Requires
@cesto/sdk 0.4.2 or later.@cesto/sdk ships two entry points. The package root is the server client documented
everywhere else — it authenticates with a secret cesto_sk_… key and refuses to run in a
browser. The /client subpath is its read-only twin, built for the place a secret key can
never go:
What it can do
Products
list, get, analytics, getChart — identical params and responses to the server client.Fees
fees.get — the deposit breakdown for a basket, so you can price an investment before the user connects a wallet.products resource is the same class, so every option documented there applies.
fees.get always returns the anonymous breakdown: open populated, close and
rebalance null, user-specific balances zero. That’s a property of the endpoint, not of
the missing key — the server client sees exactly the same shape.
Geo works out of the box
Basket listings andgeoStatus.canInvest depend on where the reader is, and the API
derives that from the request IP.
Called from the browser, that IP is your visitor’s own — so the answer is right with
nothing to configure. This is the one thing the browser client does better than a
server-side proxy: a backend calling on a user’s behalf sends its own datacenter IP, and
has to forward the visitor’s location explicitly to get the same result.
What it deliberately cannot do
Opening, closing, and rebalancing are absent from this entry point — not omitted for later, but excluded by design. Those routes need a write-scopedcesto_sk_… key, and
shipping one to a browser hands every visitor the ability to move funds for any of your
users.
Writing from a browser wallet
The supported shape keeps the key on your server and the wallet in the browser:1
Prepare on your server
Your backend calls
cesto.open.prepare(…) with the secret key and returns the unsigned
transactions to the page.2
Sign in the browser
The user signs them with their wallet (Phantom, Solflare, …). The private key never
leaves the wallet.
3
Submit from your server
Your backend calls
cesto.positions.submit({ executionId, transactions }).Configuration
The transport half of the server client’s options, minus the key and the URL — the SDK always targets the production API:number
default:"60000"
Per-request timeout in milliseconds.
number
default:"2"
Max automatic retries on transient failures (408, 429, 5xx, network errors, timeouts).
typeof fetch
Custom fetch implementation. Defaults to the global
fetch.baseURL option — every request goes to the production API. For local
development against a local API, set the CESTO_BASE_URL environment variable instead.
Errors
The same typed hierarchy as the server client, hung offCestoClient for instanceof
checks:
Rate limits
Anonymous reads are limited per IP — your visitor’s, not your server’s — so one user’s browsing cannot exhaust another’s budget. The limits are generous enough for normal browsing (hundreds of requests per minute); a429 arrives as a RateLimitError carrying
retryAfter.