Skip to content

SDKs

TypeScript SDK

Server-side session helpers, permit validation, and typed holds.

The TypeScript SDK adds durable identity and control requests to your existing model client. Use the session client for current integrations; standalone check helpers address retired endpoints.

Create a session client#

Create Integrity with the deployment platform key, explicit HTTPS base URL, and persisted session ID. Use it in server-side Node applications; keep credentials out of the browser.

Continuous helpers require SDK 0.6.1 or the compatible release supplied with your deployment. Start with the quickstart, which uses Node.js 22 or later with OpenAI TypeScript 7.15.0, fetchOptions: { redirect: "error" }, and maxRetries: 0.

Session methods#

MethodContract
headers(operationId)Return platform, session, and operation headers.
recover(operationId)Read the durable operation without repeating inference.
authorize(operationId, action)Request a permit for the exact supported action.
verifyPermit(permit, action, { authorizationVersion, governingDigest }?)Validate again at execution; pass the governing pins retained by your harness.
report(operationId, { authorization_operation_id, permit_id, action, outcome, evidence? })Report succeeded, failed, or unknown with the exact original action and permit.
receipt(operationId, originalEventJson)Retain original executor-signed event text.
finish(operationId, outcome)Close platform admission as completed, abandoned, or failed.

Control methods need persisted operation IDs. The provider client still selects the intended customer model and carries its provider credential.

Enforce permits in the harness#

verifyPermit returns an action snapshot after checking the echoed action and session, expiry, and any governing pins supplied by your harness. Treat the server action digest as opaque. Keep a durable ledger of consumed permits before execution; this local helper does not execute actions or establish their external effects.

For receipt, provide the executor's original signed JSON text. The SDK does not construct a signature or register an executor. The current connection requires an already installed exact-scope signer.

Errors and unsupported controls#

IntegrityHold forbids automatic retry. IntegrityUncertainOutcome means a transport failure prevented a known result; recover the original operation. raiseForIntegrityHold recognizes a hold body from an HTTP error or provider SSE error event.

Two codes are the exception and say so in the body with automatic_retry_authorized: true and retry_after_seconds: a 503 container_not_ready (the gateway container is still starting; wait, then re-send the same operation ID) and a review_capacity_exhausted hold (no verdict was formed; keep the held evaluation, wait, then evaluate again under a new operation ID). If your own deadline or call budget runs out while you are still reading an issued operation back, treat that as operation_observation_exhausted_no_retry: the outcome is unknown to you, not failed; read the operation back under a fresh budget and never resubmit it. Hold reasons such as placeholder_argument_value and citation_not_found_in_named_root are explained on the errors page.

The current Base connection does not support reviewCase, dynamic executor registration, or tool-schema changes within a session. A method existing in the SDK is not evidence that the connection implements it.

Continuous controls never retry automatically or follow redirects. The control timeout defaults to 360,000 milliseconds. Read configuration and the full control contract.