{"_id":"@2stars/verifai-web","_rev":"4-0fa4de146e8ca3fb6939a57a744a04a4","name":"@2stars/verifai-web","dist-tags":{"latest":"3.3.0"},"versions":{"3.1.0":{"name":"@2stars/verifai-web","version":"3.1.0","keywords":["2stars","verifai","device-trust","fingerprint","behavioral-biometrics","fraud-detection","zero-knowledge"],"license":"MIT","_id":"@2stars/verifai-web@3.1.0","maintainers":[{"name":"omriak","email":"omriakon111@gmail.com"}],"homepage":"https://github.com/2stars-io/verifai-web#readme","bugs":{"url":"https://github.com/2stars-io/verifai-web/issues"},"dist":{"shasum":"c7a3a25a9a88efaaabf21f68410d5cc59145ed93","tarball":"https://registry.npmjs.org/@2stars/verifai-web/-/verifai-web-3.1.0.tgz","fileCount":9,"integrity":"sha512-h8eare0PJz+dEoYa5+9Y3w97BL+yZRs4rSPBucg780cdPxBEKu6lYPrcnK+UTT4jtVW+Y9c9RJVIOXJm9h1hJA==","signatures":[{"sig":"MEUCIElvzf9EINKtA8WrOLrM/Rf3SOEbsCIKR2IYExvGZXlzAiEAkQgy9v0TQYGTy2tsVg+zDkVFgT1SbuiyFTsXbrrkb+I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":44203},"main":"src/index.js","type":"module","engines":{"node":">=18"},"exports":{".":{"import":"./src/index.js","default":"./src/index.js"}},"gitHead":"474ad44255bb574990e5766efefc390ff68c39f2","scripts":{"test":"node test/smoke.mjs"},"_npmUser":{"name":"omriak","email":"omriakon111@gmail.com"},"repository":{"url":"git+https://github.com/2stars-io/verifai-web.git","type":"git"},"_npmVersion":"11.12.1","description":"Zero-knowledge device-trust SDK for browsers. Signal hashes + behavioral biometrics (mouse, keystroke, scroll) — pairs with the 2Stars VerifAI backend on api.2stars.io/verifai/v1.","directories":{},"_nodeVersion":"24.15.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/verifai-web_3.1.0_1778958579246_0.4567113851963902","host":"s3://npm-registry-packages-npm-production"}},"3.2.0":{"name":"@2stars/verifai-web","version":"3.2.0","keywords":["2stars","verifai","device-trust","fingerprint","behavioral-biometrics","fraud-detection","zero-knowledge"],"license":"MIT","_id":"@2stars/verifai-web@3.2.0","maintainers":[{"name":"omriak","email":"omriakon111@gmail.com"},{"name":"warodri","email":"warodri@gmail.com"}],"homepage":"https://github.com/2stars-io/verifai-web#readme","bugs":{"url":"https://github.com/2stars-io/verifai-web/issues"},"dist":{"shasum":"1f7da6caccb3a1a387052a0862ffdb013e300965","tarball":"https://registry.npmjs.org/@2stars/verifai-web/-/verifai-web-3.2.0.tgz","fileCount":9,"integrity":"sha512-4TydEMBDNRBWjAb4GrxoCSk1Bia1e5mTvQFYQnX5o5U5G35DwqO8xekmWTE4fZruQroCy5PTHDVHro4yV5Yi9A==","signatures":[{"sig":"MEUCIC/vacDz1uOYmnDNztDFgAEvfqow+Rp4S4/Kz70AR55RAiEA6XN5HGEB7Pf70NwNiaRAjrsA0iX2eS/nrQPPGTvIXfo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47356},"main":"src/index.js","type":"module","engines":{"node":">=18"},"exports":{".":{"import":"./src/index.js","default":"./src/index.js"}},"gitHead":"474ad44255bb574990e5766efefc390ff68c39f2","scripts":{"test":"node test/smoke.mjs"},"_npmUser":{"name":"omriak","email":"omriakon111@gmail.com"},"repository":{"url":"git+https://github.com/2stars-io/verifai-web.git","type":"git"},"_npmVersion":"11.12.1","description":"Zero-knowledge device-trust SDK for browsers. Signal hashes + behavioral biometrics (mouse, keystroke, scroll) — pairs with the 2Stars VerifAI backend on api.2stars.io/verifai/v1.","directories":{},"_nodeVersion":"24.15.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/verifai-web_3.2.0_1782991729652_0.6785986315093506","host":"s3://npm-registry-packages-npm-production"}},"3.3.0":{"name":"@2stars/verifai-web","version":"3.3.0","description":"Zero-knowledge device-trust SDK for browsers. Signal hashes + behavioral biometrics (mouse, keystroke, scroll) — pairs with the 2Stars VerifAI backend on api.2stars.io/verifai/v1.","type":"module","main":"src/index.js","exports":{".":{"import":"./src/index.js","default":"./src/index.js"}},"scripts":{"test":"node test/smoke.mjs"},"engines":{"node":">=18"},"repository":{"type":"git","url":"git+https://github.com/2stars-io/verifai-web.git"},"bugs":{"url":"https://github.com/2stars-io/verifai-web/issues"},"homepage":"https://github.com/2stars-io/verifai-web#readme","keywords":["2stars","verifai","device-trust","fingerprint","behavioral-biometrics","fraud-detection","zero-knowledge"],"license":"MIT","publishConfig":{"access":"public"},"gitHead":"474ad44255bb574990e5766efefc390ff68c39f2","_id":"@2stars/verifai-web@3.3.0","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-4RMDCZDHtiJ9gTsg01P3L8gsT/PTGZws8oZdjqOLFZU1UHqW1ri4oZiG3p+EZJNCRTzIsIYe4Wo2R6Y7PkOiNQ==","shasum":"b74c42e4d4699d3cd0b37700066deb3350733235","tarball":"https://registry.npmjs.org/@2stars/verifai-web/-/verifai-web-3.3.0.tgz","fileCount":10,"unpackedSize":52443,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDbWK0z+mXV/mCyGZKs3RIxnyrLsrCVB9iqgtt4dISoYwIgOU9V9oMHts0jXAx0FXEJ/yHTUl4P3ix815prFfITE7s="}]},"_npmUser":{"name":"omriak","email":"omriakon111@gmail.com"},"directories":{},"maintainers":[{"name":"omriak","email":"omriakon111@gmail.com"},{"name":"warodri","email":"warodri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/verifai-web_3.3.0_1785490996529_0.8522494399201981"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-16T19:09:39.117Z","modified":"2026-07-31T09:43:16.838Z","3.1.0":"2026-05-16T19:09:39.374Z","3.2.0":"2026-07-02T11:28:49.801Z","3.3.0":"2026-07-31T09:43:16.646Z"},"bugs":{"url":"https://github.com/2stars-io/verifai-web/issues"},"license":"MIT","homepage":"https://github.com/2stars-io/verifai-web#readme","keywords":["2stars","verifai","device-trust","fingerprint","behavioral-biometrics","fraud-detection","zero-knowledge"],"repository":{"type":"git","url":"git+https://github.com/2stars-io/verifai-web.git"},"description":"Zero-knowledge device-trust SDK for browsers. Signal hashes + behavioral biometrics (mouse, keystroke, scroll) — pairs with the 2Stars VerifAI backend on api.2stars.io/verifai/v1.","maintainers":[{"name":"omriak","email":"omriakon111@gmail.com"},{"name":"warodri","email":"warodri@gmail.com"}],"readme":"# @2stars/verifai-web\n\nZero-knowledge device trust for browser apps. Same surface as [`com.github.2stars-io:verifai-android`](https://github.com/2stars-io/verifai-android) — pairs with the same backend at `https://api.2stars.io/verifai/v1`.\n\n```js\nimport { VerifAI } from '@2stars/verifai-web';\n\nVerifAI.init({ apiKey: 'hbs_live_…' });\nVerifAI.attachPasswordField(document.getElementById('password'));\n\nconst r = await VerifAI.verify(userEmail);\nswitch (r.status) {\n  case 'TRUSTED':    allow(); break;\n  case 'NEW_DEVICE': showApprovalPending(r.sessionId); break;\n  case 'REJECTED':   blockWith(r.reason); break;\n  default:           retryOrError();\n}\n```\n\n## Install\n\n```bash\nnpm install @2stars/verifai-web\n```\n\nOr via `<script type=\"module\">` if you prefer no bundler:\n\n```html\n<script type=\"module\">\n  import { VerifAI } from 'https://unpkg.com/@2stars/verifai-web/src/index.js';\n  VerifAI.init({ apiKey: 'hbs_live_…' });\n</script>\n```\n\nPure ESM. No build step. Works in every evergreen browser. Node ≥ 18 for the test harness.\n\n## What this SDK does\n\nThree independent axes of trust, each opt-in by your API key's feature flags:\n\n| Axis | Catches | Feature flag |\n|---|---|---|\n| **Device fingerprint** (11 signal categories — UA, locale, canvas, WebGL, audio, hardware, etc.) | Different browser / device | `verifai-patterns` + `verifai-verification` |\n| **Behavioral biometrics** (mouse velocity / curvature, click rhythm, cursor region, scroll velocity, keystroke flight time + bigram timing) | Wrong human on right browser | `verifai-behavioral` |\n| **Server-side patterns** | Re-registration cadence, multi-user device, long absence, impossible travel | always-on alongside verification |\n\nEverything is hashed in the browser. The server only ever sees opaque SHA-256 fingerprints.\n\n## Full API surface\n\n| Method | Purpose |\n|---|---|\n| `init(opts)` | One-time SDK init. `opts = { apiKey, baseUrl?, timeoutMs? }` |\n| `register(userId)` | First-ever login on this browser |\n| `verify(userId)` | Every subsequent login |\n| `getTrustScore(userId)` | Lookup current trust level + score |\n| `listDevices(userId)` | All trusted devices for the user |\n| `removeDevice(deviceId)` | Forget a device |\n| `approveDevice(sessionId, approvedBy?)` | Approve another device from this trusted one |\n| `rejectDevice(sessionId, reason?)` | Reject a pending session |\n| `isSameNetwork(remoteIP)` | Local IP comparison for proximity gates |\n| `attachPasswordField(input)` | Capture keystroke timing on a password field |\n| `getBehavioralCapture()` | Live counts of captured gestures (debug UI) |\n\n## Response shape (verify)\n\n```ts\n{\n  status: 'TRUSTED' | 'NEW_DEVICE' | 'PENDING' | 'REJECTED' | 'FEATURE_DISABLED' | 'ERROR',\n  trustScore: number,                         // 0-100 composite (3.2.0+ server)\n  trustLevel: 'BASELINE' | 'MEDIUM' | 'HIGH' | 'VERY_HIGH',\n  deviceId: string,\n  sessionId: string | null,                   // present on NEW_DEVICE\n  scoreBreakdown?: Record<string, number>,    // per-axis 0-100 (3.2.0+ server)\n  behavioral?: BehavioralReport,\n  patterns?: PatternsReport,\n  strictMode?: StrictModeReport,\n  advanced?: AdvancedReport,                  // 3.2.0+ server\n  reason?: string,\n  error?: string,\n}\n```\n\n## Versioning\n\nCurrent: **3.1.0** — 11 signal categories, 6 mouse-behavioral categories + 3 keystroke categories. Mirror of the Android SDK's behavioral coverage adapted to web inputs.\n\n## Privacy\n\n- **No raw signals leave the browser.** Every signal is hashed locally with a per-device salt.\n- **No tracking pixels.** Calls go only to the API base you configure (default `https://api.2stars.io/verifai/v1`).\n- **No third-party deps at runtime.** Pure browser APIs.\n\n## Companion SDKs\n\n- [`com.github.2stars-io:verifai-android`](https://github.com/2stars-io/verifai-android) — same surface for Android\n- [`@2stars/video-js`](https://github.com/2stars-io/video-js) — 2Stars video platform core SDK\n- [OpenAPI spec](https://api.2stars.io/openapi/verifai.json) — generate a client in any language\n\n## License\n\nMIT — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}