{"_id":"@ai-sdk-byok/drizzle","name":"@ai-sdk-byok/drizzle","dist-tags":{"latest":"0.2.0"},"versions":{"0.2.0":{"name":"@ai-sdk-byok/drizzle","version":"0.2.0","description":"Drizzle SQL storage adapter for ai-sdk-byok.","license":"MIT","homepage":"https://github.com/Xyri1/ai-sdk-byok#readme","repository":{"type":"git","url":"git+https://github.com/Xyri1/ai-sdk-byok.git","directory":"packages/drizzle"},"bugs":{"url":"https://github.com/Xyri1/ai-sdk-byok/issues"},"type":"module","sideEffects":false,"engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./migrations/*.sql":"./migrations/*.sql"},"dependencies":{"ai-sdk-byok":"0.2.0"},"peerDependencies":{"drizzle-orm":">=0.41.0"},"devDependencies":{"drizzle-orm":"^0.41.0"},"gitHead":"cff83260a3c7842fe854831db7119edb6f96ef2f","_id":"@ai-sdk-byok/drizzle@0.2.0","_nodeVersion":"24.13.0","_npmVersion":"11.18.0","dist":{"integrity":"sha512-MzhpcMZj381j0NLoL8zQqvCWhrDabReQo91/PdtSFa/wRLw8ms1HGUY2u31brQv1vHXRXfnu6ozYMIdEYSm2+Q==","shasum":"b170b184b4f8aa869af0bb39593f352a4a4687b3","tarball":"https://registry.npmjs.org/@ai-sdk-byok/drizzle/-/drizzle-0.2.0.tgz","fileCount":7,"unpackedSize":51804,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDqPtu2t3O/3q7lAhitCjUnHePv3VFI3SSsfsRPF5GlRwIgd4GUAH2aXDPXH/kjkYqWarBv5bVOOQnODfYjZVo4wps="}]},"_npmUser":{"name":"xyril","email":"tsuixyril@gmail.com"},"directories":{},"maintainers":[{"name":"xyril","email":"tsuixyril@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/drizzle_0.2.0_1784447269948_0.9067898627857534"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-19T07:47:49.841Z","0.2.0":"2026-07-19T07:47:50.083Z","modified":"2026-07-19T07:47:50.250Z"},"maintainers":[{"name":"xyril","email":"tsuixyril@gmail.com"}],"description":"Drizzle SQL storage adapter for ai-sdk-byok.","homepage":"https://github.com/Xyri1/ai-sdk-byok#readme","repository":{"type":"git","url":"git+https://github.com/Xyri1/ai-sdk-byok.git","directory":"packages/drizzle"},"bugs":{"url":"https://github.com/Xyri1/ai-sdk-byok/issues"},"license":"MIT","readme":"# @ai-sdk-byok/drizzle\n\nDrizzle-backed PostgreSQL storage adapter for [`ai-sdk-byok`](https://github.com/Xyri1/ai-sdk-byok). Credentials are encrypted in trusted application code before they reach SQL.\n\n## Install\n\n```sh\nnpm install ai-sdk-byok @ai-sdk-byok/drizzle drizzle-orm\n```\n\n`drizzle-orm` is a peer dependency. Install and configure a PostgreSQL-compatible Drizzle driver in the application; this package does not create connections or own pooling.\n\n## Requirements\n\n- Node.js 22 or newer.\n- A PostgreSQL database.\n- A caller-owned Drizzle database instance.\n- Trusted server-side code for the master key and credential retrieval.\n\nThe initial supported dialect is `postgres`. SQLite is not supported by this adapter yet.\n\n## Migration setup\n\nApply [`migrations/0001_ai_sdk_byok_init.sql`](migrations/0001_ai_sdk_byok_init.sql) to the application database. When installed from npm, the file is available at `node_modules/@ai-sdk-byok/drizzle/migrations/0001_ai_sdk_byok_init.sql` and can be copied into the application's migrations directory.\n\nApplications using Drizzle Kit can instead generate a migration from the exported `aiSdkByokKeys` schema. Use either the shipped SQL migration or the generated equivalent, not both.\n\n## Usage\n\n`db` is the application's configured Drizzle PostgreSQL database:\n\n```ts\nimport { createByokManager } from 'ai-sdk-byok';\nimport { drizzleAdapter } from '@ai-sdk-byok/drizzle';\n\nexport const byok = createByokManager({\n  storage: drizzleAdapter({\n    db,\n    dialect: 'postgres',\n    encryption: {\n      current: {\n        version: 'v1',\n        key: process.env.AI_SDK_BYOK_MASTER_KEY!,\n      },\n    },\n  }),\n});\n```\n\nGenerate a string master key with `openssl rand -base64 32` and keep it in a server-side secret. The adapter accepts the configured `current` key for new writes and optional `previous` keys for reading older rows.\n\n## Key rotation\n\nSet the new key as `current` and keep the old key in `previous`. New writes and credential rotations use `current`; `previous` keys are read-only and decrypt rows carrying their matching version. Re-encryption of existing rows may be deferred, so keep each previous key configured while those rows remain.\n\n## Security\n\n- The master key is never stored in SQL.\n- Losing the master key makes stored credentials unrecoverable.\n- If a master key leaks, rows encrypted under that key must be treated as compromised when their ciphertext may also have been exposed. Affected users should rotate their provider API keys.\n- This adapter protects against database-only compromise, including leaked backups, dumps, and read replicas. It does not protect against application-server compromise.\n- Cryptography is pinned to AES-256-GCM with a 32-byte base64 master key, a new random 12-byte nonce for each write, and additional authenticated data bound to `(userId, provider)`.\n\nSQL stores metadata plus base64url ciphertext, nonce, and the non-secret encryption-key version. Plaintext credentials and key material remain in trusted application memory.\n","readmeFilename":"README.md","_rev":"1-65589bea22e3ea39698bfa74125fae85"}