{"_id":"@1xsecret/sdk","_rev":"4-ac65038fddc0198d3421de69aaa8ddfd","name":"@1xsecret/sdk","dist-tags":{"latest":"0.2.0"},"versions":{"0.0.1":{"name":"@1xsecret/sdk","version":"0.0.1","keywords":["1xsecret","one-time-secret","end-to-end-encryption","secret-sharing","sdk"],"author":{"name":"1xSecret contributors"},"license":"MIT","_id":"@1xsecret/sdk@0.0.1","maintainers":[{"name":"fkammer.cc","email":"frederik@cabin.consulting"}],"homepage":"https://github.com/1xSecret/1xSecret/tree/main/sdk","bugs":{"url":"https://github.com/1xSecret/1xSecret/issues"},"dist":{"shasum":"790c1ace3eecaac87cf8e27a7a5a83e4c2155d3c","tarball":"https://registry.npmjs.org/@1xsecret/sdk/-/sdk-0.0.1.tgz","fileCount":9,"integrity":"sha512-pS2sBsJmOPV1EFg8Fz3RzsUYrun3daaIyLRufZ4snMB0gjzb2ZWMLWsXvOuxar/2ieJIdg2J6uW30MB2Nda4nA==","signatures":[{"sig":"MEYCIQCSScTg53MHeKRxi1SVtez4Cw0ClI9r4drPicF+C4QJbgIhAMHpy1xldwWbhALhE8CJU4JgoyfKS2wUqprSr4xZX2jV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89322},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"5c2ffdb5305347bdda06486a91123dc2963a9bbd","scripts":{"test":"vitest run","build":"tsup","prepack":"pnpm build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"fkammer.cc","email":"frederik@cabin.consulting"},"deprecated":"bootstrap release — use >=0.1.0","repository":{"url":"git+https://github.com/1xSecret/1xSecret.git","type":"git","directory":"sdk"},"_npmVersion":"11.12.1","description":"Client SDK for 1xSecret — seal and reveal one-time, end-to-end-encrypted secrets from Node.js. Permissively licensed (MIT) for use in any project, including closed-source.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","dependencies":{"hash-wasm":"^4.12.0","@noble/curves":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.0.1_1784207536896_0.9165484394578671","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@1xsecret/sdk","version":"0.1.0","keywords":["1xsecret","one-time-secret","end-to-end-encryption","secret-sharing","sdk"],"author":{"name":"1xSecret contributors"},"license":"MIT","_id":"@1xsecret/sdk@0.1.0","maintainers":[{"name":"fkammer.cc","email":"frederik@cabin.consulting"}],"homepage":"https://github.com/1xSecret/1xSecret/tree/main/sdk","bugs":{"url":"https://github.com/1xSecret/1xSecret/issues"},"dist":{"shasum":"fadc85b9339053071f97b09a034c605a47a572d7","tarball":"https://registry.npmjs.org/@1xsecret/sdk/-/sdk-0.1.0.tgz","fileCount":9,"integrity":"sha512-R3UnCo14eGBnu/2Cqv+9bkdW/M7W/wRcsbiB3OSE6jaXuAZfYuKO/qsOGsHvuzMuffFK56SYXfTCoYzyB0m3rA==","signatures":[{"sig":"MEYCIQCWK/rCbxLC3YooHXdzCPtZbHHrmC+25RRr/XDDOd1MewIhAPhsngXgSumy2LPg1tpGo/Y63yyR1zwmedPiLpyU3AJZ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@1xsecret%2fsdk@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":89322},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"5c2ffdb5305347bdda06486a91123dc2963a9bbd","scripts":{"test":"vitest run","build":"tsup","prepack":"pnpm build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4baf121d-8595-411d-9cfd-eeab015f38d9"}},"repository":{"url":"git+https://github.com/1xSecret/1xSecret.git","type":"git","directory":"sdk"},"_npmVersion":"12.0.1","description":"Client SDK for 1xSecret — seal and reveal one-time, end-to-end-encrypted secrets from Node.js. Permissively licensed (MIT) for use in any project, including closed-source.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"hash-wasm":"^4.12.0","@noble/curves":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.0_1784208216094_0.8994270116685945","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@1xsecret/sdk","version":"0.2.0","description":"Client SDK for 1xSecret — seal and reveal one-time, end-to-end-encrypted secrets from Node.js. Permissively licensed (MIT) for use in any project, including closed-source.","keywords":["1xsecret","one-time-secret","end-to-end-encryption","secret-sharing","sdk"],"license":"MIT","author":{"name":"1xSecret contributors"},"homepage":"https://github.com/1xSecret/1xSecret/tree/main/sdk","repository":{"type":"git","url":"git+https://github.com/1xSecret/1xSecret.git","directory":"sdk"},"bugs":{"url":"https://github.com/1xSecret/1xSecret/issues"},"publishConfig":{"access":"public"},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=20"},"sideEffects":false,"scripts":{"build":"tsup","test":"vitest run","typecheck":"tsc --noEmit","prepack":"pnpm build"},"dependencies":{"@noble/curves":"^2.2.0","hash-wasm":"^4.12.0"},"devDependencies":{"tsup":"^8.5.1","typescript":"^5","vitest":"^4.1.10"},"gitHead":"24df74811e7e2a4dbc0e4c986ec7e1f86083728b","_id":"@1xsecret/sdk@0.2.0","_nodeVersion":"24.18.0","_npmVersion":"12.0.1","dist":{"integrity":"sha512-MwBowXBntJ9KL8JokXXrk02edKWYTyOYXRLPGp5j+k4ewy6q5r/lZFkeL+Sdxi9MrakS2SP5YVg4537ZXRwRKw==","shasum":"3e977faf4f03247cfaa486621c036fd10f8a8dbd","tarball":"https://registry.npmjs.org/@1xsecret/sdk/-/sdk-0.2.0.tgz","fileCount":9,"unpackedSize":89330,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@1xsecret%2fsdk@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEUhIHZ8Ak/sOdozjpjfv8gTJUZkD/94PwwqHZBbcT/7AiBpgwf6Gnu72lhX7kQHrgKPhj6LFD8vrKzKvACd+lWG+g=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4baf121d-8595-411d-9cfd-eeab015f38d9"}},"directories":{},"maintainers":[{"name":"fkammer.cc","email":"frederik@cabin.consulting"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.2.0_1785222929765_0.8157092991738131"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-16T13:12:16.729Z","modified":"2026-07-28T07:15:30.239Z","0.0.1":"2026-07-16T13:12:17.032Z","0.1.0":"2026-07-16T13:23:36.259Z","0.2.0":"2026-07-28T07:15:29.938Z"},"bugs":{"url":"https://github.com/1xSecret/1xSecret/issues"},"author":{"name":"1xSecret contributors"},"license":"MIT","homepage":"https://github.com/1xSecret/1xSecret/tree/main/sdk","keywords":["1xsecret","one-time-secret","end-to-end-encryption","secret-sharing","sdk"],"repository":{"type":"git","url":"git+https://github.com/1xSecret/1xSecret.git","directory":"sdk"},"description":"Client SDK for 1xSecret — seal and reveal one-time, end-to-end-encrypted secrets from Node.js. Permissively licensed (MIT) for use in any project, including closed-source.","maintainers":[{"name":"fkammer.cc","email":"frederik@cabin.consulting"}],"readme":"# @1xsecret/sdk\n\nClient SDK for [1xSecret](https://github.com/1xSecret/1xSecret) — seal and reveal\n**one-time, end-to-end-encrypted secrets** from a Node.js backend (or any WebCrypto\nruntime). All encryption and decryption happen locally; the server only ever sees\nciphertext, and each secret can be viewed exactly once.\n\n- **Permissively licensed (MIT)** — use it in any project, **including closed-source\n  and commercial** ones. (The 1xSecret server is AGPL-3.0; this client SDK is a separate,\n  MIT-licensed package.)\n- Byte-for-byte compatible with the 1xSecret web app: a secret sealed with the SDK opens\n  in the browser and vice versa.\n- Points at the public instance `https://1xsecret.com` by default; set `apiUrl` to your\n  own self-hosted deployment.\n\n## Install\n\n```sh\nnpm install @1xsecret/sdk\n```\n\nRequires Node.js ≥ 20 (for global `crypto` and `fetch`), or any runtime with WebCrypto.\n\n## Usage\n\n```ts\nimport { OneXSecretClient } from \"@1xsecret/sdk\";\n\nconst client = new OneXSecretClient({\n  // apiUrl: \"https://secrets.your-company.com\", // defaults to https://1xsecret.com\n});\n\n// Seal a secret and get a one-time link.\nconst { link } = await client.seal({\n  text: \"client_secret=abc123\",\n  password: \"shared-out-of-band\", // optional but recommended\n  expiresIn: \"1d\", // \"10m\" | \"1h\" | \"1d\" | \"7d\" | \"30d\"\n});\nconsole.log(link);\n// https://1xsecret.com/en/s/<id>#v1.<key>[.pw]\n//   ^ the part after \"#\" is the decryption key; it never reaches the server.\n\n// Reveal (and burn) a secret.\nconst secret = await client.reveal({\n  link,\n  password: \"shared-out-of-band\",\n});\nconsole.log(secret); // \"client_secret=abc123\"\n```\n\nYou can also reveal from an id + fragment instead of a full link:\n\n```ts\nawait client.reveal({ id, fragment: \"v1.<key>.pw\", password });\n```\n\n## How it works\n\nThe SDK generates a random 256-bit key per secret, optionally stretches your password\nwith Argon2id, derives an AES-256-GCM key and an Ed25519 keypair via HKDF, encrypts the\ntext locally, and uploads only the ciphertext plus a public key. The decryption key lives\nin the URL fragment (`#…`), which browsers and this SDK never send to the server. On\nretrieval the SDK proves possession with an Ed25519 signature over a fresh server\nchallenge; the server hands over the ciphertext and destroys it in the same step.\n\nSee the [security whitepaper](https://github.com/1xSecret/1xSecret/blob/main/docs/SECURITY.md)\nfor the full scheme.\n\n## Errors\n\n`reveal()` and `seal()` throw typed errors you can branch on:\n\n| Error                     | When                                                        |\n| ------------------------- | ---------------------------------------------------------- |\n| `WrongPasswordError`      | Wrong password (the secret is **not** consumed). Has `retryAfterSeconds` if the server started throttling. |\n| `RetrievalThrottledError` | Too many attempts from this network; has `retryAfterSeconds`. |\n| `SecretUnavailableError`  | Missing, expired, or already retrieved.                    |\n| `RetrievalRestrictedError`| A SAFEGUARDED instance forbids retrieval from this network. |\n| `CreationRestrictedError` | A SAFEGUARDED instance forbids creation from this network. |\n| `InvalidLinkError`        | The link/fragment is missing or malformed.                 |\n| `ApiRequestError`         | Other HTTP/validation errors (`status`, `code`).           |\n\n```ts\nimport { WrongPasswordError } from \"@1xsecret/sdk\";\n\ntry {\n  await client.reveal({ link, password });\n} catch (err) {\n  if (err instanceof WrongPasswordError) {\n    // safe to prompt again — the secret was not consumed\n  }\n}\n```\n\n## API\n\n- `new OneXSecretClient({ apiUrl?, fetch?, basePath? })`\n- `client.seal({ text, password?, expiresIn?, locale? }) → { id, link, fragment, restrictedRetrieval }`\n- `client.reveal({ link } | { id, fragment }, password?) → string`\n\n## Versioning & compatibility\n\nThe SDK is versioned independently of the server — it changes far less often. Its\n**major** version tracks the 1xSecret server: a breaking API or crypto-scheme change\n(e.g. a new `1xsecret/vN` scheme) bumps both to the next major. Within a major, any SDK\nversion works against any server of the same major, so `@1xsecret/sdk@1.x` talks to any\n1xSecret `1.x` server. Minor and patch releases are independent.\n\n## License\n\nMIT © 1xSecret contributors.\n","readmeFilename":"README.md"}