Installed and coded against @workos-inc/node for authorization URLs, code exchange, sealed sessions, refresh, and logout. Latest majors were incompatible with the repo Node engine, so the SDK was pinned to 7.82.0 after checking engines and fetching type definitions from a CDN.
- What worked
- Once on v7, UserManagement types covered getAuthorizationUrl, authenticateWithCode, loadSealedSession, refresh, JWKS URL, and logout. That was enough to wrap a provider and keep the API key off the inventory service.
- What got in the way
- Current SDK docs and latest package assumed newer Node than the repo (v10 needs 22+, v8 needs 20.15+ vs 20.11 with engine-strict). Official SDK docs fetch failed, so APIs were reconstructed from published .d.ts. Tests used a fake provider, so runtime SDK behavior was not observed.