> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# QumoClient

> Constructing the client, its configuration, and the error every failed call throws.

## QumoClient

The Qumo SDK client. Owns request execution and exposes one property per
resource namespace.

**Example**

```ts theme={null}
const client = new QumoClient({
  baseUrl: "https://api.qumo.example.com",
  token: "your-admin-token",
});
const list = await client.projects.list();
```

```ts theme={null}
new QumoClient(config: QumoConfig)
```

### Namespaces

* [`client.auth`](/sdk/reference/auth) — Sessions, sign-in, two-factor auth, personal tokens and the account.
* [`client.tenants`](/sdk/reference/tenants) — Workspaces: listing, settings, usage and invoices.
* [`client.projects`](/sdk/reference/projects) — Projects, their usage, budgets, alerts and connection limits.
* [`client.apiKeys`](/sdk/reference/api-keys) — Project API keys, their usage and IP allowlists.
* [`client.audit`](/sdk/reference/audit) — Audit log and the audit webhook.
* [`client.iam`](/sdk/reference/iam) — IAM role bindings and built-in roles.
* [`client.invitations`](/sdk/reference/invitations) — Invitations to join a workspace.
* [`client.notifications`](/sdk/reference/notifications) — Notification policies.
* [`client.identities`](/sdk/reference/identities) — Machine identities and their tokens.
* [`client.credentials`](/sdk/reference/credentials) — Relay credentials and the keys that verify them.
* [`client.pricing`](/sdk/reference/pricing) — Plans, SKUs and published pricing.
* [`client.ipAllowlists`](/sdk/reference/ip-allowlists) — IP allowlists for machine identities.
* [`client.paymentMethods`](/sdk/reference/payment-methods) — Saved payment methods.
* [`client.billing`](/sdk/reference/billing) — Billing summary, checkout and the billing portal.

### request

```ts theme={null}
request<T>(path: string, options?: RequestInit): Promise<T>
```

Executes an authenticated request against the configured base URL and
parses the response body as JSON.

Use the resource namespaces for typed coverage; fall back to this method
for endpoints the SDK does not yet wrap. For non-JSON responses (file
downloads, blobs, streams), use [`QumoClient.requestRaw`](/sdk/reference/client#requestraw).

### requestRaw

```ts theme={null}
requestRaw(path: string, options?: RequestInit): Promise<Response>
```

Executes an authenticated request and returns the raw `Response`,
without JSON parsing. Use this for non-JSON bodies — file downloads,
blobs, streams — where `request` would wrongly parse the bytes as
JSON. Shares the same auth/CSRF header injection and throws [`APIError`](/sdk/reference/client#apierror)
on a non-ok status, so error handling is identical.

## QumoConfig

Options for constructing a [`QumoClient`](/sdk/reference/client#qumoclient).

* **`baseUrl`** `string` — The control plane's base URL, e.g. `https://api.qumo-deploy.com`. An empty string makes requests relative to the current origin (browser use).
* **`token?`** `string` — Bearer token sent as `Authorization: Bearer …`. Takes precedence over `apiKey`.
* **`apiKey?`** `string` — API key sent as `X-API-Key`, used when no `token` is set.
* **`csrfToken?`** `() => string | null | undefined` — Supplies the CSRF token for cookie-authenticated (browser session) calls. The server requires `X-CSRF-Token` on every mutating request made with the `qumo_session` cookie; Bearer/API-key callers are exempt and can omit this. Called per request so a rotated token is picked up without rebuilding the context. Returning null/undefined sends no header.

## APIError

Thrown for every non-2xx response. `message` is the server's `error` field,
or the HTTP status text when the body has none.

```ts theme={null}
new APIError(status: number, message: string, data?: unknown)
```

Created by the client for a failed response; you rarely construct one.

* **`status`** — The HTTP status code.
* **`message`** — The server's error message.
* **`data`** — The parsed response body, or its raw text when it is not JSON.
