OHMYHOST_TOKEN from a private environment file or your secret store, then create an explicit client:
{ client } as the last argument. Each call returns its response body directly, without a .data wrapper. With throwOnError: true, an API error throws its problem object: act on code, retryable and suggested_action. With throwOnError: false, a failed call resolves to undefined. Keep this token outside browser bundles and application source. A project or user ID identifies a resource but does not authorize access.
For an asynchronous mutation, retain its idempotency key and observe the returned operation. Handle typed API errors rather than silently returning success. API contract · Authentication · Deployment workflow.