{"_id":"@builtbyecho/reverbin","_rev":"5-2b2173a51fe40d19ef9978a6bebb1670","name":"@builtbyecho/reverbin","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.0":{"name":"@builtbyecho/reverbin","version":"0.1.0","keywords":["agents","email","inbox","reverbin","sdk","typescript","webhooks"],"license":"MIT","_id":"@builtbyecho/reverbin@0.1.0","maintainers":[{"name":"builtbyecho","email":"builtbyecho@agentmail.to"}],"homepage":"https://reverbin.com","bugs":{"url":"https://github.com/Wdustin1/reverbin/issues"},"dist":{"shasum":"8cc4167568f1e9541273e13804b2f7a1208ae991","tarball":"https://registry.npmjs.org/@builtbyecho/reverbin/-/reverbin-0.1.0.tgz","fileCount":7,"integrity":"sha512-vQMs0Pvd0xW9WTuKOrOsLPp5WfNuLogGwn0b1Zf/KnnKXy6D7IIQZtwar+n+34dRYfeG1s95AlCmyblrRREVUw==","signatures":[{"sig":"MEYCIQDz+XwOEOExzw1djECye0VEOYTXvId/IszXzlErxk+9GAIhANU74SdV7Umj1lAUVV0EYnRtFT14hyeeIpgLvPEdScP/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@builtbyecho%2freverbin@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":40189},"main":"./dist/client.js","type":"module","types":"./dist/client.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./webhook-signatures":{"types":"./dist/webhook-signatures.d.ts","import":"./dist/webhook-signatures.js"}},"gitHead":"1f5dcdd3805352fad11bb5bbb97305319bf94b80","_npmUser":{"name":"builtbyecho","email":"builtbyecho@agentmail.to"},"repository":{"url":"git+https://github.com/Wdustin1/reverbin.git","type":"git"},"_npmVersion":"11.6.2","description":"Node.js ESM SDK for Reverbin agent inboxes, threads, messages, approvals, webhooks, credentials, billing, and account lifecycle APIs.","directories":{},"sideEffects":false,"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reverbin_0.1.0_1783738754417_0.3103226287414067","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@builtbyecho/reverbin","version":"0.1.1","keywords":["agents","email","inbox","reverbin","sdk","typescript","webhooks"],"license":"MIT","_id":"@builtbyecho/reverbin@0.1.1","maintainers":[{"name":"builtbyecho","email":"builtbyecho@agentmail.to"}],"homepage":"https://reverbin.com","bugs":{"url":"https://github.com/Wdustin1/reverbin/issues"},"dist":{"shasum":"03b4366797495edc9dcdccd0c77760199198ea68","tarball":"https://registry.npmjs.org/@builtbyecho/reverbin/-/reverbin-0.1.1.tgz","fileCount":7,"integrity":"sha512-sd/1hWhHPggX6D9jyMbVbcJ97f6zEEFpI1JzwF2EUuIFYtLejJD312hG8PACvGybawX5yBJFQXGqAps4K1it1A==","signatures":[{"sig":"MEUCIQDUlYhbTshh/MZRhjjYpmOtkNUsDJQw5NddNu64ziF1AQIgWgv2TMB6VkYiLy3CSAusgiW0fUsICXepmceDh21AnmY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@builtbyecho%2freverbin@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":40721},"main":"./dist/client.js","type":"module","types":"./dist/client.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./webhook-signatures":{"types":"./dist/webhook-signatures.d.ts","import":"./dist/webhook-signatures.js"}},"gitHead":"7058f4fc4a6819e2d614a3537824f9a0ffb477cc","_npmUser":{"name":"builtbyecho","email":"builtbyecho@agentmail.to"},"repository":{"url":"git+https://github.com/Wdustin1/reverbin.git","type":"git"},"_npmVersion":"11.6.2","description":"Node.js ESM SDK for Reverbin agent inboxes, threads, messages, approvals, webhooks, credentials, billing, and account lifecycle APIs.","directories":{},"sideEffects":false,"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reverbin_0.1.1_1783744377998_0.899484232984904","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@builtbyecho/reverbin","version":"0.1.2","keywords":["agents","email","inbox","reverbin","sdk","typescript","webhooks"],"license":"MIT","_id":"@builtbyecho/reverbin@0.1.2","maintainers":[{"name":"builtbyecho","email":"builtbyecho@agentmail.to"}],"homepage":"https://reverbin.com","bugs":{"url":"https://github.com/Wdustin1/reverbin/issues"},"dist":{"shasum":"e85f4bc6be40e440da2eda611ab3c94d7b7dc8e3","tarball":"https://registry.npmjs.org/@builtbyecho/reverbin/-/reverbin-0.1.2.tgz","fileCount":7,"integrity":"sha512-q9NxkXh0Z0aAq5eL/ocLF46Rr12XVWCsmxIhJ9wtQQLQAUWbFvIR8OEwl/KGcy8n4DJ4G9WGL95D/l32KCqLsA==","signatures":[{"sig":"MEUCIQDiCbyrSAPGtsD7aitFm3h9GSDwhz2DaNxrqxQDMG/AAQIgJ6ZC8Uu157MuOuTzTG3Yg6xganWpQTMOYWGW8Tqg1Os=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@builtbyecho%2freverbin@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":40721},"main":"./dist/client.js","type":"module","types":"./dist/client.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./webhook-signatures":{"types":"./dist/webhook-signatures.d.ts","import":"./dist/webhook-signatures.js"}},"gitHead":"488d1a4d67c6378574db3a8db38489f58c0a07ae","_npmUser":{"name":"builtbyecho","email":"builtbyecho@agentmail.to"},"repository":{"url":"git+https://github.com/Wdustin1/reverbin.git","type":"git"},"_npmVersion":"11.6.2","description":"Node.js ESM SDK for Reverbin agent inboxes, threads, messages, approvals, webhooks, credentials, billing, and account lifecycle APIs.","directories":{},"sideEffects":false,"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reverbin_0.1.2_1783744579047_0.6838295934487029","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@builtbyecho/reverbin","version":"0.1.3","keywords":["agents","email","inbox","reverbin","sdk","typescript","webhooks"],"license":"MIT","_id":"@builtbyecho/reverbin@0.1.3","maintainers":[{"name":"builtbyecho","email":"builtbyecho@agentmail.to"}],"homepage":"https://reverbin.com","bugs":{"url":"https://github.com/Wdustin1/reverbin/issues"},"dist":{"shasum":"ed1dc721c6c2021cc67296033536117f63dad216","tarball":"https://registry.npmjs.org/@builtbyecho/reverbin/-/reverbin-0.1.3.tgz","fileCount":7,"integrity":"sha512-Dg5Gqk7EBHK94wVh87VjTyu0aN6+enSsNff1L61nGDGr1NiajjnlSPHPrxZiMoB6oWRHf8DFaImHxOO/VEseFQ==","signatures":[{"sig":"MEQCIEwbMGOBHrykYKbPdlD82GWXlJ1UjgixJt/qQqWaXHOyAiBZrhiV9082DrfOMThJ3PPLcx1u/Ajd7Ao8pgbakv5nYQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@builtbyecho%2freverbin@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":40721},"main":"./dist/client.js","type":"module","types":"./dist/client.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./webhook-signatures":{"types":"./dist/webhook-signatures.d.ts","import":"./dist/webhook-signatures.js"}},"gitHead":"8a4fe927137d5239762b77a5229d06a926ff0bbd","_npmUser":{"name":"builtbyecho","email":"builtbyecho@agentmail.to"},"repository":{"url":"git+https://github.com/Wdustin1/reverbin.git","type":"git"},"_npmVersion":"11.6.2","description":"Node.js ESM SDK for Reverbin agent inboxes, threads, messages, approvals, webhooks, credentials, billing, and account lifecycle APIs.","directories":{},"sideEffects":false,"_nodeVersion":"24.10.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/reverbin_0.1.3_1783744786218_0.7037388398907183","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@builtbyecho/reverbin","version":"0.1.4","description":"Node.js ESM SDK for Reverbin agent inboxes, threads, messages, approvals, webhooks, credentials, billing, and account lifecycle APIs.","type":"module","main":"./dist/client.js","types":"./dist/client.d.ts","exports":{".":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./webhook-signatures":{"types":"./dist/webhook-signatures.d.ts","import":"./dist/webhook-signatures.js"}},"sideEffects":false,"engines":{"node":">=20"},"publishConfig":{"access":"public","provenance":false},"repository":{"type":"git","url":"git+https://github.com/Wdustin1/reverbin.git"},"bugs":{"url":"https://github.com/Wdustin1/reverbin/issues"},"homepage":"https://reverbin.com","license":"MIT","keywords":["agents","email","inbox","reverbin","sdk","typescript","webhooks"],"gitHead":"db5f6d57b6e2a072dd4d623604a0ce71bcd52ca8","_id":"@builtbyecho/reverbin@0.1.4","_nodeVersion":"24.10.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-WYgF9uXhwhmv6TUn7rMGCwGMMmzpz4Bm28bIdwe4hBSaQ2CgPSXd8TSm571Fosax0kR2q7OFbRm3lm6DsWfhuQ==","shasum":"9e005d913dcfbf0f5e4c2b00a0d8aa04dc60c736","tarball":"https://registry.npmjs.org/@builtbyecho/reverbin/-/reverbin-0.1.4.tgz","fileCount":7,"unpackedSize":42211,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDMBd5z0boYHWRJslPRraCPei3q/RJlEcjjsZ+wG0VRRgIhAOl26IT16takJ2mnjqKd/IXu6X/mp5DLi2wg2XQCgPLS"}]},"_npmUser":{"name":"builtbyecho","email":"builtbyecho@agentmail.to"},"directories":{},"maintainers":[{"name":"builtbyecho","email":"builtbyecho@agentmail.to"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/reverbin_0.1.4_1788273721946_0.4170730677172747"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-11T02:59:14.307Z","modified":"2026-09-01T14:42:02.264Z","0.1.0":"2026-07-11T02:59:14.544Z","0.1.1":"2026-07-11T04:32:58.116Z","0.1.2":"2026-07-11T04:36:19.187Z","0.1.3":"2026-07-11T04:39:46.383Z","0.1.4":"2026-09-01T14:42:02.067Z"},"bugs":{"url":"https://github.com/Wdustin1/reverbin/issues"},"license":"MIT","homepage":"https://reverbin.com","keywords":["agents","email","inbox","reverbin","sdk","typescript","webhooks"],"repository":{"type":"git","url":"git+https://github.com/Wdustin1/reverbin.git"},"description":"Node.js ESM SDK for Reverbin agent inboxes, threads, messages, approvals, webhooks, credentials, billing, and account lifecycle APIs.","maintainers":[{"name":"builtbyecho","email":"builtbyecho@agentmail.to"}],"readme":"# @builtbyecho/reverbin\n\nZero-dependency Node.js ESM SDK for the Reverbin API: agent inboxes, threads, messages, approvals, signed webhooks, API keys, billing, and account lifecycle operations.\n\n## Install\n\nInstall the public Node.js package from npm:\n\n```sh\nnpm install @builtbyecho/reverbin\n```\n\nThe SDK requires Node.js 20 or newer, uses Node's built-in `fetch`, and supports ESM imports only. Browser runtimes are not supported; never put a Reverbin API key in client-side code.\n\n## Authenticated client\n\n```js\nimport { ReverbinClient } from '@builtbyecho/reverbin';\n\nconst apiKey = process.env.REVERBIN_API_KEY;\nconst inboxId = process.env.REVERBIN_INBOX_ID;\nif (!apiKey || !inboxId) throw new Error('REVERBIN_API_KEY and REVERBIN_INBOX_ID are required');\n\nconst reverbin = new ReverbinClient({\n  baseUrl: process.env.REVERBIN_BASE_URL ?? 'https://api.reverbin.com',\n  apiKey,\n  timeoutMs: 30_000,\n});\n\nconst threads = await reverbin.inboxes.threads(inboxId);\nconst latest = threads.data[0];\nif (latest) {\n  await reverbin.threads.reply(latest.id, {\n    text: 'Received — I am handling this from the agent workflow.',\n  });\n}\n```\n\nSignup already creates the first inbox. Use the returned `REVERBIN_INBOX_ID`; call `reverbin.inboxes.create` only when the workflow needs another inbox and the account has quota.\n\n## Self-serve signup\n\nThe public signup method does not require an API key. It does require a stable caller-owned idempotency key:\n\n```js\nimport { randomUUID } from 'node:crypto';\nimport { ReverbinClient } from '@builtbyecho/reverbin';\n\nconst reverbin = new ReverbinClient();\nconst result = await reverbin.signups.create({\n  idempotency_key: randomUUID(),\n  requester_email: 'builder@example.com',\n  agent_name: 'Support Agent',\n  agent_use_case: 'Handle customer support replies and escalate unusual requests.',\n  preferred_inbox_name: 'support-agent',\n});\n\nif (result.credentials_returned) {\n  // Store result.api_key.token now; it is returned once. Never print it.\n  const agent = new ReverbinClient({ apiKey: result.api_key.token });\n  await agent.signups.verifyOperator('<six-digit-code-from-operator>');\n  console.log(result.inbox.email_address);\n} else {\n  // Safe replay: identifiers and a recovery message, but no credentials.\n  console.log(result.message);\n}\n```\n\nKeep the original idempotency key with the request outcome. Reuse it only with the identical request body after a lost response. Until the six-digit operator code is verified, the new key may read its inbox and send only to the operator email. Use `signups.resendOperatorVerification()` when the current code expires.\n\n## Core method groups\n\n| Group | Methods |\n| --- | --- |\n| `signups` | `create`, `verifyOperator`, `resendOperatorVerification` |\n| `inboxes` | `create`, `list`, `get`, `threads` |\n| `messages` | `compose`, `list` |\n| `threads` | `get`, `messages`, `reply`, `forward` |\n| `approvals` | `list`, `approve`, `reject` |\n| `webhooks` | `create`, `list`, `deliveries`, `rotateSecret`, `revoke` |\n| `apiKeys` | `create`, `list`, `rotate`, `revoke` |\n| `billing` | `plans`, `checkout`, `portal` |\n| `account` | `export`, `requestDeletion`, `cancelDeletion` |\n| `auditLogs` | `list` |\n| `signupRequests` | `create`, `list`, `update` for legacy operator-assisted workflows |\n\nSee https://reverbin.com/docs/api for request and response contracts.\n\n## Pagination\n\nCollection methods return `{ data, next_cursor, has_more }`. Pass `next_cursor` back unchanged as `cursor` to the same method and parent resource:\n\n```js\nconst first = await reverbin.inboxes.list({ limit: 25 });\nconst second = first.has_more\n  ? await reverbin.inboxes.list({ limit: 25, cursor: first.next_cursor })\n  : null;\n```\n\nCursors are opaque and tenant-, collection-, and parent-bound.\n\n## Timeouts, aborts, and errors\n\nRequests time out after 30 seconds by default. Configure `timeoutMs` on the client or per request, and pass a caller `AbortSignal` in method request options. The client does not retry requests automatically.\n\n```js\nimport {\n  ReverbinApiError,\n  ReverbinClient,\n  ReverbinResponseError,\n  ReverbinTimeoutError,\n} from '@builtbyecho/reverbin';\n\nconst controller = new AbortController();\ntry {\n  await reverbin.inboxes.list(undefined, {\n    signal: controller.signal,\n    timeoutMs: 5_000,\n  });\n} catch (error) {\n  if (error instanceof ReverbinApiError) {\n    console.error(error.status, error.code, error.requestId, error.retryAfterSeconds, error.quota);\n  } else if (error instanceof ReverbinTimeoutError) {\n    console.error('Timed out after', error.timeoutMs);\n  } else if (error instanceof ReverbinResponseError) {\n    console.error('Malformed API response', error.status, error.requestId);\n  }\n}\n```\n\nAPI error details are recursively credential-redacted. Even so, do not log one-time signup, API-key, or webhook-secret responses.\n\n## Webhook signatures\n\nRegister only a real reachable HTTPS endpoint, then store the returned secret immediately:\n\n```js\nconst webhookUrl = process.env.REVERBIN_WEBHOOK_URL;\nif (!webhookUrl) throw new Error('REVERBIN_WEBHOOK_URL is required');\n\nconst webhook = await reverbin.webhooks.create({\n  url: webhookUrl,\n  events: ['email.received', 'email.sent', 'email.failed'],\n});\n// Store webhook.secret now; it is returned once.\n```\n\nVerify the signature against the exact raw request bytes before parsing or acting on a webhook:\n\n```js\nimport { verifyWebhookSignature } from '@builtbyecho/reverbin/webhook-signatures';\n\nconst valid = verifyWebhookSignature(rawBody, signatureHeader, webhookSecret);\n```\n\nDuring credential-rotation grace, verify `x-echo-email-signature-previous` separately with the previous secret. The stable `x-echo-email-*` header prefix is retained for wire compatibility.\n\nAfter signature verification succeeds, atomically claim the unique `x-echo-email-delivery` value before performing side effects, using a durable processing lease and completed state. Commit transactional business changes and the completed state together. For external side effects, enqueue a transactional outbox operation keyed by the delivery ID. A completed claim returns success without re-executing; an expired processing lease may be retried. This deduplicates concurrent and repeated deliveries without losing retryability.\n\n## Retry and idempotency boundaries\n\nThe SDK never retries automatically.\n\n- Signup, Stripe Checkout/Portal, API-key rotation, and webhook-secret rotation require explicit `idempotency_key` inputs. Reuse the same key only with the identical body after a lost response.\n- Do not blindly retry compose, reply, forward, approval decisions, inbox creation, webhook creation/revocation, API-key creation/revocation, or account mutations after an ambiguous response. Inspect resource, thread, audit, or delivery state first.\n- Signup replay prevents duplicate provisioning but intentionally omits one-time credentials.\n\n## Launch limitations\n\nOutbound attachments are not supported in the launch SDK. Compose, reply, and forward accept text plus optional HTML. Inbound attachments remain available in the authenticated human mail console.\n","readmeFilename":"README.md"}