{"_id":"@basis-theory/shopify-js","_rev":"5-8413cb2e908cc26d0fa17d7b1af25a7c","name":"@basis-theory/shopify-js","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@basis-theory/shopify-js","version":"1.0.0","keywords":["shopify","payment app","encryption","decrypt","token","node","elliptic curve"],"author":{"name":"Basis Theory","email":"support@basistheory.com"},"license":"Apache-2.0","_id":"@basis-theory/shopify-js@1.0.0","maintainers":[{"name":"kevinperaza-bt","email":"kevin@basistheory.com"},{"name":"justjordant","email":"jordan@basistheory.com"},{"name":"jleon15","email":"josue@basistheory.com"},{"name":"lcschy","email":"lucas@basistheory.com"},{"name":"briangonzalezatbt","email":"brian.gonzalez@basistheory.com"},{"name":"dhudec","email":"drew@basistheory.com"},{"name":"davi.basistheory","email":"davi@basistheory.com"},{"name":"armsteadj1","email":"armsteadj1@gmail.com"},{"name":"matthew_basistheory","email":"matthew@basistheory.com"},{"name":"bt-platform","email":"platform@basistheory.com"}],"homepage":"https://github.com/Basis-Theory/shopify-js#readme","bugs":{"url":"https://github.com/Basis-Theory/shopify-js/issues"},"dist":{"shasum":"9ee65961aa787528fa7589737e9fe006be9e1068","tarball":"https://registry.npmjs.org/@basis-theory/shopify-js/-/shopify-js-1.0.0.tgz","fileCount":6,"integrity":"sha512-aVQm3egynA4BsNmN6zTj3TA6d6OZ2Xl1n1iLFpyyai904CnchGndBY2QeX+eODhJAE7X9iF7Ur9SiI9WuuyKKQ==","signatures":[{"sig":"MEYCIQDUg2r/Mxva73uU8ba8Bzntunfz/MRmqUJbVa7mXk6SBgIhAOFa9qcoUT17wLAeYEElr1dGxD9btVfD9dOXEUvNyqW0","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":27091},"main":"index.js","types":"types.d.ts","engines":{"node":">=16"},"gitHead":"547b48407cda91efb1052a6e8f8f6c0da8cf04f5","targets":{"main":{"sourceMap":false}},"_npmUser":{"name":"bt-platform","email":"platform@basistheory.com"},"repository":{"url":"git+https://github.com/Basis-Theory/shopify-js.git","type":"git"},"_npmVersion":"9.9.2","description":"Basis Theory utility for decrypting Shopify Payment App Session payload","directories":{},"_nodeVersion":"20.10.0","dependencies":{"ec-key":"^0.0.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/shopify-js_1.0.0_1703869717615_0.05058349719883748","host":"s3://npm-registry-packages"}},"1.0.1":{"name":"@basis-theory/shopify-js","version":"1.0.1","keywords":["shopify","payment app","encryption","decrypt","token","node","elliptic curve"],"author":{"name":"Basis Theory","email":"support@basistheory.com"},"license":"Apache-2.0","_id":"@basis-theory/shopify-js@1.0.1","maintainers":[{"name":"kevinperaza-bt","email":"kevin@basistheory.com"},{"name":"justjordant","email":"jordan@basistheory.com"},{"name":"jleon15","email":"josue@basistheory.com"},{"name":"lcschy","email":"lucas@basistheory.com"},{"name":"briangonzalezatbt","email":"brian.gonzalez@basistheory.com"},{"name":"dhudec","email":"drew@basistheory.com"},{"name":"davi.basistheory","email":"davi@basistheory.com"},{"name":"armsteadj1","email":"armsteadj1@gmail.com"},{"name":"matthew_basistheory","email":"matthew@basistheory.com"},{"name":"bt-platform","email":"platform@basistheory.com"}],"homepage":"https://github.com/Basis-Theory/shopify-js#readme","bugs":{"url":"https://github.com/Basis-Theory/shopify-js/issues"},"dist":{"shasum":"f915fea98e71843191a59fb5c636c37582c95e1f","tarball":"https://registry.npmjs.org/@basis-theory/shopify-js/-/shopify-js-1.0.1.tgz","fileCount":6,"integrity":"sha512-XCYeN+hWRDcL66xZHMbUYK7EZa35/H/B8cl2bAL7pJsUNQn2uJTFh4FtH/1lYLRlD94NLOacf7NGfBLtCiCYDQ==","signatures":[{"sig":"MEUCIFObqd2j7CSqj7b7J7LyUBayohY/r+3xpGVXoQ+UimwFAiEAxlRLRneQDF/908vbC1aKTHJctZOrIxg2j9lLRJrZ5b0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":27201},"main":"index.js","types":"types.d.ts","engines":{"node":">=16"},"gitHead":"2f8e9bdfaea36f9980fdd16576b37a7d3238da37","targets":{"main":{"sourceMap":false}},"_npmUser":{"name":"bt-platform","email":"platform@basistheory.com"},"repository":{"url":"git+https://github.com/Basis-Theory/shopify-js.git","type":"git"},"_npmVersion":"10.4.0","description":"Basis Theory utility for decrypting Shopify Payment App Session payload","directories":{},"resolutions":{"semver":"^7.5.4","msgpackr":"^1.10.1","@babel/traverse":"^7.23.2"},"_nodeVersion":"20.11.0","dependencies":{"ec-key":"^0.0.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/shopify-js_1.0.1_1706188837514_0.599552404328414","host":"s3://npm-registry-packages"}},"1.0.2":{"name":"@basis-theory/shopify-js","version":"1.0.2","description":"Basis Theory utility for decrypting Shopify Payment App Session payload","repository":{"type":"git","url":"git+https://github.com/Basis-Theory/shopify-js.git"},"license":"Apache-2.0","author":{"name":"Basis Theory","email":"support@basistheory.com"},"types":"types.d.ts","main":"index.js","engines":{"node":">=16"},"targets":{"main":{"sourceMap":false}},"dependencies":{"ec-key":"^0.0.6"},"resolutions":{"@babel/traverse":"^7.23.2","msgpackr":"^1.10.1","semver":"^7.5.4"},"publishConfig":{"access":"public"},"keywords":["shopify","payment app","encryption","decrypt","token","node","elliptic curve"],"gitHead":"221cee4dbf9ba10c6795388bfb0f195122c9a067","_id":"@basis-theory/shopify-js@1.0.2","bugs":{"url":"https://github.com/Basis-Theory/shopify-js/issues"},"homepage":"https://github.com/Basis-Theory/shopify-js#readme","_nodeVersion":"22.23.1","_npmVersion":"11.18.0","dist":{"integrity":"sha512-Y58rqfbITXjyz7XDe77+5b4gql8Bw1U3aKmsOncikv+dDc5u1FCzjW8A7Rp0kgnD6FLXq9KwzgoNG2zpMZKfcg==","shasum":"0d3ac52c70bb87bd89532fe247457cf6da0f0514","tarball":"https://registry.npmjs.org/@basis-theory/shopify-js/-/shopify-js-1.0.2.tgz","fileCount":6,"unpackedSize":27201,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@basis-theory%2fshopify-js@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDojDeaBVtTlLuoLzhE4xw/mqotEstIp4Wk6pBAZ9C7EAIhALgrp0vOZN5mnhT08usP3gcmZqA+cm4371hGzjMTjDK7"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4c75efc7-ea86-4634-a800-c62cfe109746"}},"directories":{},"maintainers":[{"name":"lcschy","email":"lucas@basistheory.com"},{"name":"briangonzalezatbt","email":"brian.gonzalez@basistheory.com"},{"name":"dhudec","email":"drew@basistheory.com"},{"name":"davi.basistheory","email":"davi@basistheory.com"},{"name":"armsteadj1","email":"armsteadj1@gmail.com"},{"name":"matthew_basistheory","email":"matthew@basistheory.com"},{"name":"bt-platform","email":"platform@basistheory.com"},{"name":"jleon15","email":"josue@basistheory.com"},{"name":"kevinperaza-bt","email":"kevin@basistheory.com"},{"name":"greathouse-bt","email":"robert@basistheory.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/shopify-js_1.0.2_1783448290504_0.05136099718802756"},"_hasShrinkwrap":false}},"time":{"created":"2023-12-29T17:08:37.496Z","modified":"2026-07-07T18:18:11.055Z","1.0.0":"2023-12-29T17:08:37.842Z","1.0.1":"2024-01-25T13:20:37.784Z","1.0.2":"2026-07-07T18:18:10.661Z"},"bugs":{"url":"https://github.com/Basis-Theory/shopify-js/issues"},"author":{"name":"Basis Theory","email":"support@basistheory.com"},"license":"Apache-2.0","homepage":"https://github.com/Basis-Theory/shopify-js#readme","keywords":["shopify","payment app","encryption","decrypt","token","node","elliptic curve"],"repository":{"type":"git","url":"git+https://github.com/Basis-Theory/shopify-js.git"},"description":"Basis Theory utility for decrypting Shopify Payment App Session payload","maintainers":[{"name":"lcschy","email":"lucas@basistheory.com"},{"name":"briangonzalezatbt","email":"brian.gonzalez@basistheory.com"},{"name":"dhudec","email":"drew@basistheory.com"},{"name":"davi.basistheory","email":"davi@basistheory.com"},{"name":"armsteadj1","email":"armsteadj1@gmail.com"},{"name":"matthew_basistheory","email":"matthew@basistheory.com"},{"name":"bt-platform","email":"platform@basistheory.com"},{"name":"jleon15","email":"josue@basistheory.com"},{"name":"kevinperaza-bt","email":"kevin@basistheory.com"},{"name":"greathouse-bt","email":"robert@basistheory.com"}],"readme":"# Basis Theory Shopify JS\n\n![Version](https://img.shields.io/npm/v/%40basis-theory/shopify-js) ![GitHub Workflow Status (with event)](https://img.shields.io/github/actions/workflow/status/Basis-Theory/shopify-js/release.yml) ![License](https://img.shields.io/npm/l/%40basis-theory%2Fshopify-js)\n\nUtility library for decrypting Shopify Payment App credit card payload.\n\n## Features\n\n- **Shopify Payment App decryption**: Securely decrypt user payment method (credit card) data using easy-to-interact interfaces.\n- **Private Key rotation**: Map your decryption keys by certificate fingerprint for easy rotation.\n\n## Shopify Payment App Setup\n\nFollow the steps in [Shopify Payments App documentation](https://shopify.dev/docs/apps/payments/create-a-payments-app) to create a Payments App and Credit Card Payments App Extension.\n\n## Installation\n\nInstall the package using NPM:\n\n```shell\nnpm install @basis-theory/shopify-js --save\n```\n\nOr Yarn:\n\n```shell\nyarn add @basis-theory/shopify-js\n```\n\n## Usage\n\nThe credit card payment app extension requires a Payment Session URL, where the Payment Session payload is posted to, containing encrypted credit card data.\n\nThe examples below show how to load the private key from the File System into a Buffer, using samples from this repository. But you can load them from you KMS, secret manager, configuration, etc.\n\n> ⚠️ Decrypting the Shopify Payment Session payload must be done in a PCI DSS compliant environment.\n\nIf you need help understanding the risks associated with decrypting and manipulating the various forms of cardholder data in your own systems, [reach out to us](https://basistheory.com/contact).\n\n```javascript\nimport { ShopifyPaymentSessionContext } from '@basis-theory/shopify-js';\nimport * as fs from 'fs';\nimport paymentSession from './test/fixtures/paymentSession.json';\n\n// load private key into buffer\nconst privateKeyPem = fs.readFileSync(\n  './test/fixtures/certificates/private_key.pem'\n);\n\n// create decryption context\nconst context = new ShopifyPaymentSessionContext({\n  privateKeyPem,\n});\n\n// decrypt the payment method\nconsole.log(context.decrypt(paymentSession.payment_method));\n```\n\nOr using key rotation:\n\n```javascript\nimport { ShopifyPaymentSessionContext } from '@basis-theory/shopify-js';\nimport * as fs from 'fs';\nimport paymentSession from './test/fixtures/paymentSession.json';\n\n// load private keys into buffer\nconst privateKeyPemA = fs.readFileSync(\n  './test/fixtures/certificates/private_key_a.pem'\n);\nconst privateKeyPemB = fs.readFileSync(\n  './test/fixtures/certificates/private_key_b.pem'\n);\n\n// create decryption context\nconst context = new ShopifyPaymentSessionContext({\n  privateKeyPem: {\n    // get the certificate fingerprint in Shopify payment app certificates dashboard\n    '23f3812e093737252e98d47aa790ba5e607188837ec9aea797c0dde8ed7ef674':\n      privateKeyPemA,\n    '84d14a26c7d80e4975ed646f8ba8484a5ee8de970a04f1cf61b775aa7cbdc9cf':\n      privateKeyPemB,\n  },\n});\n\n// decrypt the payment method\nconsole.log(context.decrypt(paymentSession.payment_method));\n```\n\n## Reactors\n\nThis package is available to use in [Reactors](https://developers.basistheory.com/docs/concepts/what-are-reactors) context. This enables you to perform decryption and tokenization of the credit card data in an outsourced cardholder data environment hosted by Basis Theory.\n\n[Contact us](https://basistheory.com/contact) to understand how to set up Proxy with mTLS support to listen to Shopify Payment Session request and decrypt it at an isolated environment.\n\nProxy Request Transform code example:\n\n```javascript\nconst { ShopifyPaymentSessionContext } = require('@basis-theory/shopify-js');\n\nmodule.exports = async function (req) {\n  const {\n    bt,\n    args: {\n      headers,\n      body: { payment_method, ...body },\n    },\n    configuration: { PRIVATE_KEY_A, PRIVATE_KEY_B },\n  } = req;\n\n  const context = new ShopifyPaymentSessionContext({\n    privateKeyPem: {\n      // get the certificate fingerprint in Shopify payment app certificates dashboard\n      '23f3812e093737252e98d47aa790ba5e607188837ec9aea797c0dde8ed7ef674':\n        PRIVATE_KEY_A,\n      '84d14a26c7d80e4975ed646f8ba8484a5ee8de970a04f1cf61b775aa7cbdc9cf':\n        PRIVATE_KEY_B,\n    },\n  });\n\n  const {\n    data: { full_name, pan, month, year, verification_value },\n  } = context.decrypt(payment_method);\n\n  const token = await bt.tokens.create({\n    type: 'card',\n    data: {\n      number: pan,\n      expiration_month: month,\n      expiration_year: year,\n      cvc: verification_value,\n    },\n  });\n\n  return {\n    headers,\n    body: {\n      ...body,\n      payment_method: token,\n    },\n  };\n};\n```\n","readmeFilename":"README.md"}