{"_id":"@2fapi/server","_rev":"2-c0a60c79f563fc399c671f188c1f7743","name":"@2fapi/server","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.0":{"name":"@2fapi/server","version":"1.0.0","keywords":["zkproof","authentication","server","verification-engine","ristretto255","pedersen","sigma-protocol"],"author":{"name":"Continuum Identity","email":"contact@continuum-identity.com"},"license":"SEE LICENSE IN LICENSE","_id":"@2fapi/server@1.0.0","maintainers":[{"name":"plu9in","email":"plu9in@gmail.com"}],"homepage":"https://github.com/gthstepsecurity/2fapi-server","bugs":{"url":"https://github.com/gthstepsecurity/2fapi-server/issues"},"dist":{"shasum":"c52062577864a67a39e10e142936f1173773d80a","tarball":"https://registry.npmjs.org/@2fapi/server/-/server-1.0.0.tgz","fileCount":1170,"integrity":"sha512-MCakq07VaJFtweDoFr2QIZCMFMEBxLZIUt2gRaGklVKH0IRg+WrJEHh1Z3ID1985xvT09ACPX/IZlSxUoGVZzA==","signatures":[{"sig":"MEUCIAJRUygxLjBDywrtG7MqFB3UywziPO5KWcG2jBTv8NDTAiEA/J9TXK09ZYnoR9sXSIcgMH5Ka/5CWDjS7z7UtqDhGpo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1219935},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"4f3639b68b3c40df4edb27785db341903123d2f6","scripts":{"dev":"npx tsx start.ts","build":"tsc","clean":"rm -rf dist","start":"node --enable-source-maps dist/start.js","migrate":"npx tsx infrastructure/postgresql/migrator.ts"},"_npmUser":{"name":"plu9in","email":"plu9in@gmail.com"},"repository":{"url":"git+https://github.com/gthstepsecurity/2fapi-server.git","type":"git"},"_npmVersion":"11.5.1","description":"2FApi Server — Zero-Knowledge Proof Verification Engine","directories":{},"_nodeVersion":"22.17.0","dependencies":{"pg":"^8.20.0","argon2":"^0.44.0","fastify":"^5.8.2","ioredis":"^5.10.1","@noble/ed25519":"^3.0.1","@2fapi/protocol-spec":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/server_1.0.0_1774614636422_0.05361169262623888","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@2fapi/server","version":"1.1.0","description":"Continuum Ghost Server — Zero-Knowledge Proof Verification Engine","license":"SEE LICENSE IN LICENSE","author":{"name":"Continuum Identity","email":"contact@continuum-identity.com"},"homepage":"https://github.com/gthstepsecurity/2fapi-server","repository":{"type":"git","url":"git+https://github.com/gthstepsecurity/2fapi-server.git"},"keywords":["zkproof","authentication","server","verification-engine","ristretto255","pedersen","sigma-protocol"],"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"tsc","start":"node --enable-source-maps dist/start.js","dev":"npx tsx start.ts","migrate":"npx tsx infrastructure/postgresql/migrator.ts","clean":"rm -rf dist"},"dependencies":{"@2fapi/protocol-spec":"^1.0.0","@noble/ed25519":"^3.0.1","argon2":"^0.44.0","fastify":"^5.8.2","ioredis":"^5.10.1","pg":"^8.20.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.9.3"},"engines":{"node":">=22.0.0"},"_id":"@2fapi/server@1.1.0","gitHead":"33ec3f1b2cea8d9ca81e705651ba5cbbaaaf84cb","bugs":{"url":"https://github.com/gthstepsecurity/2fapi-server/issues"},"_nodeVersion":"22.17.0","_npmVersion":"11.5.1","dist":{"integrity":"sha512-2YOcIdHoCqKJvTZu7zZlb7beFcn1C8YsSNgOXj3vXQsohZPKaBSYCR00iC8EEySejBgm1p393Jv/fO0Ffh43+A==","shasum":"066fb8811bae2f05a74809c6e5542f3dde6704d4","tarball":"https://registry.npmjs.org/@2fapi/server/-/server-1.1.0.tgz","fileCount":1170,"unpackedSize":1220048,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC1vCohBGOx4y3VNV1GbaKiFNzCTcFVjSauFZGzUZ+k+AIgaQEW5GSR2G/YczMupVK3s39FC4gD3DopATgIRZrkjR0="}]},"_npmUser":{"name":"plu9in","email":"plu9in@gmail.com"},"directories":{},"maintainers":[{"name":"plu9in","email":"plu9in@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/server_1.1.0_1774618763877_0.0611827293194418"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-27T12:30:36.356Z","modified":"2026-03-27T13:39:24.217Z","1.0.0":"2026-03-27T12:30:36.614Z","1.1.0":"2026-03-27T13:39:24.078Z"},"bugs":{"url":"https://github.com/gthstepsecurity/2fapi-server/issues"},"author":{"name":"Continuum Identity","email":"contact@continuum-identity.com"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/gthstepsecurity/2fapi-server","keywords":["zkproof","authentication","server","verification-engine","ristretto255","pedersen","sigma-protocol"],"repository":{"type":"git","url":"git+https://github.com/gthstepsecurity/2fapi-server.git"},"description":"Continuum Ghost Server — Zero-Knowledge Proof Verification Engine","maintainers":[{"name":"plu9in","email":"plu9in@gmail.com"}],"readme":"# @2fapi/server\n\n> **Continuum Ghost — The Secret That Doesn't Exist**\n>\n> Zero-Knowledge Proof verification engine for APIs.\n\nThe server **never sees, stores, or transmits** the client's secret. It stores only mathematical commitments — public values that are useless without the client's secret.\n\n## License\n\nThis software is licensed under the [Business Source License 1.1](./LICENSE).\n\n| Usage | Allowed? |\n|-------|----------|\n| Self-host for your own APIs | **Yes** |\n| Modify for internal use | **Yes** |\n| Read, audit, contribute | **Yes** |\n| Offer ZKP auth as a competing managed service | **No** |\n\nConverts to **Apache 2.0** on 2030-03-23.\n\nFor managed hosting, see [Continuum Ghost Cloud](https://2fapi.continuum-identity.com).\nFor alternative licensing: licensing@continuum-identity.com\n\n## Quick Start\n\n### With Docker Compose\n\n```bash\ngit clone https://github.com/gthstepsecurity/2fapi-server.git\ncd 2fapi-server\n\n# Configure credentials\ncp .env.example .env\n# Edit .env — set POSTGRES_PASSWORD and REDIS_PASSWORD\n\n# Start PostgreSQL + Redis\ndocker compose up -d\n\n# Install and run\nnpm install\nnpm run migrate\nnpm run dev\n```\n\nServer starts at `http://localhost:3000`. Health check: `http://localhost:3000/health`.\n\n### With npm\n\n```bash\nnpm install @2fapi/server\n```\n\n```typescript\nimport { createServer } from \"@2fapi/server\";\n\nconst app = createServer({\n  enrollClient: enrollmentService,\n  requestChallenge: challengeService.requestChallenge,\n  verifyProof: verificationService,\n  issueToken: accessControlService.issueToken,\n  validateToken: accessControlService.validateToken,\n  revokeClient: lifecycleService.revokeClient,\n  rotateCommitment: lifecycleService.rotateCommitment,\n  rateLimiting: {\n    global: { maxRequests: 10000, windowMs: 1000 },\n    perIp: { maxRequests: 100, windowMs: 1000 },\n  },\n});\n\nawait app.listen({ port: 3000 });\n```\n\n## Architecture\n\n5 bounded contexts, hexagonal architecture:\n\n```\nsrc/\n├── client-registration/      — Enrollment, commitment storage, rotation, revocation\n├── authentication-challenge/ — Nonce generation, session management\n├── zk-verification/          — Sigma proof verification, Fiat-Shamir\n├── api-access-control/       — Token issuance, audience restriction, validation\n├── security-monitoring/      — Lockout, audit trail, anomaly detection\n├── api-gateway/              — Fastify routes, middleware, rate limiting\n├── config/                   — Bootstrap, environment, service wiring\n└── shared/                   — Constant-time utils, rate limiters\n```\n\nEach bounded context follows hexagonal architecture:\n- **Domain**: models, ports (interfaces), services — zero external dependencies\n- **Application**: use cases implementing driving ports\n- **Infrastructure**: adapters (PostgreSQL, Redis, napi-rs crypto)\n\n## Requirements\n\n- **Node.js** >= 22\n- **PostgreSQL** >= 16\n- **Redis** >= 7\n- **napi-rs crypto module** (Ristretto255 via curve25519-dalek)\n\n## Security\n\n- 28-pass internal red team audit, 109 findings, 0 open\n- 1,940+ automated tests\n- Constant-time verification, timing-safe error responses\n- OPRF-based credential derivation — offline brute-force impossible\n- 2-of-2 secret sharing — secret never exists in cleartext\n- Provably secure under DLOG assumption on Ristretto255\n\n## Client SDK\n\nPair with [@2fapi/client-sdk](https://www.npmjs.com/package/@2fapi/client-sdk) (Apache 2.0) for client-side proof generation.\n\n## Protocol Specification\n\nSee [@2fapi/protocol-spec](https://www.npmjs.com/package/@2fapi/protocol-spec) (Apache 2.0) for the canonical protocol definition.\n","readmeFilename":"README.md"}