kinlock-sdk
The only way any other layer talks to the contract. packages/sdk is the
TypeScript client; services/indexer mirrors chain events into Postgres for
lists, never for money-moving decisions.
Public API
Released as v0.3.0 as a GitHub Release tarball (not published to npm; see
ADR-0026 for why). Current public exports:
createLockreleaserefunddeclinegetLockgetPayeeverifyReceiptbuildClaimLinkparseClaimLinkpreflighttoBaseUnitsfromBaseUnitsgenerateSaltcomputeRefHashbuildRequestLinkparseRequestLink
Rules the SDK enforces
getLockandgetPayeeread chain state. Indexer-backed reads are for lists only, and the API that serves them says so.buildClaimLinkputs the reference and salt in the URL fragment. The SDK never logs, persists, or transmits them.- Amounts are
bigintin code, decimal strings in JSON, never a JavaScriptnumber. preflightchecks sender balance, payee Active status, a recent payout change (≤ 7 days), a duplicateref_hashfor the payee, and an authorized USDC trustline on the payout account.
Indexer
chain_events → Postgres → list API. Idempotent writes keyed on
(tx_hash, event_index), so replaying events is safe. A gap in event retrieval
stops ingestion and alerts; it's never silently skipped.
Not yet deployed anywhere public. The app's list pages (/send,
/request, /payee) degrade gracefully to a "can't load right now"
state until that happens.
Stack
TypeScript, strict mode, no any. Zod validation at every external boundary (HTTP, RPC responses, env). @stellar/stellar-sdk plus generated TS bindings from the contract.