CarpoSDK docs

Initialize the React client

Create a shared Carpo client and mount its provider.

Create the client once for the project and environment it represents. Pass a storageBucketId only when the app needs the combined Storage client.

'use client'

import { useState } from 'react'
import { QueryClient, QueryClientProvider } from '@tanstack/react-query'
import { CarpoProvider, createCarpoClient } from '@carpodev/carpo-sdk'

export function AppProviders({ children }: { children: React.ReactNode }) {
  const [queryClient] = useState(() => new QueryClient())
  const [carpo] = useState(() => createCarpoClient({
    apiUrl: 'https://api.carpo.dev',
    projectId: 'your-project-id',
    databaseId: 'your-database-id',
    storageBucketId: 'your-bucket-id',
    environment: 'production',
  }))

  return (
    <QueryClientProvider client={queryClient}>
      <CarpoProvider client={carpo}>{children}</CarpoProvider>
    </QueryClientProvider>
  )
}

CarpoProvider must be inside the TanStack QueryClientProvider. createCarpoClient returns auth, database, and functions; it adds storage when storageBucketId is configured.

Configuration

OptionRequiredDescription
apiUrlYesAbsolute Carpo API origin without an /api suffix or path
projectIdYesCarpo project ID
databaseIdYesManaged database ID used by the Database Data API and Realtime
environmentNoproduction or development, default production
storageBucketIdNoEnables client.storage and Storage hooks
getAccessTokenNoGetter for a Project Auth JWT or user scoped API key
getAccessTokenCacheKeyNoStable, non secret user identity for bearer query cache isolation
fetchNoCustom fetch implementation for Carpo API requests
uploadFetchNoCustom fetch implementation for signed Storage transfers

The client uses cookie credentials by default. Use bearer authentication only when your app intentionally uses Project Auth tokens instead of the session cookie.

What the provider manages

The provider subscribes to Better Auth's session hook and gates Database queries while the initial session loads. It scopes Database and Storage query keys by the current user. On a user change, it cancels and removes that user's cached service data. Storage queries wait for the initial session lookup, then the API evaluates the bucket policy, including any public policy.

The provider also updates the Realtime identity when session credentials change, which closes the old connection and requests a new short lived ticket.

On this page