Client Options
Every createClient and per-request option in @mrzr/api-client with its default: baseUrl, timeout, auth mode, token storage, CSRF and cancellation.
All options are optional.
Client options
createClient(options)
Connection
| Option | Default | Description |
|---|---|---|
baseUrl | env var, else page origin | Prefix for relative URLs. See environment variables |
timeout | 30000 | Timeout per attempt, in ms. 0 disables it |
headers | {} | Added to every request |
credentials | "same-origin", or "include" in cookie mode | Passed to fetch |
authOrigins | [] | Other origins allowed to receive the token and CSRF header |
plugins | [] | See Plugins |
Errors and logging
| Option | Default | Description |
|---|---|---|
throwError | true | Throw ApiError on failure. false returns { status: false } instead |
onError | – | (res) => void, called for every failed request |
onLog | console.info | Receives a log entry for requests sent with log: true |
Auth
| Option | Default | Description |
|---|---|---|
authMode | "header" | "header" (bearer token) or "cookie" (httpOnly cookies) |
storage | "memory" | "memory", "session", "local", "cookie" or your own adapter |
storageKey | "apiclient" | Prefix for storage keys and the tab channel |
loginUrl | "/auth/login" | Used by api.login() |
refreshUrl | "/auth/refresh" | Used for token refresh |
logoutUrl | "/auth/logout" | Used by api.logout() |
refreshSkewMs | 30000 | Refresh this long before the token expires. 0 disables it |
extractTokens | built-in | Where tokens are in the response. See custom token shapes |
buildRefreshBody | { refresh } | Body of the refresh request |
exposeTokens | false | Allow api.getAccessToken(). See WebSockets |
onAuthStateChanged | – | (state) => void on every auth change |
onAuthFailure | – | Session ended: refresh rejected or logged out |
CSRF (cookie mode)
| Option | Default | Description |
|---|---|---|
xsrfCookieName | – | Cookie to read the CSRF token from |
xsrfHeaderName | "X-CSRF-Token" | Header to send it in |
getCsrfToken | – | () => string | Promise<string>. Takes precedence over the cookie |
Runtime
| Option | Default | Description |
|---|---|---|
worker | true | Run requests in a Web Worker |
multiTab | true | Sync auth between tabs |
cancel | false | true, or { methods, takeLatest, throwOnCancel }. See Cancellation |
Per-request options
The last argument of get, post, put, patch and delete. These override the client options for one call.
| Option | Description |
|---|---|
params | Query-string parameters. Nested objects and arrays are supported |
addTemplateToUrl | Fill {placeholders}: "/users/{id}" + { id: 7 } |
addToUrl | Append path segments |
headers | Extra headers |
timeout | Timeout for this call |
baseUrl | Different base URL for this call |
responseType | "auto" (default), "json", "text", "blob" or "arrayBuffer" |
throwError | Override the client setting |
skipAuth | Don't send the token |
refreshTokenCheck | false skips 401 → refresh → retry |
uploadSkewMs | Refresh first if the token expires within this many ms |
fullData | Keep the whole body in data, don't unwrap { data } |
stringifyBody | false sends a plain-object body as-is |
beforeFunc | Transform the body before sending |
afterFunc | Transform the payload on success |
hideErrorMessage | Don't call onError for this request |
log | Log this request through onLog |
cancelable | Opt this request in or out of cancellation |
cancelKey | Name to cancel this request by |
cancelGroup | Tags to cancel several requests together |
takeLatest | Cancel the previous request with the same key |
throwOnCancel | Throw instead of resolving when canceled |
Native fetch options such as signal, cache, mode and keepalive pass straight through.
Frameworks
Use @mrzr/api-client with TanStack Query, SWR, React, Next.js App Router and Vue. Short, copy-paste setups for each, including server rendering.
API Reference
Every method of the @mrzr/api-client ApiClient and every package export, with signatures: requests, auth, cancellation, ApiError and helper functions.