ExperimentalOptional Readonly ExperimentaladditionalAdditional SSRF allow-list host suffixes. By default the SDK locks the default transport to host suffixes derived from the Partner authorize response. Pass an explicit list to add trusted hosts, for example a test proxy. An empty array adds no hosts and leaves the default guard enabled.
Only consulted when PartnerClientOptions.transport is unset; a custom transport is the user's responsibility to harden.
Optional Readonly ExperimentalallowAllow direct custom authorize realms for tests or private proxies. Leave disabled unless the configured host is trusted with the Master Application Key.
Optional Readonly ExperimentaldisableExplicitly disable the default SSRF guard after authorize.
This is intended only for controlled simulator/private-proxy tests. Never enable it for URLs derived from untrusted input or production credentials. Only consulted when PartnerClientOptions.transport is unset.
Optional Readonly ExperimentalfollowFollow same-origin GET/HEAD redirects in the default fetch transport after checking each target with the SSRF guard. POST redirects remain blocked. Defaults to true.
Readonly ExperimentalmasterThe Master Application Key secret.
Readonly ExperimentalmasterThe Master Application Key ID for the partner administrator account.
Optional Readonly ExperimentalpartnerStorage backend for Partner authorization state. Defaults to
InMemoryPartnerAccountInfo. Cached authorization whose endpoint
URLs fail the configured realm policy is ignored by this client until
authorize() replaces it; shared stores are not cleared during
construction.
Optional Readonly ExperimentalrealmB2 realm to authenticate against. Accepts a known realm-map key
("production" or "staging") or a direct base URL. Custom HTTPS hosts
are trusted with the Master Application Key during authorize, so never
derive realm from untrusted input. URL values must use HTTPS, or
loopback IP literal HTTP for local testing only; Master Application Key
credentials are sent unencrypted over loopback HTTP. Unsupported schemes,
malformed URLs, non-URL strings, plaintext HTTP hostnames such as
localhost, and non-loopback plaintext HTTP are rejected before
credentials are sent. URL values must not include userinfo, query strings,
or fragments. Defaults to "production".
Optional Readonly ExperimentalretryOverride retry behavior (max retries, backoff, and per-attempt timeout).
Optional Readonly ExperimentaltransportCustom HTTP transport. Defaults to FetchTransport. Wrapped by RetryTransport.
Optional Readonly ExperimentaluserCustom user-agent string prepended to the SDK default.
Configuration options for creating a PartnerClient.
Partner API surface; shape may change as the Partner API docs evolve.