This runs a complete bridge from Node with keys your server holds: the shape of a bot, a treasury move or a test script. A browser app does the same steps through your backend, or with your project id: see Browser apps.
Server-held keys are for test networks and for your own funds. Never ask users for their keys; they sign in their own wallets.
1

Get a key

Make a secret API key (c8n_sk_…) in the hub dashboard. Keep it in your server’s secret store, or in a git-ignored .env file as HUB_API_KEY. See Testing.
2

Create the client

The transport sends the key in x-api-key on every call, under /v1: there is no sign-in and no session to renew. It refuses, before any call, a value that is not a secret key (a project id, for example) with a message that says so.
3

Pick a route from the catalog

Amounts are always decimal strings in base units. Build your pickers from the catalog rather than hard-coding chains, assets or contract addresses: they move when the hub is redeployed.
4

Get a quote and check it

quote.lane.kind says what the user will do (here wrap-native: one transaction). vetQuote compares every field that moves money with your request and the catalog. executeQuote runs the same checks again right before signing, so this step is for showing them, not a requirement.
5

Execute it

The SDK re-quotes if too little time is left to sign, sends the transaction, registers the order with the hub, and follows it until the chain shows it settled.
6

Read the history

With your key and no subject of your own, this is the history of hubTransport’s one subject (default): every order made that way, whoever placed it. A service that acts for users of its own names each one with subject, and then lists only that user’s orders (Executing on a server for your users). decimals is never guessed: a token the catalog does not list can come back without it. See Order history.

When something fails

Every error the SDK throws has a user-facing message and an action:
A refused key throws a HubError whose isCredentialRefused is true (EPX0001: missing or malformed; EPX0002: unknown, revoked or expired). Fix the key before calling again: 20 refused credentials within a minute lock your IP out for the rest of that minute (EPX0081). See Errors for the full list.

The runnable version

The SDK repository’s examples/node-quickstart has this as scripts, configured by a .env with HUB_BASE_URL and HUB_API_KEY: pnpm smoke (a read-only check of a hub, starting with one call that checks your key), pnpm catalog, pnpm quote, pnpm bridge, pnpm orders and pnpm refund. See Testing.