Developer reference
Build a server-side client
Keep API credentials private, enforce finite request lifetimes and validate each response.
Hold a Helm API token on your integration server. A browser bundle is not a secret store. Use the exact application origin and a finite timeout covering response-body consumption.
Read accounts
const response = await fetch(`${appOrigin}/api/v1/v2/accounts`, {
headers: {
Authorization: `Bearer ${token}`,
Accept: 'application/json'
},
signal: AbortSignal.timeout(5000),
redirect: 'error'
})
const body = await response.json()
if (!response.ok) {
throw new Error(`Helm request failed: ${response.status}`)
}
if (!body || !Object.hasOwn(body, 'data')) {
throw new Error('Unexpected Helm response')
}
const accounts = body.dataappOrigin and token belong to your integration’s configuration. Validate the returned endpoint-specific shape before consuming it. The example avoids following a redirect with authorization credentials.
Error policy
Handle 401, 403, 429 and 503 distinctly. A 503 is an unavailable answer, not no money. Read Retry-After for 429. Avoid automatically retrying financial writes unless the endpoint’s identical-intent contract is preserved.
Display policy
Preserve account currencies, dates and evidence labels. Do not invent a combined total by summing unlike currencies. Do not label a single movement page as full history.
Logging policy
Keep safe statuses and request identifiers. Exclude token, Authorization headers and complete financial bodies. Revoke exposed credentials promptly.
Continue with quickstart, pagination and idempotency.