@mrzr/api-client

Client Options

Every createClient and per-request option in @mrzr/api-client with its default: baseUrl, timeout, auth mode, token storage, CSRF and cancellation.

All options are optional.

Client options

createClient(options)

Connection

OptionDefaultDescription
baseUrlenv var, else page originPrefix for relative URLs. See environment variables
timeout30000Timeout per attempt, in ms. 0 disables it
headers{}Added to every request
credentials"same-origin", or "include" in cookie modePassed to fetch
authOrigins[]Other origins allowed to receive the token and CSRF header
plugins[]See Plugins

Errors and logging

OptionDefaultDescription
throwErrortrueThrow ApiError on failure. false returns { status: false } instead
onError–(res) => void, called for every failed request
onLogconsole.infoReceives a log entry for requests sent with log: true

Auth

OptionDefaultDescription
authMode"header""header" (bearer token) or "cookie" (httpOnly cookies)
storage"memory""memory", "session", "local", "cookie" or your own adapter
storageKey"apiclient"Prefix for storage keys and the tab channel
loginUrl"/auth/login"Used by api.login()
refreshUrl"/auth/refresh"Used for token refresh
logoutUrl"/auth/logout"Used by api.logout()
refreshSkewMs30000Refresh this long before the token expires. 0 disables it
extractTokensbuilt-inWhere tokens are in the response. See custom token shapes
buildRefreshBody{ refresh }Body of the refresh request
exposeTokensfalseAllow api.getAccessToken(). See WebSockets
onAuthStateChanged–(state) => void on every auth change
onAuthFailure–Session ended: refresh rejected or logged out
OptionDefaultDescription
xsrfCookieName–Cookie to read the CSRF token from
xsrfHeaderName"X-CSRF-Token"Header to send it in
getCsrfToken–() => string | Promise<string>. Takes precedence over the cookie

Runtime

OptionDefaultDescription
workertrueRun requests in a Web Worker
multiTabtrueSync auth between tabs
cancelfalsetrue, or { methods, takeLatest, throwOnCancel }. See Cancellation

Per-request options

The last argument of get, post, put, patch and delete. These override the client options for one call.

OptionDescription
paramsQuery-string parameters. Nested objects and arrays are supported
addTemplateToUrlFill {placeholders}: "/users/{id}" + { id: 7 }
addToUrlAppend path segments
headersExtra headers
timeoutTimeout for this call
baseUrlDifferent base URL for this call
responseType"auto" (default), "json", "text", "blob" or "arrayBuffer"
throwErrorOverride the client setting
skipAuthDon't send the token
refreshTokenCheckfalse skips 401 → refresh → retry
uploadSkewMsRefresh first if the token expires within this many ms
fullDataKeep the whole body in data, don't unwrap { data }
stringifyBodyfalse sends a plain-object body as-is
beforeFuncTransform the body before sending
afterFuncTransform the payload on success
hideErrorMessageDon't call onError for this request
logLog this request through onLog
cancelableOpt this request in or out of cancellation
cancelKeyName to cancel this request by
cancelGroupTags to cancel several requests together
takeLatestCancel the previous request with the same key
throwOnCancelThrow instead of resolving when canceled

Native fetch options such as signal, cache, mode and keepalive pass straight through.

On this page