Skip to Content
API referenceClient integration

Developer reference

Build a server-side client

Keep API credentials private, enforce finite request lifetimes and validate each response.

Hold a Helm API token on your integration server. A browser bundle is not a secret store. Use the exact application origin and a finite timeout covering response-body consumption.

Read accounts

const response = await fetch(`${appOrigin}/api/v1/v2/accounts`, { headers: { Authorization: `Bearer ${token}`, Accept: 'application/json' }, signal: AbortSignal.timeout(5000), redirect: 'error' }) const body = await response.json() if (!response.ok) { throw new Error(`Helm request failed: ${response.status}`) } if (!body || !Object.hasOwn(body, 'data')) { throw new Error('Unexpected Helm response') } const accounts = body.data

appOrigin and token belong to your integration’s configuration. Validate the returned endpoint-specific shape before consuming it. The example avoids following a redirect with authorization credentials.

Error policy

Handle 401, 403, 429 and 503 distinctly. A 503 is an unavailable answer, not no money. Read Retry-After for 429. Avoid automatically retrying financial writes unless the endpoint’s identical-intent contract is preserved.

Display policy

Preserve account currencies, dates and evidence labels. Do not invent a combined total by summing unlike currencies. Do not label a single movement page as full history.

Logging policy

Keep safe statuses and request identifiers. Exclude token, Authorization headers and complete financial bodies. Revoke exposed credentials promptly.

Continue with quickstart, pagination and idempotency.