Client & server SDK · Web & Node.js

JavaScript / TypeScript SDK

Modern browsers; Node.js 22+ for server code and package builds. ESM, CommonJS and TypeScript declarations are included.

Install from GitHub

The SDK source is public on the main branch. These instructions use Git or a locally built package; package registry releases are a separate step.

Installation
git clone --branch main https://github.com/pubbio/sdk-js.git
cd sdk-js
npm ci
npm pack
# In your application, install the generated tarball:
npm install /absolute/path/to/sdk-js/pubb-sdk-0.2.0.tgz

Use your application's package manager to install the tarball. @pubb/sdk/server is an import from the same package, not a second dependency.

Subscribe to events

Use your public app key from the Pubb dashboard. Subscribe before publishing a matching event from your trusted backend.

client.ts
import { Pubb } from "@pubb/sdk";

const pubb = new Pubb("YOUR_PUBLIC_APP_KEY");
pubb.subscribe("notifications")
  .bind("message.sent", data => console.log(data))
  .bind("pubb:subscription_error", error => console.error(error));
pubb.connect();

// On component cleanup or application teardown:
// pubb.disconnect();

Create the client in your application's lifecycle, such as a React effect, and disconnect in its cleanup. Reconnects resubscribe automatically; refresh durable state from your backend after an interruption.

Publish from your server

Set PUBB_APP_ID, PUBB_APP_KEY and PUBB_APP_SECRET in your server environment. Keep this module in trusted backend code.

server.ts
import { PubbServer } from "@pubb/sdk/server";

const pubb = new PubbServer({
  appId: process.env.PUBB_APP_ID!,
  key: process.env.PUBB_APP_KEY!,
  secret: process.env.PUBB_APP_SECRET!,
});
const result = await pubb.trigger("notifications", "message.sent", {
  message: "Hello from Pubb!",
});
console.log(result.publicationId);

HTTP 202 confirms acceptance for processing, not delivery. The response includes publicationId and duplicate. SDKs do not automatically retry publications; reuse an idempotency key when retrying the same event. The API accepts 1–100 channels and up to 10 KiB of UTF-8 JSON data.

Private and presence channels

Set authEndpoint to your own authenticated backend route for private or presence channels. After checking channel access, your server can return authenticatePrivateChannel(socketId, channelName) or authenticatePresenceChannel(socketId, channelName, verifiedUserId, userInfo) as JSON.

Your backend receives socket_id and channel_name, checks the authenticated user’s access, and returns auth plus channel_data for presence. Derive the presence user ID from the session and forward the signed channel_data unchanged.

Keep the app secret on your trusted server. Public channels must not carry personal or restricted data. Read the channel access reference for the protocol.

Verify your integration

  1. Subscribe to notifications in your app or the dashboard’s Live console.
  2. Publish message.sent to the same application and channel from your backend.
  3. Check the event payload, connection cleanup and recovery after a disconnect. Test denied access as well as successful private subscriptions.

The repositories include automated tests and examples. Verify end-to-end delivery with your own application before sending production traffic. Refetch durable state after reconnecting; missed events are not replayed.

Legacy pusher:* and pusher_internal:* control names are retained where required by the protocol. Their presence alone does not imply drop-in compatibility with every Pusher client or server.