03·Hands-on·12 min
The dontcode SDK
The SDK is one package with no runtime dependencies. It runs anywhere fetch does: Node 18 and up, edge runtimes, and the browser (though the key itself stays on the server).
Install
pnpm add dontcode
Configure
When you create a key, the reveal panel gives you two environment variables. Add them to your server environment:
DONTCODE_API_URL=https://backend.dontcode.co
DONTCODE_API_KEY=dc_...
The client reads both by default, so it takes no arguments:
import { dontcode } from 'dontcode'
const client = dontcode()
First call
Every method maps to one gateway route. A count is a good first call because it needs no data to exist:
const total = await client.db.profiles.count()
If the table does not exist yet, the response is an error, and that still proves the key works: an unauthenticated request never gets that far. Without a key, the gateway answers 401 Missing API key.
Errors and timeouts
Non-2xx responses throw a DontCodeError with status, a stable code, and the full body. Every request has a timeout (10 seconds by default; set timeoutMs to change it), so a slow gateway fails fast instead of hanging your server.
Rate limits are per project and per namespace. Read RateLimit-Remaining and RateLimit-Scope on responses to pace yourself; a 429 carries Retry-After.
Where DontCode fits
The Keys page shows when each key was last used, which is how this lesson's check knows your call arrived. The same page is where you revoke a key the moment it leaks.
Check your understanding
1.You call dontcode() with no environment variables set. What happens on the first request?
2.How long does an SDK request wait before giving up, by default?
Your task
Backend ProjectInstall the SDK, set DONTCODE_API_URL and DONTCODE_API_KEY on your server, and make any call with the client. The check passes once the gateway records your key as used.