{"_id":"@55387.ai/uniauth-server","_rev":"7-f3338494f432504871fe1870b23f02b5","name":"@55387.ai/uniauth-server","dist-tags":{"latest":"1.2.4"},"versions":{"1.0.0":{"name":"@55387.ai/uniauth-server","version":"1.0.0","keywords":["auth","authentication","middleware","jwt","sdk"],"_id":"@55387.ai/uniauth-server@1.0.0","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"dist":{"shasum":"b2e1003343f0471f1430f8ca7f82b716e1213533","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.0.0.tgz","fileCount":9,"integrity":"sha512-k8w8aqWpcLCs9+LplkAmXPSE3xD356NH1FwlZNlqVQe4Kgxj08ofDb4nxJfAxI9+5tBicnsQcAV9/Appy6U3Dw==","signatures":[{"sig":"MEUCIQChLkdIUDzgup7ybzfvovQtGHDjdv4TvcJTBnwGWpbK2gIgJ11b9ZnhKH17AhHB2tWwXHJXeP71Mk4KdPzFl6/w/E8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65746},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.mjs","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"bba62c84dd631b403dac8419c4daec80b51b69b8","scripts":{"dev":"tsup src/index.ts --format cjs,esm --dts --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","test:watch":"vitest"},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"_npmVersion":"11.6.2","description":"UniAuth Server SDK - Token verification for Node.js backends","directories":{},"_nodeVersion":"25.2.1","dependencies":{"jose":"^5.9.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/uniauth-server_1.0.0_1767013144107_0.3600271914346522","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@55387.ai/uniauth-server","version":"1.1.1","keywords":["auth","authentication","middleware","jwt","sdk"],"_id":"@55387.ai/uniauth-server@1.1.1","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"dist":{"shasum":"5fd10496f2da1c1132c72c7c90e733b085d888e4","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.1.1.tgz","fileCount":9,"integrity":"sha512-/OiIkPFmFBWPEBfQdTU8uFKAcqXSxg30f4ILwJO2xpoAS1U71DyGkjuMRxaPVyYG/M5zxZBwVEi5wxQhXw5Qyg==","signatures":[{"sig":"MEYCIQCxpioibTR7jfJOY7tph79cuR+FrRSIcObxISEf7FqhvQIhAIdJyru3Rv7OlKFNwhFOvpcsJutgJe8/XnVNTLqVb3xy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65771},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.mjs","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"47d2b9e892dc3d02f14e476945dbc8f961bd98ae","scripts":{"dev":"tsup src/index.ts --format cjs,esm --dts --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","test:watch":"vitest"},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"_npmVersion":"11.6.2","description":"UniAuth Server SDK - Token verification for Node.js backends","directories":{},"_nodeVersion":"25.2.1","dependencies":{"jose":"^5.9.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/uniauth-server_1.1.1_1767023172210_0.44574511013227314","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@55387.ai/uniauth-server","version":"1.1.2","keywords":["auth","authentication","middleware","jwt","sdk"],"_id":"@55387.ai/uniauth-server@1.1.2","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"dist":{"shasum":"1dcb6bc41f5b230ee60c735508f9319b5519814f","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.1.2.tgz","fileCount":9,"integrity":"sha512-LnL0TZodtFBbF6F1f42xoBy6wJXOYvu6/KoaEvo7B5R4pL/nApZDNVsfG83vp3n7J7QrUpJKV4RpnMlNC3nEUw==","signatures":[{"sig":"MEQCIHsrsyYuH5uNkhtcveaLG3d56+X/wzxkfgJSMU0rnwLnAiB/k59O8qQMby7q0vzC8qEwsUfj4X3G3UmwGvxuHDz2Qg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65771},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.mjs","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"731ac76835f0bf4e020f3851677d1c14daa6ab29","scripts":{"dev":"tsup src/index.ts --format cjs,esm --dts --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","test:watch":"vitest"},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"_npmVersion":"11.6.2","description":"UniAuth Server SDK - Token verification for Node.js backends","directories":{},"_nodeVersion":"25.2.1","dependencies":{"jose":"^5.9.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/uniauth-server_1.1.2_1768173518219_0.7695788891071911","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@55387.ai/uniauth-server","version":"1.2.0","keywords":["auth","authentication","middleware","jwt","sdk"],"_id":"@55387.ai/uniauth-server@1.2.0","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"dist":{"shasum":"4a663c4f0d59605e32600a13d4c7a5c616c79394","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.2.0.tgz","fileCount":9,"integrity":"sha512-NtCh6cFUc1q8aH2LM5WZ3fK3GCkBcWWO802WAg2MOQdzjM3isT5uZRbOak7q4ZVhSgJ7Xq3kF5iD/yqjzln7wQ==","signatures":[{"sig":"MEYCIQCvz4KuROCPFGrzAHDNqqKu+R609MZe6kvLiE/jgUNJJAIhAMvoHXTShMiHjdafuVxcK1zSLAOj7OykLlM0AVt4FEPF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68923},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.mjs","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"576d1618aa8602d9a2d17cec0f392fc9b33e817f","scripts":{"dev":"tsup src/index.ts --format cjs,esm --dts --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","test:watch":"vitest"},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"_npmVersion":"11.6.2","description":"UniAuth Server SDK - Token verification for Node.js backends","directories":{},"_nodeVersion":"25.2.1","dependencies":{"jose":"^5.9.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/uniauth-server_1.2.0_1768777412158_0.34529558712858033","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@55387.ai/uniauth-server","version":"1.2.1","keywords":["auth","authentication","middleware","jwt","sdk"],"_id":"@55387.ai/uniauth-server@1.2.1","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"dist":{"shasum":"92a2f40dfa4c05e486da2ac1bf9ddf6ee6c79d63","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.2.1.tgz","fileCount":7,"integrity":"sha512-3L4QstB5utVXfjqaW4FiGSTXKk5z8BG0pXUGpwc35qaw7pkJtgNY0Heqm0iT5WQSdqsOG+T48pSBQ9qSijKp3w==","signatures":[{"sig":"MEUCIHjc699DXGdR82iIYt8Y3VUyT/8PIECao22qi0sVTJ8+AiEAi6Krn2CItBhb6dozLiUEol2i5H8syoyXaUia7WCanuY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":83433},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.mjs","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"702f1df46a8e121a346601d6bf98ad038374b404","scripts":{"dev":"tsup src/index.ts --format cjs,esm --dts --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","test:watch":"vitest"},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"_npmVersion":"11.8.0","description":"UniAuth Server SDK - Token verification for Node.js backends","directories":{},"_nodeVersion":"25.5.0","dependencies":{"jose":"^5.9.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/uniauth-server_1.2.1_1770687447712_0.3089011267142321","host":"s3://npm-registry-packages-npm-production"}},"1.2.3":{"name":"@55387.ai/uniauth-server","version":"1.2.3","keywords":["auth","authentication","middleware","jwt","sdk"],"_id":"@55387.ai/uniauth-server@1.2.3","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"dist":{"shasum":"3e9ece25a9b621132554573035d342fd668c5195","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.2.3.tgz","fileCount":6,"integrity":"sha512-KIz6uZ+c095twPLQQj2xdqsFgLzrIEkX7kYhFzrpMd/mWLkWyIQAR+6oUskhGp6xAIptlqHYOSvrqnqE8JnR9A==","signatures":[{"sig":"MEQCID+2B071RFCuLsZsz7H57KdjTRv1VOt8v6ue3msFkvy5AiBXylTvLssUF1+D+OLhyMEQMThgt/7JK2T6oSJVuGSvWw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41660},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.mjs","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"d1df7088f5db2a020f67a20a81dd0b29d775e8ea","scripts":{"dev":"tsup src/index.ts --format cjs,esm --dts --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","test:watch":"vitest"},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"_npmVersion":"11.8.0","description":"UniAuth Server SDK - Token verification for Node.js backends","directories":{},"_nodeVersion":"25.5.0","dependencies":{"jose":"^5.9.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.5","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/uniauth-server_1.2.3_1770740933735_0.7444287458196852","host":"s3://npm-registry-packages-npm-production"}},"1.2.4":{"name":"@55387.ai/uniauth-server","version":"1.2.4","description":"UniAuth Server SDK - Token verification for Node.js backends","type":"module","main":"./dist/index.js","module":"./dist/index.mjs","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"publishConfig":{"access":"public"},"scripts":{"build":"tsup src/index.ts --format cjs,esm --dts --clean","dev":"tsup src/index.ts --format cjs,esm --dts --watch","test":"vitest run","test:watch":"vitest","lint":"eslint src --ext .ts","clean":"rm -rf dist"},"dependencies":{"jose":"^5.9.6"},"devDependencies":{"@types/node":"^22.10.2","tsup":"^8.3.5","typescript":"^5.7.2","vitest":"^2.1.8"},"keywords":["auth","authentication","middleware","jwt","sdk"],"gitHead":"9122e48985c5413826715462e3ef89140d044a93","_id":"@55387.ai/uniauth-server@1.2.4","_nodeVersion":"25.5.0","_npmVersion":"11.8.0","dist":{"integrity":"sha512-8Bi6J4+eB1jEGdvahtsny9jZdmgcd4jswEclNq23umtX2fxJZPyhXI6UsLNNWipC45XaVglQxzBjeVUbuepU8A==","shasum":"57a17199cd5f4b9d8fc648b76d5deffe358a0974","tarball":"https://registry.npmjs.org/@55387.ai/uniauth-server/-/uniauth-server-1.2.4.tgz","fileCount":7,"unpackedSize":49589,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICrIT/0J16XZ+LKPQc1eTX53RrnjQt09gh1dduFQ/wAUAiEAnIxxO1d/gp2P/XIO2cT+Yp3EuHRuqc5p98jBGoJeGpo="}]},"_npmUser":{"name":"rosslin","email":"atai829525@gmail.com"},"directories":{},"maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/uniauth-server_1.2.4_1770856742843_0.46541006002872964"},"_hasShrinkwrap":false}},"time":{"created":"2025-12-29T12:59:03.997Z","modified":"2026-02-12T00:39:03.151Z","1.0.0":"2025-12-29T12:59:04.244Z","1.1.1":"2025-12-29T15:46:12.371Z","1.1.2":"2026-01-11T23:18:38.373Z","1.2.0":"2026-01-18T23:03:32.345Z","1.2.1":"2026-02-10T01:37:27.883Z","1.2.3":"2026-02-10T16:28:53.910Z","1.2.4":"2026-02-12T00:39:03.009Z"},"keywords":["auth","authentication","middleware","jwt","sdk"],"description":"UniAuth Server SDK - Token verification for Node.js backends","maintainers":[{"name":"rosslin","email":"atai829525@gmail.com"}],"readme":"# @55387.ai/uniauth-server\n\n> UniAuth Backend SDK — Token verification & middleware for Node.js servers.\n>\n> UniAuth 后端 SDK — Node.js 服务端令牌验证和中间件。\n\n**Version / 版本:** 1.2.2\n\n## Install / 安装\n\n```bash\nnpm install @55387.ai/uniauth-server\n# or / 或\npnpm add @55387.ai/uniauth-server\n```\n\n## Quick Start / 快速开始\n\n```typescript\nimport { UniAuthServer } from '@55387.ai/uniauth-server';\n\nconst auth = new UniAuthServer({\n  baseUrl: 'https://sso.55387.xyz',\n  clientId: process.env.UNIAUTH_CLIENT_ID!,\n  clientSecret: process.env.UNIAUTH_CLIENT_SECRET!,\n});\n\n// Verify token / 验证令牌\nconst payload = await auth.verifyToken(accessToken);\nconsole.log('User ID:', payload.sub);\n```\n\n## Middleware / 中间件\n\n### Express\n\n```typescript\nimport express from 'express';\nconst app = express();\n\napp.use('/api/*', auth.middleware());\n\napp.get('/api/profile', (req, res) => {\n  res.json({ user: req.user, payload: req.authPayload });\n});\n```\n\n### Hono\n\n```typescript\nimport { Hono } from 'hono';\nconst app = new Hono();\n\napp.use('/api/*', auth.honoMiddleware());\n\napp.get('/api/profile', (c) => {\n  return c.json({ user: c.get('user') });\n});\n```\n\n## SSO Backend Proxy / SSO 后端代理\n\nWhen your app is a **Confidential Client**, token exchange must happen on the server.\n\n当应用配置为 **机密客户端** 时，Token 交换必须在服务端完成。\n\n```\nUser → Frontend → /api/auth/login → Backend → redirect to UniAuth SSO\n                                                      ↓\nUser ← Frontend ← redirect ← Backend (set cookie) ← SSO callback\n                                      ↑\n                         Backend exchanges code with client_secret\n```\n\nSee full implementation: [AI Integration Guide](../../docs/AI_INTEGRATION_GUIDE.md#2b-backend-proxy-confidential-client)\n\n完整实现见: [集成指南](../../docs/AI_INTEGRATION_GUIDE.md#2b-backend-proxy-confidential-client)\n\n## Token Introspection / 令牌内省\n\nRFC 7662 compliant token introspection:\n\n```typescript\nconst result = await auth.introspectToken(accessToken);\n\nif (result.active) {\n  console.log('User:', result.sub);\n  console.log('Scope:', result.scope);\n}\n```\n\n## API Reference / API 参考\n\n### Config / 配置\n\n```typescript\ninterface UniAuthServerConfig {\n  baseUrl: string;        // UniAuth server URL\n  clientId: string;       // OAuth2 client ID\n  clientSecret: string;   // OAuth2 client secret\n  jwtPublicKey?: string;  // JWT public key (local verification)\n}\n```\n\n### Methods / 方法\n\n| Method | Description / 说明 |\n|--------|-----------|\n| `verifyToken(token)` | Verify access token / 验证访问令牌 |\n| `introspectToken(token)` | RFC 7662 introspection / 令牌内省 |\n| `isTokenActive(token)` | Check if token is active / 检查令牌状态 |\n| `getUser(userId)` | Get user info / 获取用户信息 |\n| `middleware()` | Express middleware / Express 中间件 |\n| `honoMiddleware()` | Hono middleware / Hono 中间件 |\n| `clearCache()` | Clear token cache / 清除令牌缓存 |\n\n### Token Verification Flow / 令牌验证流程\n\n```\nverifyToken(token)\n  │\n  ├─ 1. POST /api/v1/auth/verify (App Key + Secret)\n  │     ↓ success → return payload\n  │     ↓ 404 or network error\n  │\n  ├─ 2. POST /api/v1/oauth2/introspect (Basic Auth, RFC 7662)\n  │     ↓ active:true → return payload\n  │     ↓ fail\n  │\n  └─ 3. Local JWT verification (if jwtPublicKey configured)\n```\n\n### Types / 类型\n\n```typescript\ninterface TokenPayload {\n  sub: string;              // User ID\n  iss?: string;             // Issuer\n  aud?: string | string[];  // Audience\n  exp: number;              // Expiration\n  iat: number;              // Issued at\n  scope?: string;           // Scopes\n  phone?: string;           // Phone number\n  email?: string;           // Email\n}\n```\n\n## Error Handling / 错误处理\n\n```typescript\nimport { ServerAuthError, ServerErrorCode } from '@55387.ai/uniauth-server';\n\ntry {\n  await auth.verifyToken(token);\n} catch (error) {\n  if (error instanceof ServerAuthError) {\n    switch (error.code) {\n      case ServerErrorCode.INVALID_TOKEN:  // Invalid / 令牌无效\n      case ServerErrorCode.TOKEN_EXPIRED:  // Expired / 令牌过期\n    }\n  }\n}\n```\n\n## 🤖 AI Agent Prompts / AI 智能体提示词\n\nThis package includes an AI-ready integration prompt. Copy it into your AI coding assistant (Claude, Cursor, Copilot, etc.) to generate a complete backend protection setup automatically.\n\n本包附带 AI 集成提示词。将其复制到 AI 编程助手中，即可自动生成完整的后端保护代码。\n\n```bash\n# After install, find the prompt at:\n# 安装后，提示词文件位于：\ncat node_modules/@55387.ai/uniauth-server/ai-prompts/backend-protection.md\n```\n\n> [!TIP]\n> Replace placeholders like `YOUR_UNIAUTH_URL` and `YOUR_CLIENT_SECRET` before pasting into your AI assistant.\n> 粘贴到 AI 助手前，请替换 `YOUR_UNIAUTH_URL` 和 `YOUR_CLIENT_SECRET` 等占位符。\n\nSee all prompts: [docs/ai-prompts/](../../docs/ai-prompts/README.md)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}