{"_id":"@arcboxlabs/deviceid","_rev":"2-5f385255c1485b907d85dc430b58878b","name":"@arcboxlabs/deviceid","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@arcboxlabs/deviceid","version":"0.1.0","license":"MIT","_id":"@arcboxlabs/deviceid@0.1.0","maintainers":[{"name":"aprilnea","email":"github@sku.moe"}],"homepage":"https://github.com/arcboxlabs/deviceid#readme","bugs":{"url":"https://github.com/arcboxlabs/deviceid/issues"},"dist":{"shasum":"ff4d516f7e7e9b753524785cd1b7055c2e36dcaa","tarball":"https://registry.npmjs.org/@arcboxlabs/deviceid/-/deviceid-0.1.0.tgz","fileCount":5,"integrity":"sha512-Gdq4Gb6DCfNXdFOcn4hgUFd8IA1qK/xbeg3kNtW/eiuRA6I1Ji/uE11N751m0A5OPV/OWcEML+P9ivBbtXMCnA==","signatures":[{"sig":"MEQCIDlj0Aciw7b87P1AN4khao0E2sFxIYBBpK4lxS7UeOOPAiAVbGQRXz0lqxc6+K+NOfkrRIg/ETWhDF+OfnDqFkwDNQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31176},"main":"index.js","napi":{"targets":["aarch64-apple-darwin","x86_64-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc","x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu"],"binaryName":"deviceid"},"types":"index.d.ts","engines":{"node":">= 18"},"gitHead":"7d60f28edd902385e1c95a17ec8bb9deadbd8eaf","scripts":{"lint":"cargo clippy --all-targets -- -D warnings","test":"node --test __test__/*.test.mjs","build":"napi build --platform --release","format":"cargo fmt","build:debug":"napi build --platform","prepublishOnly":"napi prepublish -t npm"},"_npmUser":{"name":"aprilnea","email":"github@sku.moe"},"repository":{"url":"git+https://github.com/arcboxlabs/deviceid.git","type":"git"},"_npmVersion":"11.11.0","description":"A device ID that can't be faked: the fingerprint of a key your hardware holds","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"packageManager":"pnpm@11.9.0","devDependencies":{"@napi-rs/cli":"^3.7.2"},"optionalDependencies":{"@arcboxlabs/deviceid-darwin-arm64":"0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/deviceid_0.1.0_1783201940110_0.5799119573611524","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@arcboxlabs/deviceid","version":"0.1.1","description":"A device ID that can't be faked: the fingerprint of a key your hardware holds","license":"MIT","repository":{"type":"git","url":"git+https://github.com/arcboxlabs/deviceid.git"},"main":"index.js","types":"index.d.ts","engines":{"node":">= 18"},"napi":{"binaryName":"deviceid","targets":["aarch64-apple-darwin","x86_64-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc","x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu"]},"scripts":{"build":"napi build --platform --release","build:debug":"napi build --platform","test":"node --test __test__/*.test.mjs","format":"cargo fmt","lint":"cargo clippy --all-targets -- -D warnings","prepublishOnly":"napi prepublish -t npm"},"packageManager":"pnpm@11.9.0","optionalDependencies":{"@arcboxlabs/deviceid-darwin-arm64":"0.1.1","@arcboxlabs/deviceid-darwin-x64":"0.1.1","@arcboxlabs/deviceid-win32-x64-msvc":"0.1.1","@arcboxlabs/deviceid-win32-arm64-msvc":"0.1.1","@arcboxlabs/deviceid-linux-x64-gnu":"0.1.1","@arcboxlabs/deviceid-linux-arm64-gnu":"0.1.1"},"devDependencies":{"@napi-rs/cli":"^3.7.2"},"gitHead":"24723504a1e90855be7a10cccc6c5adaf1d6b1d5","_id":"@arcboxlabs/deviceid@0.1.1","bugs":{"url":"https://github.com/arcboxlabs/deviceid/issues"},"homepage":"https://github.com/arcboxlabs/deviceid#readme","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-rliPyory/bNUj+WFQIrVqnjT7xT6ZZOlf+FABc7gkCIe9uhgtRedHX5IBvf2vJRZqFIHJ+8eCdRPu4la0mUYiw==","shasum":"02e8635260d955643f0ed423447764fe23c0cd69","tarball":"https://registry.npmjs.org/@arcboxlabs/deviceid/-/deviceid-0.1.1.tgz","fileCount":5,"unpackedSize":31881,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICyRr5CASlNj8zEWdTMJ3e7bjLFOqU/aUdGsg8RXdaLqAiALs/PqWzc9OAV80lzzYNrbqkhOYTUwLPX8zyaAof2D0g=="}]},"_npmUser":{"name":"aprilnea","email":"github@sku.moe"},"directories":{},"maintainers":[{"name":"aprilnea","email":"github@sku.moe"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/deviceid_0.1.1_1783258511594_0.1774881128281327"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-04T21:52:19.993Z","modified":"2026-07-05T13:35:11.842Z","0.1.0":"2026-07-04T21:52:20.237Z","0.1.1":"2026-07-05T13:35:11.728Z"},"bugs":{"url":"https://github.com/arcboxlabs/deviceid/issues"},"license":"MIT","homepage":"https://github.com/arcboxlabs/deviceid#readme","repository":{"type":"git","url":"git+https://github.com/arcboxlabs/deviceid.git"},"description":"A device ID that can't be faked: the fingerprint of a key your hardware holds","maintainers":[{"name":"aprilnea","email":"github@sku.moe"}],"readme":"# @arcboxlabs/deviceid\n\nA device ID that can't be faked: the fingerprint of a key your hardware holds.\n\nReadable machine identifiers (serial numbers, `IOPlatformUUID`, `/etc/machine-id`)\nare spoofable — a server can never verify that a client actually read them from\nhardware. `deviceid` inverts the model: it generates a P-256 keypair inside the\nmachine's security hardware and derives the device ID from the public key.\nClaiming the ID means signing with the key; cloning the ID means extracting a\nprivate key that physically cannot leave the chip.\n\n| Platform | Backend | `protection` |\n| --- | --- | --- |\n| macOS | Secure Enclave (CryptoKit, no entitlements needed) | `hardware` |\n| Windows | TPM 2.0 (CNG platform crypto provider) | `hardware` |\n| WSL2 | Bridge to the host Windows TPM | `hardware` |\n| Linux | Keyring-encrypted key | `software` |\n\nFail-closed: with no usable backend (Windows without a TPM, Linux without a\nSecret Service — typically VMs), `ensureDeviceId` throws rather than silently\ndowngrading. Pair it with your own software fallback if you need one.\n\nBuilt on [godaddy/hardware-enclave](https://github.com/godaddy/hardware-enclave),\nexposed to Node.js via [napi-rs](https://napi.rs) prebuilt binaries.\n\n## Usage\n\n```ts\nimport { ensureDeviceId } from '@arcboxlabs/deviceid';\n\nconst device = ensureDeviceId({ dir: '~/.myapp/keys' });\n\ndevice.id;            // 'SHA256:Jgr0OcWi…' — stable fingerprint of the public key\ndevice.publicKeyPem;  // SPKI PEM, enroll this with your server\ndevice.protection;    // 'hardware' | 'software'\ndevice.sign(payload); // base64url P1363 ECDSA signature (SHA-256)\n```\n\nSignatures verify with WebCrypto as-is:\n\n```ts\nconst key = await crypto.subtle.importKey('spki', spkiDer, { name: 'ECDSA', namedCurve: 'P-256' }, false, ['verify']);\nconst ok = await crypto.subtle.verify({ name: 'ECDSA', hash: 'SHA-256' }, key, signature, payload);\n```\n\n## Development\n\nRust comes project-scoped via [devenv](https://devenv.sh); macOS additionally\nneeds Xcode Command Line Tools for the Swift bridge.\n\n```sh\ndevenv shell\npnpm build   # napi build --platform --release\npnpm test    # exercises the real hardware backend\n```\n","readmeFilename":"README.md"}