{"_id":"@vitalpoint/near-phantom-auth","_rev":"31-dfd5660027e75f0e518f200b6f5847ff","name":"@vitalpoint/near-phantom-auth","dist-tags":{"latest":"0.8.3"},"versions":{"0.1.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.1.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.1.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"79a63e842f870786ad18c37f844a2ccc4f06bc02","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.1.1.tgz","fileCount":14,"integrity":"sha512-w8lcCMgv7PBGHWf00g2DnFdo5HejSO2L14trHwU7NkS2/6UbCLuzBM9TGEhxC/NRf3rW0g8+K8axaTsByxfp8A==","signatures":[{"sig":"MEUCIQDq4nYqQVqnJ1r386ROgvozPlIQQikY5G96i/hgpZU/8AIgXenhvwSEKMsl7qh3gpWTZ/0/IxHP9FFb/OqMVYABhAI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":461063},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.mjs","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.mjs","require":"./dist/server/index.cjs"}},"gitHead":"5a7c9c96d011b79acef16239583f41472f1da1e4","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.1.1_1770733458263_0.4651660691481876","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"d8582dac2aa486ed17bf5b9354af541bab7f2e0a","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.0.tgz","fileCount":14,"integrity":"sha512-Wcv2cFN2YcBF1h6Pq5cYfLRZ+xZpQTwHm673Nh8WasKx1zP0UcQBrgCsI1CveywD4FGLjee2Kqm/uaGU7jWTFQ==","signatures":[{"sig":"MEQCIFXNKmR6EruOwmfsc9AxPKbHQ2DuZ1cjWa5zzCXhdmGpAiA8H9OV0Dy04hU1lF42Ut7bwycqtiTssw/p3unCJA5QuQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":657364},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.mjs","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.mjs","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.0_1770753929610_0.5781576465815681","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"e357dbabea18e78dda4d800ff2a4964115292f5f","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.1.tgz","fileCount":14,"integrity":"sha512-aXpvHujv/T8EzXYbPA5Jmi69g2nE7O9vszMy0hh2kqPndNSmz4viBKbBHDfLgIuFKRbY8ThlyAcP2K1/KqRPSA==","signatures":[{"sig":"MEUCIQDqvyrwKreNmIrbfbkLSkzEZ3I20BMUsTZaeFXsGUYAZgIgChVT+KKZrnDMFLF4Pbb6ZT6dDpljwn7RTQ1K5SA88Fo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":657361},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.1_1770786135448_0.46611559416971016","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.2","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.2","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"4c49f86804d02e095da216aabfe113d8ab28ecaa","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.2.tgz","fileCount":14,"integrity":"sha512-mr6XukN5zNpSvjw8VCbQtZJwqntdxZXwuo7cXymIfeL6TQXo0sHzdLhPOxzW7bouhmYNnV2ddrSYYddBchzV+Q==","signatures":[{"sig":"MEUCIHVsws9LYoM8o55YVy7YFvb1g537C1KU/PnsQFl4KpN9AiEA2MEc2H8Rpgwb9Ml0rXkZYRrlg9qp9DGQToxA6qR9RKE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":659217},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.2_1770809275707_0.010310904041569202","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.3","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.3","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"8b0760cfd9965aba33687fbed1debe57fc91475b","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.3.tgz","fileCount":22,"integrity":"sha512-/zMtOBHVkdX6h+S/4c+OQCjookWt+uZxTN36pF3BoxUbX8yQkOn4vKDRF1g76hvKxlpbm0SDcnJsyQlqYZ33Zg==","signatures":[{"sig":"MEUCIFt1osqvDv5v4Q3c4Tehr0AHDuelfwVz5pN3JEDZFugsAiEAr2fgvdCyhj2H4wg75vD+cYYF3QG2ZIwoeJ5yJRAb5U8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":723737},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.3_1770810739694_0.291228535755675","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.4","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.4","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"772c764a5d52a5c6ef3bcdd2cc9e194f6db3f135","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.4.tgz","fileCount":22,"integrity":"sha512-L/kN84lWRtYNLk4Peq7KcbAKhYesrGyaJhWvU6u3bV7kf1bsmYbnFo6+PXwT4pJ48hOMdrgBL+gNH0aIZpeoUg==","signatures":[{"sig":"MEYCIQCroCVMHmMKnJ1VIaRawSSfqSbU8nPpkaUL/Eu94ZCN1gIhANrWxSh9G0EU1ASriJa1P5FJoQPKhOPYKLr9pWBucvGK","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":723737},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.4_1770814847961_0.08857632978702257","host":"s3://npm-registry-packages-npm-production"}},"0.2.5":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.5","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.5","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"24c73fa8982f7b6956bfe6897a10fb78c7758e1d","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.5.tgz","fileCount":22,"integrity":"sha512-OO2/19XWbZqFD3+0Eq8bcRoyj3PlGSmzCDmi+tnORbpgvuJw24zjX0PQQEtpfjXqDXXaTSPe7dDTZSgv9nnVGw==","signatures":[{"sig":"MEQCIHyuZ+Us9azP4qYzCwLR31Pj4HPaZN5PQGT47lrZ9QhXAiBwqAsFTLZIGIXsGg6AUxvWLnMD7H8SZKdr6IuoWPRuKg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":727216},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.5_1770821366367_0.8915195786168058","host":"s3://npm-registry-packages-npm-production"}},"0.2.6":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.6","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.6","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"e3550d9cc2cba3d543bb49946ee66618a604a8be","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.6.tgz","fileCount":22,"integrity":"sha512-fYKN44A+kVaT1N4ZlOuXKrqnKBej+xkilYERZMYvz308m5bEWOq2yDZx3aT7AWTyErdgSp/hU64aOTv/k/s8EA==","signatures":[{"sig":"MEQCIGTcPV19Cl8dQRYy5hzbcqZlzTDXV9F6s6Rh0WsiBY/MAiA0hSgl9MF3iVqtNdVL1v/uvNDQ8/wYkE3e+6SUpdE91g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":769867},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.6_1770822458053_0.9501367474134652","host":"s3://npm-registry-packages-npm-production"}},"0.2.7":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.7","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.7","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"93e272b15a0e1c09d692dba77a04704774caec36","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.7.tgz","fileCount":22,"integrity":"sha512-hzAohxUf/UH8SWp5YH5tAHKF4DW5KT59ST1lwjke6C+kDsdk+SbSXqE9c8ENULrnI5f6bodHd8KBBNOayiFd1w==","signatures":[{"sig":"MEUCIQCf6EMuWjblobWgfO/Cp9kfAR9JFg82YkE9liTkC0fT2QIgB8IleXArxTNXkqfCaupdHwmHGANG+WT7mLBdb7yAosM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":771791},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.7_1770822544564_0.14351500841694098","host":"s3://npm-registry-packages-npm-production"}},"0.2.8":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.8","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.8","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"4f742bb83e09d8de94acf864aaeffeb25a2c5bdd","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.8.tgz","fileCount":22,"integrity":"sha512-t8zl/euljzvz2bLsprGU6YWviVcNJn3G3FgrAgmN25Vq11iQz70sPEhMouXCExyrHCs/+fSSgEYbQ3JUhd3Szw==","signatures":[{"sig":"MEUCIQDrbyUX/aOnatgep+VLM54pEQPdgQOXVQ4rIPQQo/KhkQIgfOfqpmH5PURloJoKJm3lOP1jOQUHUooVU94USqIiwtc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":773929},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.8_1770822702406_0.4771582680649398","host":"s3://npm-registry-packages-npm-production"}},"0.2.9":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.9","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.9","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"81037274af0f444b8c0b01da5d7b07d2b98f2f82","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.9.tgz","fileCount":22,"integrity":"sha512-IEqMjIPXdJbsIBMmK8y7eGdC75RoYfmXC6soofim2a+27yL+6qmbnQmCLjkmipuYGTLrZv7XLMqy+UhQCjxvcA==","signatures":[{"sig":"MEUCIFlwLy5D5iMpOhXHcvT/q6x8elrCoPZFfDLaJAJwSgjFAiEAjujwyfIzZiWqncDIoV2BS80Aksca5lMeUII/2BHOZfY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":773219},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.9_1770822962214_0.3992991505491701","host":"s3://npm-registry-packages-npm-production"}},"0.2.10":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.10","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.10","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"856ddca44fa54cfd821b84adb3e433c8bf9b4f28","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.10.tgz","fileCount":22,"integrity":"sha512-F9XGtfJOuWhGfHuTL7HX8Ikl6sjoW9L+ywp6HJZsQgUxdPRigSb5XojzRAdAgsRdAbPH2uXL1sCimDmB48l/HQ==","signatures":[{"sig":"MEYCIQC6dCJ7J72uhZo/Vss17ao0bhnY/F7pqcnug6G5YoNuywIhAO3Y1CTdsD7TFUtP4u9PLlszvOzWPvSoYQRSkWIpmSxT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":780396},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d49ca060c1b439cc6bb1abe035eca49c1e7675e9","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.10_1770823926411_0.04912530896551037","host":"s3://npm-registry-packages-npm-production"}},"0.2.12":{"name":"@vitalpoint/near-phantom-auth","version":"0.2.12","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.2.12","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"8b39e88faf6a6928f81bd17f4ade6afd7d79d2b9","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.2.12.tgz","fileCount":22,"integrity":"sha512-OQ18Cp7aHqw0ZV6YCuSCq5oU0Ny7Ao6xiGBTiNXIJSyC/lh9CXFRawtnag2FrkoS03UGG8y3yOv3OExzxypsYA==","signatures":[{"sig":"MEQCIAhc7eU6FvDITbcgNRuTAL0jrj62PwStIuPMEuLbcDDpAiA0Q5rBWx9MJwxHvEj2QVeQXaFngBcUv9tzmpprutwmHg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":781545},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"d09b6836e13b703c45a4f24344cd02c535889a21","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.2.12_1771940690724_0.847063039467306","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.3.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.3.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"151099d3cf8ef01a9ffd1c1658bf36dfc4a5d65f","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.3.0.tgz","fileCount":22,"integrity":"sha512-/jgiOiFQ+GJaPgfkM4dYrUmZA5NipnwfHZfp/PSTwTzLvjGZdzre1imXlyEhDkvrpV9VaLlcMviplcsn/dDTbQ==","signatures":[{"sig":"MEQCIDV32p2s1o5f7KCoeEZAapfPH2zcB+97PLJZpC5hkASTAiB6Dg/MvNNVr5tQZ+A4yRceIDqcYS5q0ASPBa46zMJyyQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":808566},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"c53043a8d2fc40d71206266d6b6e3ba4573cb2a6","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.3.0_1772133364737_0.4743415830098898","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.4.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.4.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"31a0c01160c465f35753ffd8f0570e324b8bf3ce","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.4.0.tgz","fileCount":22,"integrity":"sha512-W7xQDKI/fsZ8MvttfjXRmEDK7zx0AN1xIz+eskxwflIPXRL8yB9I7yuY8hUuFevICKS2+DHYX/2eXymBZ4fYVA==","signatures":[{"sig":"MEUCIAeJtT4Ap2AJKRBroKSC8Uk9x4wSwOSco1CLQgJe4/ueAiEAmG5+ph8ANkQ07ymdeOx0Maj1FrIdDNSpXNqjKh/5BJg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":861200},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"}},"gitHead":"c53043a8d2fc40d71206266d6b6e3ba4573cb2a6","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.4.0_1772208668861_0.7901859136567178","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.4.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.4.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"0e53c162d4277dbc95cad8e01d7dded3571a7d18","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.4.1.tgz","fileCount":28,"integrity":"sha512-ctg9aRc1kW7ESlhHMbM+wXxWkMaRTxaJvxv7g3mZHLqoSt37UrlZMgQCBmaB8xnB9lRdJITtSetECsB6qmlKWA==","signatures":[{"sig":"MEUCIQCx34UXk1jNAkXfQ0QMZbHpfwENaCbedIGSF00+7j05JQIgKVEtCbnJAsKVcniwck729/FJLQ3cE+5AWvceZjxysc4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":902054},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"c53043a8d2fc40d71206266d6b6e3ba4573cb2a6","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.4.1_1772208838902_0.11964453895655569","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@vitalpoint/near-phantom-auth","version":"0.4.2","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.4.2","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"04ee3022460db070f55c20e627a6a3af92ae49c0","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.4.2.tgz","fileCount":28,"integrity":"sha512-trrLkWspMlLzfZG0AcZ2kC3mzMkLAyEu9N6GYDXknbRX8AyiKogRzH1RklFEpnAWgYf1/9xI89/6MxohGKcQUQ==","signatures":[{"sig":"MEUCIBCt3dIleDN7UzeP4m6/F84HZvOuCdyI8ANSwHeKYX8KAiEAj8ce98adxPvqFK+5S0ZhSFidEwh+6AFurjZhGplIr2I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":902054},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"6965de818a05153a1b7a8a0008d05c39e8897450","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.4.2_1772553098677_0.0020591679408215047","host":"s3://npm-registry-packages-npm-production"}},"0.4.3":{"name":"@vitalpoint/near-phantom-auth","version":"0.4.3","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.4.3","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"e2d16177778e6a16bb46989949a5f07207abc765","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.4.3.tgz","fileCount":28,"integrity":"sha512-eLJTdEM3DQxsS+ahLC9fZSqqcfgBgoKoKgh2sIZLN2UYYarHU5cAbH1z+gcg6xoiVvaBYxtdkbFfYNCdN2DEsg==","signatures":[{"sig":"MEUCIQCAkILoWudqJUJqOjeACckK6p72maA2sIpiNDLveDxfeQIgdDQjRhR7pGDGw7tdpDS9UiNh3TA4VY8AIZISwDXsS6k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":903744},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"e9a4e6713c0e7b161e599a080a870f284116d11c","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.4.3_1772578511838_0.7007993733500095","host":"s3://npm-registry-packages-npm-production"}},"0.4.4":{"name":"@vitalpoint/near-phantom-auth","version":"0.4.4","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.4.4","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"12875811304f4ab78fc15ce32e164b54c55b30d4","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.4.4.tgz","fileCount":28,"integrity":"sha512-tA/9Ztu1t5YS9f2Pe4O0rcE7maPy5jWwDNEJ5eZ/VLbzaePXS5UwvMbgfwCjI+3zgsrf8KBoCtE5u+w7DRxjfg==","signatures":[{"sig":"MEUCIQDH/ehe5LprWOOj1MybdnLDbGKtxwREp25ZagYkefIQPwIgcz5XaXrbxuz7ppMfuzzcD2/0aTkIBBbZk/k9qn8IFF0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":896121},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"c72e5e63afe9702952f04f5da8652eddc1c22830","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/crypto":"^2.0.1","@near-js/signers":"^0.2.1","@near-js/keystores":"^0.2.1","@near-js/providers":"^1.0.1","@near-js/transactions":"^2.0.1","@simplewebauthn/server":"^11.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.4.4_1772967439829_0.4602999315216658","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.5.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.5.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"a2f5fa56d47460dec0e705da0635c0e823ac5c8c","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.5.0.tgz","fileCount":28,"integrity":"sha512-sctuAHYKldp6nsg5N4J36C+f27SqR0UeQoZjuGzVRQdcNx3MuwLxK6JgZ+2pAbpNQyXT7PsoirSmqQHBCkOfFg==","signatures":[{"sig":"MEYCIQC9i5WzsdHGDCvqjm2f4Eei8hGLGoMjgfzHNqFbeFuGNwIhAORf8YYszX5bGv0CisWmvQ0DzSXWE9F6mhXqW69MDchw","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":896381},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"dbc019e028eb77ba57a15e6358fd721785dffa32","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.0.2","tweetnacl":"^1.0.3","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.3.0","vitest":"^3.0.0","@types/pg":"^8.16.0","typescript":"^5.7.0","@types/node":"^22.0.0","@types/react":"^19.2.13","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.5.0_1772969888244_0.9186279041674614","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.5.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.5.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"0a8912b0928e37e02eff38ee334632a5bc41d67e","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.5.1.tgz","fileCount":28,"integrity":"sha512-R+aQcd5Jc0pjGutryMFMpsW/ctQ90/LO1FtYh5Wzg3d+JDFKxorGdSXMlxx5NH8gyrWKTqfR7aZvJPP9rHlqgw==","signatures":[{"sig":"MEYCIQDeBQmVxrAMWVgQY6DWferburYEFVl1Z5Z9MmeXorrlqAIhAOoVlkNBCSI14r/JJUICLsBrhEy4sgSZfKKAMXWf9f12","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":896382},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"b8b9c4228db2efe2ab591eda7b49267a7aa4ed01","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.1.1","tweetnacl":"^1.0.3","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","typescript":"^5.9.3","@types/node":"^25.3.5","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.5.1_1772971498060_0.4939907998674413","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@vitalpoint/near-phantom-auth","version":"0.5.2","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.5.2","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/jim-agent/near-phantom-auth#readme","bugs":{"url":"https://github.com/jim-agent/near-phantom-auth/issues"},"dist":{"shasum":"be0015f74552905375438dced0bba5378f9e8cae","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.5.2.tgz","fileCount":28,"integrity":"sha512-KHTImX2mCP0MvsxK/ngjkbyUwKSxwJ7mgF+bJy9D5U43C+9Ojp+D8dYtHZsIMrbObUA0J0A5SlOghjqJzimjsQ==","signatures":[{"sig":"MEMCHyVvYmQcpJm5K9rC8rNyjr+LygPMyw85xiPAav8wgxwCIFGmSWmD5y7FcYVIqDee7MHjQPfRfUhsRJyCkmvPfsar","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":896414},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"df4717205776f2e20a77eefbe0118f6eafcc2415","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/jim-agent/near-phantom-auth.git","type":"git"},"_npmVersion":"11.6.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.13.0","dependencies":{"bs58":"^6.0.0","cookie":"^1.1.1","tweetnacl":"^1.0.3","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","typescript":"^5.9.3","@types/node":"^25.3.5","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.5.2_1772972058351_0.05666816202912517","host":"s3://npm-registry-packages-npm-production"}},"0.5.3":{"name":"@vitalpoint/near-phantom-auth","version":"0.5.3","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.5.3","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"62b7eee8fed2fc922c0753417ad03dbe40e5ef4f","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.5.3.tgz","fileCount":28,"integrity":"sha512-nvCXzZIz5FxEqo2SBfRDiCfg8ye2HOUp5JM70+XoRaQoPEJRS96R0UNw389hfZWW4VhJ1po4tPrnAof5o3w42w==","signatures":[{"sig":"MEUCIGuHtqCIqzARbUqE+2SzYpTzOCHFtJFuCHLo0rv9MX9pAiEA8xoonZz1X8RkjJKCd2l3mMM5PwrOphZtMsHk3Aj6mak=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@vitalpoint%2fnear-phantom-auth@0.5.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1095024},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"81bf91a7398996f62c4c3e860aee6c9da9a696c4","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.0","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.5.3_1773582610212_0.7114955408343617","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.6.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.6.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"743019d58319f8a2091ba450aa1b9b77f6251d84","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.6.0.tgz","fileCount":28,"integrity":"sha512-S9es7uuRV3UwKvl/jdwDcyQx3VFHUFH4diQFCf73aoyBA0VYOJELG9LNsJDcIeo+V9L1SOiIKTJ9VFY4UcF8jw==","signatures":[{"sig":"MEUCIBhi0F9TxW360p89X6bGmCAY4zb0qn+lHv3dFEgJgMDAAiEAtQvm4Tv1aQNovJGL6Uug/s8Dxva7cK9avMXKELT8Qs0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@vitalpoint%2fnear-phantom-auth@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1132216},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"ae64f446caa4915cf376f1089d9df0737a876d30","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.6.0_1776642756118_0.5868638166258935","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.6.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.6.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"3ac74da24a10e993fe936fdf25cc2fc3ac6e2e13","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.6.1.tgz","fileCount":28,"integrity":"sha512-8MjLiOcvtzc/ubXmf5/F1bdQmxwxHcG1fuWiq6RodUvfUTbJX05rmm27JlqE0rtSNIMUeydZDXlHh1wVZ5o3+Q==","signatures":[{"sig":"MEUCIQChLdxNf5ShZ4b3NxWMZOMrM6W5u4PbF3Bd2vqmAQfGzwIgX5vUZFlF2TealYP5toou/pHBoPXUAZhJ/ROWV9LXl9Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1155210},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"c793a3c5074ccd2cdc53fd9ac209ac1baae62fcd","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.1","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.6.1_1777466909572_0.1060160126351184","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.7.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.7.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"5f69d6f98029aff86e5a0c19387c77c27643d0ac","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.7.0.tgz","fileCount":28,"integrity":"sha512-m5Z5RIxaIQjoFAuj6obqvamP/EKRcn/3h0ay4pBHI0YQ2Y1jKcHhTZezEmTunKSDki1PUX7IvEtWW8uZzRGczg==","signatures":[{"sig":"MEYCIQDWMuJzikma/rzlWXV12/JWtsk/k74bvqTF/Q5LLddJ+wIhANBgFMfZhH8twZIlnyRGxYzhQ3o995ltpGNfUouEQIQq","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1348209},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"4117f2a57ee5ec3595ebd71c124ab51e74c208db","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"11.9.0","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"24.14.0","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.7.0_1777573033208_0.05502580286665126","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.7.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.7.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"750084d78622551390e3dc1087062dbbf6dddb45","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.7.1.tgz","fileCount":28,"integrity":"sha512-td2S7EUcPPLb32UUv7LnV9DqDsSfrze8/JSIInE4/9ggTObTf79QQ6MUDC7oL3ub6lPLYw+ScjB+4iwU43h9Jg==","signatures":[{"sig":"MEUCICnbn85XfoNgcF2Hu5GM1XRNQ8qCZ35OxbvVLELMdVYcAiEA0p77eIX5ZtpWENTfc3uY1PPZQs91V+rJQGBVNvb63V4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1368029},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"3366409b40b32b1749fd2dcdd9e95f0d2767b10e","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.1","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.7.1_1777576974917_0.23073190913101804","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@vitalpoint/near-phantom-auth","version":"0.8.0","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.8.0","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"4920e3919afe652f930328c164b3fbe286c311a4","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.8.0.tgz","fileCount":28,"integrity":"sha512-ybvSiSqgJ47BFQj3Ym/SRpStoXisG7UFZHVd7MyKXgae5vIX8aFvF5GnOiYgB+qvJ/uu5irNOXZ/AlL+H+BQYA==","signatures":[{"sig":"MEYCIQCcJ2LHWxmB0kuavTRsIAT5aUgulbUnAUq/bGczZ7VmHQIhAIVn4Yh8+Cr23Q62sMy37DPzIS9z6utm5M1bVnbOZ1zi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@vitalpoint%2fnear-phantom-auth@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1541671},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"0a2a0b09148ce186deed7ebb277130262c1cbd2d","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.8.0_1780251788591_0.7506510235345862","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@vitalpoint/near-phantom-auth","version":"0.8.1","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.8.1","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"f707942d81ad50b9a97eebfe235f902d3d5073d4","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.8.1.tgz","fileCount":28,"integrity":"sha512-vgh6pHYAdYl22HIWdqjypICv+sUYSAd1XL5JSZB6E8flvzbHQjNGl5rvn8LEi5cVZywjGIoOL3wgejVgLxnCKg==","signatures":[{"sig":"MEUCIHGpGiBs1PaPXFLF5mcQRVgE3FvCR7AhqcifYQ2VJPHeAiEAwOqn84vvWcqQ6Oynb03QGe9MblITrhuy9/On86QDslQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@vitalpoint%2fnear-phantom-auth@0.8.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1542901},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"3baa88a93ab425fe40630fdd54ec025d20c61c79","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.8.1_1787698027664_0.73661441569177","host":"s3://npm-registry-packages-npm-production"}},"0.8.2":{"name":"@vitalpoint/near-phantom-auth","version":"0.8.2","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","_id":"@vitalpoint/near-phantom-auth@0.8.2","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"dist":{"shasum":"7a972095a2967fd9dab3a75c273d6e6281423f7d","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.8.2.tgz","fileCount":28,"integrity":"sha512-SoXfw4gEJwH9B/r5TNOdoaLGUJiaQk8SQ9EXxaUtAu5CCsm56fJ5OxQXzujVxl/vjZOZSsEyRerk1QPFqKJCBg==","signatures":[{"sig":"MEYCIQDAXNyeIp+nFEccs2LNi0/P/nCwnIWGSlsohq0H7iL+WAIhAMdkRBa6QaqBps4ynmT9hdfHakwgp8TteyLhOtFEwreF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@vitalpoint%2fnear-phantom-auth@0.8.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1551595},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"}},"gitHead":"557b3cfe529bff6573bfd6993e25e7bf21e1ae87","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest","build":"tsup","prepare":"npm run build","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"repository":{"url":"git+https://github.com/VitalPointAI/near-phantom-auth.git","type":"git"},"_npmVersion":"10.8.2","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.3.6","bs58":"^6.0.0","pino":"^10.3.1","bn.js":"^5.2.3","cookie":"^1.1.1","csrf-csrf":"^4.0.3","tweetnacl":"^1.0.3","cookie-parser":"^1.4.7","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@near-js/crypto":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","express-rate-limit":"^8.3.1","@aws-sdk/client-ses":"^3.1009.0","@near-js/transactions":"^2.5.1","@simplewebauthn/server":"^13.2.3"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.0.18","@types/pg":"^8.18.0","supertest":"^7.2.2","typescript":"^5.9.3","@types/node":"^25.3.5","@types/bn.js":"^5.2.0","@types/react":"^19.2.14","@types/cookie":"^1.0.0","@types/express":"^5.0.6","@types/supertest":"^7.2.0","@types/cookie-parser":"^1.4.10"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","express":"^4.18.0 || ^5.0.0"},"peerDependenciesMeta":{"react":{"optional":true},"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/near-phantom-auth_0.8.2_1787739286273_0.8879667059904486","host":"s3://npm-registry-packages-npm-production"}},"0.8.3":{"name":"@vitalpoint/near-phantom-auth","version":"0.8.3","description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./server":{"types":"./dist/server/index.d.ts","import":"./dist/server/index.js","require":"./dist/server/index.cjs"},"./webauthn":{"types":"./dist/webauthn/index.d.ts","import":"./dist/webauthn/index.js","require":"./dist/webauthn/index.cjs"},"./client":{"types":"./dist/client/index.d.ts","import":"./dist/client/index.js","require":"./dist/client/index.cjs"}},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest","lint":"eslint src/","typecheck":"tsc --noEmit","prepublishOnly":"npm run build","prepare":"npm run build"},"keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"author":{"name":"VitalPoint AI"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/VitalPointAI/near-phantom-auth.git"},"dependencies":{"@aws-sdk/client-ses":"^3.1009.0","@near-js/crypto":"^2.5.1","@near-js/keystores":"^2.5.1","@near-js/providers":"^2.5.1","@near-js/signers":"^2.5.1","@near-js/transactions":"^2.5.1","@near-js/types":"^2.5.1","@near-js/utils":"^2.5.1","@simplewebauthn/server":"^13.2.3","bn.js":"^5.2.3","bs58":"^6.0.0","cookie":"^1.1.1","cookie-parser":"^1.4.7","csrf-csrf":"^4.0.3","express-rate-limit":"^8.3.1","pino":"^10.3.1","tweetnacl":"^1.0.3","zod":"^4.3.6"},"devDependencies":{"@types/bn.js":"^5.2.0","@types/cookie":"^1.0.0","@types/cookie-parser":"^1.4.10","@types/express":"^5.0.6","@types/node":"^25.3.5","@types/pg":"^8.18.0","@types/react":"^19.2.14","@types/supertest":"^7.2.0","supertest":"^7.2.2","tsup":"^8.5.1","typescript":"^5.9.3","vitest":"^4.0.18"},"peerDependencies":{"express":"^4.18.0 || ^5.0.0","react":"^18.0.0 || ^19.0.0"},"peerDependenciesMeta":{"express":{"optional":true},"react":{"optional":true}},"engines":{"node":">=18.0.0"},"_id":"@vitalpoint/near-phantom-auth@0.8.3","gitHead":"1dcb1fa1272c4b1c7f218e03ee46eeee7c925718","bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-zADo8lCvJ54xbDenyXzgxkTl+1fVxSMdk8991Bf2lcBzyjKM2d3b2ew0ws6PAc4BIYPtuKKJUf8gg47qbv9O6w==","shasum":"a03c032ba5632fccc6170223512e15cb831c7ec4","tarball":"https://registry.npmjs.org/@vitalpoint/near-phantom-auth/-/near-phantom-auth-0.8.3.tgz","fileCount":28,"unpackedSize":1554347,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@vitalpoint%2fnear-phantom-auth@0.8.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAzLYY4rGB3XIxAhsIjPwZcCrQo4/SbTJm3D7bnilLU5AiEAm9YjytE3QQMWIdslaH7QUDSn+dgs85+xHs+6kGBSwPo="}]},"_npmUser":{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"},"directories":{},"maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/near-phantom-auth_0.8.3_1787775335671_0.9460742019354238"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-10T14:24:18.173Z","modified":"2026-08-26T20:15:36.122Z","0.1.1":"2026-02-10T14:24:18.480Z","0.2.0":"2026-02-10T20:05:29.846Z","0.2.1":"2026-02-11T05:02:15.731Z","0.2.2":"2026-02-11T11:27:55.881Z","0.2.3":"2026-02-11T11:52:19.910Z","0.2.4":"2026-02-11T13:00:48.140Z","0.2.5":"2026-02-11T14:49:26.530Z","0.2.6":"2026-02-11T15:07:38.246Z","0.2.7":"2026-02-11T15:09:04.718Z","0.2.8":"2026-02-11T15:11:42.604Z","0.2.9":"2026-02-11T15:16:02.444Z","0.2.10":"2026-02-11T15:32:06.707Z","0.2.12":"2026-02-24T13:44:50.929Z","0.3.0":"2026-02-26T19:16:04.969Z","0.4.0":"2026-02-27T16:11:09.004Z","0.4.1":"2026-02-27T16:13:59.094Z","0.4.2":"2026-03-03T15:51:38.822Z","0.4.3":"2026-03-03T22:55:12.028Z","0.4.4":"2026-03-08T10:57:20.039Z","0.5.0":"2026-03-08T11:38:08.484Z","0.5.1":"2026-03-08T12:04:58.239Z","0.5.2":"2026-03-08T12:14:18.519Z","0.5.3":"2026-03-15T13:50:10.427Z","0.6.0":"2026-04-19T23:52:36.267Z","0.6.1":"2026-04-29T12:48:29.748Z","0.7.0":"2026-04-30T18:17:13.436Z","0.7.1":"2026-04-30T19:22:55.151Z","0.8.0":"2026-05-31T18:23:08.793Z","0.8.1":"2026-08-25T22:47:07.825Z","0.8.2":"2026-08-26T10:14:46.444Z","0.8.3":"2026-08-26T20:15:35.818Z"},"bugs":{"url":"https://github.com/VitalPointAI/near-phantom-auth/issues"},"author":{"name":"VitalPoint AI"},"license":"MIT","homepage":"https://github.com/VitalPointAI/near-phantom-auth#readme","keywords":["near","authentication","passkey","webauthn","mpc","anonymous","decentralized","web3"],"repository":{"type":"git","url":"git+https://github.com/VitalPointAI/near-phantom-auth.git"},"description":"Anonymous passkey authentication with NEAR MPC accounts and decentralized recovery","maintainers":[{"name":"vitalpoint","email":"a.luhning@vitalpoint.ai"}],"readme":"# near-phantom-auth\n\n**Drop-in anonymous authentication for any web app — passkeys + NEAR MPC accounts + decentralized recovery, with no email, no phone, and no PII.**\n\n> **Privacy-first**: No email, no phone, no PII. Just biometrics and blockchain.\n\n## Why use this?\n\nMost \"anonymous\" auth solutions still ask for an email or phone number for recovery. This package treats anonymity as a hard constraint and ships everything you need to honor it:\n\n- **Truly anonymous sign-up** — users register with a passkey (Face ID, Touch ID, Windows Hello). No email, no phone, no real name. Identity is a randomly-generated codename (`ALPHA-BRAVO-42`) the server cannot link to a person.\n- **Per-user NEAR account out of the box** — every passkey user gets a deterministic 64-char hex implicit account on NEAR (`testnet` or `mainnet`). Optionally auto-funded from your treasury so it is on-chain immediately. The account is the user's, not yours.\n- **Account recovery without identity** — two recovery paths, both anonymity-preserving:\n  - **Wallet recovery** — link a NEAR wallet on-chain via a `FullAccess` key. We never see the wallet; the link lives only on the blockchain.\n  - **Password + IPFS recovery** — your password encrypts a recovery blob (AES-256-GCM); we pin the ciphertext to IPFS via Pinata/Web3.Storage/Infura. Lose your device, recover with `password + CID`.\n- **OAuth track for users who want it** — Google / GitHub / X-Twitter sign-in is available as a fully separate identity stream that does NOT cross-contaminate the anonymous track. OAuth users live in a different table with a different type.\n- **Standalone MPC account helper** (v0.6.1+) — if you only need NEAR account provisioning (not the full passkey/recovery stack), import `MPCAccountManager` directly and skip everything else.\n- **End-to-end encryption ready** — the WebAuthn PRF extension (v0.6.0+) returns a stable 32-byte sealing key per credential, derived inside the authenticator's secure enclave. Hand it to any DEK provisioner downstream.\n- **Production-hardened** — Zod input validation on every endpoint, tiered rate limiting, opt-in CSRF, `HttpOnly` cookies, structured logging with treasury-key redaction, and a 280+ test suite.\n\n## Feature reference\n\n- **Passkey Authentication**: Face ID, Touch ID, Windows Hello, hardware keys — no passwords\n- **NEAR MPC Accounts**: User-owned accounts via Chain Signatures (8-node threshold MPC) on testnet or mainnet\n- **Standalone `MPCAccountManager`** (v0.6.1+): Provision and recover NEAR accounts without the full auth stack — see [MPCAccountManager (v0.6.1+)](#mpcaccountmanager-v061) below\n- **Anonymous Identity**: Compound codenames (ALPHA-BRAVO-42, SWIFT-FALCON-73) — we never know who you are\n- **OAuth Authentication**: Google, GitHub, and X/Twitter sign-in (separate identity track that never touches the anonymous user table)\n- **Decentralized Recovery**:\n  - Link a NEAR wallet (on-chain `FullAccess` access key, not stored in our DB)\n  - Password + IPFS backup (encrypted, you hold the keys)\n- **HttpOnly Sessions**: XSS-proof cookie-based sessions\n- **Input Validation**: Zod schemas on all 18 endpoints — malformed requests rejected before reaching handlers\n- **Rate Limiting**: Tiered per-endpoint limits (auth: 20/15min, recovery: 5/hr)\n- **CSRF Protection**: Opt-in Double Submit Cookie with automatic OAuth callback exemption\n- **Structured Logging**: Injectable pino logger with sensitive field redaction (treasury private key, etc.); silent by default\n- **Automatic Cleanup**: Scheduler removes expired sessions, challenges, and OAuth states\n- **PRF-Derived Sealing Key** (v0.6.0+): WebAuthn PRF extension produces a stable per-credential 32-byte sealing key for end-to-end encryption — opt-in via `passkey.prfSalt`/`requirePrf`, graceful degradation on Firefox/older authenticators\n\n## WebAuthn PRF Extension (DEK Sealing Key)\n\nSince v0.6.0, the library requests the WebAuthn PRF (Pseudo-Random Function) extension on every registration and login. A PRF-capable authenticator deterministically derives 32 bytes per credential (HMAC-SHA-256 over the RP-supplied salt, computed inside the authenticator's secure enclave). The 32 bytes are hex-encoded as `sealingKeyHex` and posted in the body of `/register/finish` and `/login/finish`. Downstream services (e.g., an auth-service DEK provisioner) can use this stable key material to seal/unseal per-user encrypted data.\n\n> **The 32 bytes never leave the authenticator's secure enclave in raw form. Only the salt and the derived hex are seen by application code.**\n\n### Configuration\n\n```tsx\nimport { AnonAuthProvider } from '@vitalpoint/near-phantom-auth/client';\n\nfunction App() {\n  return (\n    <AnonAuthProvider\n      apiUrl=\"/auth\"\n      passkey={{\n        prfSalt: new TextEncoder().encode('my-app-prf-sealing-v1'),\n        requirePrf: false,\n      }}\n    >\n      <AuthDemo />\n    </AnonAuthProvider>\n  );\n}\n```\n\nThe same `passkey: { prfSalt, requirePrf }` shape is also accepted on `createAnonAuth({ passkey })` server-side for symmetry with the client surface. On the server this is type documentation only — the library does not use these values at runtime on the server; the salt and enforcement rules live entirely in the browser.\n\nIf `passkey` is omitted, the library defaults to `prfSalt = new TextEncoder().encode('near-phantom-auth-prf-v1')` and `requirePrf = false`.\n\n### Salt Immutability\n\n- **Do not change the salt after deployment.**\n- The PRF output is deterministic over (credential, salt). Changing the salt by one byte produces a different sealing key and makes any data encrypted with the original key inaccessible.\n- The `v1` suffix is a rotation identifier, not a semver — it does NOT mean \"to be upgraded later.\" Treat the chosen salt as a permanent constant for the lifetime of the deployment.\n\n### Browser Support\n\n| Browser / Authenticator                       | Registration PRF                     | Login PRF | Notes                                                              |\n| --------------------------------------------- | ------------------------------------ | --------- | ------------------------------------------------------------------ |\n| Chrome / Edge ≥116                            | yes                                  | yes       | iCloud Keychain / Google Password Manager / Chrome 147+ Windows Hello |\n| Safari ≥18 (iOS 18, macOS 15)                 | yes                                  | yes       | Synced platform passkeys                                           |\n| Firefox                                       | no                                   | no        | PRF not yet implemented as of mid-2025; graceful degradation applies |\n| Hardware keys (YubiKey, etc.)                 | no (returns `enabled: true` only)    | yes       | First sealing key arrives on first successful login, not registration |\n| Chrome ≤146 Windows Hello                     | no                                   | yes       | Same hardware-key behavior                                         |\n\nWhen the authenticator does not return a PRF result, `sealingKeyHex` is omitted from the POST body (the field is absent, not sent as `null`). With `requirePrf: false` (default), the registration/login ceremony completes normally and the user can still use unencrypted features — encrypted endpoints simply 401 until the user logs in again on a PRF-capable device. With `requirePrf: true`, the `register()`/`login()` hook methods throw an `Error` whose message starts with `PRF_NOT_SUPPORTED`; the `useAnonAuth` hook surfaces this as `state.error` via the existing catch path. Choose `requirePrf: true` only if your user base is restricted to PRF-capable authenticators — otherwise you will lock out Firefox users entirely.\n\n### Migration for Existing Accounts (NULL Key Bundles)\n\nUsers who registered before v0.6.0 do not have a DEK provisioned server-side — their account records have a NULL key bundle (`users.mlkem_ek IS NULL`). Once the auth-service is patched so that `provisionUserKeys()` fires whenever `getUserKeyBundle(userId)` returns `null` on login (not only for brand-new `isNewUser` registrations), these accounts auto-bootstrap on next successful login. No client-side migration is required: starting at v0.6.0 the library ships `sealingKeyHex` on every login for PRF-capable authenticators, and the server decides — based on the presence of an existing key bundle — whether to provision a new DEK or unwrap the existing one.\n\n## Cross-Domain Passkeys (v0.7.0)\n\n`near-phantom-auth@0.7.0` adds optional support for the WebAuthn [Related Origin\nRequests](https://passkeys.dev/docs/advanced/related-origins/) feature, letting\na single deployment accept passkey assertions from multiple registrable domains\n(e.g. `shopping.com` + `shopping.co.uk` + `shopping.de`).\n\n### What the library does\n\nWhen `rp.relatedOrigins` is configured at `createAnonAuth()` startup, the library:\n\n1. **Validates** each entry's shape, scheme (https only, http://localhost permitted\n   only when `rpId === 'localhost'`), wildcard absence, and suffix-domain pairing\n   at startup. Misconfiguration throws with a classified message — no silent\n   acceptance into production.\n2. **Spreads** the validated paired tuples into `expectedOrigin` and\n   `expectedRPID` on every `verifyRegistrationResponse` /\n   `verifyAuthenticationResponse` call, preserving pairing by tuple order.\n3. **Caps** the list at 5 entries (browser support has a 5-label minimum;\n   additional entries are silently ignored by Chrome/Safari).\n\n### What the consumer must do\n\n**The library does NOT auto-host `/.well-known/webauthn`.** Hosting is a\nper-deployment concern — the library cannot see your hosting topology.\n\nServe a JSON document at `https://{primaryRpId}/.well-known/webauthn` with\n`Content-Type: application/json` listing the related origins. Skeleton:\n\n```json\n{\n  \"origins\": [\n    \"https://shopping.co.uk\",\n    \"https://shopping.ie\",\n    \"https://shopping.ca\"\n  ]\n}\n```\n\nHosting requirements (per [passkeys.dev/docs/advanced/related-origins/](https://passkeys.dev/docs/advanced/related-origins/)):\n\n- URL: `https://{primaryRpId}/.well-known/webauthn` (not the related domain)\n- `Content-Type: application/json`\n- HTTPS only — browsers will not fetch over plain HTTP for non-localhost rpIds\n- The primary RP ID itself MUST NOT be in the array — it's implicit\n- Maximum 5 unique eTLD+1 labels — entries beyond the cap are silently ignored\n- No wildcards in the array\n\nUse your existing static-asset pipeline (Next.js `public/`, Vercel/Cloudflare\nstatic assets, S3+CloudFront, etc.) — the library does not own request routing\nfor `/.well-known/*` paths.\n\n### Browser support\n\nCross-domain passkey support shipped in Chrome 128 (Aug 2024) and Safari 18\n(Sep 2024). Firefox users see `SecurityError` on registrations that span\ndomains; the recommended graceful degradation is for Firefox users to\nregister a separate passkey per domain.\n\n### Server-side configuration\n\nPass `rp.relatedOrigins` to `createAnonAuth()` as an array of paired tuples\n(NOT two parallel arrays — see [security note](#security-paired-tuple-vs-parallel-arrays)\nbelow):\n\n```typescript\nimport { createAnonAuth } from '@vitalpoint/near-phantom-auth/server';\n\nconst auth = createAnonAuth({\n  // ... other config ...\n  rp: {\n    name: 'My App',\n    id: 'shopping.com',\n    origin: 'https://shopping.com',\n    relatedOrigins: [\n      { origin: 'https://shopping.co.uk', rpId: 'shopping.co.uk' },\n      { origin: 'https://shopping.ie',    rpId: 'shopping.ie' },\n    ],\n  },\n});\n```\n\n### Security: paired tuple vs parallel arrays\n\nThe library uses an `Array<{ origin, rpId }>` paired-tuple shape — NOT two\nparallel arrays — because `@simplewebauthn/server` does not cross-check\norigin↔rpId pairing. It tests independent membership of each list. If your\nconfig drifted (e.g. via a `.map()` reorder of one array), the library would\naccept assertions where `originA` was signed under `rpIdB`, even though that\ncombination has no allowlist relationship.\n\nThe paired-tuple shape makes pairing intent **structural** — it cannot be\nsilently broken by a refactor because the array IS the list of pairs.\n\n### References\n\n- [passkeys.dev — Related Origin Requests](https://passkeys.dev/docs/advanced/related-origins/)\n- [web.dev — WebAuthn Related Origin Requests](https://web.dev/articles/webauthn-related-origin-requests)\n- [W3C WebAuthn Level 3 §5.10.3](https://www.w3.org/TR/webauthn-3/) — Related Origin Requests algorithm\n\n## Second-Factor Enrolment Hook (v0.7.0)\n\n`near-phantom-auth@0.7.0` exposes `hooks.afterAuthSuccess` — an inline,\nblocking hook that fires AFTER auth succeeds (passkey verify + DB persist\n+ MPC funding) but BEFORE session creation. The hook lets consumers gate\nsession issuance on a second factor (TOTP, push notification, hardware\ntoken, manual approval, etc.) without forcing the library into the\nsecret-storage business.\n\n### What the library does\n\nThe library invokes your hook at five fire points:\n\n1. `POST /register/finish` — after passkey verify + `mpcManager.createAccount`\n   + `db.createUser` + `db.createPasskey`, BEFORE `sessionManager.createSession`.\n   Fires INSIDE the `db.transaction()` wrapper — a hook throw rolls back the\n   DB rows. (`src/server/router.ts`)\n2. `POST /login/finish` — after passkey verify + `db.getUserById`, BEFORE\n   `sessionManager.createSession`. NO transaction wrapper on this path —\n   a hook throw produces a 500 but no DB rollback is needed (the\n   passkey-counter update already committed by `passkeyManager.finishAuthentication`\n   must persist for replay protection). (`src/server/router.ts`)\n3. `POST /oauth/:provider/callback` — three success branches:\n   - **Existing user, same provider** — fires after `db.getOAuthUserByProvider`.\n   - **Existing user, link by email** — fires after `db.linkOAuthProvider`.\n   - **New user** — fires after `mpcManager.createAccount` + `db.createOAuthUser`\n     + IPFS recovery setup.\n   NO transaction wrapper on any OAuth branch. (`src/server/oauth/router.ts`)\n\nThe hook receives a discriminated-union context:\n\n```typescript\nexport type AfterAuthSuccessProvider = 'google' | 'github' | 'twitter';\n\nexport type AfterAuthSuccessCtx =\n  | { authMethod: 'passkey-register'; userId: string; codename: string;\n      nearAccountId: string; req: express.Request }\n  | { authMethod: 'passkey-login';    userId: string; codename: string;\n      nearAccountId: string; req: express.Request }\n  | { authMethod: 'oauth-google' | 'oauth-github' | 'oauth-twitter';\n      userId: string; codename?: string; nearAccountId: string;\n      provider: AfterAuthSuccessProvider; req: express.Request };\n```\n\nThe hook returns:\n\n```typescript\ntype AfterAuthSuccessResult =\n  | { continue: true }\n  | { continue: false; status: number; body: Record<string, unknown> };\n```\n\nOn `continue: true`, the library proceeds with `sessionManager.createSession`\nand the standard response. On `continue: false`, the library spreads\nconsumer's `body` into the response, echoes a structured\n`secondFactor: { status, body }` field, and **DOES NOT** create a session\n(no `Set-Cookie` header is emitted).\n\nHook ctx surfaces `userId`, `codename`, and `nearAccountId` to your code —\nthe library does NOT log or telemetrize these fields (anonymity invariant).\n\n### What the consumer must do\n\nWire the hook on `createAnonAuth({ ..., hooks: { afterAuthSuccess: ... } })`.\nInside, use the discriminator to narrow:\n\n```typescript\nafterAuthSuccess: async (ctx) => {\n  if (ctx.authMethod === 'passkey-register') {\n    // Maybe: enqueue 2FA enrolment ceremony\n    return { continue: false, status: 202, body: { totpUri: '...' } };\n  }\n  if (ctx.authMethod === 'passkey-login') {\n    // Verify a TOTP code already submitted by the client (e.g., in req.body.totp).\n    const totp = (ctx.req.body as any).totp;\n    if (!totp || !(await verifyTotp(ctx.userId, totp))) {\n      return { continue: false, status: 401, body: { error: 'TOTP required' } };\n    }\n  }\n  if (ctx.authMethod.startsWith('oauth-')) {\n    // ctx.provider is now narrowed to AfterAuthSuccessProvider.\n    // ctx.codename is OPTIONAL on OAuth — OAuthUser does not carry a codename in v0.7.0.\n  }\n  return { continue: true };\n}\n```\n\n`ctx.req` is the **bare Express Request** — it carries cookies, headers,\nbody, etc. The library does NOT sanitize this surface; what your hook\nreads from `req` is your responsibility.\n\n### MPC orphan trade-off (HOOK-06)\n\n**`mpcManager.createAccount` runs BEFORE the database transaction opens\non `/register/finish` (and outside any transaction wrapper on the OAuth\nnew-user branch).** A hook throw OR a `continue: false` AFTER MPC funding\nleaves an **orphaned funded NEAR implicit account with no DB record**.\nThe library cannot recover the on-chain funds.\n\n**Mitigation:** make your hook idempotent and non-throwing. Prefer\n`{ continue: false, status, body }` over `throw new Error(...)` for soft\nfailures (TOTP not yet submitted, push notification timeout, etc.).\nA returned `continue: false` does not roll back the DB — it commits the\nuser + passkey rows but skips session creation. Your subsequent retry\ncan use the same `userId` to complete enrolment.\n\n**OAuth Branch 3 (new user) extends the trade-off:** because OAuth has no\ntransaction wrapper at all, a `continue: false` on the new-user branch\nleaves the `oauth_users` row, the MPC account, **AND the IPFS recovery blob**\nall committed. Same mitigation applies.\n\n### Cookie semantics\n\nOn `continue: false`, the response carries NO live `Set-Cookie` header — the\nsession was never created. (The OAuth callback always emits expired\n`oauth_state` / `oauth_code_verifier` clear-cookie hygiene, which is NOT\na session cookie.) Your client should detect short-circuit by inspecting\n`response.body.secondFactor` (the structured echo) and initiate the\nsecond-factor enrolment ceremony you specified in `body`.\n\n### References\n\n- REQUIREMENTS: `HOOK-02..06` in `.planning/REQUIREMENTS.md`\n- Type definitions: `src/types/index.ts` (search for `AfterAuthSuccessCtx`)\n- Re-export surface: `import type { AfterAuthSuccessCtx, AfterAuthSuccessResult, AfterAuthSuccessProvider } from '@vitalpoint/near-phantom-auth/server';`\n\n## Lazy-Backfill Hook (v0.7.0)\n\n`near-phantom-auth@0.7.0` exposes `hooks.backfillKeyBundle` — a pass-through\nhook that fires inside `POST /login/finish` when the authenticator returned a\nfresh PRF sealing key (`sealingKeyHex`). The hook lets consumers run their own\nkey-bundle migration ceremony for pre-v0.6.0 NULL-bundle accounts without the\nlibrary taking any opinion on the consumer's schema, transaction boundaries, or\nrecovery topology.\n\nThe contract is deliberately narrow: the library hands the consumer the\nminimal context (`userId`, `codename`, `nearAccountId`, `sealingKeyHex`, `req`),\ninvokes the hook, echoes the result on the response, and otherwise steps aside.\nBackfill failure NEVER blocks login. A hook throw is caught, logged at WARN\nwith a redacted payload, and the response continues with\n`backfill: { backfilled: false, reason: 'skipped' }`.\n\n### What the library does\n\nThe library invokes the hook at exactly one fire point:\n\n- `POST /login/finish` — after passkey verify + `db.getUserById`, after any\n  Phase 14 `hooks.afterAuthSuccess` that returned `continue: true`, BEFORE\n  `sessionManager.createSession`. It fires only when `sealingKeyHex` was\n  supplied in the request body. No PRF means no fresh sealing key, so the hook\n  is silently skipped and no `backfill` field appears on the response.\n\nSequential ordering when both Phase 14 and Phase 15 hooks are configured:\n\n1. `hooks.afterAuthSuccess` runs first.\n2. If it returns `{ continue: false, ... }`, the response short-circuits and\n   the backfill hook is not invoked.\n3. If it returns `{ continue: true }` (or is absent), and `sealingKeyHex` is\n   present, and `hooks.backfillKeyBundle` exists, the backfill hook fires.\n4. The result is echoed on the login response under an additive `backfill` key,\n   alongside the existing `success`, `codename`, and `passkey?` fields.\n\nThe hook receives:\n\n```typescript\nimport type { Request } from 'express';\n\nexport interface BackfillKeyBundleCtx {\n  userId: string;\n  codename: string;\n  nearAccountId: string;\n  sealingKeyHex: string;\n  req: Request;\n}\n```\n\nThe hook returns:\n\n```typescript\nexport type BackfillReason =\n  | 'already-current'\n  | 'no-legacy-data'\n  | 'completed'\n  | 'skipped';\n\nexport interface BackfillKeyBundleResult {\n  backfilled: boolean;\n  reason?: BackfillReason;\n}\n```\n\nExample login response when the hook runs:\n\n```json\n{\n  \"success\": true,\n  \"codename\": \"ALPHA-BRAVO-7\",\n  \"passkey\": { \"backedUp\": false, \"backupEligible\": false },\n  \"backfill\": { \"backfilled\": true, \"reason\": \"completed\" }\n}\n```\n\n### What the consumer must do\n\nImplement the migration in your own application code:\n\n```typescript\nhooks: {\n  backfillKeyBundle: async (ctx) => {\n    const legacy = await legacyStore.getNullBundleRow(ctx.userId);\n    if (!legacy) return { backfilled: false, reason: 'no-legacy-data' };\n\n    const bundle = await deriveKeyBundleFromSealingKey(ctx.sealingKeyHex);\n\n    await appDb.transaction(async (tx) => {\n      await tx.keyBundles.upsert({\n        userId: ctx.userId,\n        encryptedBundle: bundle.encryptedBundle,\n        wrappedDek: bundle.wrappedDek,\n      });\n      await tx.legacyBundles.markMigrated(ctx.userId);\n    });\n\n    return { backfilled: true, reason: 'completed' };\n  },\n}\n```\n\n`ctx.req` is the bare Express `Request`. The library does not sanitize it.\nIf your hook reads cookies, headers, or extra body fields from `req`, that is\nyour responsibility.\n\n### Consumer-owns-schema contract\n\nThe library does not persist key bundles. It does not add schema, run schema\nmigrations, or choose how your application stores encrypted material.\n\nThe library also does not run a transaction around the hook. If your migration\ntouches multiple tables, you must provide your own transaction discipline.\nThat is the point of the pass-through design: the library provides the auth\nlifecycle fire point, but the consumer owns the data model.\n\nBACKFILL-03 is load-bearing here: if your hook throws, the library catches the\nerror, logs a redacted WARN entry, and still completes login. The fallback\nresponse is:\n\n```json\n{\n  \"backfill\": { \"backfilled\": false, \"reason\": \"skipped\" }\n}\n```\n\n### Dual-recovery + IPFS-orphan footnote\n\nThe library does not migrate existing IPFS recovery blobs. Those blobs remain\nconsumer-owned. If your backfill replaces the recovery method, an older IPFS\nrecovery blob may still exist but no longer be referenced by your current\nrecovery path.\n\nThat creates an explicit dual-recovery state:\n\n- your new key-bundle recovery path may be current\n- the old IPFS recovery blob may still exist\n- the library will not reconcile or delete it for you\n\nIf you want old blobs cleaned up, documented, or kept as a temporary fallback,\nhandle that in your own migration logic.\n\n### Known limitation\n\nThe Phase 15 hook is awaited inline and currently has no library-side timeout.\nA hook that hangs will delay login. Consumer hooks must resolve in finite time.\nTimeout policy is deferred to a later release.\n\n### References\n\n- REQUIREMENTS: `BACKFILL-01..04` in `.planning/REQUIREMENTS.md`\n- Type definitions: `src/types/index.ts` (search for `BackfillKeyBundleCtx`)\n- Re-export surface: `import type { BackfillKeyBundleCtx, BackfillKeyBundleResult, BackfillReason } from '@vitalpoint/near-phantom-auth/server';`\n\n## Hooks (v0.7.0)\n\nv0.7.0 adds consumer extension points without removing or renaming the v0.6.1\nAPI surface. The release is additive: existing passkey, recovery, OAuth, PRF,\nand `MPCAccountManager` consumers continue to compile while new consumers can\nopt into hooks and cross-domain passkey configuration.\n\n| Surface | Purpose | Key contract |\n|---------|---------|--------------|\n| `hooks.afterAuthSuccess` | Inline second-factor gating after auth succeeds and before session creation. | Handles passkey register, passkey login, and OAuth callback success. Returning `{ continue: false, status, body }` short-circuits and echoes `secondFactor`. See [Second-Factor Enrolment Hook (v0.7.0)](#second-factor-enrolment-hook-v070). |\n| `hooks.backfillKeyBundle` | Pass-through lazy key-bundle migration for pre-v0.6.0 NULL-bundle accounts. | Fires only on `/login/finish` when `sealingKeyHex` exists. The library follows a consumer-owned schema contract: it does not persist bundles, wrap a transaction, or migrate IPFS blobs. See [Lazy-Backfill Hook (v0.7.0)](#lazy-backfill-hook-v070). |\n| `hooks.onAuthEvent` | Privacy-preserving lifecycle analytics. | Event shapes enforce the anonymity invariant: no `userId`, `codename`, `nearAccountId`, email, raw IP, or raw user-agent fields. Default is fire-and-forget; set `awaitAnalytics: true` when the event must complete before the response. |\n| `rp.relatedOrigins` | Cross-domain passkeys via WebAuthn Related Origin Requests. | Use paired tuples (`{ origin, rpId }`) with a maximum of 5 related origins. The library validates scheme, wildcard absence, suffix-domain pairing, and cap at startup. See [Cross-Domain Passkeys (v0.7.0)](#cross-domain-passkeys-v070). |\n\nImportant release notes:\n\n- **MPC orphan trade-off:** `hooks.afterAuthSuccess` runs after MPC funding on\n  registration and OAuth new-user paths. Hook failures or soft short-circuits\n  can leave funded on-chain accounts or committed OAuth/IPFS state; use\n  idempotent hooks and prefer returned `{ continue: false }` for soft failures.\n- **consumer-owned schema:** `hooks.backfillKeyBundle` gives your code\n  `sealingKeyHex` and user identifiers, then steps aside. Your application owns\n  the schema, transaction, migration, and any cleanup for old IPFS recovery\n  blobs.\n- **anonymity invariant:** library analytics events and hook error logs never\n  include user identifiers or PRF sealing material. Consumer hooks receive\n  sensitive context intentionally and are responsible for their own handling.\n- **5 related origins:** browsers cap related-origin passkey support; the\n  library enforces a maximum of 5 related origins and does not auto-host\n  `/.well-known/webauthn`.\n\n## Enterprise Identity Module (v0.8.x)\n\nThe enterprise module is opt-in and off by default. If `enterprise` config is\nabsent, `createAnonAuth()` exposes no enterprise API, no `scimRouter`, no\nenterprise database initialization, and no enterprise middleware lookup. The\nanonymous passkey track remains the default package behavior.\n\nEnterprise identity binding lets an organization bind an external IdP subject\nfrom Okta, Entra, PingFederate, Google Workspace, or another IdP to the same\nNEAR DID/MPC account model used elsewhere in the package.\n\n```ts\nimport { createAnonAuth } from '@vitalpoint/near-phantom-auth/server';\n\nconst auth = createAnonAuth({\n  // existing config unchanged\n  nearNetwork: 'testnet',\n  sessionSecret: process.env.SESSION_SECRET!,\n  database: { type: 'postgres', connectionString: process.env.DATABASE_URL! },\n  enterprise: {\n    enabled: true,\n    binding: { mintMpcIfMissing: true },\n    passkeyStepUp: false,\n    serverManagedDek: true,\n    scim: {\n      enabled: true,\n      bearerToken: process.env.SCIM_BEARER_TOKEN!,\n      attributeMapping: {\n        userName: 'email',\n        'name.formatted': 'displayName',\n      },\n    },\n  },\n});\n\nif (auth.scimRouter) {\n  app.use('/scim/v2', auth.scimRouter);\n}\n```\n\nThe binding API is available as `auth.enterprise` only when enterprise is\nenabled:\n\n```ts\nawait auth.enterprise?.linkIdentity({\n  externalIdp: 'okta',\n  externalSub: '00u123',\n  externalAttrs: { email: 'employee@example.com' },\n});\n\nawait auth.enterprise?.unlinkIdentity({\n  externalIdp: 'okta',\n  externalSub: '00u123',\n  mode: 'revoke',\n});\n\nconst binding = await auth.enterprise?.resolveByExternalId('okta', '00u123');\n```\n\nSCIM is protected by the bearer token you configure. The package validates that\ntoken on every SCIM request; it does not issue or rotate the token. SCIM\n`active:false` and DELETE revoke the enterprise binding and invalidate live\nenterprise sessions.\n\nThe package provides mechanism, not product policy. It stores bindings, handles\nSCIM lifecycle, emits enterprise lifecycle events, and reuses NEAR MPC account\nminting. Your application still owns role-to-permission mapping, dashboard\nscopes, audit log format and sink, \"disable anonymity in mode X\" decisions, and\ngovernment smartcard specifics. Generic OIDC and SAML connectors remain\npromote-later work after real-tenant hardening.\n\n### Enterprise PRF and DEK Modes\n\nEnterprise IdP authentication alone does not produce a WebAuthn PRF sealing key.\nUse `enterprise.passkeyStepUp: true` when enterprise users must register or use\na passkey after IdP auth so downstream systems can rely on authenticator-rooted\nPRF material. Use `enterprise.serverManagedDek: true` when your deployment\nprovisions the user's DEK from a server- or enclave-held key hierarchy instead.\nPure IdP enterprise auth without passkey step-up does not have the same\nauthenticator-rooted DEK property as passkey users.\n\n## Installation\n\n```bash\nnpm install @vitalpoint/near-phantom-auth\n```\n\nThe package provides both server and client exports:\n- `@vitalpoint/near-phantom-auth/server` - Express router, session management, MPC accounts\n- `@vitalpoint/near-phantom-auth/client` - React hooks, WebAuthn helpers, API client\n\nBoth are included in the single package - no separate installs needed.\n\n## Quick Start\n\n### Server (Express)\n\n```typescript\nimport express from 'express';\nimport { createAnonAuth } from '@vitalpoint/near-phantom-auth/server';\n\nconst app = express();\n\nconst auth = createAnonAuth({\n  nearNetwork: 'testnet',\n  sessionSecret: process.env.SESSION_SECRET!,\n  database: {\n    type: 'postgres',\n    connectionString: process.env.DATABASE_URL!,\n  },\n  rp: {\n    name: 'My App',\n    id: 'myapp.com',\n    origin: 'https://myapp.com',\n  },\n  // Recommended for production: prevents account ID prediction\n  derivationSalt: process.env.DERIVATION_SALT!,\n  // Recommended for maximum anonymous-track privacy: omit session metadata\n  sessionMetadata: {\n    ipAddress: 'omit',\n    userAgent: 'omit',\n  },\n  recovery: {\n    wallet: true,\n    ipfs: {\n      pinningService: 'pinata',\n      apiKey: process.env.PINATA_API_KEY,\n      apiSecret: process.env.PINATA_API_SECRET,\n    },\n  },\n});\n\n// Initialize database schema\nawait auth.initialize();\n\n// Mount auth routes\napp.use('/auth', auth.router);\n\n// Mount OAuth routes (optional)\nif (auth.oauthRouter) {\n  app.use('/auth/oauth', auth.oauthRouter);\n}\n\n// Protect routes\napp.get('/api/me', auth.requireAuth, (req, res) => {\n  res.json({\n    codename: req.anonUser!.codename,\n    nearAccountId: req.anonUser!.nearAccountId,\n  });\n});\n\napp.listen(3000);\n```\n\n### Client (React)\n\n```tsx\nimport { AnonAuthProvider, useAnonAuth } from '@vitalpoint/near-phantom-auth/client';\n\nfunction App() {\n  return (\n    <AnonAuthProvider apiUrl=\"/auth\">\n      <AuthDemo />\n    </AnonAuthProvider>\n  );\n}\n\nfunction AuthDemo() {\n  const {\n    isLoading,\n    isAuthenticated,\n    codename,\n    nearAccountId,\n    webAuthnSupported,\n    register,\n    login,\n    logout,\n    error,\n    clearError,\n  } = useAnonAuth();\n\n  if (isLoading) return <div>Loading...</div>;\n\n  if (!webAuthnSupported) {\n    return <div>Your browser doesn't support passkeys.</div>;\n  }\n\n  if (!isAuthenticated) {\n    return (\n      <div>\n        <h1>Anonymous Auth Demo</h1>\n        {error && (\n          <p style={{ color: 'red' }}>\n            {error} <button onClick={clearError}>x</button>\n          </p>\n        )}\n        <button onClick={register}>Register (Create Identity)</button>\n        <button onClick={() => login()}>Sign In (Existing Identity)</button>\n      </div>\n    );\n  }\n\n  return (\n    <div>\n      <h1>Welcome, {codename}</h1>\n      <p>NEAR Account: {nearAccountId}</p>\n      <button onClick={logout}>Sign Out</button>\n    </div>\n  );\n}\n```\n\n> **Important**: Always use the client library's `register` and `login` functions rather than implementing WebAuthn manually. WebAuthn uses base64url encoding (not standard base64), and the client library handles this correctly.\n\n### Client (Vanilla JS / Non-React)\n\nFor non-React applications, use the lower-level functions:\n\n```typescript\nimport {\n  createApiClient,\n  createPasskey,\n  authenticateWithPasskey,\n  isWebAuthnSupported\n} from '@vitalpoint/near-phantom-auth/client';\n\nconst api = createApiClient({ baseUrl: '/auth' });\n\n// Check support\nif (!isWebAuthnSupported()) {\n  console.error('WebAuthn not supported');\n}\n\n// Register\nasync function register() {\n  const { challengeId, options, tempUserId, codename } = await api.startRegistration();\n  const credential = await createPasskey(options); // Handles base64url encoding\n  const result = await api.finishRegistration(challengeId, credential, tempUserId, codename);\n  console.log('Registered as:', result.codename);\n}\n\n// Login\nasync function login() {\n  const { challengeId, options } = await api.startAuthentication();\n  const credential = await authenticateWithPasskey(options); // Handles base64url encoding\n  const result = await api.finishAuthentication(challengeId, credential);\n  console.log('Logged in as:', result.codename);\n}\n```\n\n## How It Works\n\n### Registration Flow\n\n```\n1. User clicks \"Register\"\n2. Browser creates passkey (biometric prompt)\n3. Server creates NEAR account via MPC\n4. User gets compound codename (e.g., ALPHA-BRAVO-42)\n5. Session cookie set (HttpOnly, Secure, SameSite=Strict)\n```\n\n### Authentication Flow\n\n```\n1. User clicks \"Sign In\"\n2. Browser prompts for passkey (biometric)\n3. Server verifies signature (constant-time comparison)\n4. Session cookie set\n```\n\n### Recovery Options\n\n#### Wallet Recovery\n- User links existing NEAR wallet\n- Wallet added as on-chain access key (NOT stored in our database)\n- Recovery: Sign with wallet -> Create new passkey\n\n#### Password + IPFS Recovery\n- User sets strong password\n- Recovery data encrypted with password (AES-256-GCM)\n- Encrypted blob stored on IPFS via concurrent multi-gateway pinning\n- User saves: password + IPFS CID\n- Recovery: Provide password + CID -> Decrypt -> Create new passkey\n\n## MPCAccountManager (v0.6.1+)\n\nStandalone helper for provisioning NEAR implicit accounts and verifying recovery wallets. Exported from `@vitalpoint/near-phantom-auth/server` as a runtime value. Use this directly when you only need the account-provisioning pipeline — not the full passkey + session + recovery stack — for example when integrating with an existing auth service via a sidecar.\n\n### When to use it\n\n| Use case | Use this | Use full `createAnonAuth` |\n|----------|----------|---------------------------|\n| Building a complete anonymous auth flow (passkey + sessions + recovery) | — | yes |\n| Provisioning NEAR accounts for users authenticated by another system | yes | — |\n| Server-to-server account creation triggered by a webhook | yes | — |\n| Verifying that a wallet has `FullAccess` on a user's NEAR account | yes | yes (via `auth.mpc.verifyRecoveryWallet`) |\n| Idempotent retry of provisioning from a queue worker | yes | — |\n\n### Quick start\n\n```typescript\nimport {\n  MPCAccountManager,\n  type MPCAccountManagerConfig,\n  type CreateAccountResult,\n} from '@vitalpoint/near-phantom-auth/server';\n\nconst manager = new MPCAccountManager({\n  networkId: 'testnet',                                    // or 'mainnet'\n  treasuryAccount: process.env.NEAR_TREASURY_ACCOUNT!,\n  treasuryPrivateKey: process.env.NEAR_TREASURY_KEY!,\n  derivationSalt: process.env.NEAR_DERIVATION_SALT!,        // REQUIRED — see Security\n  fundingAmount: '0.01',                                   // optional; default '0.01' NEAR\n});\n\nconst result: CreateAccountResult = await manager.createAccount('user-id');\n// result.nearAccountId  matches /^[a-f0-9]{64}$/  (64-char hex implicit account)\n// result.mpcPublicKey   is `ed25519:${bs58.encode(publicKeyBytes)}`\n// result.derivationPath is `near-anon-auth,user-id`\n// result.onChain        is true after successful funding\n```\n\n### Derivation function\n\nThe account ID is a pure function of `(derivationSalt, userId)` — same arguments always produce the same account. There is no randomness; idempotent retry is safe.\n\n```\nseedInput      = `implicit-${derivationSalt}-${userId}`\nseed           = SHA-256(seedInput)\npublicKeyBytes = first 32 bytes of SHA-512(seed)\nnearAccountId  = publicKeyBytes.toString('hex')         // 64-char lowercase hex\nmpcPublicKey   = `ed25519:${bs58.encode(publicKeyBytes)}`\nderivationPath = `near-anon-auth,${userId}`\n```\n\nIf `derivationSalt` is omitted (only possible via the looser internal `MPCConfig` type), account IDs become predictable from user IDs alone — the standalone `MPCAccountManagerConfig` type makes the salt REQUIRED at compile time.\n\n### Idempotency (MPC-03)\n\n`createAccount(userId)` is idempotent. A second call against an already-provisioned account short-circuits via `view_account` and issues zero additional `broadcast_tx_commit` calls — the existing on-chain account is returned with `onChain: true`.\n\n### Concurrent calls (MPC-06)\n\nTwo concurrent `createAccount` calls for the same `userId` from different replicas converge to a single provisioned account. The loser of the nonce race retries `view_account` once and returns success when the winner has already provisioned the account.\n\n### Error paths (MPC-10)\n\n`createAccount` throws when:\n\n| Condition | Thrown error | Suggested HTTP status |\n|-----------|--------------|-----------------------|\n| NEAR RPC is unreachable (fetch throws) | `Error('RPC unreachable', { cause })` | 503 |\n| Treasury balance is too low | `Error('Treasury underfunded', { cause })` | 503 |\n| Any other broadcast failure | `Error('Transfer failed', { cause })` | 502 |\n\nThe `cause` field always contains the original RPC error message for debugging.\n\n`verifyRecoveryWallet` throws **only** when the NEAR RPC is unreachable (consumer should return 500). It returns `false` (does not throw) for missing accounts, FunctionCall-only keys, or unknown access keys.\n\n### Security expectations\n\n- **`derivationSalt` is REQUIRED** at the type level — TypeScript rejects an `MPCAccountManagerConfig` literal that omits it. Use a per-tenant secret salt to prevent cross-tenant account ID collision.\n- **`treasuryPrivateKey` is never logged** — the manager replaces the raw string with a `KeyPair` object on construction. The default-silent pino logger is wired with redact paths (`config.treasuryPrivateKey`, `*.treasuryPrivateKey`); even an accidental `log.info({ config }, '...')` emits `[Redacted]` instead of the secret.\n- **Transactions are signed in-process** — no `near-cli` shell-out, no `process.exec` injection vector.\n- **`verifyRecoveryWallet` returns true ONLY for `FullAccess` keys** — FunctionCall-scoped keys (which cannot sign arbitrary transactions) cannot satisfy recovery verification.\n- **Dist bundle is leak-audited** — the published `dist/server/index.js` is checked at build time to confirm zero `ed25519:<base58>` string literals are baked in.\n\n### Frozen contract (consumer pin)\n\nThe following surface is FROZEN — no field, method, or return-shape rename without a coordinated PR:\n\n- `class MPCAccountManager`\n- `createAccount(userId: string): Promise<CreateAccountResult>`\n- `verifyRecoveryWallet(nearAccountId: string, recoveryWalletPublicKey: string): Promise<boolean>`\n- `interface MPCAccountManagerConfig` (with `derivationSalt: string` REQUIRED)\n- `type CreateAccountResult` (= `MPCAccount`)\n\n## API Routes\n\n### Passkey Authentication\n\n| Method | Route | Description |\n|--------|-------|-------------|\n| POST | `/register/start` | Start passkey registration |\n| POST | `/register/finish` | Complete registration, create NEAR account |\n| POST | `/login/start` | Start authentication |\n| POST | `/login/finish` | Complete authentication |\n| POST | `/logout` | End session |\n| GET | `/session` | Get current session |\n| GET | `/csrf-token` | Get CSRF token (when CSRF enabled) |\n\n### Recovery\n\n| Method | Route | Description |\n|--------|-------|-------------|\n| POST | `/recovery/wallet/link` | Start wallet linking |\n| POST | `/recovery/wallet/verify` | Complete wallet linking |\n| POST | `/recovery/wallet/start` | Start wallet recovery |\n| POST | `/recovery/wallet/finish` | Complete wallet recovery |\n| POST | `/recovery/ipfs/setup` | Create IPFS backup |\n| POST | `/recovery/ipfs/recover` | Recover from IPFS |\n\n### Account Management\n\n| Method | Route | Description |\n|--------|-------|-------------|\n| POST | `/account/reregister-passkey` | Re-register passkey after recovery |\n| DELETE | `/account` | Delete account and all associated data |\n\n### OAuth (mounted separately)\n\n| Method | Route | Description |\n|--------|-------|-------------|\n| GET | `/oauth/providers` | List available OAuth providers |\n| GET | `/oauth/:provider/start` | Start OAuth flow (google, github, twitter) |\n| POST | `/oauth/:provider/callback` | Handle OAuth callback |\n| POST | `/oauth/:provider/link` | Link additional provider to account |\n\n## Configuration\n\n### Full Configuration\n\n```typescript\nconst auth = createAnonAuth({\n  // === Required ===\n  nearNetwork: 'testnet',           // 'testnet' or 'mainnet'\n  sessionSecret: '...',             // Session signing secret\n  database: {\n    type: 'postgres',               // 'postgres' or 'custom'\n    connectionString: '...',        // PostgreSQL connection string\n    // OR\n    // type: 'custom',\n    // adapter: myCustomAdapter,    // DatabaseAdapter implementation\n  },\n\n  // === WebAuthn Relying Party ===\n  rp: {\n    name: 'My App',\n    id: 'myapp.com',\n    origin: 'https://myapp.com',\n    // Optional v0.7.0 (RPID-01): cross-domain passkey support via WebAuthn\n    // Related Origin Requests. Paired tuples — NOT two parallel arrays.\n    // Max 5 entries. See \"Cross-Domain Passkeys (v0.7.0)\" below.\n    // relatedOrigins: [\n    //   { origin: 'https://myapp.co.uk', rpId: 'myapp.co.uk' },\n    //   { origin: 'https://myapp.de',    rpId: 'myapp.de' },\n    // ],\n  },\n\n  // === Privacy (recommended for production) ===\n  derivationSalt: '...',           // Prevents NEAR account ID prediction\n\n  // === Session ===\n  sessionDurationMs: 7 * 24 * 60 * 60 * 1000, // Default: 7 days\n  sessionMetadata: {\n    ipAddress: 'omit',             // 'store' (default), 'omit', 'hash', or 'truncate'\n    userAgent: 'omit',             // 'store' (default), 'omit', or 'hash'\n  },\n\n  // === Codename Generation ===\n  codename: {\n    style: 'nato-phonetic',         // ALPHA-BRAVO-42 (default)\n    // style: 'animals',            // SWIFT-FALCON-73\n    // generator: (userId) => `AGENT-${userId.slice(0, 8)}`, // Custom\n  },\n\n  // === Recovery ===\n  recovery: {\n    wallet: true,                   // Enable on-chain wallet recovery\n    ipfs: {                         // Enable IPFS + password recovery\n      pinningService: 'pinata',     // 'pinata', 'web3storage', 'infura', 'custom'\n      apiKey: '...',\n      apiSecret: '...',\n    },\n  },\n\n  // === OAuth (optional) ===\n  oauth: {\n    callbackBaseUrl: 'https://myapp.com/auth/callback',\n    google: { clientId: '...', clientSecret: '...' },\n    github: { clientId: '...', clientSecret: '...' },\n    twitter: { clientId: '...', clientSecret: '...' },\n  },\n\n  // === MPC Account Config (optional) ===\n  mpc: {\n    treasuryAccount: 'your-treasury.near',\n    treasuryPrivateKey: process.env.NEAR_TREASURY_PRIVATE_KEY,\n    fundingAmount: '0.01',          // NEAR per new account\n    accountPrefix: 'anon',          // Account name prefix\n    derivationSalt: '...',          // Alternative to top-level derivationSalt\n  },\n\n  // === Logging (optional) ===\n  logger: pinoInstance,             // pino logger; silent/disabled if omitted\n\n  // === Rate Limiting (optional, sensible defaults) ===\n  rateLimiting: {\n    auth: { windowMs: 900000, limit: 20 },      // 20 req / 15 min\n    recovery: { windowMs: 3600000, limit: 5 },   // 5 req / 1 hr\n  },\n\n  // === CSRF Protection (optional, disabled by default) ===\n  csrf: {\n    secret: '...',                  // HMAC secret (must differ from sessionSecret)\n  },\n\n  // === Email (optional, for OAuth recovery passwords) ===\n  email: {\n    region: 'us-east-1',           // AWS SES region\n    accessKeyId: '...',            // Optional (uses instance profile if omitted)\n    secretAccessKey: '...',\n    fromAddress: 'noreply@myapp.com',\n  },\n});\n```\n\n### Environment Variables\n\n```bash\n# Required\nSESSION_SECRET=your-secure-session-secret\nDATABASE_URL=postgresql://user:pass@localhost:5432/mydb\n\n# Privacy (recommended for production)\nDERIVATION_SALT=your-random-secret-salt\n\n# NEAR Network ('testnet' or 'mainnet')\nNEAR_NETWORK=mainnet\n\n# Mainnet: Treasury for auto-funding new accounts\nNEAR_TREASURY_ACCOUNT=your-treasury.near\nNEAR_TREASURY_PRIVATE_KEY=ed25519:5abc123...\nNEAR_FUNDING_AMOUNT=0.01  # optional, default 0.01\n\n# Optional: Recovery via IPFS (Pinata)\nPINATA_API_KEY=your-pinata-key\nPINATA_API_SECRET=your-pinata-secret\n\n# Optional: Recovery via IPFS (Web3.Storage)\nWEB3_STORAGE_TOKEN=your-web3storage-token\n\n# Optional: Recovery via IPFS (Infura)\nINFURA_IPFS_PROJECT_ID=your-project-id\nINFURA_IPFS_PROJECT_SECRET=your-project-secret\n\n# Optional: OAuth providers\nGOOGLE_CLIENT_ID=...\nGOOGLE_CLIENT_SECRET=...\nGITHUB_CLIENT_ID=...\nGITHUB_CLIENT_SECRET=...\nTWITTER_CLIENT_ID=...\nTWITTER_CLIENT_SECRET=...\n\n# Optional: CSRF protection\nCSRF_SECRET=your-csrf-secret\n\n# Optional: AWS SES email\nAWS_SES_REGION=us-east-1\nAWS_SES_ACCESS_KEY_ID=...\nAWS_SES_SECRET_ACCESS_KEY=...\nAWS_SES_FROM_ADDRESS=noreply@myapp.com\n```\n\n### Cleanup Scheduler\n\nExpired sessions, challenges, and OAuth states are not cleaned automatically by `createAnonAuth`. Use the standalone cleanup scheduler:\n\n```typescript\nimport { createCleanupScheduler } from '@vitalpoint/near-phantom-auth/server';\n\nconst scheduler = createCleanupScheduler(auth.db, logger, 5 * 60 * 1000); // every 5 min\n\n// On graceful shutdown:\nprocess.on('SIGTERM', () => scheduler.stop());\n```\n\n### MPC Account Funding (Mainnet)\n\nOn NEAR mainnet, implicit accounts (64-char hex addresses) need initial funding to become active on-chain. Configure a treasury account to auto-fund new user accounts:\n\n```typescript\nconst auth = createAnonAuth({\n  nearNetwork: 'mainnet',\n  // ... other config\n\n  mpc: {\n    treasuryAccount: 'your-treasury.near',\n    treasuryPrivateKey: process.env.NEAR_TREASURY_PRIVATE_KEY,\n    fundingAmount: '0.01',\n    accountPrefix: 'myapp',\n  },\n});\n```\n\n**How it works:**\n1. New user registers with passkey\n2. System derives deterministic implicit account ID (64-char hex)\n3. Treasury sends 0.01 NEAR to activate the account\n4. User can now receive/send NEAR immediately\n\n**Cost estimation:**\n- ~0.01 NEAR per new user\n- 1 NEAR funds ~100 new accounts\n- Treasury account needs ~0.00182 NEAR minimum balance to stay active\n\n> **Testnet**: On testnet, accounts are auto-created via the NEAR testnet helper API with test tokens. No treasury needed.\n\n## Security Recommendations\n\n### Hardware Security Keys\n\nFor maximum security, we recommend using a hardware security key instead of platform authenticators (Face ID, fingerprint). Hardware keys provide:\n\n- **Phishing resistance**: Credentials bound to specific domains\n- **No biometric data exposure**: Key never leaves the device\n- **Cross-device portability**: Use the same key on multiple devices\n- **Air-gapped signing**: Private keys never touch your computer\n\n**Recommended: [Nitrokey](https://shop.nitrokey.com/shop?aff_ref=39)** - Open source hardware security keys with FIDO2/WebAuthn support. Made in Germany with open firmware you can audit.\n\n### Production Checklist\n\n- [ ] Set `derivationSalt` to prevent NEAR account ID prediction\n- [ ] Set `sessionSecret` to a cryptographically random value (32+ bytes)\n- [ ] Enable `csrf` with a separate secret if your frontend is on a different origin\n- [ ] Configure `rateLimiting` thresholds appropriate for your traffic\n- [ ] Set `sessionMetadata` to `omit` or `hash` IP/user-agent data if your threat model treats operational metadata as identifying\n- [ ] Provide a `logger` instance with appropriate redaction for your environment\n- [ ] Run `createCleanupScheduler` to prevent expired record accumulation\n\n## Privacy and Anonymity Audit\n\nThis section documents exactly what the package stores, logs, and exposes for passkey (anonymous) users. The goal: **it must be impossible to link a passkey user to a real-world identity through anything this package does.** Enterprise identity is a separate opt-in track; it does not change anonymous defaults.\n\n### What We Store (Passkey Users)\n\n| Data | Stored | Location | Identity Risk |\n|------|--------|----------|---------------|\n| Email | No | - | - |\n| Phone | No | - | - |\n| Real name | No | - | - |\n| Codename | Yes | Database | None - randomly generated from `crypto.randomBytes()` |\n| NEAR account ID | Yes | Database + Blockchain | None - derived from random UUID + salt |\n| Passkey public key | Yes | Database | None - device-generated, unlinkable |\n| Session IP address | Configurable | Database (`anon_sessions`) | Raw values only when `sessionMetadata.ipAddress` uses `store`; otherwise omitted, HMAC-hashed, or coarse-truncated |\n| Session user agent | Configurable | Database (`anon_sessions`) | Raw values only when `sessionMetadata.userAgent` uses `store`; otherwise omitted or HMAC-hashed |\n| Recovery wallet link | No | On-chain only | - |\n| IPFS backup CID | Yes | Database | None - content is AES-256-GCM encrypted |\n\n### What We Cannot Know\n\n- **Real identity of passkey users** - no PII is collected or stored at any point in the passkey flow\n- **Link between codename and real person** - codenames are random, not derived from identity\n- **Link between NEAR account and real person** - account IDs are derived from random UUIDs (with `derivationSalt`, they are also unpredictable)\n- **Contents of IPFS recovery backups** - encrypted with user-chosen password, never stored server-side\n- **Which wallet belongs to which user** - recovery wallet linkage is on-chain only, not in our database\n\n### Anonymity Design Decisions\n\n**WebAuthn attestation is set to `'none'`**. The package never requests device attestation, which means the server never learns the manufacturer, model, or firmware version of the user's authenticator. This is intentional - attestation is an identity vector.\n\n**OAuth and passkey tracks are fully separated**. OAuth users (who have email/name) and passkey users (who are anonymous) are stored in separate database tables (`oauth_users` vs `anon_users`) with separate TypeScript types. OAuth identity data never leaks into anonymous user records.\n\n**Enterprise identity is a third opt-in track**. Enterprise users live in\n`enterprise_users`, not `anon_users` or `oauth_users`. External IdP subjects,\nSCIM ids, and chosen `externalAttrs` stay on that enterprise track. The package\ndoes not join `enterprise_users` into `anon_users`, does not copy enterprise PII\ninto anonymous sessions or anonymous route responses, and does not add\nenterprise identifiers to `AnalyticsEvent`.\n\n**Codenames are purely random**. Generated from `crypto.randomBytes()` selecting from word lists. Not derived from user ID, device, IP, or any other input. Two users on the same device get unrelated codenames.\n\n**Logging is silent by default**. If no `logger` is provided, zero output is produced. When logging is enabled, passkey flow log calls contain no identity data - only error objects, NEAR account IDs, and operational metadata.\n\n**Rate limiting is in-memory only**. IP addresses are used as rate limit keys by `express-rate-limit` but are never persisted to disk or database by the rate limiter. They exist only in the Node.js process memory for the duration of the rate limit window.\n\n### Session Metadata Policy\n\n`createAnonAuth({ sessionMetadata })` controls whether session IP addresses\nand user-agent strings are persisted:\n\n| Field | Policy | Stored value |\n|-------|--------|--------------|\n| `ipAddress` | `store` | Raw IP address. This is the backwards-compatible default. |\n| `ipAddress` | `omit` | No IP address is stored. Recommended for maximum anonymity. |\n| `ipAddress` | `hash` | Deterministic `hmac-sha256:<hex>` using `sessionSecret`; pseudonymous and still correlatable within the deployment. |\n| `ipAddress` | `truncate` | Coarse network only: IPv4 `/24` or IPv6 `/48`. Invalid IPs are omitted. |\n| `userAgent` | `store` | Raw user-agent string. This is the backwards-compatible default. |\n| `userAgent` | `omit` | No user-agent string is stored. Recommended for maximum anonymity. |\n| `userAgent` | `hash` | Deterministic `hmac-sha256:<hex>` using `sessionSecret`; pseudonymous and still correlatable within the deployment. |\n\nUse `omit` for both fields when operational session metadata is not required.\nUse `hash` only when you need same-source correlation without raw values.\nUse IP `truncate` when coarse abuse/debugging context is acceptable but raw\naddresses are not.\n\n### Session IP and User Agent\n\nSession records include optional `ipAddress` and `userAgent` fields. These are standard Express operational metadata used for session security (detecting session hijacking, abuse patterns). They are:\n\n- **Ephemeral** - cleaned up when sessions expire (via cleanup scheduler or expiry)\n- **Not exposed** - never returned in any API response\n- **Not logged** - not included in any log call\n- **Not linked to identity** - there is no identity to link to; the user record contains only a random UUID, random codename, and NEAR account\n- **Configurable** - raw storage is retained only for backwards compatibility; set `sessionMetadata` to omit, hash, or IP-truncate values before persistence\n\nWith full database access under the default `store` policy, an attacker would see: a random UUID, a random codename, a NEAR account, and a list of session IPs/user agents. But there is no name, email, phone, or external identifier to connect any of it to a real person. The IP tells you a session came from an ISP - not who the person is. For the strictest anonymous-track posture, configure `sessionMetadata: { ipAddress: 'omit', userAgent: 'omit' }` so those operational fields are not stored at all.\n\n### Threat Model Summary\n\n| Threat | Mitigated | How |\n|--------|-----------|-----|\n| Server operator identifies user | Yes | No PII in anonymous user record |\n| Database breach reveals identity | Yes | Only random UUIDs, codenames, and public keys |\n| Log exfiltration reveals identity | Yes | Logging silent by default; no PII in passkey log calls |\n| Device fingerprinting via WebAuthn | Yes | Attestation set to `'none'` |\n| Cross-track deanonymization (OAuth -> passkey) | Yes | Separate DB tables and type system |\n| Cross-track deanonymization (enterprise -> passkey) | Yes | `enterprise_users` is opt-in and separate from `anon_users`; no enterprise identifiers in anonymous analytics or route responses |\n| NEAR account -> real identity | Yes | Derived from random UUID; unpredictable with `derivationSalt` |\n| Recovery backup contents leaked | Yes | AES-256-GCM encrypted with user password |\n| Rate limiter IP persistence | Yes | In-memory only, never written to disk |\n\n## License\n\nMIT\n\n## Contributing\n\nContributions welcome! Please read our contributing guidelines first.\n","readmeFilename":"README.md"}