Request scoped client
Forward an incoming user's identity while keeping service policies in effect.
Use createCarpoServerRequestClient() when server work should run with the incoming user's identity. It creates an Auth client and optional policy checked Database, Storage, and Functions clients for one Fetch API Request.
import { createCarpoServerRequestClient } from '@carpodev/carpo-sdk/server/request'
export async function loadTodos(request: Request) {
const carpo = createCarpoServerRequestClient({
request,
apiUrl: process.env.CARPO_API_URL!,
projectId: process.env.CARPO_PROJECT_ID!,
environment: 'production',
databaseId: process.env.CARPO_DATABASE_ID!,
storageBucketId: process.env.CARPO_STORAGE_BUCKET_ID,
})
try {
const { data: session, error } = await carpo.auth.getSession()
if (error || !session) return []
const result = await carpo.database.from<Todo>('todos').select({
where: { completed: false },
orderBy: 'id',
})
return result.rows
} finally {
await carpo.close()
}
}The client forwards only cookie, authorization, x-api-key, and origin headers, and only to the configured Carpo API origin. It uses the incoming identity by default for Auth and Function calls. Its Database and Storage clients use the same policy checked APIs as browser clients. They do not connect to Turso with a privileged token.
Set databaseId to expose carpo.database and storageBucketId to expose carpo.storage. Both are optional. The request scoped Database client supports the same table methods as the React client, but it does not provide privileged SQL.
Use this client for user initiated server rendering, route handlers, and server jobs that must preserve a verified user identity. Do not place request scoped clients in a module level singleton. Create one from the incoming request so another user's headers cannot be reused.