{"_id":"@sealed-api-gateway/console","_rev":"6-add907592f839db5928ad7fd99ba4910","name":"@sealed-api-gateway/console","dist-tags":{"latest":"1.0.2"},"versions":{"0.1.0":{"name":"@sealed-api-gateway/console","version":"0.1.0","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"author":{"name":"JAINEEL PATEL"},"license":"MIT","_id":"@sealed-api-gateway/console@0.1.0","maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"dist":{"shasum":"8841a85cfb047384eeedd3fb3bedf3208dc34626","tarball":"https://registry.npmjs.org/@sealed-api-gateway/console/-/console-0.1.0.tgz","fileCount":111,"integrity":"sha512-Kz/kpeCauzf6K816clw7GH4hFOX41VD1TgR3rNCzBfGNf9jsTUloy6te4ohn9wWhdj8NU826Vm8VRi2IVR5lwQ==","signatures":[{"sig":"MEQCIBhEe4yjerdje+5PhpG5+fcEJwKT3smDEFTinSwDMjCnAiAQAAlp2iAsfiynFICcF5+R/pKgKCmXRHAjq9e9SR/O2Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":247643},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.17"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./page":{"types":"./dist/page-entry.d.ts","default":"./dist/page-entry.js"},"./unlock":{"types":"./dist/unlock-entry.d.ts","default":"./dist/unlock-entry.js"},"./package.json":"./package.json"},"gitHead":"8e175a783b06efce9415b7140b2b8d88834f3f44","scripts":{"build":"npm run clean && tsc -p tsconfig.build.json && node ../../scripts/postbuild.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","verify":"node ../../scripts/verify-dist.mjs","type-check":"tsc -p tsconfig.json --noEmit","verify:pack":"node ../../scripts/verify-pack.mjs","prepublishOnly":"npm run build && npm run verify && npm run verify:pack && npm run verify:publish","verify:publish":"node ../../scripts/verify-publish.mjs"},"_npmUser":{"name":"jaineelpatel","email":"jaineelp2@gmail.com"},"repository":{"url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","type":"git","directory":"packages/console"},"_npmVersion":"11.16.0","description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"sealedGateway":{"copyToDist":[],"clientModules":["dist/DebugConsole.js","dist/UnlockForm.js","dist/Toolbar.js","dist/CopyButton.js","dist/table/index.js","dist/analys/index.js"],"serverOnlyModules":["dist/index.js","dist/page.js","dist/page-entry.js","dist/unlock-entry.js","dist/unlock-route.js","dist/auth.js"]},"typesVersions":{"*":{"page":["./dist/page-entry.d.ts"],"unlock":["./dist/unlock-entry.d.ts"]}},"_hasShrinkwrap":false,"peerDependencies":{"next":">=13.4.0 <17","react":">=18.2.0 <20","@mui/material":">=5 <10","@emotion/react":">=11","@emotion/styled":">=11","@mui/icons-material":">=5 <10","@sealed-api-gateway/core":">=0.1.1 <1"},"_npmOperationalInternal":{"tmp":"tmp/console_0.1.0_1785778082345_0.5755078985784183","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@sealed-api-gateway/console","version":"0.2.0","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"author":{"name":"JAINEEL PATEL"},"license":"MIT","_id":"@sealed-api-gateway/console@0.2.0","maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"dist":{"shasum":"708cdfe1a30687f89cb10571bb88678540c4cc17","tarball":"https://registry.npmjs.org/@sealed-api-gateway/console/-/console-0.2.0.tgz","fileCount":95,"integrity":"sha512-RKK7oM6reFn3lAa6JfO5nv+GvHoeYmjQx2f99/LLYSgH+LxFfkmbPhxH6HIWYHUOX5BCMFp24xnfLajlc234vw==","signatures":[{"sig":"MEQCIBNP6PX8d1QAiI1J9NBu6jAlUBW8OZYEmErEj2v+85PrAiA6I95jihbIldQ+yE4gOqecYh+c9Q4mSp6Om+KGBf/WVA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":244181},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.17"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"gitHead":"8e175a783b06efce9415b7140b2b8d88834f3f44","scripts":{"build":"npm run clean && tsc -p tsconfig.build.json && node ../../scripts/postbuild.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","verify":"node ../../scripts/verify-dist.mjs","type-check":"tsc -p tsconfig.json --noEmit","verify:pack":"node ../../scripts/verify-pack.mjs","prepublishOnly":"npm run build && npm run verify && npm run verify:pack && npm run verify:publish","verify:publish":"node ../../scripts/verify-publish.mjs"},"_npmUser":{"name":"jaineelpatel","email":"jaineelp2@gmail.com"},"repository":{"url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","type":"git","directory":"packages/console"},"_npmVersion":"11.16.0","description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"sealedGateway":{"copyToDist":[],"clientModules":["dist/GatewayConsole.js","dist/DebugConsole.js","dist/UnlockForm.js","dist/Toolbar.js","dist/CopyButton.js","dist/table/index.js","dist/analys/index.js"],"serverOnlyModules":["dist/index.js","dist/hotkey.js","dist/theme.js"]},"_hasShrinkwrap":false,"peerDependencies":{"next":">=13.4.0 <17","react":">=18.2.0 <20","@mui/material":">=5 <10","@emotion/react":">=11","@emotion/styled":">=11","@mui/icons-material":">=5 <10","@sealed-api-gateway/core":">=0.3.0 <1"},"_npmOperationalInternal":{"tmp":"tmp/console_0.2.0_1785780625044_0.9521800975554635","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@sealed-api-gateway/console","version":"0.2.1","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"author":{"name":"JAINEEL PATEL"},"license":"MIT","_id":"@sealed-api-gateway/console@0.2.1","maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"dist":{"shasum":"85e332275a8d1c23825edf4c88cdfcc4c8a690c6","tarball":"https://registry.npmjs.org/@sealed-api-gateway/console/-/console-0.2.1.tgz","fileCount":95,"integrity":"sha512-h608wbW+0BJ3O4DahIlsRQWL4+IL7nmQQ6fwVThqpBuvpBDo09j9uN1HzCM0QJIxq9zjU9vzmHkaLwEjLfhRng==","signatures":[{"sig":"MEYCIQDAqDOIWyZqlyLqmMI6ataJjfthrkjITo1rGpLdRmPJGgIhAK3abXWFuGPalHU9WuqQzjRkxdOV43YVcRtj6FHFCkXu","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":245097},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.17"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"gitHead":"8e175a783b06efce9415b7140b2b8d88834f3f44","scripts":{"build":"npm run clean && tsc -p tsconfig.build.json && node ../../scripts/postbuild.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","verify":"node ../../scripts/verify-dist.mjs","type-check":"tsc -p tsconfig.json --noEmit","verify:pack":"node ../../scripts/verify-pack.mjs","prepublishOnly":"npm run build && npm run verify && npm run verify:pack && npm run verify:publish","verify:publish":"node ../../scripts/verify-publish.mjs"},"_npmUser":{"name":"jaineelpatel","email":"jaineelp2@gmail.com"},"repository":{"url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","type":"git","directory":"packages/console"},"_npmVersion":"11.16.0","description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"sealedGateway":{"copyToDist":[],"clientModules":["dist/GatewayConsole.js","dist/DebugConsole.js","dist/UnlockForm.js","dist/Toolbar.js","dist/CopyButton.js","dist/table/index.js","dist/analys/index.js"],"serverOnlyModules":["dist/index.js","dist/hotkey.js","dist/theme.js"]},"_hasShrinkwrap":false,"peerDependencies":{"next":">=13.4.0 <17","react":">=18.2.0 <20","@mui/material":">=5 <10","@emotion/react":">=11","@emotion/styled":">=11","@mui/icons-material":">=5 <10","@sealed-api-gateway/core":">=0.3.0 <1"},"_npmOperationalInternal":{"tmp":"tmp/console_0.2.1_1785785376157_0.7377348842479974","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@sealed-api-gateway/console","version":"1.0.0","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"author":{"name":"JAINEEL PATEL"},"license":"MIT","_id":"@sealed-api-gateway/console@1.0.0","maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"dist":{"shasum":"2a00ffbfb9043958ec5cfa1ce8be2943a6a58181","tarball":"https://registry.npmjs.org/@sealed-api-gateway/console/-/console-1.0.0.tgz","fileCount":95,"integrity":"sha512-bfwTXld5ce5sLHjFc3x8yaka3bxNOFk0X3qC658mOzpYDDGT+tm99XZMWxuCfo0RMxostIElVDocPTQouT6wCg==","signatures":[{"sig":"MEQCIAhUZoLBiA/hPTl0qNRmXujoGHWj9Tg6z1UmMaTvxfi+AiASq+VOYyUSISZ3YJF++J7lOJS33t24NTWgN/oT6JBB1g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":245097},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.17"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"gitHead":"8e175a783b06efce9415b7140b2b8d88834f3f44","scripts":{"build":"npm run clean && tsc -p tsconfig.build.json && node ../../scripts/postbuild.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","verify":"node ../../scripts/verify-dist.mjs","type-check":"tsc -p tsconfig.json --noEmit","verify:pack":"node ../../scripts/verify-pack.mjs","prepublishOnly":"npm run build && npm run verify && npm run verify:pack && npm run verify:publish","verify:publish":"node ../../scripts/verify-publish.mjs"},"_npmUser":{"name":"jaineelpatel","email":"jaineelp2@gmail.com"},"repository":{"url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","type":"git","directory":"packages/console"},"_npmVersion":"11.16.0","description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"sealedGateway":{"copyToDist":[],"clientModules":["dist/GatewayConsole.js","dist/DebugConsole.js","dist/UnlockForm.js","dist/Toolbar.js","dist/CopyButton.js","dist/table/index.js","dist/analys/index.js"],"serverOnlyModules":["dist/index.js","dist/hotkey.js","dist/theme.js"]},"_hasShrinkwrap":false,"peerDependencies":{"next":">=13.4.0 <17","react":">=18.2.0 <20","@mui/material":">=5 <10","@emotion/react":">=11","@emotion/styled":">=11","@mui/icons-material":">=5 <10","@sealed-api-gateway/core":">=1.0.0 <2"},"_npmOperationalInternal":{"tmp":"tmp/console_1.0.0_1786114687347_0.17446845901559804","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@sealed-api-gateway/console","version":"1.0.1","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"author":{"name":"JAINEEL PATEL"},"license":"MIT","_id":"@sealed-api-gateway/console@1.0.1","maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"dist":{"shasum":"6f886a203eaf8326351896f2f2311b78797a74fc","tarball":"https://registry.npmjs.org/@sealed-api-gateway/console/-/console-1.0.1.tgz","fileCount":95,"integrity":"sha512-RB8pmxYTU6HAcpzjzDbZVsHxNEoyvEN0zE0ZlQQ12ER76UA84kHvOnnvIHyTDNICkWKA48wxZjUGAsKL1z9r3g==","signatures":[{"sig":"MEUCICDXW2XKN7lRyh/aGAp9gFanR3FlHDalPnBzgD8sKLclAiEAotX9Ohgcm73v1RuLKL99fGlemTBH3pthqPFCmGOHaG8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":245973},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.17"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"gitHead":"8e175a783b06efce9415b7140b2b8d88834f3f44","scripts":{"build":"npm run clean && tsc -p tsconfig.build.json && node ../../scripts/postbuild.mjs","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","verify":"node ../../scripts/verify-dist.mjs","type-check":"tsc -p tsconfig.json --noEmit","verify:pack":"node ../../scripts/verify-pack.mjs","prepublishOnly":"npm run build && npm run verify && npm run verify:pack && npm run verify:publish","verify:publish":"node ../../scripts/verify-publish.mjs"},"_npmUser":{"name":"jaineelpatel","email":"jaineelp2@gmail.com"},"repository":{"url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","type":"git","directory":"packages/console"},"_npmVersion":"11.16.0","description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"sealedGateway":{"copyToDist":[],"clientModules":["dist/GatewayConsole.js","dist/DebugConsole.js","dist/UnlockForm.js","dist/Toolbar.js","dist/CopyButton.js","dist/table/index.js","dist/analys/index.js"],"serverOnlyModules":["dist/index.js","dist/hotkey.js","dist/theme.js"]},"_hasShrinkwrap":false,"peerDependencies":{"next":">=13.4.0 <17","react":">=18.2.0 <20","@mui/material":">=5 <10","@emotion/react":">=11","@emotion/styled":">=11","@mui/icons-material":">=5 <10","@sealed-api-gateway/core":">=1.0.0 <2"},"_npmOperationalInternal":{"tmp":"tmp/console_1.0.1_1786115542501_0.132053597757809","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@sealed-api-gateway/console","version":"1.0.2","description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"license":"MIT","author":{"name":"JAINEEL PATEL"},"repository":{"type":"git","url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","directory":"packages/console"},"bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","type":"module","sideEffects":false,"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"types":"./dist/index.d.ts","engines":{"node":">=18.17"},"peerDependencies":{"@emotion/react":">=11","@emotion/styled":">=11","@mui/icons-material":">=5 <10","@mui/material":">=5 <10","@sealed-api-gateway/core":">=1.0.0 <2","next":">=13.4.0 <17","react":">=18.2.0 <20"},"scripts":{"clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","build":"npm run clean && tsc -p tsconfig.build.json && node ../../scripts/postbuild.mjs","type-check":"tsc -p tsconfig.json --noEmit","verify":"node ../../scripts/verify-dist.mjs","verify:pack":"node ../../scripts/verify-pack.mjs","verify:publish":"node ../../scripts/verify-publish.mjs","prepublishOnly":"npm run build && npm run verify && npm run verify:pack && npm run verify:publish"},"sealedGateway":{"clientModules":["dist/GatewayConsole.js","dist/DebugConsole.js","dist/UnlockForm.js","dist/Toolbar.js","dist/CopyButton.js","dist/table/index.js","dist/analys/index.js"],"serverOnlyModules":["dist/index.js","dist/hotkey.js","dist/theme.js"],"copyToDist":[]},"publishConfig":{"access":"public"},"gitHead":"8e175a783b06efce9415b7140b2b8d88834f3f44","_id":"@sealed-api-gateway/console@1.0.2","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-IC8TzFOtuneIy2kvrcJiknRjnYci8HQQ6jLFjzqMQwX3fSY9hRfNHTZzz5webAaVtk7Ms03gWCi3rKYOknx8mA==","shasum":"3dca5a4696360cc1e3d3ef670253fef9ec2ceada","tarball":"https://registry.npmjs.org/@sealed-api-gateway/console/-/console-1.0.2.tgz","fileCount":95,"unpackedSize":249294,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDHahnhVSVQwZE9XminlpKZtmlfSgDQTyxtoXJKVT5wwwIhALsOIW2SB/32xg6rqXERUr9IfbmRh7F6NeKA3CE5FTtT"}]},"_npmUser":{"name":"jaineelpatel","email":"jaineelp2@gmail.com"},"directories":{},"maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/console_1.0.2_1786118832654_0.7489342033864275"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-03T17:28:02.147Z","modified":"2026-08-07T16:07:12.976Z","0.1.0":"2026-08-03T17:28:02.487Z","0.2.0":"2026-08-03T18:10:25.365Z","0.2.1":"2026-08-03T19:29:36.355Z","1.0.0":"2026-08-07T14:58:07.493Z","1.0.1":"2026-08-07T15:12:22.658Z","1.0.2":"2026-08-07T16:07:12.795Z"},"bugs":{"url":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/issues"},"author":{"name":"JAINEEL PATEL"},"license":"MIT","homepage":"https://github.com/JAINEELPATEL/sealed-api-gateway-npm/tree/main/packages/console#readme","keywords":["nextjs","devtools","network-inspector","debug-console","api-gateway","mui","app-router"],"repository":{"type":"git","url":"git+https://github.com/JAINEELPATEL/sealed-api-gateway-npm.git","directory":"packages/console"},"description":"A password-gated, Network-tab-style console for reading the traffic @sealed-api-gateway/core seals.","maintainers":[{"name":"jaineelpatel","email":"jaineelp2@gmail.com"}],"readme":"<div align=\"center\">\n\n# @sealed-api-gateway/console\n\n**Read the traffic the gateway hid — a Network tab for calls the Network tab can no longer show.**\n\n[![npm](https://img.shields.io/npm/v/@sealed-api-gateway/console?style=flat-square&color=0ca30c)](https://www.npmjs.com/package/@sealed-api-gateway/console)\n[![License: MIT](https://img.shields.io/badge/License-MIT-0ca30c.svg?style=flat-square)](LICENSE)\n[![Next.js](https://img.shields.io/badge/Next.js-13.4%20–%2016-000000?style=flat-square&logo=nextdotjs)](#compatibility)\n[![React](https://img.shields.io/badge/React-18%20|%2019-2a78d6?style=flat-square&logo=react)](#compatibility)\n[![MUI](https://img.shields.io/badge/MUI-5%20|%206%20|%207%20|%209-2a78d6?style=flat-square&logo=mui)](#compatibility)\n\n</div>\n\n---\n\n## What it does\n\n[`@sealed-api-gateway/core`](https://www.npmjs.com/package/@sealed-api-gateway/core) turns every API call into one opaque `POST`. That is the point — and it also means DevTools can no longer help you debug.\n\nThis puts the plaintext back, behind a password:\n\n| | |\n| --- | --- |\n| **Request list** | Status, method, name, page, tab, size, time |\n| **Detail pane** | Headers · Params · Payload · Response · Timing |\n| **JSON tree** | Folding, line-numbered, searchable |\n| **Binary** | Inline preview, hex dump, download |\n| **Copy as cURL** | Against the **real** backend, so a failing call goes straight to a backend engineer |\n| **Analysis** | Status distribution, size and duration over time, p95 and error-rate tiles |\n\n> [!IMPORTANT]\n> **Unset the password and the console does not exist.** With no `SECURE_GATEWAY_PASSWORD`, the component renders `null`, the unlock endpoint `404`s, and **nothing is recorded anywhere**. That is the off switch, and it is the default.\n\n---\n\n## Contents\n\n- [Install](#install) · [Quick start](#quick-start)\n- [Opening it](#opening-it) · [Everything you can change](#everything-you-can-change)\n- [Theming](#theming) · [The password gate](#the-password-gate)\n- [Compatibility](#compatibility) · [Troubleshooting](#troubleshooting)\n- [At a glance](#at-a-glance) · [FAQ](#faq) · [Design decisions](#design-decisions)\n\n---\n\n## Install\n\n```bash\nnpm i @sealed-api-gateway/console\n```\n\nPeers: `@sealed-api-gateway/core` (≥ 0.3.0), `next`, `react`, `@mui/material`, `@mui/icons-material`, `@emotion/react`, `@emotion/styled`.\n\nIf you already render with MUI, this package is the only new thing.\n\n---\n\n## Quick start\n\n**One component and one environment variable.** No route file, no middleware change.\n\n### 1. Mount it beside the gateway\n\n```tsx\n// app/layout.tsx\nimport { SecureApiGateway } from '@sealed-api-gateway/core';\nimport { GatewayConsole } from '@sealed-api-gateway/console';\n\nexport default function RootLayout({ children }: { children: React.ReactNode }) {\n  return (\n    <html lang=\"en\">\n      <body>\n        <SecureApiGateway />\n        <GatewayConsole />\n        {children}\n      </body>\n    </html>\n  );\n}\n```\n\n### 2. Set a password\n\n```bash\n# .env\nSECURE_GATEWAY_PASSWORD=pick-something-long\n```\n\n### 3. Make sure the gateway route exists\n\n```bash\nnpx sealed-gateway-init\n```\n\nThe console adds **no route of its own** — but it reaches the gateway over HTTP\nfor its handshake and unlock, so the gateway's route has to be mounted.\n\n> [!IMPORTANT]\n> From `@sealed-api-gateway/core` 1.0 the **gateway itself no longer needs that\n> file** — it uses Server Actions by default. If you installed core alone and\n> skipped `sealed-gateway-init`, run it now, or the console will sit locked with\n> its unlock endpoint returning 404.\n>\n> This is the console's one outstanding rough edge, and it is temporary: moving\n> it onto core's Server Actions is the next change, and will not alter this\n> package's API.\n\n### 4. Restart and press **Ctrl/Cmd + Shift + D**\n\n> [!NOTE]\n> The console renders MUI components, so it must sit **inside** whatever provides your theme. If your `ThemeProvider` lives below the layout root, mount `<GatewayConsole />` inside it instead.\n\n<details>\n<summary><b>Why is there no route file, and no middleware change?</b></summary>\n\n<br>\n\nEarlier versions needed `app/gw-debug/page.tsx` and `app/gw-debug/api/unlock/route.ts`. A console rendered as a *route* needs route files, and Next derives routes from the filesystem — no package can create one.\n\nSo it no longer renders as a route. It is an **overlay**, mounted from your layout, and its unlock endpoint hangs off the **gateway's** route, which you had to create anyway. Two files became zero.\n\nThat also removes the old middleware note: there is no `/gw-debug` path for auth middleware to intercept, so nothing needs excluding.\n\n</details>\n\n---\n\n## Opening it\n\n| | |\n| --- | --- |\n| **Ctrl/Cmd + Shift + D** | Toggles the overlay |\n| **`#gw-debug`** in the URL | Opens it, survives a reload, and can be shared with a colleague |\n| **Escape** | Closes it |\n\nThere is deliberately **no visible launcher button**. The console hangs off every page of your app, and a floating button would sit in front of real users who cannot open it anyway.\n\nCtrl/Cmd + Shift + **I**, **J** and **C** are DevTools in every major browser and cannot be intercepted — which is why the default avoids them.\n\n---\n\n## Everything you can change\n\n### Props on `<GatewayConsole />`\n\n| Prop | Type | Default | What it changes |\n| --- | --- | --- | --- |\n| `gatewayRoot` | `string` | `'/api/gw'` | Where the gateway route is mounted. Must match `<SecureApiGateway basePath>`. |\n| `hotkey` | `Hotkey \\| null` | `Ctrl/Cmd + Shift + D` | The shortcut. `null` disables it. |\n| `hash` | `string \\| null` | `'gw-debug'` | The URL hash that opens it. `null` disables it. |\n| `colors` | `ConsoleThemeOptions` | built-in palettes | Colour overrides → [theming](#theming) |\n\n```tsx\n<GatewayConsole\n  gatewayRoot=\"/api/proxy\"\n  hotkey={{ key: 'K', ctrlOrMeta: true, alt: true }}\n  hash=\"inspector\"\n  colors={{ dark: { '--sg-ok': '#00d68f' } }}\n/>\n```\n\nA `Hotkey` is `{ key, ctrlOrMeta?, shift?, alt? }`. Modifiers you do **not** ask for must be absent, so `Ctrl+Shift+D` does not also fire on `Ctrl+Shift+Alt+D`.\n\n### Environment variables\n\nThe console adds none of its own. It reads two from the gateway:\n\n| Variable | Effect |\n| --- | --- |\n| `SECURE_GATEWAY_PASSWORD` | Unset ⇒ console does not exist and nothing is recorded. Set ⇒ console available behind it. |\n| `SECURE_GATEWAY_UNLOCK_TTL_HOURS` | How long an unlock lasts. Default `8`. |\n\n### Mounting it somewhere of your own\n\nIf you want the console inside an admin shell, a drawer or a tab rather than as an overlay, compose the pieces yourself:\n\n```tsx\nimport { DebugConsole, UnlockForm } from '@sealed-api-gateway/console';\n\nconst [unlocked, setUnlocked] = useState(false);\n\nreturn unlocked\n  ? <DebugConsole onClose={close} colors={colors} />\n  : <UnlockForm onUnlocked={() => setUnlocked(true)} onClose={close} />;\n```\n\nBoth accept `gatewayRoot`.\n\n### What you deliberately cannot change\n\n| Fixed behaviour | Why |\n| --- | --- |\n| The log holds only **your own** browser's traffic | It is read from your browser's storage. There is no server-side log and no way to see another user's requests. |\n| Retention is 1 hour / 300 entries | A developer tool that grows without bound in every user's browser is a bug, not a feature. |\n| Binary bodies are capped (~3 MB in memory, ~110 KB shared across tabs) | So one screenshot cannot evict the whole log. |\n| Nothing is recorded without a password | The off switch has to be the default, or the tool becomes a liability. |\n\n---\n\n## Theming\n\nEvery colour lives in one place, exported as data:\n\n```ts\nimport { LIGHT, DARK } from '@sealed-api-gateway/console';\n```\n\n42 variables as light/dark pairs — surfaces, text, borders, chart marks, JSON syntax, search highlight. Override any of them **by name**; everything you do not name keeps its default:\n\n```tsx\n<GatewayConsole\n  colors={{\n    dark:  { '--sg-ok': '#00d68f', '--sg-server': '#ff5c5c' },\n    light: { '--sg-bg': '#ffffff' },\n  }}\n/>\n```\n\n> [!NOTE]\n> In the copy-the-folder version you edited `theme.ts` directly. Inside `node_modules` you cannot, so the palettes became exported data plus a merge. That is the one place packaging made this worse — and it is why the [reference application](https://github.com/JAINEELPATEL/Sealed-API-Gateway) still ships the console as a folder you own outright.\n\n### It does not read your theme, on purpose\n\nThe console cannot assume the app it is dropped into has a dark scheme, a CSS-variable theme, or a usefully configured palette — so it ships its own defaults and stays legible anywhere. MUI components inside it (buttons, chips, inputs) still follow your theme, so it never looks foreign.\n\nIt does follow your **light/dark choice**, resolved in three tiers:\n\n| Tier | Used when | How |\n| --- | --- | --- |\n| 1 | `theme.applyStyles` exists (MUI 5.18+) | Dark values nested under your theme's own colour-scheme selector — the only form correct for a `createTheme({ cssVariables, colorSchemes })` theme, where `palette.mode` reports the *default* mode rather than the active one |\n| 2 | Older themes | `theme.palette.mode` |\n| 3 | Opt-in | `prefers-color-scheme`, via `colors={{ followOsWhenHostIsLight: true }}` |\n\n---\n\n## The password gate\n\n| State | Behaviour |\n| --- | --- |\n| **Password unset** | Component renders `null`, unlock endpoint `404`s, nothing recorded |\n| **Wrong password** | `401`. Ten attempts per five minutes, then `429` |\n| **Unlocked** | `httpOnly; SameSite=Strict` cookie, 8 hours by default |\n| **Password changed** | Every outstanding unlock dies immediately |\n\nThe cookie is a self-verifying `<expiry>.<hmac>` pair keyed on the password itself. There is no session store to keep, and rotating the password *is* the revocation mechanism.\n\n> [!NOTE]\n> **What the password is actually for.** The console shows a visitor their **own** browser's traffic — which they could already reach through DevTools. The password keeps the tool out of casual reach; it does not protect data from the person operating the browser. Nothing here can show another user's requests.\n\n---\n\n## Compatibility\n\n| | Supported |\n| --- | --- |\n| **Next.js** | 13.4 – 16, App Router |\n| **React** | 18.2 – 19 |\n| **MUI** | 5, 6, 7, 9 — there is no v8; the majors went 5 → 6 → 7 → 9 |\n| **Node** | ≥ 18.17 |\n| **`@sealed-api-gateway/core`** | ≥ 0.3.0 — earlier versions have no unlock endpoint |\n\nSpanning MUI 5 through 9 takes care, because prop and slot APIs were renamed between majors and the old and new names are **mutually exclusive**: MUI 9 rejects `PaperProps`, MUI 5 does not know `slotProps`. The affected spots use composition and `sx`, which behave identically on every major.\n\n---\n\n## Troubleshooting\n\n| Symptom | Cause | Fix |\n| --- | --- | --- |\n| Hotkey does nothing | No password set, so the console is switched off | Set `SECURE_GATEWAY_PASSWORD` and restart |\n| Hotkey does nothing, password *is* set | The gateway route is missing or mounted elsewhere | `npx sealed-gateway-init`, or pass `gatewayRoot` |\n| Unlock returns 404, gateway itself works fine | Core 1.0+ runs on Server Actions, so you may never have created the route the console needs | `npx sealed-gateway-init` |\n| Console opens but is empty | No traffic captured yet | Trigger an API call — only gateway-routed origins appear |\n| Unlock succeeds, then the form returns | `gatewayRoot` disagrees with `<SecureApiGateway basePath>` | Make them match |\n| Overlay renders unstyled | Mounted outside your `ThemeProvider` | Move `<GatewayConsole />` inside it |\n| `Cannot find module '@sealed-api-gateway/core'` | Peer not installed | `npm i @sealed-api-gateway/core` |\n| Unlock returns `404` | Core older than 0.3.0 | `npm i @sealed-api-gateway/core@latest` |\n\n---\n\n---\n\n## At a glance\n\n| | |\n| --- | --- |\n| Request list with status, method, size, timing | ✅ |\n| Detail pane — Headers · Params · Payload · Response · Timing | ✅ |\n| Folding, line-numbered JSON tree | ✅ |\n| Binary preview with hex dump and download | ✅ |\n| Copy as cURL, against the **real** backend | ✅ |\n| Analysis — status mix, size and duration over time, p95, error rate | ✅ |\n| Filters shared across both views | ✅ |\n| Cross-tab log | ✅ |\n| Opens with a hotkey or a URL hash | ✅ |\n| Needs a route file of its own | ❌ none |\n| Shows other users' traffic | ❌ never |\n\n## FAQ\n\n**Can it show another user's requests?**\nNo. The log is read from your own browser's storage. There is no server-side log,\nand no mechanism by which one browser could see another's traffic.\n\n**What does the password actually protect?**\nIt keeps the tool out of casual reach. The console shows a visitor their **own**\ntraffic — which they could already reach through DevTools — so the password is a\nlock on a convenience, not a barrier around secrets.\n\n**What happens with no password set?**\nThe component renders `null`, the unlock endpoint 404s, and **nothing is\nrecorded**. That is the default, and it is why installing this is safe in\nproduction before you have decided whether to enable it.\n\n**How long is an unlock good for?**\nEight hours by default; set `SECURE_GATEWAY_UNLOCK_TTL_HOURS` to change it.\nChanging the password revokes every outstanding unlock immediately, because the\ncookie is keyed on the password itself.\n\n**Does it slow the app down?**\nOnly when open. While closed it is a single component that has made one handshake\nrequest and rendered nothing.\n\n**Can I restyle it?**\nEvery colour is an exported variable you can override by name — see\n[Theming](#theming). If you expect to restyle heavily, the\n[reference app](https://github.com/JAINEELPATEL/Sealed-API-Gateway) ships the\nconsole as a folder you own outright.\n\n**Can I put it somewhere other than an overlay?**\nYes — compose `DebugConsole` and `UnlockForm` yourself. See\n[mounting it somewhere of your own](#mounting-it-somewhere-of-your-own).\n\n---\n\n## Design decisions\n\n**Why an overlay instead of a route?**\nA console rendered as a route needs route files, and no package can create them —\nNext derives routes from the filesystem. As an overlay it needs none, so\ninstalling is `npm i` plus one component.\n\n**Why no visible launcher button?**\nIt hangs off every page of your app. A floating button would sit in front of real\nusers, who cannot open it anyway.\n\n**Why `Ctrl/Cmd + Shift + D`?**\n`Ctrl+Shift+I`, `+J` and `+C` are DevTools in every major browser and cannot be\nintercepted. A shortcut the browser eats is one nobody can use and nobody can\ndebug.\n\n**Why does it not read colours from my theme?**\nIt cannot assume the app it is dropped into has a dark scheme, a CSS-variable\ntheme, or a usefully configured palette. It ships its own defaults so it stays\nlegible anywhere — while MUI components inside it still follow your theme, so it\nnever looks foreign.\n\n**Why does the password gate live in the gateway package?**\nSo the console needs no server route. The gateway already owns one, so the unlock\nendpoint hangs off it.\n\n\n## Relationship to the reference app\n\nExtracted from [Sealed-API-Gateway](https://github.com/JAINEELPATEL/Sealed-API-Gateway), a full Next.js app demonstrating the gateway and console together.\n\n| | Reference app | This package |\n| --- | --- | --- |\n| Where it renders | its own route, `/gw-debug` | an overlay, on every page |\n| Colours | edit `theme.ts` | `colors` prop + exported palettes |\n| Install | copy a folder | `npm i` + one component |\n| Customising the UI | fork freely, it is your code | props only |\n\nIf you expect to restyle heavily, the folder is still the better choice.\n\n---\n\n## Licence\n\n[MIT](LICENSE) © 2026 JAINEEL PATEL\n","readmeFilename":"README.md"}