QumoClient
The Qumo SDK client. Owns request execution and exposes one property per resource namespace. ExampleNamespaces
client.auth— Sessions, sign-in, two-factor auth, personal tokens and the account.client.tenants— Workspaces: listing, settings, usage and invoices.client.projects— Projects, their usage, budgets, alerts and connection limits.client.apiKeys— Project API keys, their usage and IP allowlists.client.audit— Audit log and the audit webhook.client.iam— IAM role bindings and built-in roles.client.invitations— Invitations to join a workspace.client.notifications— Notification policies.client.identities— Machine identities and their tokens.client.credentials— Relay credentials and the keys that verify them.client.pricing— Plans, SKUs and published pricing.client.ipAllowlists— IP allowlists for machine identities.client.paymentMethods— Saved payment methods.client.billing— Billing summary, checkout and the billing portal.
request
QumoClient.requestRaw.
requestRaw
Response,
without JSON parsing. Use this for non-JSON bodies — file downloads,
blobs, streams — where request would wrongly parse the bytes as
JSON. Shares the same auth/CSRF header injection and throws APIError
on a non-ok status, so error handling is identical.
QumoConfig
Options for constructing aQumoClient.
baseUrlstring— The control plane’s base URL, e.g.https://api.qumo-deploy.com. An empty string makes requests relative to the current origin (browser use).token?string— Bearer token sent asAuthorization: Bearer …. Takes precedence overapiKey.apiKey?string— API key sent asX-API-Key, used when notokenis set.csrfToken?() => string | null | undefined— Supplies the CSRF token for cookie-authenticated (browser session) calls. The server requiresX-CSRF-Tokenon every mutating request made with thequmo_sessioncookie; Bearer/API-key callers are exempt and can omit this. Called per request so a rotated token is picked up without rebuilding the context. Returning null/undefined sends no header.
APIError
Thrown for every non-2xx response.message is the server’s error field,
or the HTTP status text when the body has none.
status— The HTTP status code.message— The server’s error message.data— The parsed response body, or its raw text when it is not JSON.