{"_id":"@cqaiclub/cqai-account-sdk","_rev":"3-189ca195080b8e0872db89f03321d8bc","name":"@cqaiclub/cqai-account-sdk","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@cqaiclub/cqai-account-sdk","version":"0.1.0","_id":"@cqaiclub/cqai-account-sdk@0.1.0","maintainers":[{"name":"gdxw","email":"dxw525224259@gmail.com"}],"dist":{"shasum":"f1568c47821760578e6f4cd38c3b1cb61b48d65f","tarball":"https://registry.npmjs.org/@cqaiclub/cqai-account-sdk/-/cqai-account-sdk-0.1.0.tgz","fileCount":13,"integrity":"sha512-DbffMumIAmQuIZA0kAbvM+VGf3lY8+t4JO6PhY8SCmYlJDmgF8Ju81BV2feqspncr+fgMM866L4kWybhwntvLw==","signatures":[{"sig":"MEUCIAyzyEnfw8rNPCyph79+sM9etF23mzUkPUoDAz8L7+nRAiEA7m521/EHjATFshqU1G/qpXkwKXNBjMpePKDOvgbVBcM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60146},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"997bd352bd5e5a12c9c4aabd89c0dd6a7a362f84","scripts":{"test":"npm run build && node --test","build":"tsc -p tsconfig.json","prepare":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"gdxw","email":"dxw525224259@gmail.com"},"_npmVersion":"11.16.0","description":"Server-side TypeScript SDK for NewAPI login, account provisioning, tokens, usage, and billing","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^26.4.0"},"_npmOperationalInternal":{"tmp":"tmp/cqai-account-sdk_0.1.0_1788437352672_0.3433699697262904","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@cqaiclub/cqai-account-sdk","version":"0.1.1","_id":"@cqaiclub/cqai-account-sdk@0.1.1","maintainers":[{"name":"gdxw","email":"dxw525224259@gmail.com"}],"dist":{"shasum":"c06b42b8b1388c64d82dc91ec252238c984d0ce7","tarball":"https://registry.npmjs.org/@cqaiclub/cqai-account-sdk/-/cqai-account-sdk-0.1.1.tgz","fileCount":13,"integrity":"sha512-PFNIdtcLWaW4o4sUr9oUkEZzykKoXcgw+l7DyjkyuffVYVOyEExKuaLLPBvBEOhKjAZETCzv7MoArI336BE5IQ==","signatures":[{"sig":"MEYCIQCRBfm1TIfrWdNUFT5P0j8SvhNyGumuEIvd0ZseOV3SawIhAI0gDuv9d7ypOvZZixcmAZJ2n9cxhC2uSZPCHeXzKtQW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60750},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"6428eb2842daa6f1a9e8a84518c5b3d2b41614fe","scripts":{"test":"npm run build && node --test","build":"tsc -p tsconfig.json","prepare":"npm run build","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"gdxw","email":"dxw525224259@gmail.com"},"_npmVersion":"10.9.2","description":"Server-side TypeScript SDK for NewAPI login, account provisioning, tokens, usage, and billing","directories":{},"_nodeVersion":"22.17.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.3","@types/node":"^26.4.0"},"_npmOperationalInternal":{"tmp":"tmp/cqai-account-sdk_0.1.1_1788693329855_0.903418058078987","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@cqaiclub/cqai-account-sdk","version":"0.1.2","description":"Server-side TypeScript SDK for NewAPI login, account provisioning, tokens, usage, and billing","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test":"npm run build && node --test","prepare":"npm run build"},"engines":{"node":">=18"},"devDependencies":{"@types/node":"^26.4.0","typescript":"^5.6.3"},"gitHead":"4832ac77311b9ae5f2f0c73845f707c1020f0d80","_id":"@cqaiclub/cqai-account-sdk@0.1.2","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-sp4e8Fot/Ve4zlBpFo1mUriMxkE97B8MMJMFdGBKqzdRNbVzXzGKdAz5mJI+jKapd2EpeaN0NkWjIgIe82B+vw==","shasum":"a98deab2fbb933de9783621304ea3d89b45f94ca","tarball":"https://registry.npmjs.org/@cqaiclub/cqai-account-sdk/-/cqai-account-sdk-0.1.2.tgz","fileCount":13,"unpackedSize":62049,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIF1Z7TCK+ssNaGdlGhBfZktY23ynlVsmv65unje5LFqzAiEAgv3oOuae4Zr7UFoRWPeKAmlUhDrbQn1pldzF59PwqQc="}]},"_npmUser":{"name":"gdxw","email":"dxw525224259@gmail.com"},"directories":{},"maintainers":[{"name":"gdxw","email":"dxw525224259@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cqai-account-sdk_0.1.2_1789183865849_0.6191884279663993"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-03T12:09:12.179Z","modified":"2026-09-12T03:31:06.110Z","0.1.0":"2026-09-03T12:09:12.822Z","0.1.1":"2026-09-06T11:15:29.995Z","0.1.2":"2026-09-12T03:31:05.973Z"},"description":"Server-side TypeScript SDK for NewAPI login, account provisioning, tokens, usage, and billing","maintainers":[{"name":"gdxw","email":"dxw525224259@gmail.com"}],"readme":"# CQAI Account SDK\n\nServer-side TypeScript clients for the NewAPI HTTP interface. NewAPI remains\nthe source of truth for dashboard users, API keys, quota, usage, and billing.\nThis package does not contain an identity provider integration or a local\ndatabase.\n\n## Install\n\n```bash\nnpm install @cqaiclub/cqai-account-sdk\n```\n\nBefore the first npm release, install directly from GitHub. The package's\n`prepare` script builds `dist` during installation:\n\n```bash\nnpm install github:cqai-club/cqai-account-sdk\n```\n\n## Dashboard login and account queries\n\n```ts\nimport { NewApiAuthClient } from '@cqaiclub/cqai-account-sdk'\n\nconst auth = new NewApiAuthClient({\n  baseUrl: process.env.NEW_API_URL!,\n  // Keep the access token and refresh cookie on a trusted backend.\n  origin: process.env.NEW_API_ORIGIN,\n  credentials: 'include',\n})\n\nconst login = await auth.login({\n  username: 'alice',\n  password: process.env.NEW_API_PASSWORD!,\n})\n\nif (login.kind === 'two_factor') {\n  const authenticated = await auth.login2FA(login.flowToken, getTotpCode())\n  console.log(authenticated.user?.username)\n} else {\n  console.log(login.user?.username)\n}\n\nconst user = await auth.getSelf()\nconst tokens = await auth.listTokens({ page: 1, pageSize: 20 })\nconst fullKey = await auth.getTokenKey(tokens.items[0].id)\n\n// refresh() uses the HttpOnly new_api_refresh cookie captured by the client.\nawait auth.refresh()\nawait auth.logout()\n```\n\n`login()` returns a discriminated union. A successful password login stores the\ndashboard access token and refresh cookie in the client. When Node's `fetch`\ncannot expose `Set-Cookie`, pass a custom `cookieJar` or use a same-origin\nbrowser request with `credentials: 'include'`.\n\nThe login endpoint may require a Cloudflare Turnstile token. Pass it as the\nsecond argument: `auth.login(request, { turnstile })`. If password encryption\nis enabled in NewAPI, provide the caller-encrypted fields\n`passwordEncrypted` and `encryptionKeyId`; the SDK does not handle private RSA\nkeys.\n\n## Service provisioning and relay usage\n\nProvisioning is server-only and requires the protected NewAPI service token:\n\n```ts\nimport { NewApiClient } from '@cqaiclub/cqai-account-sdk'\n\nconst newApi = new NewApiClient({\n  baseUrl: process.env.NEW_API_URL!,\n  serviceToken: process.env.NEW_API_INTERNAL_TOKEN!,\n})\n\nconst binding = await newApi.provision({\n  issuer: 'https://accounts.example.com',\n  subject: 'user-123',\n  platform: 'writer-app',\n  email: 'alice@example.com',\n  username: 'alice',\n  name: 'Alice',\n  role: 1,\n}, { idempotencyKey: 'writer-app:user-123' })\n\nif (binding.apiKey) {\n  // Store the key only in the platform backend.\n  const usage = await newApi.getTokenUsage(binding.apiKey)\n  const subscription = await newApi.getSubscription(binding.apiKey)\n  const billing = await newApi.getBillingUsage(binding.apiKey)\n  console.log(usage.totalAvailable, subscription.accessUntil, billing.totalUsage)\n}\n```\n\n`NEW_API_INTERNAL_TOKEN` must exactly match the value configured on NewAPI.\nUse a long random value and never expose it through a `VITE_*` variable or a\nbrowser bundle.\n\n`getTokenUsage()`, `getSubscription()`, and `getBillingUsage()` use a relay\nAPI key. They must not be called with a dashboard access token or the service\ntoken. The token list endpoint intentionally returns a masked key; call\n`getTokenKey(id)` only on a trusted backend when the full key is required.\n\nProvisioning creates or reuses the NewAPI user/key binding. NewAPI-generated\nprovisioning users do not return a dashboard password, so provisioning is not a\nreplacement for a user login flow. Existing users can use `login()` with their\nNewAPI credentials, or the product can keep its own login and use provisioning\nserver-to-server.\n\n`email`, `username`, `name`, and `role` are optional trusted profile fields.\nThe Relay implementation uses `role` only when creating a new user. Set\n`syncProfile: true` only when the trusted backend intentionally wants to update\nan existing user's non-conflicting username and display name; it never changes\nthe existing role, group, quota, or credentials.\n\n## API surface\n\n- `NewApiAuthClient`: encryption-key lookup, login, 2FA, registration, refresh,\n  logout, current-user lookup, token CRUD, and full-key retrieval.\n- `NewApiClient`: protected provisioning plus relay-key usage and billing.\n- `MemoryCookieJar`: small single-origin cookie jar for Node server processes.\n- `AiAccountError`: normalized HTTP/business error with `status`, `code`, and\n  optional `retryAfter`.\n\nDo not put `serviceToken`, dashboard access tokens, user passwords, or full API\nkeys in browser bundles or logs. For browser applications, use a same-origin\nbackend proxy when possible; cross-origin refresh depends on cookie, CORS, and\ntrusted-origin configuration in NewAPI.\n\n## Development\n\n```bash\nnpm run typecheck\nnpm run build\n```\n","readmeFilename":"README.md"}