import { TuyaContext } from '@tuya/tuya-connector-nodejs';
const tuya = new TuyaContext({
baseUrl: 'https://openapi.tuyacn.com',
accessKey: 'xx',
secretKey: 'xx',
});
const device = await tuya.device.detail({
device_id: 'device_id'
});
tokenStore
By default, tokenStore
is implemented based on memory. We recommend that you implement the store instance in your service. In the following code block, the Redis Store is used as an example.
// tokenStore.ts
import { TuyaTokenStorInterface, TuyaTokensSave } from '@tuya/tuya-connector-nodejs';
import IORedis from 'ioredis';
export class RedisTokenStore implements TuyaTokenStorInterface {
private readonly client: IORedis.Redis;
private readonly key: string;
constructor(client: IORedis.Redis, key: string = 'tuya::token') {
this.client = client;
this.key = key;
}
async setTokens(tokens: TuyaTokensSave): Promise<boolean> {
const res = await this.client.set(this.key, JSON.stringify(tokens));
return ! ! res;
}
async getAccessToken(): Promise<string | undefined> {
const jsonStr = await this.client.get(this.key) || '{}';
const tokens: TuyaTokensSave = JSON.parse(jsonStr);
return tokens && tokens.access_token;
}
async getRefreshToken(): Promise<string | undefined> {
const jsonStr = await this.client.get(this.key) || '{}';
const tokens: TuyaTokensSave = JSON.parse(jsonStr);
return tokens.refresh_token;
}
}
// index.ts
import { RedisTokenStore } from './tokenStore';
import IoRedis from 'ioredis';
const redis = new IoRedis();
const tuya = new TuyaContext({
baseUrl: 'https://openapi.tuyacn.com',
accessKey: 'xx',
secretKey: 'xx',
store: new RedisTokenStore(redis),
});
httpClient
tuya-connector
uses Axios as httpClient
by default, and exposes replaceable parameters. If necessary, you can also customize httpClient
.
import axios from 'axios';
import { TuyaContext } from '@tuya/tuya-connector-nodejs';
const tuya = new TuyaContext({
baseUrl: 'https://openapi.tuyacn.com',
accessKey: 'xx',
secretKey: 'xx',
rpc: axios
});
tuya-connector
encapsulates common APIs, and declares the types of reqeust and response parameters. You can customize additional API requests.
import { TuyaContext } from '@tuya/tuya-connector-nodejs';
const tuya = new TuyaContext({
baseUrl: 'https://openapi.tuyacn.com',
accessKey: 'xx',
secretKey: 'xx',
});
const { data } = await tuya.request({
method: 'GET',
path: '/v1.0/xx',
body: {},
});
Apply for authorization key. On the Cloud Development Platform, you can create a project to get the access ID and access secret of the cloud application.
Global error codes. For more information, see Global Error Codes.
FAQs
tuya openapi nodejs sdk
The npm package @tuya/tuya-connector-nodejs receives a total of 1,476 weekly downloads. As such, @tuya/tuya-connector-nodejs popularity was classified as popular.
We found that @tuya/tuya-connector-nodejs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.