{"_id":"@aceint/auth","_rev":"3-95c76f5d0029b83ed8699501bc831d07","name":"@aceint/auth","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@aceint/auth","version":"1.0.0","keywords":["aceint","auth","saas","sdk","typescript"],"license":"MIT","_id":"@aceint/auth@1.0.0","maintainers":[{"name":"aceint","email":"sdk.aceint@gmail.com"}],"dist":{"shasum":"ddda8aa7e8c819bd38aba39b05bfd1384afce1da","tarball":"https://registry.npmjs.org/@aceint/auth/-/auth-1.0.0.tgz","fileCount":9,"integrity":"sha512-Nuw0ajSfFbr3QyCulKenIvua3EvvNLqReRSv9V8V+DYVeqEeSDGze9cRV50Y57m3FNAWxOyF8NhrgAtbwlNRHA==","signatures":[{"sig":"MEUCIBYHa5O/52yH/u4t3gyD5+ohgNKaZVld0au7t8rgKbKaAiEAhaqnkMLLfoD6lr/AAkksdgpCsRCxCR+jMpcUz30LnyU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47754},"main":"dist/index.cjs","types":"dist/index.d.ts","module":"dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"aceint","email":"sdk.aceint@gmail.com"},"_npmVersion":"11.5.1","description":"Thin TypeScript SDK for Aceint public SaaS auth APIs.","directories":{},"sideEffects":false,"_nodeVersion":"24.6.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^24.6.1"},"_npmOperationalInternal":{"tmp":"tmp/auth_1.0.0_1775047273858_0.44530099718769844","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@aceint/auth","version":"1.0.1","keywords":["aceint","auth","saas","sdk","typescript"],"license":"MIT","_id":"@aceint/auth@1.0.1","maintainers":[{"name":"aceint","email":"sdk.aceint@gmail.com"}],"dist":{"shasum":"5d72b48add57f23de7ffb9e4e537e461d026f959","tarball":"https://registry.npmjs.org/@aceint/auth/-/auth-1.0.1.tgz","fileCount":9,"integrity":"sha512-ZScFXdwGlqgGvD8snKw4GlHxA0bAGEDgKOj3o3HgVMTzr+72IBxiK07zg8ktJdOCXZVS+40Z4z46nqi7GoMQzA==","signatures":[{"sig":"MEUCIQCCu74fiSfY0L4QP1ljECFevmKS6BX0F5of853TVtRw4QIgNch4xcpn5kGvwpHwOI2KDJfATsJQlwVaty7eUnGBStc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48822},"main":"dist/index.cjs","types":"dist/index.d.ts","module":"dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup"},"_npmUser":{"name":"aceint","email":"sdk.aceint@gmail.com"},"_npmVersion":"11.5.1","description":"Thin TypeScript SDK for Aceint public SaaS auth APIs.","directories":{},"sideEffects":false,"_nodeVersion":"24.6.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^24.6.1"},"_npmOperationalInternal":{"tmp":"tmp/auth_1.0.1_1775131961305_0.041547733980910495","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@aceint/auth","version":"1.0.2","description":"Thin TypeScript SDK for Aceint public SaaS auth APIs.","license":"MIT","type":"module","main":"dist/index.cjs","module":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"sideEffects":false,"engines":{"node":">=18"},"publishConfig":{"access":"public"},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run"},"keywords":["aceint","auth","saas","sdk","typescript"],"devDependencies":{"@types/node":"^24.6.1","tsup":"^8.5.0","typescript":"^5.9.3","vitest":"^3.2.4"},"_id":"@aceint/auth@1.0.2","_nodeVersion":"24.6.0","_npmVersion":"11.5.1","dist":{"integrity":"sha512-Q7iN9RQb5bMBbLOw0ry1VIpTXunGafEwFe/3olX/H+gguFeAhAcEfvrwTq0o559hv3n7UPMIUzWW1CNkyGlIvw==","shasum":"891483bc763673776ae44e089a8a89bd07175bf2","tarball":"https://registry.npmjs.org/@aceint/auth/-/auth-1.0.2.tgz","fileCount":9,"unpackedSize":48842,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD/LujIrQ/q+PklZxTqg14Y1leEJTCPA/Z6T0ra1MhXdwIgBXn5FS+BIX04B0mQ/jq0Onzh0bQ3hIYbIdo3rDrgV0s="}]},"_npmUser":{"name":"aceint","email":"sdk.aceint@gmail.com"},"directories":{},"maintainers":[{"name":"aceint","email":"sdk.aceint@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/auth_1.0.2_1775162136443_0.19088326641120146"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-01T12:41:13.713Z","modified":"2026-04-02T20:35:36.703Z","1.0.0":"2026-04-01T12:41:13.999Z","1.0.1":"2026-04-02T12:12:41.528Z","1.0.2":"2026-04-02T20:35:36.584Z"},"license":"MIT","keywords":["aceint","auth","saas","sdk","typescript"],"description":"Thin TypeScript SDK for Aceint public SaaS auth APIs.","maintainers":[{"name":"aceint","email":"sdk.aceint@gmail.com"}],"readme":"# `@aceint/auth`\n\nLow-level TypeScript SDK for Aceint client-auth token issuance, refresh, and revoke flows.\n\n## Use This Package For\n\n- issuing access and refresh tokens from your backend\n- refreshing access tokens with a valid refresh token\n- revoking a refresh token or token family\n\nThis package is intended for backend or server environments.\n\nDo not use it directly from your frontend application. Frontend apps should call your backend, and your backend should call Aceint.\n\nIf you are integrating Aceint AI interview session APIs and want the SDK to manage token reuse and refresh on your backend, use `@aceint/ai-interviews`.\n\n## Requirements\n\n- Node.js `>=18`\n- Aceint client credentials from the Aceint `Credentials` tab\n\n## Installation\n\n```bash\nnpm install @aceint/auth\n```\n\n## Public Modes\n\nThe SDK uses explicit modes instead of raw URLs.\n\n- `dev` → `https://dev.aceint.ai/backend/api/v1`\n- `prod` → `https://interview.aceint.ai/backend/api/v1`\n\nUse `dev` for development, QA, and integration testing.\n\nUse `prod` for live production traffic.\n\n## Quick Start\n\n```ts\nimport { SaasAuthClient } from '@aceint/auth';\n\nconst client = new SaasAuthClient({\n  mode: 'dev',\n  clientPublicId: process.env.ACEINT_CLIENT_PUBLIC_ID!,\n  apiKey: process.env.ACEINT_API_KEY!,\n  apiSecret: process.env.ACEINT_API_SECRET!,\n});\n\nconst token = await client.getToken({ accessTtl: '15m' });\nconsole.log(token.access_token);\n```\n\nSwitch `mode` to `prod` when you are ready for production traffic.\n\n## Credential Mapping\n\nPass the credential values exactly as issued in Aceint:\n\n- `clientPublicId` -> `client_public_id`\n- `apiKey` -> `ACEINT_API_KEY`\n- `apiSecret` -> `ACEINT_API_SECRET`\n\nStore these values only in your backend environment or secret manager.\n\n## Supported TTL Values\n\n- `15m`\n- `30m`\n- `1h`\n- `6h`\n- `24h`\n\n`never` is not supported for `access_ttl`. Access tokens always expire.\n\n`never` applies only to credential-side `refresh_ttl` policies, not to `access_ttl`.\n\n## Token Lifetime Fields\n\nSuccessful token responses include:\n\n- `expires_in`: seconds until the access token expires\n- `refresh_expires_in`: seconds until the refresh token expires\n\n## API\n\n### `new SaasAuthClient(options)`\n\nCreates a client configured for one Aceint environment and one set of client credentials.\n\n### `client.getToken(options?)`\n\nUses the configured mode and credentials to call `POST /client-auth/token`.\n\n```ts\nconst token = await client.getToken({ accessTtl: '15m' });\n```\n\nAllowed access TTL values for `getToken`: `15m`, `30m`, `1h`, `6h`, `24h`.\n\n### `client.refreshToken(input)`\n\nCalls `POST /client-auth/refresh`.\n\n```ts\nconst nextToken = await client.refreshToken({\n  refreshToken: token.refresh_token,\n  accessTtl: '30m',\n});\n```\n\nAllowed access TTL values for `refreshToken`: `15m`, `30m`, `1h`, `6h`, `24h`.\n\n### `client.revokeToken(input)`\n\nCalls `POST /client-auth/revoke`.\n\n```ts\nconst revoked = await client.revokeToken({\n  refreshToken: token.refresh_token,\n  revokeFamily: true,\n});\n```\n\n## Example Flow\n\n```ts\nimport { SaasAuthClient } from '@aceint/auth';\n\nconst client = new SaasAuthClient({\n  mode: 'dev',\n  clientPublicId: process.env.ACEINT_CLIENT_PUBLIC_ID!,\n  apiKey: process.env.ACEINT_API_KEY!,\n  apiSecret: process.env.ACEINT_API_SECRET!,\n});\n\nconst token = await client.getToken({ accessTtl: '15m' });\n\n// Use token.access_token against your protected Aceint APIs.\n\nconst refreshed = await client.refreshToken({\n  refreshToken: token.refresh_token,\n  accessTtl: '15m',\n});\n\nawait client.revokeToken({\n  refreshToken: refreshed.refresh_token,\n  revokeFamily: true,\n});\n```\n\n## Recommended Integration Pattern\n\nUse this package inside a reusable backend service layer such as `AceintService`.\n\nRecommended request flow:\n\n`frontend -> your backend -> AceintService -> Aceint API`\n\nThe SDK is intentionally thin. Your backend service layer should decide when to:\n\n- reuse an active access token\n- refresh an expired access token\n- request a brand-new token with stored credentials\n- attach `Authorization: Bearer <access_token>` to upstream Aceint API calls\n\nFor Aceint AI interview session integrations, `@aceint/ai-interviews` is the higher-level package built on top of this one.\n\n## Response Types\n\n```ts\ntype TokenResponse = {\n  access_token: string;\n  refresh_token: string;\n  expires_in: number;\n  refresh_expires_in: number;\n  token_type: 'Bearer';\n};\n\ntype RevokeResponse = {\n  success: boolean;\n  revoked: Record<string, unknown> | null;\n};\n```\n\n## Error Handling\n\nThe SDK throws `SaasAuthError` for request failures. It preserves:\n\n- backend message\n- HTTP status code\n- parsed response body when available\n\n## Notes\n\n- This SDK does not cache tokens.\n- This SDK does not auto-refresh tokens for you.\n- This SDK is the low-level auth layer, not the full AI interview session SDK.\n","readmeFilename":"README.md"}