# Install and verify

## Before you start

The package does not declare an engine requirement. Use a maintained Node.js release appropriate to your host application.

Use a project with a `package.json`. Check the runtime and package manager:

```bash
node --version
npm --version
```

## Install the documented version

```bash
npm install @qentrah/auth-sdk@0.3.4
```

## Confirm the installation

```bash
npm ls @qentrah/auth-sdk
```

The output should show `@qentrah/auth-sdk@0.3.4`. Commit the lockfile so another developer installs the same dependency tree.

## Environment Variables

Use your own secret manager, hosting provider settings, or deployment environment.

```bash
QENTRAH_WORKSPACE_BASE_URL=https://app.qentrah.com
QENTRAH_PARTNER_CLIENT_ID=<your-partner-client-id>
QENTRAH_PARTNER_CLIENT_SECRET=<optional-confidential-client-secret>
QENTRAH_PARTNER_REDIRECT_URI=https://your-app.example.com/api/qentrah/oauth/callback
QENTRAH_PARTNER_SCOPES="organization:read client:read"
QENTRAH_WEBHOOK_SIGNING_SECRET=<your-webhook-signing-secret>
```

`QENTRAH_PARTNER_CLIENT_SECRET` is only needed for confidential client setups. Never place it in browser-visible configuration.

You can normalize the public OAuth settings with:

```ts
import { qentrahPartnerAuthorityFromEnv } from "@qentrah/auth-sdk/partner";

const authority = qentrahPartnerAuthorityFromEnv({
  QENTRAH_WORKSPACE_BASE_URL: process.env.QENTRAH_WORKSPACE_BASE_URL,
  QENTRAH_PARTNER_CLIENT_ID: process.env.QENTRAH_PARTNER_CLIENT_ID,
  QENTRAH_PARTNER_REDIRECT_URI: process.env.QENTRAH_PARTNER_REDIRECT_URI,
  QENTRAH_PARTNER_SCOPES: process.env.QENTRAH_PARTNER_SCOPES,
});
```

## Browser Connect Button

```html
<button id="qentrah-authorize">Authorize with Qentrah</button>
```

```ts
import { mountQentrahAuthorizeButton } from "@qentrah/auth-sdk/partner/browser";

mountQentrahAuthorizeButton({
  buttonId: "qentrah-authorize",
  startUrl: "/api/qentrah/oauth/start",
  label: "Authorize with Qentrah",
  disabledLabel: "Opening...",
  onError(error) {
    reportConnectionError(error);
  },
});
```

The button should point at a backend route in your app. It should not receive tokens or secrets.

## Expected result

The connect button opens your backend start route. It cannot complete authorization until you implement server-side state and token storage and register the callback URI.