Skip to main content
Requirements: Node.js 20 or newer. The package is ESM only (import); from CommonJS use await import("@versoai/core"). Source: github.com/vrsoai/verso-fetch. Creates a signed, single-use link to the hosted connect or manage page.
Returns { url, token }. url is https://connect.tryverso.ai/start?token=… for connect and …/manage?token=… for manage. Throws when purpose is not connect or manage, or when expiresInSeconds is zero, negative or above 900.

verifyWebhook(secret, signatureHeader, body, toleranceSec?)

Checks the X-Verso-Signature header of a delivery. Synchronous, returns a boolean, never throws.
Pass the raw body, not a re-serialized object: the signature covers the bytes Verso sent. With Express, mount express.raw({ type: "application/json" }) on the webhook route.

Types

WebhookEvent narrows on event, so event.payload is typed inside a switch. Field-by-field descriptions are in the webhooks guide.

Versions

0.2.0 reduces the package to the surface above. The internal helpers that 0.1.0 exported (createSupabaseClient, PgcryptoVaultProvider, markActive and the other connection helpers, enqueueWebhook, renderShell, the database record types) were never meant for partners and are gone, along with the @versoai/core/* subpath exports. If you imported any of them, you were running Verso’s server code: talk to us.