# SDKs

Official clients are generated from the [OpenAPI specification](https://sigwise.ai/docs/guide/openapi.md),
so every endpoint and schema in the [API reference](https://sigwise.ai/docs/reference.md) is available,
typed, in each language.

| Language | Package | Requires |
|----------|---------|----------|
| Node.js / TypeScript | `@sigwise/sdk` | Node 18+, no dependencies |
| Python | `sigwise-sdk` | Python 3.8+, no dependencies |
| Go | `github.com/sigwise/sigwise-go` | Go 1.21+, standard library only |
| PHP | `sigwise/sdk` | PHP 8.1+ with `ext-curl` |

> **Coming soon**
>
> The SDKs are on their way to npm, PyPI, the Go module proxy and Packagist.
> Until then, call the API directly: see [Authentication](https://sigwise.ai/docs/guide/authentication.md)
> for how to sign requests.

## What every SDK does

- **Signs every request** with your key's secret: a fresh 60-second HS256
  token bound to the request's method and path. The secret is never sent.
- **Reads configuration from the environment:** `ANALYZE_API_KEY`,
  `ANALYZE_SECRET` and `ANALYZE_BASE_URL`.
- **Retries safely:** idempotent requests (`GET`, `PUT`, `DELETE`) are retried
  after network errors, `429` and `5xx`, with exponential backoff; `POST`
  requests never are.
- **Raises typed errors** with the HTTP status, the error `code` and message.
- **Verifies webhooks:** a helper checks `X-Webhook-Signature` and the
  timestamp and parses the payload.

## Same API, idiomatic in each language

Resources and methods follow the API: `objects.get`, `events.ingest`,
`signals.upsert`, `webhooks.create` and so on.

Node.js:

```ts
import { SigWise } from "@sigwise/sdk";

const sigwise = new SigWise({ apiKey: "your_key_id", secret: "your_secret" });
const object = await sigwise.objects.get("user-42");
const page = await sigwise.objects.list({ q: "is_scammer >= 90", sort: "flagged" });
```

Python:

```python
from sigwise import SigWise

sigwise = SigWise(api_key="your_key_id", secret="your_secret")
obj = sigwise.objects.get("user-42")
page = sigwise.objects.list(q="is_scammer >= 90", sort="flagged")
```

Go:

```go
client := sigwise.New("your_key_id", "your_secret")
obj, err := client.Objects.Get(ctx, "user-42")
page, err := client.Objects.List(ctx, &sigwise.ListObjectsParams{Q: sigwise.String("is_scammer >= 90")})
```

PHP:

```php
$sigwise = new SigWise\Client('your_key_id', 'your_secret');
$object = $sigwise->objects->get('user-42');
$page = $sigwise->objects->list(['q' => 'is_scammer >= 90', 'sort' => 'flagged']);
```

Each generated package has a README with installation, configuration, error
handling, webhook verification and a reference of every method.

## Other languages

Anything that can compute an HMAC-SHA256 can call the API. See
[Authentication](https://sigwise.ai/docs/guide/authentication.md) for signing examples, and point any
OpenAPI tool at the [specification](https://sigwise.ai/docs/guide/openapi.md).
