{"_id":"@acegalaxy/notion-vault","_rev":"2-0062b16ca3f7ca68081e59a48458074c","name":"@acegalaxy/notion-vault","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@acegalaxy/notion-vault","version":"0.1.0","keywords":["notion","vault","secrets","env","config","dotenv","secret-management"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","_id":"@acegalaxy/notion-vault@0.1.0","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"homepage":"https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs#readme","bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs/issues"},"dist":{"shasum":"9bab57dbb328971bf9aa678e379c6b643a05b309","tarball":"https://registry.npmjs.org/@acegalaxy/notion-vault/-/notion-vault-0.1.0.tgz","fileCount":26,"integrity":"sha512-gOYf0vW2X5XFkNSocpk6UbRP5BHKk2LTp0HDuo6Z4c2pBMxf9qxlQgnNj8oA98PucVG45dhEoWSPI+tONKmgdQ==","signatures":[{"sig":"MEYCIQDBezNIYxSHD+t6L1Zjynm2wzz6fdzISUQiEyM4J8PedwIhAKZeiGtWoRK5FTmhh/4itq0xH7T92w2owgGXRYj3Igc8","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57194},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"},"./package.json":"./package.json"},"gitHead":"6a2f18ed975c302a659380479b7aee22fa2ee23f","private":false,"scripts":{"test":"node --test test/*.test.js","build":"tsc","clean":"rm -rf dist","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"repository":{"url":"git+https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs.git","type":"git"},"_npmVersion":"11.12.1","description":"Load secrets from Notion vault databases into process.env. Supports multi-DB query, project/env filtering, alias expansion, in-memory TTL cache, and bootstrap row pattern.","directories":{},"_nodeVersion":"25.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/notion-vault_0.1.0_1778139314003_0.5188565614032377","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@acegalaxy/notion-vault","version":"0.1.1","description":"Load secrets from Notion vault databases into process.env. Supports multi-DB query, project/env filtering, alias expansion, in-memory TTL cache, and bootstrap row pattern.","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"},"./package.json":"./package.json"},"scripts":{"build":"tsc","prepublishOnly":"npm run build","clean":"rm -rf dist","test":"node --test test/*.test.js","pretest":"npm run build"},"keywords":["notion","vault","secrets","env","config","dotenv","secret-management"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","private":false,"engines":{"node":">=20"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs.git"},"bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs/issues"},"homepage":"https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs#readme","devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"gitHead":"3083d881c7d8f52c4488062513c2780969997c6f","_id":"@acegalaxy/notion-vault@0.1.1","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-U4XSzBfkq6TfL/TzUEzbgpAmQsxbjN0+vukOG4+sZeaKWRhCXa0d0K1fc7c5EbyRzVs3+OsWfyvNRHVdCRqeSA==","shasum":"6153e0a01899bbec7029ed4d8efc9756ab322cb1","tarball":"https://registry.npmjs.org/@acegalaxy/notion-vault/-/notion-vault-0.1.1.tgz","fileCount":26,"unpackedSize":57194,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEl4LeLHgJUHVPUDMCNwNdX1C1yb+f/4QiNbCnRonYMUAiBAu9eDkO+pYg3fz11NNYqRt8cGTVw2u4z9AX+WeyQTLA=="}]},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"directories":{},"maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/notion-vault_0.1.1_1778139549824_0.5816420454565825"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-07T07:35:13.863Z","modified":"2026-05-07T07:39:10.094Z","0.1.0":"2026-05-07T07:35:14.173Z","0.1.1":"2026-05-07T07:39:09.969Z"},"bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs/issues"},"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","homepage":"https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs#readme","keywords":["notion","vault","secrets","env","config","dotenv","secret-management"],"repository":{"type":"git","url":"git+https://github.com/acegalaxy-co/ace_commons-notion-vault-nodejs.git"},"description":"Load secrets from Notion vault databases into process.env. Supports multi-DB query, project/env filtering, alias expansion, in-memory TTL cache, and bootstrap row pattern.","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"readme":"# @acegalaxy/notion-vault\n\n[![npm version](https://img.shields.io/npm/v/@acegalaxy/notion-vault.svg)](https://www.npmjs.com/package/@acegalaxy/notion-vault)\n[![license](https://img.shields.io/npm/l/@acegalaxy/notion-vault.svg)](LICENSE)\n[![node](https://img.shields.io/node/v/@acegalaxy/notion-vault.svg)](https://nodejs.org)\n\n**Library only.** Load secrets from Notion vault databases into `process.env`.\n\nSupports multi-DB query, project/env filtering, alias expansion (backward compat for legacy key prefixes), in-memory TTL cache, and a bootstrap row pattern for self-describing project metadata.\n\nZero runtime dependencies — uses native `fetch` (Node 18+).\n\n## Install\n\n```bash\nnpm install @acegalaxy/notion-vault\n```\n\n## Setup\n\nCreate one or more Notion databases to store your secrets (one DB per project / scope is recommended). Each DB ID + reader integration token is configured via env vars in your local vault config file (e.g. `.env-vault` — git-ignored, chmod 600):\n\n```\n# Reader tokens — one per project + per host (LOCAL/PROD)\nNOTION_VAULT_<PROJECT>_READER_TOKEN_LOCAL=<notion-token>\nNOTION_VAULT_<PROJECT>_READER_TOKEN_PROD=<notion-token>\n\n# DB IDs — one per scope (per-project recommended for least-privilege)\nNOTION_VAULT_<PROJECT>_DB_ID=<notion-db-id>\nNOTION_VAULT_SHARED_INFRA_DB_ID=<notion-db-id>\nNOTION_VAULT_BOTS_WRITE_DB_ID=<notion-db-id>\nNOTION_VAULT_SHARED_CONFIG_DB_ID=...\n```\n\n## Library usage\n\n```js\nconst { VaultLoader, buildDatabasesFromEnv } = require('@acegalaxy/notion-vault');\nconst { parseEnvFile } = require('@acegalaxy/notion-vault/env-file');\n\nconst envFile = parseEnvFile('/path/to/.env-vault');\nconst loader = new VaultLoader({\n  token: envFile.NOTION_VAULT_MYPROJECT_READER_TOKEN_LOCAL,\n  databases: buildDatabasesFromEnv(envFile),\n  ttlMs: 10 * 60 * 1000, // 10 min\n});\n\nconst secrets = await loader.load({\n  projects: ['myproject', 'shared'],\n  env: process.env.NODE_ENV === 'production' ? 'PROD' : 'LOCAL',\n  injectAliases: true,\n});\nObject.assign(process.env, secrets);\n```\n\n## Bootstrap pattern\n\nInstead of hardcoding DB IDs in env files, you can store project metadata in a single bootstrap Notion DB and let projects discover their own vault DBs at startup:\n\n```js\nconst loader = await VaultLoader.fromBootstrap({\n  bootstrapToken: process.env.BOOTSTRAP_TOKEN,\n  bootstrapDbId: process.env.BOOTSTRAP_DB_ID,\n  project: 'myproject',\n  env: 'LOCAL',\n});\nconst secrets = await loader.load({ projects: ['myproject'], env: 'LOCAL' });\n```\n\n## How filters work\n\nEach row in a vault DB has:\n\n- `env` — multi-select: `PROD`, `LOCAL`, `DEV`, `ALL`\n- `project` (or `projects` for shared resources) — which projects use this key\n- `category` — `llm`, `notion`, `git`, `infra`, etc.\n- `active` — checkbox (rows can be deactivated without deletion)\n\nWhen you call `load({ projects, env })`:\n\n- `env`: row matches if `row.env` contains the requested env, OR contains `ALL`.\n- `projects`: row matches if `row.projects` intersects, OR contains `shared` (which applies to any project).\n- `active=false` rows are skipped by default (set `activeOnly: false` to include).\n\n## Alias expansion\n\nA `alias_keys` field on a row lists historical names (e.g. `FW_OPENAI_API_KEY, NEXUS_OPENAI_API_KEY`) so existing code reading old keys keeps working.\n\nDisable with `injectAliases: false` if you only want canonical names.\n\n## Caching\n\nThe first call to `load()` or `stats()` queries all DBs once and caches rows for 10 minutes (configurable). Subsequent calls re-filter cached rows without API calls. Call `invalidateCache()` to force a refetch.\n\n## Security notes\n\n- The library never logs secret values. `[info]` lines only show counts.\n- Use `stats()` to inspect what's in the vault without exposing values.\n- Reader tokens come from your vault config file which MUST be git-ignored and chmod 600.\n- Use the per-project least-privilege pattern: one Notion integration per project, scoped only to that project's DB.\n\n## License\n\nMIT © ACE Galaxy\n","readmeFilename":"README.md"}