Represents an authenticated user in the ESP Rainmaker Neo system. Provides methods for user operations, device management, group management, and MQTT-based real-time communication.

Constructors

Properties

eventCallbacks: EventCallbacks = {}

Registered event subscriber callbacks, keyed by event (see subscribe).

eventTeardowns: Record<string, { stop(): void }> = {}

Per-event teardown handles for backing sources started by subscribe (LAN discovery, node-updates bus, custom discovery). Kept so unsubscribe / removeAllCallbacks can stop them.

Methods

  • Exchanges identity (temporary) credentials for role-based credentials.

    Two modes — chosen by whether options.services is set:

    1. Default (no options.services): POST /v1/assumed-roles. Returns IoT/MQTT credentials scoped to the user's group/subgroup membership. Used for MQTT WebSocket auth.
    2. Per-node services (options.services with nodeId): Same route, with services and node_id in the body. Returns credentials scoped to that single node for the listed services (currently s3 and/or kvs). The response contains only the requested service permissions — no IoT/MQTT statements.

    Parameters

    • accessKey: string

      AWS access key from getTemporaryAWSCredentials.

    • secretKey: string

      AWS secret key from getTemporaryAWSCredentials.

    • sessionToken: string

      AWS session token from getTemporaryAWSCredentials.

    • Optionaloptions: AssumeRoleOptions

      Optional. To request per-node service credentials, pass services and nodeId.

    Returns Promise<AWSCredentials>

    A promise that resolves to AWSCredentials.

    Error if services is set without nodeId, or if the API call fails.

  • Connects to MQTT websocket.

    Client ID format: user:<email|phone>:<session> — required by the assume-role IoT policy which scopes iot:Connect to that prefix.

    Returns Promise<boolean>

    A promise that resolves to true if connection was successful.

    Error if connection fails or AWS credentials are not set

  • Creates an ESP device with the given parameters.

    Parameters

    • name: string

      The name of the device.

    • transport: ESPTransport

      The transport type to use.

    • Optionalsecurity: ESPSecurity

      The security type to use (optional).

    • OptionalproofOfPossession: string

      The proof of possession string (optional).

    • OptionalsoftAPPassword: string

      The SoftAP password (optional).

    • Optionalusername: string

      The username (optional).

    Returns Promise<ESPDevice>

    A promise that resolves to an ESPDevice instance.

  • Disconnects the MQTT websocket connection if one is active. No-op when MQTT was never initialized or is already disconnected.

    Returns Promise<void>

    Error if disconnection fails.

  • Returns a valid Cognito access token from storage. Refreshes the session when the stored access token is expired.

    Returns Promise<string>

    When no access/refresh token is stored, or refresh fails.

  • Returns a valid Cognito ID token from storage. Refreshes the session when the stored ID token is expired.

    Returns Promise<string>

    When no ID/refresh token is stored, or refresh fails.

  • Returns the current Cognito refresh token from storage.

    Returns Promise<string>

    When no refresh token is stored (not logged in).

  • Gets temporary AWS credentials for the authenticated user.

    Calls POST /v1/user/credentials with the Cognito ID token as Bearer auth. Refreshes the session (refresh token → new tokens) when the ID token is expired locally, or when the API returns 401 with an expired-token message, then retries. Delegates to fetchTemporaryAWSCredentials.

    Returns Promise<ESPAWSCredentials>

    Temporary AWS credentials (access key, secret key, session token, expiration).

    If the user is not logged in (missing ID/refresh token).

    If a network error occurs or the API request fails.

  • Logs out the user by invalidating the server session (best-effort), disconnecting MQTT, clearing tokens/credentials, and resetting local state.

    Returns Promise<boolean>

    A promise that resolves to true if local cleanup completed, false if an unexpected error occurred.

  • Registers a delivery endpoint for the calling user on the given integration (SigV4-signed PUT /v1/integrations/{integrationId}/endpoints). The server derives an endpoint_id per integration type and returns it.

    Callers must persist the returned endpoint_id to later address the endpoint (e.g. for ESPRMNeoUser.unregisterIntegrationEndpoint).

    Parameters

    • integrationId: string

      Target integration id (from ESPRMNeoUser.listIntegrations).

    • appToken: string

      Delivery credential (delivery_credentials.app_token), e.g. the push token.

    • Optionallocale: string

      Optional locale (e.g. en_US).

    Returns Promise<string>

    The endpoint_id derived and returned by the server.

  • Unregisters one specific delivery endpoint for the calling user on the given integration (SigV4-signed DELETE /v1/integrations/{integrationId}/endpoints/{endpointId}), cleaning up the underlying delivery registration.

    Parameters

    Returns Promise<SuccessResponse>

    API success payload (optional { message } on success).

  • Extends the current session using a refresh token.

    Parameters

    • refreshToken: string

    Returns Promise<void>