Skip to main content
The AvraAPI Node.js SDK is the recommended integration path for Node.js and TypeScript backends. It authenticates each request with your Project Client ID, Client Secret, and selected environment, then returns JSON as an ApiResponse or generated media as a BinaryResponse.
This SDK is for trusted server-side code only. Never put a Project Client Secret in browser JavaScript, a mobile app, a public repository, a frontend environment variable, or a client-facing response.

Requirements

The current published Node.js SDK release is 1.2.0. It includes Currency, Security, Location, SMS, Utilities, and the server-only Universal Payment Gateway lifecycle.

Install the SDK

Install the package in your backend application:
Use an ESM import in an ESM project:
ESM import
The package also supports CommonJS. Use require() from a .cjs file or a project configured for CommonJS:
CommonJS import
Both forms load the same public package contract. TypeScript declarations are included with the package.

Configure project credentials

Create an AvraAPI project, enable the services your backend needs, then store its credentials in the server environment. The SDK reads these names:
Server environment configuration
APIX_PROJECT_KEY is the Project Client ID. APIX_API_SECRET is its matching Client Secret and must remain private. The SDK reads process.env; it does not load a .env file itself. Use your framework, deployment platform, or an environment loader to populate process.env before creating the client.

Optional configuration

Keep the default base URL for production. Explicit values passed to ApixClient override environment values.

Create and reuse the client

Create one client after application configuration is available, then reuse it through your server’s dependency container, module singleton, or service layer. Its service accessors are lazy: a service is created only when your application first uses it.
Environment-based setup
For an application that resolves configuration itself, pass the values explicitly:
Explicit trusted-backend setup
The Client ID and Client Secret are required. If either cannot be resolved, the constructor throws before an API request is sent. The SDK also rejects a browser-like runtime before it can use the Client Secret.

Use Privacy Mode for one provider request

All provider services support withPrivacyMode(). Call it immediately before the one provider operation that needs the AvraAPI privacy guarantee:
Enable Privacy Mode for the next request
The SDK clears Privacy Mode after that request. It preserves normal routing, billing, and usage tracking while applying the platform privacy guarantee to request and response payload storage; it does not make a request anonymous. Use it for provider-service calls only: client.call() does not expose this fluent control.
lookupIp({ ip, privacyMode: true }) and the Utility methods’ privacyMode: true inputs remain supported. They send the same X-Privacy-Mode: 1 header. Prefer withPrivacyMode() when a consistent next-request style is clearer.

Read a JSON response

Most provider operations return a Promise for an ApiResponse. The operation result is in data; requestId is the safest value to retain in server logs or support records when tracing a request.
Read a typed JSON result
Do not return raw provider data or internal metadata directly to a browser.

Handle generated files and images

Utilities return a BinaryResponse for PNG, SVG, and binary PDF output. It contains a Node.js Buffer, content type, size, HTTP status, and nullable request ID. QR and PDF operations configured for Base64 return ApiResponse instead; barcode output is always binary media.
Save a generated QR image
Use getBuffer() when streaming media from your server, toDataUri() only for an approved server-rendered use, and isPdf(), isPng(), or isSvg() before choosing a media-specific workflow.

Handle errors safely

Non-success AvraAPI responses reject with typed errors. Catch a specific error only where your application has a clear recovery path, then handle ApixError as the common API fallback.
Safe async error handling
Never send a Client Secret, raw exception payload, provider diagnostic, or payment completion context to a browser response.

Universal Payment Gateway

The Node.js SDK includes the released server-only UPG surface through avraapi.payment(). It provides typed availability, checkout creation, callback verification, authoritative completion, reconciliation, gateway services, and Payment Elements helpers. Your application still owns pending orders, idempotency, callback routes, fulfilment, and final business decisions.

Universal Payment Gateway documentation

Follow the canonical checkout lifecycle, Payment Elements, completion, and gateway-specific guides. Never use the Client Secret or a completion context in browser code.

Next steps

REST API Reference

Review provider request and response contracts.

Universal Payment Gateway

Build a server-authoritative payment integration.
Last modified on October 1, 2026