Skip to content
← Public packages

@kody/doordash-driver

Request DoorDash Drive (Dasher) deliveries with JWT auth from Developer Portal access keys.

AGENTS.md

33 lines · 1.6 KB · Markdown

@kody/doordash-driver — agent notes (DoorDash Drive / Dasher)

Imports

import smokeTest from 'kody:@kody/doordash-driver/smoke-test'
import settings from 'kody:@kody/doordash-driver/settings'
import adapt from 'kody:@kody/doordash-driver/adapt'
import { createQuote } from 'kody:@kody/doordash-driver/create-quote'
import { acceptQuote } from 'kody:@kody/doordash-driver/accept-quote'
import { createDelivery } from 'kody:@kody/doordash-driver/create-delivery'
import { getDelivery } from 'kody:@kody/doordash-driver/get-delivery'
import { doorDashRequest } from 'kody:@kody/doordash-driver/request'

Setup playbook

  1. await adapt() after a community fork.
  2. await settings({ developerId, keyId }) with Portal UUIDs (not the signing secret).
  3. Send the owner the prefilled doorDashSigningSecret URL from smoke-test / settings — never ask them to paste the value in chat.
  4. Confirm host openapi.doordash.com is approved on that secret.
  5. await smokeTest() then dry-run createQuote / createDelivery. Pass confirm: true only for live writes.

Auth

  • Drive JWT: HS256, header dd-ver: DD-JWT-V1, claims aud=doordash, iss=developer_id, kid=key_id.
  • Minting uses kody.secretJwtSign({ algorithm: 'HS256', key_encoding: 'base64', header: { 'dd-ver': 'DD-JWT-V1' }, ... }) with the saved signing secret. Prefer that over passing raw signingSecret.
  • Mutations default to dry-run. GET delivery does not need confirm.

Escapes

  • Raw Drive paths: doorDashRequest({ method, path, body?, confirm? }).
  • Extra apps: account: "work" → doorDashSigningSecret-work.