qURL™ SDK & API
Build private access into your product.
Give a private resource a cryptographic identity, then let your code issue access for each task. Your app stays off the public internet while people and AI agents get a verified way in. Build with Go, TypeScript, Python, or the REST API.
How it works
Publish once. Create access from your code.
First publish a private app and save its CRID. Then run one of these examples in your server or script to create a single-use link that can be opened within one hour. The resulting session follows its own configured duration.
For link creation, use an application key from the resource owner’s account with qurl:write permission, separate from the key used for CLI enrollment. Set QURL_API_KEY to that key and QURL_RESOURCE_CRID to the CRID returned by publish. Keep the app and connector running. These calls issue links for that existing resource.
package main
import (
"context"
"fmt"
"log"
"os"
"time"
"github.com/layervai/qurl-go/qurl"
)
func main() {
crid := os.Getenv("QURL_RESOURCE_CRID")
if crid == "" {
log.Fatal("Set QURL_RESOURCE_CRID from publish")
}
client, err := qurl.OpenClient()
if err != nil { log.Fatal(err) }
resource := client.ResourceByCRID(crid)
portal, err := resource.CreatePortal(context.Background(),
qurl.ValidFor(time.Hour), qurl.OneTimeUse())
if err != nil { log.Fatal(err) }
// Print only in this local example. Deliver privately in production; do not log.
fmt.Println(portal.Link)
}Publish once. Issue access as needed.
Examples use Go v0.17.0, TypeScript v0.7.0, and Python v0.3.0. For programmatic opening of a received link, follow the link-opening guide.
Go
go get github.com/layervai/qurl-go/qurl
TypeScript
npm install @layervai/qurl
Python
pip install qurl-python
Why it’s different
The access layer you’d otherwise build yourself.
Your app stays private
Keep the origin private. LayerV checks authorization before opening the protected origin connection; your code decides when to issue access.
Expiry is built in
Issue a fresh link for each task, choose its lifetime and use limits, and revoke access when the work is done. Keep your app’s sign-in for user identity.
Keep identity separate from location
Save the CRID once. It identifies the resource by its key, while each signed link grants fresh access. A compatible opener verifies the grant against that identity.
Your first link is one call away.
Publish your app with the quickstart, then build access-link creation into your application.