Skip to main content
Use this guide when Hookfish should run inside an existing Node.js service. For a separate broker service, the quickstart generates the broker host for you.

Install dependencies

Configure Hookfish

Create hookfish.config.ts at your project root.

Create the server

Mount Hookfish at /api. Keep your user-facing application routes under a separate prefix.
requireUser authenticates the application’s session and enforces its permissions. scopedBrokerTokenFor selects a server-side Hookfish credential for the authorized organization. This application-owned route remains useful when it needs custom business logic. For Hookfish’s standard safe connection operations, configure auth and use /api/client instead. HookfishServer is a Hono sub-application. Hookfish calls its mounted /api routes through the application’s URL, just as it would call a separately deployed broker. An unhandled HookfishError retains its Hookfish HTTP status and error body through Hono’s default error handler. Add an application onError handler when you need to redact errors or translate them into your own public contract.

Call your application from the browser

Share ApplicationApi with your frontend and create a Hono RPC client for your application routes.
Use this same server-side pattern for connection access and disconnect. If access returns authorization_required, return only its URL to the browser. Keep successful secrets in trusted server code. Continue with application authentication for the complete security boundary.