{"_id":"@altrunova/secrets-manager","_rev":"2-bd9cdc12939bd0053d53d500c693c740","name":"@altrunova/secrets-manager","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@altrunova/secrets-manager","version":"1.0.0","author":{"name":"Altrunova"},"license":"MIT","_id":"@altrunova/secrets-manager@1.0.0","maintainers":[{"name":"divya-altrunova","email":"divya@altrunova.com"},{"name":"dhanvarsha","email":"dhanvarsha@altrunova.com"}],"homepage":"https://github.com/AltruNova/secrets-package-manager#readme","bugs":{"url":"https://github.com/Altrunova/secrets-package-manager/issues"},"dist":{"shasum":"bf7e134b87eaf31862cb1e8b98c484b86055ee7b","tarball":"https://registry.npmjs.org/@altrunova/secrets-manager/-/secrets-manager-1.0.0.tgz","fileCount":15,"integrity":"sha512-Afp6wISxyt/tAgZXMGToaQSeB0k+CxRtwdOQTk9PT4YYURAnRKRpzszB6iCNkxaLiV29EYAsGI1AKXDTWvgBaw==","signatures":[{"sig":"MEUCIC2HMgu/q02QdG5A6pRB2kbZTcULjpMHPIlOyk+egdZVAiEAuu/LWeJ8cxdscK1QbYxVTdL4LvJn5dVKO/l/n7Pd27o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21066},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"49a268c0af271cae7c09bb3b657814ee2ec769d6","scripts":{"build":"tsc"},"_npmUser":{"name":"divya-altrunova","email":"divya@altrunova.com"},"repository":{"url":"git+https://github.com/AltruNova/secrets-package-manager.git","type":"git"},"_npmVersion":"11.17.0","description":"Load secrets from AWS Secrets Manager and expose them by app-defined names. Fetches by AWS secret id (e.g. `STG_BACKEND_URL`), stores under a secret name (e.g. `BACKEND_URL`) so your app uses stable keys.","directories":{},"_nodeVersion":"23.7.0","dependencies":{"user":"^0.0.0","@aws-sdk/client-secrets-manager":"^3.978.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.4","@types/node":"^25.3.3"},"_npmOperationalInternal":{"tmp":"tmp/secrets-manager_1.0.0_1787232187203_0.2838213835901966","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"_id":"@altrunova/secrets-manager@1.0.1","bugs":{"url":"https://github.com/Altrunova/secrets-package-manager/issues"},"dist":{"shasum":"768ba29d683dd1b1f6ba1b80a1f741e6759466ae","tarball":"https://registry.npmjs.org/@altrunova/secrets-manager/-/secrets-manager-1.0.1.tgz","fileCount":15,"integrity":"sha512-fDNNBmujNGSn0c0AoC3q2hUpRjzneb1JtLeVKU+YDddjc/krzpeeA4awttjfz81EQu2oovmip6ZjoXJttjAveg==","signatures":[{"sig":"MEUCIQCafsAvvbpsDbwRb5e+L1ZxMAXyV+FTT6DbTH+Nl6B79AIgfQtwCgZqRjZ5nC73sbYCjiEu1Tm/BZ+JXYL11E9pVF0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDNOI/JVC0Jqx04T73H9KoNnlEOp4JWywr08U3bjXS+9wIhAP3LH92GXAZb+F13ptftCpUlGGWUxf4OARmW7hF79gaP"}],"unpackedSize":21446},"main":"dist/index.js","name":"@altrunova/secrets-manager","types":"dist/index.d.ts","author":{"name":"Altrunova"},"gitHead":"d974bbda1b9f6e9e87dcae3c5276297995e85208","license":"MIT","scripts":{"build":"tsc"},"version":"1.0.1","_npmUser":{"name":"dhanvarsha","email":"dhanvarsha@altrunova.com"},"homepage":"https://github.com/AltruNova/secrets-package-manager#readme","repository":{"url":"git+https://github.com/AltruNova/secrets-package-manager.git","type":"git"},"_npmVersion":"11.11.0","description":"Load secrets from AWS Secrets Manager and expose them by app-defined names. Fetches by AWS secret id (e.g. `STG_BACKEND_URL`), stores under a secret name (e.g. `BACKEND_URL`) so your app uses stable keys.","directories":{},"maintainers":[{"name":"divya-altrunova","email":"divya@altrunova.com"},{"name":"dhanvarsha","email":"dhanvarsha@altrunova.com"}],"_nodeVersion":"24.14.1","dependencies":{"user":"^0.0.0","@aws-sdk/client-secrets-manager":"^3.978.0"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.4","@types/node":"^25.3.3"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/secrets-manager_1.0.1_1789477276385_0.4180006523408548"}}},"time":{"created":"2026-08-20T13:23:06.788Z","modified":"2026-09-15T13:01:16.785Z","1.0.0":"2026-08-20T13:23:07.357Z","1.0.1":"2026-09-15T13:01:16.470Z"},"bugs":{"url":"https://github.com/Altrunova/secrets-package-manager/issues"},"author":{"name":"Altrunova"},"license":"MIT","homepage":"https://github.com/AltruNova/secrets-package-manager#readme","repository":{"url":"git+https://github.com/AltruNova/secrets-package-manager.git","type":"git"},"description":"Load secrets from AWS Secrets Manager and expose them by app-defined names. Fetches by AWS secret id (e.g. `STG_BACKEND_URL`), stores under a secret name (e.g. `BACKEND_URL`) so your app uses stable keys.","maintainers":[{"name":"divya-altrunova","email":"divya@altrunova.com"},{"name":"dhanvarsha","email":"dhanvarsha@altrunova.com"}],"readme":"# @altrunova/secrets-manager\r\n\r\nLoad secrets from AWS Secrets Manager and expose them by app-defined names. Fetches by AWS secret id (e.g. `STG_BACKEND_URL`), stores under a secret name (e.g. `BACKEND_URL`) so your app uses stable keys.\r\n\r\n## Installation\r\n\r\n```bash\r\nnpm install @altrunova/secrets-manager\r\n# or\r\nyarn add @altrunova/secrets-manager\r\n```\r\n\r\n**Requires:** `AWS_REGION` must be set in the environment (or the AWS SDK will resolve region via its default chain).\r\n\r\n## Quick start\r\n\r\n```ts\r\nimport { secretsManager } from \"@altrunova/secrets-manager\";\r\n\r\n// 1. Pass a dictionary: secret name (app key) → AWS secret id\r\nawait secretsManager.loadSecrets({\r\n  BACKEND_URL: \"STG_BACKEND_URL\",\r\n  JWT_SECRET: \"STG_JWT_SECRET\",\r\n});\r\n\r\n// 2. Read by secret name (the key you chose)\r\nconst backendUrl = secretsManager.getSecret(\"BACKEND_URL\");\r\nconst jwtSecret = secretsManager.getSecret(\"JWT_SECRET\");\r\n```\r\n\r\n## API\r\n\r\n### `secretsManager` (singleton)\r\n\r\nPre-built instance of `SecretsManager`. Use it when you’re fine with the default client (region from `process.env.AWS_REGION`).\r\n\r\n### `SecretsManager` (class)\r\n\r\n- **Constructor**  \r\n  Requires `process.env.AWS_REGION` to be set; otherwise throws.\r\n\r\n- **`loadSecrets(config: SecretsConfig): Promise<void>`**  \r\n  Fetches secrets from AWS (via `BatchGetSecretValue`, in batches of 20) and stores them by secret name.  \r\n  - `config` = dictionary: secret name (app key) → AWS secret id (e.g. `{ BACKEND_URL: \"STG_BACKEND_URL\" }`).  \r\n  - Response order from AWS is not guaranteed; entries are matched by secret id (Name/ARN).  \r\n  - Throws if any requested secret fails to load or has no string/binary value.\r\n\r\n- **`getSecret(secretName: string, versionId?: string): Promise<string | null>`**  \r\n  Returns the secret value for `secretName`.  \r\n  - Must call `loadSecrets` first.  \r\n  - If `versionId` is passed and differs from the cached version, the secret is fetched again for that version (and cache may be updated).  \r\n  - Throws if not loaded or secret not configured.\r\n\r\n- **`reloadSecret(secretName: string): Promise<boolean>`**  \r\n  Re-fetches a single secret from AWS and updates the cached value.  \r\n  - Uses the stored `secretId` for that `secretName`.  \r\n  - Returns `true` if the value changed, `false` if unchanged.  \r\n  - Throws if `secretName` was never loaded or the fetch fails.\r\n\r\n### Types\r\n\r\nExported from the package:\r\n\r\n- **`SecretsConfig`**\r\n\r\n  ```ts\r\n  type SecretsConfig = Record<string, string>;\r\n  // e.g. { BACKEND_URL: \"STG_BACKEND_URL\", JWT_SECRET: \"STG_JWT_SECRET\" }\r\n  ```\r\n\r\n- **`SecretConfigItem`**\r\n\r\n  ```ts\r\n  type SecretConfigItem = {\r\n    value: string;\r\n    versionId: string;\r\n    createdDate: Date;\r\n    stages: string[];\r\n    secretId: string; // AWS secret id (used for reload)\r\n  };\r\n  ```\r\n\r\n## AWS configuration\r\n\r\nUses `@aws-sdk/client-secrets-manager`. Ensure the runtime can authenticate:\r\n\r\n- **Environment:** e.g. `AWS_REGION`, `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`, or  \r\n- **Instance/role:** EC2 instance profile, ECS task role, Lambda execution role, etc.\r\n\r\n`AWS_REGION` is required by this package’s constructor.\r\n\r\n\r\n## License\r\n\r\nMIT\r\n","readmeFilename":"README.md"}