{"_id":"@bencmbrook/prefixed-api-key","_rev":"4-d6f7e38d44bfd31ca0faf0026d8fb58e","name":"@bencmbrook/prefixed-api-key","dist-tags":{"latest":"4.0.0"},"versions":{"2.0.0":{"name":"@bencmbrook/prefixed-api-key","version":"2.0.0","main":"dist/index.js","license":"MIT","description":"Generate prefixed API-keys","repository":{"type":"git","url":"git+ssh://git@github.com/bencmbrook/prefixed-api-key.git"},"scripts":{"build":"tsup --dts --clean -d dist src","test":"ava"},"devDependencies":{"@ianvs/prettier-plugin-sort-imports":"^4.1.0","@tsconfig/node18":"^18.2.1","@tsconfig/strictest":"^2.0.2","@types/eslint":"^8.44.2","@types/node":"~18.17","ava":"^4.2.0","esbuild":"^0.14.38","esbuild-register":"^3.3.2","eslint":"^8.48.0","eslint-config-prettier":"^9.0.0","prettier":"^3.0.3","tsup":"^5.12.7","typescript":"^4.6.4"},"dependencies":{"@scure/base":"^1.1.3"},"gitHead":"6e95e00b186ed78e9053b0658e10b6bf16977b83","bugs":{"url":"https://github.com/bencmbrook/prefixed-api-key/issues"},"homepage":"https://github.com/bencmbrook/prefixed-api-key#readme","_id":"@bencmbrook/prefixed-api-key@2.0.0","_nodeVersion":"18.17.0","_npmVersion":"9.6.7","dist":{"integrity":"sha512-XzK6IuDuX69eMvMtVUAN4lgDCilXADNyGsjJqp9JX7713W2OuV+R41rS/RCcvEgvPjP66y6mCQzPUUEACxaG2w==","shasum":"7f71b28433542de85d2414adf071da87b072ac70","tarball":"https://registry.npmjs.org/@bencmbrook/prefixed-api-key/-/prefixed-api-key-2.0.0.tgz","fileCount":4,"unpackedSize":7292,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDmoaCvaeoJ6H3SEiTwRMk0xassFqMOYgIFRz6XzSuIgAiEA/8REEt+7Rwu7rAfDzC121YMx335zCnOZcxuxm5bzqWM="}]},"_npmUser":{"name":"bencmbrook","email":"ben@transcend.io"},"directories":{},"maintainers":[{"name":"bencmbrook","email":"ben@transcend.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/prefixed-api-key_2.0.0_1693875108217_0.698922179149875"},"_hasShrinkwrap":false},"2.0.2":{"name":"@bencmbrook/prefixed-api-key","version":"2.0.2","main":"dist/index.js","license":"MIT","description":"Generate prefixed API-keys","repository":{"type":"git","url":"git@github.com:bencmbrook/prefixed-api-key.git"},"scripts":{"build":"tsup --dts --clean -d dist src","test":"ava","prepublish":"yarn build"},"devDependencies":{"@ianvs/prettier-plugin-sort-imports":"^4.1.0","@tsconfig/node18":"^18.2.1","@tsconfig/strictest":"^2.0.2","@types/eslint":"^8.44.2","@types/node":"~18.17","ava":"^4.2.0","esbuild":"^0.14.38","esbuild-register":"^3.3.2","eslint":"^8.48.0","eslint-config-prettier":"^9.0.0","prettier":"^3.0.3","tsup":"^5.12.7","typescript":"^4.6.4"},"dependencies":{"@scure/base":"^1.1.3"},"licenseText":"MIT License\n\nCopyright (c) 2022 Seam\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@bencmbrook/prefixed-api-key@2.0.2","dist":{"shasum":"a42b8ba3459a3c67fa3352f07d4ec8ba62194257","integrity":"sha512-tOmD69VmL2b0FFiMzV3HQb1DTYSt0hde3BzTrJThQxrx4FU7t/YiSObmSoBlF6rKFolUlLzpclqsqWTQ7WSqBg==","tarball":"https://registry.npmjs.org/@bencmbrook/prefixed-api-key/-/prefixed-api-key-2.0.2.tgz","fileCount":7,"unpackedSize":9143,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBN29/M8JiEiLYoT8XWS0zyb2YfQnEPLwnSdDOWeOWWfAiAGJQCju8lbnfQQe1gbxouQ3rlnkw8xIRoChy4W3FMsGA=="}]},"_npmUser":{"name":"bencmbrook","email":"ben@transcend.io"},"directories":{},"maintainers":[{"name":"bencmbrook","email":"ben@transcend.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/prefixed-api-key_2.0.2_1693875205594_0.3455223445911848"},"_hasShrinkwrap":false},"3.0.0":{"name":"@bencmbrook/prefixed-api-key","version":"3.0.0","main":"dist/index.js","license":"MIT","description":"Generate prefixed API-keys","repository":{"type":"git","url":"git@github.com:bencmbrook/prefixed-api-key.git"},"scripts":{"build":"tsup --dts --clean -d dist src","test":"ava","prepublish":"yarn test && yarn build"},"devDependencies":{"@ianvs/prettier-plugin-sort-imports":"^4.1.0","@tsconfig/node18":"^18.2.1","@tsconfig/strictest":"^2.0.2","@types/eslint":"^8.44.2","@types/node":"~18.17","ava":"^4.2.0","esbuild":"^0.14.38","esbuild-register":"^3.3.2","eslint":"^8.48.0","eslint-config-prettier":"^9.0.0","prettier":"^3.0.3","tsup":"^5.12.7","typescript":"^4.6.4"},"dependencies":{"@scure/base":"^1.1.3"},"licenseText":"MIT License\n\nCopyright (c) 2022 Seam\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@bencmbrook/prefixed-api-key@3.0.0","dist":{"shasum":"5e8e9c6f3e2798a73495e2c6be91c105f1fe57ab","integrity":"sha512-73Mx9UPAa9LHP/AE73Ji8tqrttOxkqwXFbWy3PVdQOp9OGC1mZPrtIkkEuxciLEKouXn2C+hhMcnuE4j1CLfsg==","tarball":"https://registry.npmjs.org/@bencmbrook/prefixed-api-key/-/prefixed-api-key-3.0.0.tgz","fileCount":7,"unpackedSize":9217,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDmeBA1d0yVPUWmvoS35tipOlyzt5a58tAYK+5T0zzgBAiEAyQVtX9mS1skhPgprxRB2v40+2RsOLrQbC5dtwftd/5I="}]},"_npmUser":{"name":"bencmbrook","email":"ben@transcend.io"},"directories":{},"maintainers":[{"name":"bencmbrook","email":"ben@transcend.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/prefixed-api-key_3.0.0_1693876611105_0.1163134783849138"},"_hasShrinkwrap":false},"3.0.1":{"name":"@bencmbrook/prefixed-api-key","version":"3.0.1","main":"dist/index.js","license":"MIT","description":"Generate prefixed API-keys","repository":{"type":"git","url":"git@github.com:bencmbrook/prefixed-api-key.git"},"scripts":{"build":"tsup --dts --clean -d dist src","test":"ava","prepublish":"yarn test && yarn build"},"devDependencies":{"@ianvs/prettier-plugin-sort-imports":"^4.1.0","@tsconfig/node18":"^18.2.1","@tsconfig/strictest":"^2.0.2","@types/eslint":"^8.44.2","@types/node":"~18.17","ava":"^4.2.0","esbuild":"^0.14.38","esbuild-register":"^3.3.2","eslint":"^8.48.0","eslint-config-prettier":"^9.0.0","prettier":"^3.0.3","tsup":"^5.12.7","typescript":"^4.6.4"},"dependencies":{"@scure/base":"^1.1.3"},"licenseText":"MIT License\n\nCopyright (c) 2022 Seam\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@bencmbrook/prefixed-api-key@3.0.1","dist":{"shasum":"02d349b6a884ba0907d1b1b71911bff32ca8dab9","integrity":"sha512-KXoBETE0MsYr2NJzvmG079YKRCY3Dk+BlryMK++2z5qRYcIvU6LkQWTyWglduA7KUnJyvpRLr/g4Nr3Ngqsxkg==","tarball":"https://registry.npmjs.org/@bencmbrook/prefixed-api-key/-/prefixed-api-key-3.0.1.tgz","fileCount":7,"unpackedSize":9233,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFYYK2bwtv2hXKOdL145CMMRlqIHWCrdz6qwGL+XM3eSAiBN8u6xs+vAj2IITolLv/uGY60ralOcz5frvQOMvPWA6A=="}]},"_npmUser":{"name":"bencmbrook","email":"ben@transcend.io"},"directories":{},"maintainers":[{"name":"bencmbrook","email":"ben@transcend.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/prefixed-api-key_3.0.1_1693876716261_0.6879877336810962"},"_hasShrinkwrap":false},"4.0.0":{"name":"@bencmbrook/prefixed-api-key","version":"4.0.0","main":"dist/index.js","license":"MIT","description":"Generate prefixed API-keys","repository":{"type":"git","url":"git@github.com:bencmbrook/prefixed-api-key.git"},"scripts":{"build":"tsup --dts --clean -d dist src","test":"ava","prepublish":"yarn test && yarn build"},"devDependencies":{"@ianvs/prettier-plugin-sort-imports":"^4.1.0","@tsconfig/node18":"^18.2.1","@tsconfig/strictest":"^2.0.2","@types/eslint":"^8.44.2","@types/node":"~18.17","ava":"^4.2.0","esbuild":"^0.14.38","esbuild-register":"^3.3.2","eslint":"^8.48.0","eslint-config-prettier":"^9.0.0","prettier":"^3.0.3","tsup":"^5.12.7","typescript":"^4.6.4"},"dependencies":{"@scure/base":"^1.1.3"},"licenseText":"MIT License\n\nCopyright (c) 2022 Seam\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@bencmbrook/prefixed-api-key@4.0.0","dist":{"shasum":"35f00d0e914e264edafd4ed2e936b04cf2cfd116","integrity":"sha512-++OY35DiZ6vXRa+D2QuTYenAcI14p+x+3Bfkgfod7EzgJM79ulTfI5Z8stJSRobu5vjxOmOxfZRkoZNGjuexRg==","tarball":"https://registry.npmjs.org/@bencmbrook/prefixed-api-key/-/prefixed-api-key-4.0.0.tgz","fileCount":7,"unpackedSize":10026,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHyCAvwZnt6VCWepn+ZaRIF/2t4scV1VQPCU9NdAk2rIAiEAqmfge/l1HWr4XHqnBNa2VgaaKcRh2uUmHXifAvSozcM="}]},"_npmUser":{"name":"bencmbrook","email":"ben@transcend.io"},"directories":{},"maintainers":[{"name":"bencmbrook","email":"ben@transcend.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/prefixed-api-key_4.0.0_1693878863512_0.8506691491527707"},"_hasShrinkwrap":false}},"time":{"created":"2023-09-05T00:51:48.133Z","2.0.0":"2023-09-05T00:51:48.386Z","modified":"2023-09-05T01:54:23.872Z","2.0.2":"2023-09-05T00:53:25.868Z","3.0.0":"2023-09-05T01:16:51.257Z","3.0.1":"2023-09-05T01:18:36.467Z","4.0.0":"2023-09-05T01:54:23.675Z"},"maintainers":[{"name":"bencmbrook","email":"ben@transcend.io"}],"description":"Generate prefixed API-keys","repository":{"type":"git","url":"git@github.com:bencmbrook/prefixed-api-key.git"},"license":"MIT","readme":"# Generate Prefixed API Keys\n\n**This is a fork of [seamapi/prefixed-api-key](https://github.com/seamapi/prefixed-api-key)**. Seam-style API Keys have many advantages:\n\n- Double clicking the api key selects the entire api key\n- The alphabet is standard across languages thanks [to the base58 RFC](https://datatracker.ietf.org/doc/html/draft-msporny-base58) and its usage in cryptocurrencies\n- They are shorter than hex and base32 api keys\n- They have prefixes [allowing secret scanning by github](https://docs.github.com/en/code-security/secret-scanning/about-secret-scanning)\n- They have a hashed component so the server doesn't need to store the api key (reducing attack surface)\n- They have unhashed Key IDs which can be mutually used by the server and key bearer/customer to identify the api key\n- They default to roughly the same number of entropy bits as UUIDv4\n\n## The Format\n\nAPI keys look like this:\n\n```\nmyapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG\n```\n\nLet's break down each component of the API key...\n\n```\nmyapp ..._...  BRTRKFsL ..._...  51FwqftsmMDHHbJAMEXXHCgG\n^              ^                 ^\nPrefix         Key ID            Secret\n```\n\n- The Prefix is used to identify the company or service creating the API Key.\n  This is very helpful in secret scanning.\n- The Key ID is stored by both the server and the key bearer/customer, it\n  can be used to identify an API key in logs or displayed on a customer's\n  dashboard. An `apiKey` can be blocklisted by its Key ID.\n- The Secret is how we authenticate this key. The secret is never stored\n  on the server, but a hash of it is stored on the server. When we receive an\n  incoming request, we search our database for `key_id` and `hash(secret)`.\n\n## Getting Started\n\n```ts\nimport { generateAPIKey } from '@bencmbrook/prefixed-api-key';\n\nconst key = await generateAPIKey({ keyPrefix: 'myapp' });\n\n// Store the key.secretHash and key.keyId in your database and give\n// key.apiKey to your customer.\n\nconsole.log(key);\n/*\n{\n  keyId: 'BRTRKFsL',\n  secretHash: 'd70d981d87b449c107327c2a2afbf00d4b58070d6ba571aac35d7ea3e7c79f37',\n  apiKey: 'myapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG'\n}\n*/\n```\n\n## Utility Methods\n\n```ts\nimport {\n  checkAPIKey,\n  extractKeyId,\n  extractSecret,\n  getAPIKeyObject,\n  hashSecret,\n} from '@bencmbrook/prefixed-api-key';\n\nhashSecret('51FwqftsmMDHHbJAMEXXHCgG');\n// \"d70d981d87b449c107327c2a2afbf00d4b58070d6ba571aac35d7ea3e7c79f37\"\n\nextractSecret('myapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG');\n// \"51FwqftsmMDHHbJAMEXXHCgG\"\n\nextractKeyId('myapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG');\n// \"BRTRKFsL\"\n\ngetAPIKeyObject('myapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG');\n/*\n{\n  keyId: 'BRTRKFsL',\n  secretHash: 'd70d981d87b449c107327c2a2afbf00d4b58070d6ba571aac35d7ea3e7c79f37',\n  apiKey: 'myapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG'\n}\n*/\n\ncheckAPIKey(\n  'myapp_BRTRKFsL_51FwqftsmMDHHbJAMEXXHCgG',\n  'd70d981d87b449c107327c2a2afbf00d4b58070d6ba571aac35d7ea3e7c79f37',\n);\n// true\n```\n","readmeFilename":"README.md"}