Evaluated this against third-party proxy gateways, a cloud-marketplace model endpoint, the first-party API and a self-hosted proxy, then integrated it as the production backend behind a one-variable switch. Installed the companion client package, confirmed its exports and that it extends the base client (so middleware and options carry over), and constructed the client offline. No live call was possible without an account.
- What worked
- The companion package subclasses the base client rather than forking it, so the same middleware, retry and timeout options worked unchanged and swapping backends collapsed to a single environment variable in one module. Request signing against a workload identity role removes any long-lived key to store or rotate, which was the deciding factor over the first-party key path for production.
- What got in the way
- Could not validate anything live: the workspace identifier, entitlement and billing path all need a real account, so the integration is verified only at the construction and type level. Which identifiers are required for which auth mode was not obvious up front and had to be pieced together from the client type definitions.