{"_id":"@build0.ai/credentials","_rev":"4-7d62986b48331717ffc598241dc46047","name":"@build0.ai/credentials","dist-tags":{"latest":"1.1.2"},"versions":{"1.0.0":{"name":"@build0.ai/credentials","version":"1.0.0","keywords":["nextjs","credentials","encryption","api","middleware","authentication","build0"],"author":{"name":"Build0.ai"},"license":"MIT","_id":"@build0.ai/credentials@1.0.0","maintainers":[{"name":"phil_build0","email":"phil@build0.ai"}],"dist":{"shasum":"27472e4300fa4a907fabdd06efea834a11fc7d3e","tarball":"https://registry.npmjs.org/@build0.ai/credentials/-/credentials-1.0.0.tgz","fileCount":4,"integrity":"sha512-mtdiiZnhTDLQdvJt8OiQOEJzqb+Yp3sdssCOaD/nnAuWuDmEf0TheoTVbxCKwmkXodc3vIdIGqtAIs9kxg57OA==","signatures":[{"sig":"MEUCIFoPapVC2zRczru/1B8+TU4Th8mv/gGklU95rilmzorAAiEAgTxRM8ExJ+WYqQTuTJQPHEftGeUGOqgp7co/m5oTets=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11351},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"86026dceed169d66fb95245f3d2a90fbe2fce72c","scripts":{"test":"echo \"Error: no test specified\" && exit 1","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"phil_build0","email":"phil@build0.ai"},"_npmVersion":"10.9.2","description":"A higher-order function for Next.js API routes that automatically handles encrypted credential retrieval and injection","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"^3.22.0","axios":"^1.6.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"next":"^14.0.0","react":"^18.0.0","typescript":"^5.0.0","@types/node":"^20.0.0"},"peerDependencies":{"next":">=13.0.0","react":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.0.0_1749927585492_0.917706149873049","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@build0.ai/credentials","version":"1.1.0","keywords":["nextjs","credentials","encryption","api","middleware","authentication","build0"],"author":{"name":"Build0.ai"},"license":"MIT","_id":"@build0.ai/credentials@1.1.0","maintainers":[{"name":"phil_build0","email":"phil@build0.ai"}],"dist":{"shasum":"00b9bc99d54a0459fbd27a1da358b90c10702a33","tarball":"https://registry.npmjs.org/@build0.ai/credentials/-/credentials-1.1.0.tgz","fileCount":4,"integrity":"sha512-ZowMwq7PVk9Qt+bkQy0425DGrh/L2ktYTprRr5+yuro1vwLLbXfY6uzokEgVGC20QWmP6OkaiCbM4rTUj+Wk8A==","signatures":[{"sig":"MEUCIGrbfGHN6PAaUJWJcQlLlzeFMYD++9UANqtXZGY2OGujAiEAk0Frri95tJWxOOKHIAmhQe7VekBZotZjmRP6RLS35sI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11773},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"aa007632c4486710494aba1677c51d8dd819159a","scripts":{"test":"echo \"Error: no test specified\" && exit 1","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"phil_build0","actor":{"name":"phil_build0","type":"user","email":"phil@build0.ai"},"email":"phil@build0.ai"},"_npmVersion":"10.9.2","description":"A higher-order function for Next.js API routes that automatically handles encrypted credential retrieval and injection","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"^3.22.0","axios":"^1.6.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"next":"^14.0.0","react":"^18.0.0","typescript":"^5.0.0","@types/node":"^20.0.0"},"peerDependencies":{"next":">=13.0.0","react":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.1.0_1751158130741_0.6109449826429327","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@build0.ai/credentials","version":"1.1.1","keywords":["nextjs","credentials","encryption","api","middleware","authentication","build0"],"author":{"name":"Build0.ai"},"license":"MIT","_id":"@build0.ai/credentials@1.1.1","maintainers":[{"name":"phil_build0","email":"phil@build0.ai"}],"dist":{"shasum":"857ec43ee23da0998226f2b3619f9e211365559c","tarball":"https://registry.npmjs.org/@build0.ai/credentials/-/credentials-1.1.1.tgz","fileCount":4,"integrity":"sha512-k7mxOn64flRXaELlCD6JgpRCN4lILzZxdkPqzrNgktRtUTEKZKeWIIgyuysMtcDIRUmL/OYtmB712Io8SR6a6g==","signatures":[{"sig":"MEUCIQDk4y5oJi3438hsZqq6jn+NRxyIY2Thg+XPAPWs7nuuiAIgawnPV8uNF1QitptXg3WODJAfBK5+H5UC7maIYGnP9Vw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11714},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"4659a9a45241a33721b8a839c92523248b20a8e5","scripts":{"test":"echo \"Error: no test specified\" && exit 1","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"phil_build0","actor":{"name":"phil_build0","type":"user","email":"phil@build0.ai"},"email":"phil@build0.ai"},"_npmVersion":"10.9.2","description":"A higher-order function for Next.js API routes that automatically handles encrypted credential retrieval and injection","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"^3.22.0","axios":"^1.6.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"next":"^14.0.0","react":"^18.0.0","typescript":"^5.0.0","@types/node":"^20.0.0"},"peerDependencies":{"next":">=13.0.0","react":">=18.0.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.1.1_1751387600200_0.5268836561932047","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@build0.ai/credentials","version":"1.1.2","description":"A higher-order function for Next.js API routes that automatically handles encrypted credential retrieval and injection","main":"dist/index.js","types":"dist/index.d.ts","scripts":{"build":"tsc","prepublishOnly":"npm run build","test":"echo \"Error: no test specified\" && exit 1"},"keywords":["nextjs","credentials","encryption","api","middleware","authentication","build0"],"author":{"name":"Build0.ai"},"license":"MIT","peerDependencies":{"next":">=13.0.0","react":">=18.0.0"},"dependencies":{"zod":"^3.22.0"},"devDependencies":{"@types/node":"^20.0.0","next":"^14.0.0","react":"^18.0.0","typescript":"^5.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_id":"@build0.ai/credentials@1.1.2","gitHead":"4659a9a45241a33721b8a839c92523248b20a8e5","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-6FRkiQjZVQm7bGDJjIz06LgPvbLUn/ci7OS4aHoUuVs43LeKTlkEQzjIdXcWbaja2im1ZYERLJ/sET7JibLGIQ==","shasum":"0ed667ff042a8df765eb26f2664809446e225f68","tarball":"https://registry.npmjs.org/@build0.ai/credentials/-/credentials-1.1.2.tgz","fileCount":4,"unpackedSize":11691,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCSQO1uzaObN6Bj9lQ0MGK02h9MZFLR349VrdSO1YTr4AIgVLXfXwiPoH83nwNPznPQRDsmoYubDuYSMIiGNpgDUsA="}]},"_npmUser":{"name":"phil_build0","email":"phil@build0.ai","actor":{"name":"phil_build0","email":"phil@build0.ai","type":"user"}},"directories":{},"maintainers":[{"name":"phil_build0","email":"phil@build0.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/credentials_1.1.2_1751387677336_0.7501999365115288"},"_hasShrinkwrap":false}},"time":{"created":"2025-06-14T18:59:45.398Z","modified":"2025-07-01T16:34:37.748Z","1.0.0":"2025-06-14T18:59:45.686Z","1.1.0":"2025-06-29T00:48:50.926Z","1.1.1":"2025-07-01T16:33:20.394Z","1.1.2":"2025-07-01T16:34:37.539Z"},"author":{"name":"Build0.ai"},"license":"MIT","keywords":["nextjs","credentials","encryption","api","middleware","authentication","build0"],"description":"A higher-order function for Next.js API routes that automatically handles encrypted credential retrieval and injection","maintainers":[{"name":"phil_build0","email":"phil@build0.ai"}],"readme":"# @build0.ai/credentials\n\nA higher-order function for Next.js API routes that automatically handles encrypted credential retrieval and injection.\n\n## Features\n\n- 🔐 Automatic credential decryption using AES-256-GCM\n- 🚀 Environment variable fallback for improved performance\n- 🛡️ Type-safe credential handling with Zod validation\n- 🔄 Seamless integration with Next.js API routes\n- 📦 Zero-config setup\n\n## Installation\n\n```bash\nnpm install @build0.ai/credentials\n```\n\n## Quick Start\n\n```typescript\nimport { withCredentials, RequestWithCredentials } from '@build0.ai/credentials';\n\nexport const GET = withCredentials(async (request: RequestWithCredentials) => {\n  // Access decrypted credentials\n  const credentials = request.appCredentials;\n  \n  // Use credentials to make authenticated API calls\n  return NextResponse.json({ status: 'success' });\n});\n```\n\n## Configuration\n\n### Environment Variables\n\nThe package requires the following environment variables:\n\n```bash\n# Required: Encryption key for credential decryption\nENCRYPTION_KEY=your-32-byte-hex-encryption-key\n\n# Option 1: Pre-encrypted credentials (recommended for performance)\nENCRYPTED_APP_CREDENTIALS=iv:authTag:encryptedData\n\n# Option 2: Fallback credential endpoint\nGET_CREDENTIALS_URL=https://your-api.com/credentials\n```\n\n### Credential Sources\n\nThe package supports two credential sources with automatic fallback:\n\n1. **Environment Variable** (Primary): `ENCRYPTED_APP_CREDENTIALS`\n   - Fastest option - no HTTP requests\n   - Ideal for production deployments\n\n2. **HTTP Endpoint** (Fallback): `GET_CREDENTIALS_URL`\n   - Fetches credentials from remote endpoint\n   - Forwards cookies for authentication\n   - Used when `ENCRYPTED_APP_CREDENTIALS` is not available\n\n## API Reference\n\n### `withCredentials(handler)`\n\nHigher-order function that wraps your API route handler.\n\n**Parameters:**\n- `handler`: Your API route handler function\n\n**Returns:**\n- Enhanced handler that provides `appCredentials` on the request object\n\n### `RequestWithCredentials`\n\nExtended Next.js request interface with credentials attached.\n\n**Properties:**\n- `appCredentials`: Decrypted and validated credentials object\n- All standard `NextRequest` properties\n\n### Credential Structure\n\nCredentials follow this TypeScript interface:\n\n```typescript\ntype Credentials = Record<string, {\n  type: string;      // Credential type\n  provider: string;  // Credential provider\n  [key: string]: any; // Additional provider-specific fields\n}>;\n```\n\n## Error Handling\n\nThe package throws `CredentialError` when:\n- Credentials cannot be decrypted\n- Network requests fail\n- Credential validation fails\n\nAPI routes return a 401 status with error details:\n\n```json\n{\n  \"error\": \"Credential access failed\",\n  \"message\": \"Detailed error message\"\n}\n```\n\n## Security\n\n- Uses AES-256-GCM encryption with authentication\n- Supports Additional Authenticated Data (AAD)\n- Validates credential structure with Zod schemas\n- Secure key management via environment variables\n\n## Example Usage\n\n### Basic API Route\n\n```typescript\n// app/api/example/route.ts\nimport { withCredentials, RequestWithCredentials } from '@build0.ai/credentials';\nimport { NextResponse } from 'next/server';\n\nexport const GET = withCredentials(async (request: RequestWithCredentials) => {\n  const { appCredentials } = request;\n  \n  // Access specific integration credentials\n  const githubCreds = appCredentials.github;\n  const slackCreds = appCredentials.slack;\n  \n  // Make authenticated API calls\n  // ...\n  \n  return NextResponse.json({ message: 'Success' });\n});\n```\n\n### With Error Handling\n\n```typescript\nexport const POST = withCredentials(async (request: RequestWithCredentials) => {\n  try {\n    const { appCredentials } = request;\n    // Your logic here\n    return NextResponse.json({ success: true });\n  } catch (error) {\n    return NextResponse.json(\n      { error: 'Internal server error' },\n      { status: 500 }\n    );\n  }\n});\n```\n\n## Development\n\n```bash\n# Install dependencies\nnpm install\n\n# Build the package\nnpm run build\n\n# Publish to npm\nnpm publish\n```\n\n## License\n\nMIT\n\n## Support\n\nFor issues and questions, please visit the [GitHub repository](https://github.com/build0-ai/credentials). ","readmeFilename":"README.md"}