{"_id":"@akeyless-community/vercel-runtime","name":"@akeyless-community/vercel-runtime","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@akeyless-community/vercel-runtime","version":"0.1.0","description":"Fetch Akeyless secrets at runtime on Vercel (Node.js) — no env-var sync required","license":"Apache-2.0","author":{"name":"Akeyless Community"},"repository":{"type":"git","url":"git+https://github.com/akeyless-community/vercel-akeyless-runtime.git"},"homepage":"https://github.com/akeyless-community/vercel-akeyless-runtime#readme","keywords":["akeyless","vercel","secrets","runtime","serverless","nextjs"],"engines":{"node":">=18"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./oidc":{"types":"./dist/vercel-oidc.d.ts","default":"./dist/vercel-oidc.js"}},"peerDependencies":{"@vercel/oidc-aws-credentials-provider":">=3.0.0"},"peerDependenciesMeta":{"@vercel/oidc-aws-credentials-provider":{"optional":true}},"scripts":{"build":"tsc -p tsconfig.json","test":"node --experimental-vm-modules node_modules/jest/bin/jest.js","prepublishOnly":"npm run build","example:install":"npm run build && cd examples/nextjs && npm install","example:dev":"npm run example:install && cd examples/nextjs && npm run dev","example:typecheck":"npm run build && cd examples/nextjs && npm install && npm run typecheck"},"publishConfig":{"access":"public"},"dependencies":{"akeyless":"^5.0.25","akeyless-cloud-id":"^1.0.0","aws4":"^1.13.2"},"devDependencies":{"@vercel/oidc-aws-credentials-provider":"^3.1.4","@types/jest":"^29.5.14","@types/node":"^20.17.0","jest":"^29.7.0","ts-jest":"^29.2.5","typescript":"^5.7.2"},"_id":"@akeyless-community/vercel-runtime@0.1.0","bugs":{"url":"https://github.com/akeyless-community/vercel-akeyless-runtime/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-l6H2I/XP39WdqsFdxwtScvxAWQNqv1Fb8eZnO7+YZxfXtc6qQtbMQtl1f2Z5N16FGMw1OpH53RdqsOf4iO5qLw==","shasum":"fd58ae232554d7b949560d8d6b820702706b59ff","tarball":"https://registry.npmjs.org/@akeyless-community/vercel-runtime/-/vercel-runtime-0.1.0.tgz","fileCount":39,"unpackedSize":79423,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCQu4v4ranmZc/TmVlKcWaQjo7DP/TXxZtDHltghCJoIgIhAIZe1uS73Wys/588w4q//iwSte9dBcC1CPN2OYxxLX6F"}]},"_npmUser":{"name":"barak-akeyless","email":"barak.a@akeyless.io"},"directories":{},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vercel-runtime_0.1.0_1781505061798_0.3508131061745321"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-15T06:31:01.559Z","0.1.0":"2026-06-15T06:31:01.937Z","modified":"2026-06-15T06:31:02.267Z"},"maintainers":[{"name":"barak-akeyless","email":"barak.a@akeyless.io"}],"description":"Fetch Akeyless secrets at runtime on Vercel (Node.js) — no env-var sync required","homepage":"https://github.com/akeyless-community/vercel-akeyless-runtime#readme","keywords":["akeyless","vercel","secrets","runtime","serverless","nextjs"],"repository":{"type":"git","url":"git+https://github.com/akeyless-community/vercel-akeyless-runtime.git"},"author":{"name":"Akeyless Community"},"bugs":{"url":"https://github.com/akeyless-community/vercel-akeyless-runtime/issues"},"license":"Apache-2.0","readme":"# @akeyless-community/vercel-runtime\n\nFetch [Akeyless](https://www.akeyless.io) secrets at **runtime** on [Vercel](https://vercel.com) (Node.js). No sync to Vercel environment variables — Akeyless stays the source of truth.\n\n**Repository:** [github.com/akeyless-community/vercel-akeyless-runtime](https://github.com/akeyless-community/vercel-akeyless-runtime)\n\n## Install\n\n```bash\nnpm install @akeyless-community/vercel-runtime\n```\n\nRequires **Node.js 18+** and the **Node.js runtime** on Vercel (not Edge).\n\n## Quick start (Next.js)\n\n### 1. Bootstrap env vars in Vercel\n\nSet only auth + path prefix (not application secrets):\n\n| Variable | Required | Example |\n|----------|----------|---------|\n| `AKEYLESS_ACCESS_ID` | Yes* | `p-xxxxx` |\n| `AKEYLESS_ACCESS_KEY` | Yes* | access key secret |\n| `AKEYLESS_SECRET_PREFIX` | Recommended | `/vercel/my-app/production` |\n| `AKEYLESS_GATEWAY_URL` | No | `https://api.akeyless.io` |\n\n\\* Or use another [auth method](#authentication) below.\n\nOrganize secrets in Akeyless:\n\n```\n/vercel/my-app/production/DATABASE_URL\n/vercel/my-app/production/STRIPE_SECRET_KEY\n```\n\n### 2. Fetch in a server route\n\n```typescript\n// app/api/checkout/route.ts\nimport { getSecret } from '@akeyless-community/vercel-runtime';\n\nexport const runtime = 'nodejs';\n\nexport async function POST() {\n  const stripeKey = await getSecret('STRIPE_SECRET_KEY');\n  // ...\n}\n```\n\nUse `getSecret` only in **server** code (Route Handlers, Server Actions, `getServerSideProps`). Never import in client components.\n\n### 3. Per-environment prefix\n\nSet `AKEYLESS_SECRET_PREFIX` per Vercel environment in the dashboard:\n\n- **Production:** `/vercel/my-app/production`\n- **Preview:** `/vercel/my-app/preview`\n- **Development:** `/vercel/my-app/development`\n\n## API\n\n### Convenience (singleton, warm-invocation friendly)\n\n```typescript\nimport { getSecret, getDefaultClient } from '@akeyless-community/vercel-runtime';\n\nconst dbUrl = await getSecret('DATABASE_URL');\n```\n\n### Explicit client\n\n```typescript\nimport { createClient } from '@akeyless-community/vercel-runtime';\n\nconst client = createClient({\n  gatewayUrl: 'https://api.akeyless.io',\n  secretPrefix: '/vercel/my-app/production',\n  accessId: process.env.AKEYLESS_ACCESS_ID!,\n  accessKey: process.env.AKEYLESS_ACCESS_KEY!,\n});\n\nawait client.getSecret('DATABASE_URL');\nawait client.getSecretAtPath('/custom/full/path');\nawait client.getDynamicSecret('db-creds');\nawait client.getRotatedSecret('rotated-api-key');\n```\n\n### Static with dynamic fallback\n\n```typescript\nawait client.getSecret('db-creds', { allowDynamicFallback: true });\n```\n\n### Bypass cache (rotation-sensitive)\n\n```typescript\nawait client.getSecret('API_KEY', { ignoreCache: true });\n```\n\n## Authentication\n\nConfigure via environment variables or `createClient({ ... })`.\n\n| Method | `AKEYLESS_ACCESS_TYPE` | Additional env |\n|--------|------------------------|----------------|\n| Access key (default) | `access_key` | `AKEYLESS_ACCESS_ID`, `AKEYLESS_ACCESS_KEY` |\n| API key | `api_key` | `AKEYLESS_ACCESS_ID`, `AKEYLESS_ACCESS_KEY` |\n| Universal Identity | `universal_identity` | `AKEYLESS_UID_TOKEN` |\n| JWT | `jwt` | `AKEYLESS_ACCESS_ID`, `AKEYLESS_JWT` |\n| AWS IAM | `aws_iam` | `AKEYLESS_ACCESS_ID`, optional `AKEYLESS_CLOUD_ID` |\n| Azure AD | `azure_ad` | `AKEYLESS_ACCESS_ID`, optional `AKEYLESS_CLOUD_ID` |\n| GCP | `gcp` | `AKEYLESS_ACCESS_ID`, optional `AKEYLESS_CLOUD_ID` |\n| Pre-authenticated | — | `AKEYLESS_TOKEN` |\n\nUse a dedicated Akeyless auth method with **read-only** access to your `/vercel/...` path.\n\n### Vercel OIDC → AWS IAM (no Akeyless access key in Vercel)\n\nRecommended for production: bootstrap with AWS role + Akeyless access ID only.\n\n1. Enable [Vercel OIDC](https://vercel.com/docs/oidc) on the project.\n2. Create an AWS IAM role trusted by `oidc.vercel.com` with `AssumeRoleWithWebIdentity`.\n3. Bind an Akeyless **AWS IAM** auth method to that role.\n4. Install the optional peer dependency:\n\n```bash\nnpm install @vercel/oidc-aws-credentials-provider\n```\n\n5. Use the built-in helper:\n\n```typescript\nimport { createClientWithVercelOidc } from '@akeyless-community/vercel-runtime';\n\nexport const runtime = 'nodejs';\n\nexport async function GET() {\n  const client = await createClientWithVercelOidc();\n  const dbUrl = await client.getSecret('DATABASE_URL');\n  // ...\n}\n```\n\nSet in Vercel:\n\n| Variable | Value |\n|----------|-------|\n| `AWS_ROLE_ARN` | IAM role ARN trusted by Vercel OIDC |\n| `AKEYLESS_ACCESS_ID` | Akeyless AWS IAM auth access ID |\n| `AKEYLESS_SECRET_PREFIX` | `/vercel/my-app/production` |\n\nSubpath import (same API):\n\n```typescript\nimport { createClientWithVercelOidc } from '@akeyless-community/vercel-runtime/oidc';\n```\n\nSee [examples/nextjs](./examples/nextjs) for a working Next.js app with both access-key and OIDC routes.\n\nOn AWS Lambda with an execution role, omit `cloudId` when using `createClient({ accessType: 'aws_iam' })` — `akeyless-cloud-id` uses ambient credentials automatically.\n\n## Caching\n\n- **Auth tokens** refresh before expiry (default margin: 1 minute).\n- **Secret values** cache in memory for **5 minutes** by default (`AKEYLESS_SECRET_CACHE_TTL_MS`).\n- Warm Vercel invocations reuse the same module singleton (`getSecret` / `getDefaultClient`).\n\nLower TTL or use `ignoreCache: true` for frequently rotated secrets.\n\n## Example app\n\n```bash\nnpm run build\ncd examples/nextjs && npm install\n# set AKEYLESS_* env vars — see examples/nextjs/README.md\nnpm run dev\n```\n\n## Local development\n\n```bash\nexport AKEYLESS_ACCESS_ID=p-xxxxx\nexport AKEYLESS_ACCESS_KEY=your-key\nexport AKEYLESS_SECRET_PREFIX=/vercel/my-app/development\n```\n\nOr pull Vercel env locally:\n\n```bash\nvercel env pull .env.local\n```\n\n## Limitations\n\n- **Node.js runtime only** — the `akeyless` SDK does not run on Vercel Edge.\n- **Network** — functions must reach your Akeyless gateway (`api.akeyless.io` or self-hosted).\n- **`NEXT_PUBLIC_*`** — values baked into the client bundle still need build-time resolution; keep those non-secret or accept build-time fetch.\n\n## Related community projects\n\n- [@akeyless-community/railway-runtime](../railway-akeyless-runtime) — Railway runtime secrets\n- [buildkite-akeyless-plugin](https://github.com/akeyless-community/buildkite-akeyless-plugin) — CI secret injection\n- [retool-akeyless-bridge](https://github.com/akeyless-community/retool-akeyless-bridge) — external secrets backend adapter\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md","_rev":"1-b72c915cb193e16d927988d11462ca30"}