{"_id":"@backbone-hq/thorax","_rev":"3-5b54675468bf90d2d528846ebc7517dd","name":"@backbone-hq/thorax","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.0":{"name":"@backbone-hq/thorax","version":"1.0.0","license":"Apache-2.0","_id":"@backbone-hq/thorax@1.0.0","maintainers":[{"name":"backbone-dev","email":"root@backbone.dev"}],"homepage":"https://github.com/backbone-hq/thorax#readme","bugs":{"url":"https://github.com/backbone-hq/thorax/issues"},"dist":{"shasum":"f06bdb740e1fe056706488e275a1588fbe865b92","tarball":"https://registry.npmjs.org/@backbone-hq/thorax/-/thorax-1.0.0.tgz","fileCount":12,"integrity":"sha512-EQ5uu3lC1Yq2Rqsm+eLFW8CrJLjBI/glOPDMuGAAXVSjC/CwZh5zzSpcvNeTeiCJxken+fy0ResNMxKKTcK9lA==","signatures":[{"sig":"MEYCIQCuz/JRfYg7s/xPPcUwEiZKbpEp6NvDi+YTToBoR01qLwIhAO2BMsEGV+P+g4ebjPKysBqkcdSkQFMw1VkjGikJS6x6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22768031},"main":"index.js","napi":{"targets":["x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl","x86_64-apple-darwin","aarch64-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc"],"binaryName":"thorax"},"_from":"file:/code/backbone/thorax/dist/releases/v1.0.0/artifacts/backbone-hq-thorax-1.0.0.tgz","types":"index.d.ts","engines":{"node":">=18"},"_npmUser":{"name":"backbone-dev","email":"root@backbone.dev"},"_resolved":"/code/backbone/thorax/dist/releases/v1.0.0/artifacts/backbone-hq-thorax-1.0.0.tgz","_integrity":"sha512-EQ5uu3lC1Yq2Rqsm+eLFW8CrJLjBI/glOPDMuGAAXVSjC/CwZh5zzSpcvNeTeiCJxken+fy0ResNMxKKTcK9lA==","repository":{"url":"git+https://github.com/backbone-hq/thorax.git","type":"git"},"_npmVersion":"11.6.2","description":"Native Node.js SDK for Thorax: secrets management for humans, agents, and apps.","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@napi-rs/cli":"3.8.5"},"_npmOperationalInternal":{"tmp":"tmp/thorax_1.0.0_1786627830304_0.7237795780741114","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@backbone-hq/thorax","version":"1.0.1","license":"Apache-2.0","_id":"@backbone-hq/thorax@1.0.1","maintainers":[{"name":"backbone-dev","email":"root@backbone.dev"}],"homepage":"https://github.com/backbone-hq/thorax#readme","bugs":{"url":"https://github.com/backbone-hq/thorax/issues"},"dist":{"shasum":"4846182434724e4312304a397d1686a0b2af69e5","tarball":"https://registry.npmjs.org/@backbone-hq/thorax/-/thorax-1.0.1.tgz","fileCount":13,"integrity":"sha512-Clx87FseqUl2F7qteDqvzaoYL2QZPhBRyFhpoYBz2riNinbPlXvM9RjqX/sMR4EPOf8ejsfOno341csRS38HdQ==","signatures":[{"sig":"MEUCIQDl4Hm8aufOxM0kZFupt5sKSXT99/1U7l4gjqRKpnBO6QIgVd583ZHf0SCea78bWGs7/hzEDK5UJpDB03Cq5ILjdNk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22771466},"main":"index.js","napi":{"targets":["x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl","x86_64-apple-darwin","aarch64-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc"],"binaryName":"thorax"},"_from":"file:/code/backbone/thorax/dist/releases/v1.0.1/artifacts/backbone-hq-thorax-1.0.1.tgz","types":"index.d.ts","engines":{"node":">=18"},"_npmUser":{"name":"backbone-dev","email":"root@backbone.dev"},"_resolved":"/code/backbone/thorax/dist/releases/v1.0.1/artifacts/backbone-hq-thorax-1.0.1.tgz","_integrity":"sha512-Clx87FseqUl2F7qteDqvzaoYL2QZPhBRyFhpoYBz2riNinbPlXvM9RjqX/sMR4EPOf8ejsfOno341csRS38HdQ==","repository":{"url":"git+https://github.com/backbone-hq/thorax.git","type":"git"},"_npmVersion":"11.6.2","description":"Native Node.js SDK for Thorax: secrets management for humans, agents, and apps.","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@napi-rs/cli":"3.8.5"},"_npmOperationalInternal":{"tmp":"tmp/thorax_1.0.1_1786645932339_0.5631500783430379","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@backbone-hq/thorax","version":"1.1.0","description":"Native Node.js SDK for Thorax: secrets management for humans, agents, and apps.","license":"Apache-2.0","main":"index.js","types":"index.d.ts","repository":{"type":"git","url":"git+https://github.com/backbone-hq/thorax.git"},"publishConfig":{"access":"public"},"napi":{"binaryName":"thorax","targets":["x86_64-unknown-linux-gnu","aarch64-unknown-linux-gnu","x86_64-unknown-linux-musl","aarch64-unknown-linux-musl","x86_64-apple-darwin","aarch64-apple-darwin","x86_64-pc-windows-msvc","aarch64-pc-windows-msvc"]},"engines":{"node":">=18"},"devDependencies":{"@napi-rs/cli":"3.8.5"},"_id":"@backbone-hq/thorax@1.1.0","bugs":{"url":"https://github.com/backbone-hq/thorax/issues"},"homepage":"https://github.com/backbone-hq/thorax#readme","_integrity":"sha512-RljnoKAJccqLFPJvTfulHbkyKXGWlyBvGmjst05Ko5RcqWDEuJWbPk7iHq+LGtndAgY2fdoOrYiTWtibfLfidA==","_resolved":"/code/backbone/thorax/dist/releases/v1.1.0/artifacts/backbone-hq-thorax-1.1.0.tgz","_from":"file:/code/backbone/thorax/dist/releases/v1.1.0/artifacts/backbone-hq-thorax-1.1.0.tgz","_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-RljnoKAJccqLFPJvTfulHbkyKXGWlyBvGmjst05Ko5RcqWDEuJWbPk7iHq+LGtndAgY2fdoOrYiTWtibfLfidA==","shasum":"87194f2a9df9e0c2de5856bf4af6f31de1683fa9","tarball":"https://registry.npmjs.org/@backbone-hq/thorax/-/thorax-1.1.0.tgz","fileCount":13,"unpackedSize":22751026,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIF9i1Y2sCp6DnVcCKpgE/7nvHNBqkVFZXH8zYkZKDezbAiEAgM2HBMUyKYP6t9B5ZTP31t3QhzxfkK/eW4LiFIHatTc="}]},"_npmUser":{"name":"backbone-dev","email":"root@backbone.dev"},"directories":{},"maintainers":[{"name":"backbone-dev","email":"root@backbone.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/thorax_1.1.0_1786660319877_0.7123926538401733"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-13T13:30:30.059Z","modified":"2026-08-13T22:32:00.386Z","1.0.0":"2026-08-13T13:30:30.739Z","1.0.1":"2026-08-13T18:32:12.664Z","1.1.0":"2026-08-13T22:32:00.180Z"},"bugs":{"url":"https://github.com/backbone-hq/thorax/issues"},"license":"Apache-2.0","homepage":"https://github.com/backbone-hq/thorax#readme","repository":{"type":"git","url":"git+https://github.com/backbone-hq/thorax.git"},"description":"Native Node.js SDK for Thorax: secrets management for humans, agents, and apps.","maintainers":[{"name":"backbone-dev","email":"root@backbone.dev"}],"readme":"# Thorax for Node.js\n\nNative Node.js SDK for [Thorax](https://github.com/backbone-hq/thorax), secrets management for humans, agents, and apps.\n\nThe SDK is a small application-facing facade over Thorax's shared operation layer. It uses the same vault validation, authorization, keychain, and cryptography as the CLI, TUI, Rust SDK, and Python SDK.\n\n## Installation\n\nThorax requires Node.js 18 or later.\n\n```sh\nnpm install @backbone-hq/thorax\n```\n\nThe SDK opens an existing Thorax vault. Install the [Thorax CLI](https://github.com/backbone-hq/thorax#installation) and run `thorax init` in your project if you do not have one yet.\n\n## Quick start\n\nBy default, `Vault.open()` opens `.thorax/vault.cord` and authenticates with the configured local identity and keychain:\n\n```js\nconst { Vault } = require(\"@backbone-hq/thorax\");\n\nconst vault = await Vault.open();\nconst databaseUrl = await vault.get(\"app/prod/db\");\n```\n\nOr with TypeScript and an explicit directory containing `vault.cord`:\n\n```ts\nimport { Vault } from \"@backbone-hq/thorax\";\n\nconst vault = await Vault.open({ path: \"/srv/my-app/.thorax\" });\nconst databaseUrl = await vault.get(\"app/prod/db\");\n```\n\nValues are strings by default. Set `asBuffer: true` when reading a binary value:\n\n```js\nconst certificate = await vault.get(\"app/prod/certificate\", { asBuffer: true });\nawait vault.set(\"app/prod/token\", Buffer.from(\"binary value\"));\n```\n\n## Working with secrets\n\n```js\nawait vault.set(\"app/prod/db\", \"postgres://localhost/app\");\nawait vault.setField(\"app/prod/db\", \"username\", \"app\");\n\nconst username = await vault.getField(\"app/prod/db\", \"username\");\nconst fields = await vault.fields(\"app/prod/db\");\nconst selectors = await vault.list(\"app/prod\");\n\nawait vault.deleteField(\"app/prod/db\", \"username\");\nawait vault.delete(\"app/prod/db\");\nvault.close();\n```\n\nSelectors may be strings such as `app/prod/db@region=eu`, or structured objects such as `{ path: [\"app\", \"prod\", \"db\"], labels: { region: \"eu\" } }`.\n\n## Authentication\n\nLocal development uses the keychain by default. You can select a particular identity or supply a passphrase to a noninteractive caller:\n\n```js\nconst { Auth, Vault } = require(\"@backbone-hq/thorax\");\n\nconst auth = Auth.fromKeychain({ user: \"alice\", passphrase: \"...\" });\nconst vault = await Vault.open({ auth });\n```\n\nFor CI and deployed applications, use a dedicated, least-privilege invite identity. `Auth.fromEnv()` reads exactly one of `THORAX_UNSAFE_INVITE` or `THORAX_UNSAFE_INVITE_FILE`:\n\n```js\nconst vault = await Vault.open({ auth: Auth.fromEnv() });\n```\n\nAn invite is a private capability. Keep it out of source control and prefer the file variable when your runtime can mount it as a secret. `Auth.fromInvite()` also accepts an invite directly.\n\n## Errors and session behavior\n\nRejected operations use Node `Error` objects whose messages are prefixed with a Thorax error category. A session validates the vault when it opens and sees its own writes immediately. Reopen the vault to pick up changes written by another process. Opening fails while the vault has unresolved conflicts.\n\nSee the [Thorax documentation](https://github.com/backbone-hq/thorax) for vault setup, selectors, access control, and the security model.\n\nThorax is licensed under the [Apache License 2.0](https://github.com/backbone-hq/thorax/blob/master/LICENSE).\n","readmeFilename":"README.md"}