{"_id":"@workos/emulate","_rev":"24-e38e2087738e12ad6774a672b5a5bbfa","name":"@workos/emulate","dist-tags":{"latest":"0.14.0"},"versions":{"0.0.1":{"name":"@workos/emulate","version":"0.0.1","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.0.1","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"nickcollisson","email":"nick.collisson@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"1fc480e4ae34b6e8f4299157a5197f313f0d60eb","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.0.1.tgz","fileCount":162,"integrity":"sha512-gMsY1j9Zwl5IZ0e+NKJQi5MmNpbS8A/Xn5KS0t27jtIHZNviKxusxjlA9vCEtkml6mkwQeMO+QWjuIjMH9QGCA==","signatures":[{"sig":"MEYCIQCmoY0mcKKIl39fcZZtalSKsA8OZc1NWs0RiBoLryYV8wIhAPXCCOIoJ0cZnpcI5XtbJ6kxsdQo75k1Ro+9UzDnDT0D","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":614603},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"0b3f3b33adc0d7967cf8f66aa2d86ffab2bcb721","scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf ./dist","start":"node ./dist/cli.js","prebuild":"npm run clean","postbuild":"chmod +x ./dist/cli.js","typecheck":"tsc --noEmit","gen:routes":"tsx scripts/gen-routes.ts","test:watch":"vitest","test:coverage":"vitest run --coverage","check:coverage":"tsx scripts/check-coverage.ts"},"_npmUser":{"name":"gjtorikian","email":"gjtorikian@gmail.com"},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.11.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"25.8.1","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"~22.19.7","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.0.1_1780087899586_0.42348833701568167","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@workos/emulate","version":"0.1.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.1.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"nickcollisson","email":"nick.collisson@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"8cf9b26271a24974f05b7210d41837f44810e9e3","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.1.0.tgz","fileCount":168,"integrity":"sha512-0f4g99yh6Ozf7wfdVlcAktrkyq2ejmweanXFnn0KMfTYdsYO5/oDgBFw+MVLhx9CoslDp2ApPgdImMZTeJ1n6g==","signatures":[{"sig":"MEUCIQDfCnn4Gm7AHXVJpED5AU7s7uLR+MbJ2dSPp0XXOz7kHAIgVkV0WKM9qGP1LGF3omWoVH2BFSXnRKCjpGgckpXZHM4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":656230},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"e20523e9170642779aaf59961efdb748e8342e42","scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf ./dist","start":"node ./dist/cli.js","prebuild":"npm run clean","postbuild":"chmod +x ./dist/cli.js","typecheck":"tsc --noEmit","gen:routes":"tsx scripts/gen-routes.ts","test:watch":"vitest","test:coverage":"vitest run --coverage","check:coverage":"tsx scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.13.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.16.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"~22.19.7","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.1.0_1780342490803_0.9884459810719257","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@workos/emulate","version":"0.2.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.2.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"4eabda2e112c30176362c78c1a935b07a5ea5ace","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.2.0.tgz","fileCount":183,"integrity":"sha512-LCypOKDGxvowDUMX4oNO/OHMMViyk7rGsc94q6jFfz+zYBlh6LirnGpHlnyPozZ0ln8G6e2BbHlWVy5JTDwLAw==","signatures":[{"sig":"MEUCIA7M2l0be0wzQmFS+ag/RabEXptIC1vARHWO667ayojuAiEAlEdZru0ycw4yE6BxWrlHOqHktv1/d8axvtN1ExVPqnU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":935908},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"58b0a0882759bcd98c1a2cba62cfd845c23a06fe","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"vitest run","build":"tsc","clean":"rm -rf ./dist","start":"node ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","prebuild":"npm run clean","fmt:check":"oxfmt --check","postbuild":"chmod +x ./dist/cli.js","typecheck":"tsc --noEmit","gen:events":"tsx scripts/gen-events.ts","gen:routes":"tsx scripts/gen-routes.ts","gen:shapes":"tsx scripts/gen-shapes.ts","test:watch":"vitest","test:coverage":"vitest run --coverage","check:coverage":"tsx scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"~22.19.7","@vitest/coverage-v8":"^4.0.18","@workos/openapi-spec":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.2.0_1783884581014_0.5347734777911886","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@workos/emulate","version":"0.2.1","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.2.1","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"56aae6a24e29b33c696f8943a755f9001b480b33","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.2.1.tgz","fileCount":183,"integrity":"sha512-fNloHbSusy9lheuaw0tQyEK88nTpsyQiG1ZSo6kKYpZN025Sy+f8l7e0vH6g4pfEXwFGPky+OJiqIVnR4hcC/w==","signatures":[{"sig":"MEUCIBGPze3TCSR/paLOkSbjcdYinHSaLo9yhMBVmLh64EqaAiEAnV6e1z3gvsQltdInggU/cE/TB3LIPsOff7YHUxYvm9k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":948849},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"a863dfea35b1785a5fe88dafb128a74cb4bdb551","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"vitest run","build":"tsc","clean":"rm -rf ./dist","start":"node ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","prebuild":"npm run clean","fmt:check":"oxfmt --check","postbuild":"chmod +x ./dist/cli.js","typecheck":"tsc --noEmit","gen:events":"tsx scripts/gen-events.ts","gen:routes":"tsx scripts/gen-routes.ts","gen:shapes":"tsx scripts/gen-shapes.ts","test:watch":"vitest","test:coverage":"vitest run --coverage","check:coverage":"tsx scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"~22.19.7","@vitest/coverage-v8":"^4.0.18","@workos/openapi-spec":"^0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.2.1_1784060857623_0.7923035736134465","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@workos/emulate","version":"0.2.2","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.2.2","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"54c1799eb4a7f20fd8b7e2596b3dd200e3908287","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.2.2.tgz","fileCount":183,"integrity":"sha512-jDudrYrx85kuoh+VpPQrJ7c0sAvfY8ZvcOildpjqN5F0YxlZAha37InpNHDCMx3ITiJlpjUWSiw0mtI/9iccBA==","signatures":[{"sig":"MEUCIF6xoVSDT5S+AVDeE0UCIGppF5fjWQhrqDywrBM3ZNqpAiEAocyaZoXEME+ia2ps8NLrKAlv09VbEp1FqMTCxe3cKxc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":976585},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"8a92825b294a692026163c3c420b1879b19638c4","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"vitest run","build":"tsc","clean":"rm -rf ./dist","start":"node ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","prebuild":"npm run clean","fmt:check":"oxfmt --check","postbuild":"chmod +x ./dist/cli.js","typecheck":"tsc --noEmit","gen:events":"tsx scripts/gen-events.ts","gen:routes":"tsx scripts/gen-routes.ts","gen:shapes":"tsx scripts/gen-shapes.ts","test:watch":"vitest","test:coverage":"vitest run --coverage","check:coverage":"tsx scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"~22.19.7","@vitest/coverage-v8":"^4.0.18","@workos/openapi-spec":"^0.41.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.2.2_1784604913653_0.5421945891932509","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@workos/emulate","version":"0.3.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.3.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"4484963f315cc2656347e4fb6f1dcd46c9389528","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.3.0.tgz","fileCount":183,"integrity":"sha512-oYYYVciSQ+nblqXHPPkvz0QSAZws2OCVMbaTEqyur/mm3Otjmqzc5zL4AT33hbskHjXtNBtEl4PQ1qwkL4RL+A==","signatures":[{"sig":"MEYCIQCwzuD3eGo1gakoHqm03mOLIlOE9ircvcgONgz9I78H/AIhAIWmo11SsdnxDTfs3puAGR5JrW3oqSEUBxZhklL6q7LL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":985444},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"e1d1a5541ebc622221e665fa0b9c7fbbf9e89970","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"vitest run","build":"tsc","clean":"rm -rf ./dist","start":"node ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","prebuild":"npm run clean","fmt:check":"oxfmt --check","postbuild":"chmod +x ./dist/cli.js","typecheck":"tsc --noEmit","gen:events":"tsx scripts/gen-events.ts","gen:routes":"tsx scripts/gen-routes.ts","gen:shapes":"tsx scripts/gen-shapes.ts","test:watch":"vitest","test:coverage":"vitest run --coverage","check:coverage":"tsx scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"~22.19.7","@vitest/coverage-v8":"^4.0.18","@workos/openapi-spec":"^0.41.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.3.0_1784649881709_0.8518672310964917","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@workos/emulate","version":"0.4.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.4.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"b35c2004c34bf828c833a8536ec0a77b82cc5a72","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.4.0.tgz","fileCount":192,"integrity":"sha512-MA4WyiYQTNIL6VnQXKu+c/MeXaZxK+0nqwUGM/ue+FAyJcpBGdkvS3AohRLqK8YY53lcf2CT3V9PLn1d0D+s1A==","signatures":[{"sig":"MEQCIBZuFWHHMNAVxc3i3fpZa7yz70CioK+ZT4PJz1XbwmmMAiA5ZbeWI74LRVzOp5j6NFwyj85D3zzG3Raw58f5pB66Rw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1015235},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"27acbc60f55480bb4fbd468f299fb233880c92ae","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","@types/bun":"^1.3.14","typescript":"^5.9.3","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.41.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.4.0_1785176048901_0.44216669721382873","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@workos/emulate","version":"0.4.1","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.4.1","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"dad3239a050f988b2ff7a3af827e74c4067d698a","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.4.1.tgz","fileCount":192,"integrity":"sha512-45EDnnO39jzV2amKLQAPEtG29Ksg+4mfuUP/rrDzfLev6cCQs9s3mkoCHI0GK09M8eouyS/hIJqyStEN1BOZSA==","signatures":[{"sig":"MEUCIQCCjY/u1mOkjrx8EhHaNXFwaPf3KEhbd+ISfyedmCzhUQIgW7L10MX9wQTkLYzJBNMBaVeafX6SU4f6C1zQZjpNNB0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1060736},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"140aafac181c9c325aeaada053f382b5d093733d","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","@types/bun":"^1.3.14","typescript":"^5.9.3","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.41.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.4.1_1785191734652_0.9545031757440017","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@workos/emulate","version":"0.5.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.5.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"15014b3d3d055e57ba31da957795af7f43fa4267","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.5.0.tgz","fileCount":195,"integrity":"sha512-J5Nwsn5BZ9nisP9vJIyCmawsjkI38dEQpl26hLL/V4QS1z0FkjBZERaHp11Fr/yKgav/w3DIpjEWbKBQOa6NCw==","signatures":[{"sig":"MEQCIDz/coKwo5vwKHJKfSZOge7KQCbhV1B0YoYLpMgF0G5lAiAwbLNqcggj67aKvN5LhAlcaleQrnyd695+Me04YYIj2A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1130081},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"d243a15f3c13b9e11280b6e60c223207fc8f4256","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.54.0","oxlint":"^1.69.0","@types/bun":"^1.3.14","typescript":"^5.9.3","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.41.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.5.0_1785874215167_0.7572721174061254","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@workos/emulate","version":"0.6.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.6.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"84143f1345af2ca199e44eddcb7c10cc06234453","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.6.0.tgz","fileCount":195,"integrity":"sha512-URbdh2jZE1FcHdNA5EqA20/qcTsU642X8HtEO1sq/p4JwXKAdsk6+gNZRm4sZw3UQdetf3fUHBliUVYcjI0nbA==","signatures":[{"sig":"MEUCIQCFS79dj+F6Yv/9lp2rYuq8RoZn7YR6sb+GSU77fjjUpAIgCDxenJi099fa97J87E+agt2kTEb4H1SWbThmzky3hY4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1156309},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"31d41be017e1e5e6cf77c4ecec1635f8d4b84de1","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.6.0_1785967710617_0.6800363041174071","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@workos/emulate","version":"0.7.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.7.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"cf2c572a7767d4b39e3496240017a0db1cc469f7","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.7.0.tgz","fileCount":198,"integrity":"sha512-vXZJiscXDYmnBuhnxHOR0oXOxMYC0eRDW7e/xqtx5yalGCTBivfhj1KAjor1Tjs73xeg2QDxPBkAtdjZrH9Qqg==","signatures":[{"sig":"MEQCIDWhGg2PCkrRor2CHZxt+mqm1COlWMCtZ/70DCPf3MKFAiBQMdO+yTAw/WsBi2lgQsQggcQLUfw3tQO7QdYpaUpAsA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1312572},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"03f0ee828d2cb1f0afa73c90762f782ac87e634a","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.16.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.18.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.7.0_1786144121983_0.5490599724843128","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@workos/emulate","version":"0.7.1","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.7.1","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"3001be6431a97cc230b693f29785d366e986ab86","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.7.1.tgz","fileCount":198,"integrity":"sha512-UXm60PFG0JaAM58FxFZtoy80L64bcvJyMvt9DlOK/bSLAs5emmDGuCI3zFR8QMN3/tro+VizUALzNyDggF/8BA==","signatures":[{"sig":"MEUCIQDuM7DJDpM3It5t/hQx5rXjStdb2wFu5w02SETBPWu50QIgdU6sRwp/zqIFsR6Ka8nEpCWI8b1EISNdAcL2eY0soA8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1324331},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"3b97f5556839d029bccc3dc2f5a840ba6c861a9d","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.17.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.19.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.7.1_1786635560680_0.9311563641147578","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@workos/emulate","version":"0.8.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.8.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"4e9a96f862328942e6872a86b9813044e2ff8f9c","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.8.0.tgz","fileCount":201,"integrity":"sha512-A3enDqGxAWJyvfjM/K2kJ/JSEEGv4UsXp3fbItsl6mu3oYDNMX3TlaPUSqrrBk1TPZSfMaS3v+rgK+sC1cxGrg==","signatures":[{"sig":"MEUCIDcebiLoEJzx5ychgiau5ECohq0mgwF6GqQdvtN1VDL5AiEA+vah07mq/PWLA8hNXU3Mo/eW3uQzx8ZIAqr0D8lHlTc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1422626},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"1aca203a89f7b390c4b33ac5c486813d0b30f352","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.17.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.19.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.8.0_1787514168528_0.9934452488098078","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@workos/emulate","version":"0.9.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.9.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"6d88f188048cde505a3ee71cd44c1d21497c7230","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.9.0.tgz","fileCount":201,"integrity":"sha512-VYjBj5YXa7yO96GmF8SVKvjwWl1jn9636vFDB/QUZNWNkzvGWz1u2Wupuwxk4Cl0wyt/3tdt8ATUYAW2DAfC3w==","signatures":[{"sig":"MEQCIE65RQBP+DFUmRj9SYril5Y5xiLa83Qz0wF/s2foZvbaAiAhMZFAGNk6w1qoPYQvQK7g9kJJrz5HuOCxvu7ZkGEziw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1451363},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"476fe2881a20bf160480780887cf81793801d72a","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.17.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.19.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.9.0_1787689015328_0.40013307583987645","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@workos/emulate","version":"0.10.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.10.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"419d6ce78685dcf85537200aee7686aafa85fc1b","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.10.0.tgz","fileCount":201,"integrity":"sha512-Su8jmbjFIeIQZ1i1sPnGxF3OipLMFFnvIRilkzMfp2+53zaonTiahLWGRwUtToTTDkIWePYtyKne89iEtlwLNA==","signatures":[{"sig":"MEQCIHTVCHhyUcN3FD3jao7xgYsAzGL+0TcyJMxbRX3RsjwdAiApYT1MHu8/Et7IApKVKRx6aQxj11SdFUE3vTwZ+0qPWA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1488617},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"736cb44b49f3f2fce6e4ee34c9978a9ff4efad9f","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.17.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.19.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.10.0_1787841583620_0.11937585792814098","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@workos/emulate","version":"0.11.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.11.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"2943bc850562de81a3e34a34afdabb160c022794","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.11.0.tgz","fileCount":204,"integrity":"sha512-W1oM26eCAwZt3fBMRvVNHyapUitF23wL8prpoWPWWdxuRxr/X93fNz7t1mDikNU68iBDfxXYShOXGZmiR6EJAQ==","signatures":[{"sig":"MEUCIBlnUiN9Ai2Fy0VHEUFqkS+Fc+KCApdGtee4SAHmwwk/AiEA3iMl21SBf1xTNzz6KtUAM1BVW5Q6bJVN6j0weNbWzpU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1562518},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"57ab6a45771e87e568dd6700b02da27585cde0fa","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.17.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.19.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.59.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.11.0_1787946863668_0.08858854998857635","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@workos/emulate","version":"0.12.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.12.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"d941c3d1740fa77f3c8cb234aea449b83cd99462","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.12.0.tgz","fileCount":207,"integrity":"sha512-J7kVy1riKg6eyIZ7L4QVQPF8IKzD/k+ZWImcIt9kzh0yGkBYnNPkNK0FrVxAbyFby/9Nwmt6VApawJQo9HWgig==","signatures":[{"sig":"MEUCIQDLIK3tWiFTvaKpbnhmt1ZydBw+6fdgJx6iqiNUCmT4JwIgH2kkWvx4FZ/1owCiWOqFHEFXtPHIBRuL6CHgGWZfWWw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1794173},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"5f9affc63160ad8c661faff3c206724148a9ce8d","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.19.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.20.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.80.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.12.0_1788468446959_0.45617239107073293","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@workos/emulate","version":"0.13.0","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.13.0","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"649632bbe131f6217127e2d2d663f70bb5da9285","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.13.0.tgz","fileCount":216,"integrity":"sha512-W9ajiZCuP5o8kBbweeaj8XTe/cARD8IP1hLs4qUu1X/1P5ddzbf2Qwzk/z9JFFyVj6Uh5Kn4mAKhR+B60K4Jsw==","signatures":[{"sig":"MEYCIQDSeXq5Ouh+3Nc5nG9jl9xJGchyUcUIBvLOcsXlvK2pLQIhANM+ECoLdPKRlhiK9lgqGuwSTn9gN3nWvY7aHl+co3qi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1980258},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"3d1c804064304c02536a823290283db1f607fdc3","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.19.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.20.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos/openapi-spec":"^0.80.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.13.0_1788973276314_0.9389696636724387","host":"s3://npm-registry-packages-npm-production"}},"0.13.1":{"name":"@workos/emulate","version":"0.13.1","keywords":["workos","emulator","authkit","sso","testing"],"author":{"name":"WorkOS"},"license":"MIT","_id":"@workos/emulate@0.13.1","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"homepage":"https://github.com/workos/emulate#readme","bugs":{"url":"https://github.com/workos/emulate/issues"},"bin":{"workos-emulate":"dist/cli.js"},"dist":{"shasum":"636ecabeb81c0ae86270b24267fcda865a6680e4","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.13.1.tgz","fileCount":216,"integrity":"sha512-5/wRpFQNMKvnp1+lwwOEZlXFGARKBMnJyGvPyD1PO28zIXGDgtITIWtNBhRtUHPPzs0tD6vhbhyr/NGhsyQuag==","signatures":[{"sig":"MEYCIQDfvmZVVmTecj+Hi32omWeQ+1zwAb6F8LIZ5hvxIpA7TAIhAIVdCm6mkhdMmKiQ6fVJNsRKbzy74LzHboOrEaK5qUGs","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCKvG96SfkQ5gapoypQZs5SjgHiILR26fRY0YHvh+OcyAIhAOrZ+pmJQTzR3MVFyolkDBcjlBP2b2lbop6YVlKhPUUZ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.13.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2018763},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"ef77d3131117a190ae76c1451060a4c397edc555","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.19.0","description":"Local WorkOS API emulator for tests and development","directories":{},"_nodeVersion":"24.20.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^2.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.3.14","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.62.0","oxlint":"^1.77.0","@types/bun":"^1.3.14","typescript":"^7.0.2","@types/node":"~22.19.7","@types/semver":"^7.7.1","@workos-inc/node":"^10.8.0","@workos/openapi-spec":"^0.80.0"},"_npmOperationalInternal":{"tmp":"tmp/emulate_0.13.1_1789485389404_0.768343278144838","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"_id":"@workos/emulate@0.14.0","bin":{"workos-emulate":"dist/cli.js"},"bugs":{"url":"https://github.com/workos/emulate/issues"},"dist":{"shasum":"e93525ba658e82d74e8baccab2db87f50503231f","tarball":"https://registry.npmjs.org/@workos/emulate/-/emulate-0.14.0.tgz","fileCount":219,"integrity":"sha512-Yh/S/6eqEq3Ul8QivVpi15Jh/rZy+fWt7kCf6w7TEnqhAc+Y7KSpB8dnaTMeQUxZLXDXogyL3C8XM21ghSrICA==","signatures":[{"sig":"MEQCIDeRr+Ark4nvc38xqjc7rTBawp+wOBV3S9s51k3is73AAiBczhLe+sRFk2qCsexIPurYi4E7gZ/SMbZhXc6r7fTCuA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGT6EKTC6ZD/T6bdgrCQ2a7fL+ttzbUKl2SbRLbCVbZJAiAEGK2nyyaDEZZ9AW0oFcy1m65j30igs8WNyIWJsSdDGQ=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@workos%2femulate@0.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2181762},"main":"./dist/index.js","name":"@workos/emulate","type":"module","types":"./dist/index.d.ts","author":{"name":"WorkOS"},"engines":{"node":">=22.11"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./core":{"types":"./dist/core/index.d.ts","import":"./dist/core/index.js"},"./workos":{"types":"./dist/workos/index.d.ts","import":"./dist/workos/index.js"}},"gitHead":"c63466f246b5060c766df4155676784543c7e171","license":"MIT","scripts":{"dev":"bun src/cli.ts","fmt":"oxfmt","lint":"oxlint","test":"bun test","build":"rm -rf ./dist && tsc && chmod +x ./dist/cli.js","clean":"rm -rf ./dist","start":"bun ./dist/cli.js","prepare":"husky","lint:fix":"oxlint --fix","fmt:check":"oxfmt --check","test:node":"bun run build && node scripts/smoke-node.mjs","typecheck":"tsc --noEmit && tsc -p tsconfig.tests.json","gen:events":"bun scripts/gen-events.ts","gen:routes":"bun scripts/gen-routes.ts","gen:shapes":"bun scripts/gen-shapes.ts","test:watch":"bun test --watch","build:binary":"bun build --compile --no-compile-autoload-dotenv --no-compile-autoload-bunfig ./src/cli.ts --outfile ./dist/workos-emulate","test:package":"bun run build && node scripts/check-package.mjs","gen:supported":"bun scripts/gen-supported.ts","test:coverage":"bun test --coverage","check:coverage":"bun scripts/check-coverage.ts"},"version":"0.14.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:07a230fb-fab6-4ed1-b5cf-0208f7ede636"}},"homepage":"https://github.com/workos/emulate#readme","keywords":["workos","emulator","authkit","sso","testing"],"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"_npmVersion":"11.19.0","description":"Local WorkOS API emulator for tests and development","directories":{},"maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"_nodeVersion":"24.21.0","dependencies":{"hono":"^4","yaml":"^2.8.2","chalk":"^5.6.2","semver":"^7.7.4","@hono/node-server":"^2.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"bun@1.4.2","devDependencies":{"husky":"^9.1.7","oxfmt":"^0.68.0","oxlint":"^1.77.0","@types/bun":"^1.4.2","typescript":"^7.0.2","@types/node":"~22.20.0","@types/semver":"^7.7.1","@workos-inc/node":"^10.8.0","@workos/openapi-spec":"^0.98.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/emulate_0.14.0_1790262840923_0.9991990419477068"}}},"time":{"created":"2026-05-29T20:51:39.333Z","modified":"2026-09-24T15:14:01.430Z","0.0.1":"2026-05-29T20:51:39.728Z","0.1.0":"2026-06-01T19:34:50.951Z","0.2.0":"2026-07-12T19:29:41.190Z","0.2.1":"2026-07-14T20:27:37.816Z","0.2.2":"2026-07-21T03:35:13.783Z","0.3.0":"2026-07-21T16:04:41.856Z","0.4.0":"2026-07-27T18:14:09.133Z","0.4.1":"2026-07-27T22:35:34.789Z","0.5.0":"2026-08-04T20:10:15.346Z","0.6.0":"2026-08-05T22:08:30.788Z","0.7.0":"2026-08-07T23:08:42.241Z","0.7.1":"2026-08-13T15:39:20.825Z","0.8.0":"2026-08-23T19:42:48.690Z","0.9.0":"2026-08-25T20:16:55.484Z","0.10.0":"2026-08-27T14:39:43.812Z","0.11.0":"2026-08-28T19:54:23.884Z","0.12.0":"2026-09-03T20:47:27.096Z","0.13.0":"2026-09-09T17:01:17.484Z","0.13.1":"2026-09-15T15:16:29.501Z","0.14.0":"2026-09-24T15:14:01.081Z"},"bugs":{"url":"https://github.com/workos/emulate/issues"},"author":{"name":"WorkOS"},"license":"MIT","homepage":"https://github.com/workos/emulate#readme","keywords":["workos","emulator","authkit","sso","testing"],"repository":{"url":"git+https://github.com/workos/emulate.git","type":"git"},"description":"Local WorkOS API emulator for tests and development","maintainers":[{"name":"gjtorikian","email":"gjtorikian@gmail.com"},{"name":"jch-workos","email":"jacob.card-howe@workos.com"},{"name":"mjdavidson","email":"matt@mattdavidson.kiwi"},{"name":"npm-workos","email":"service+npm@workos.com"},{"name":"peakematt-workos","email":"matt.peake@workos.com"},{"name":"jacobia","email":"jacobia@workos.com"},{"name":"mark-workos","email":"mark@workos.com"},{"name":"grinich","email":"mgrinich@gmail.com"},{"name":"nicknisi","email":"nick@nisi.org"}],"readme":"# WorkOS Emulate\n\nLocal WorkOS API emulator for tests and development.\n\n**[Which features are supported?](SUPPORTED.md)** — a per-feature matrix of endpoint coverage and\nhow data gets in, regenerated from the spec and the routes on every build.\n\n## Installation\n\n### Homebrew (macOS and Linux)\n\n```bash\nbrew install workos/tap/workos-emulate\n```\n\n### Direct binary download\n\nSelf-contained executables for supported macOS, Linux, and Windows targets are attached to each\n[GitHub release](https://github.com/workos/emulate/releases) — no Node, npm, or Bun required. Intel\nand x64 builds use Bun's baseline target for compatibility with older CPUs.\n\n```bash\n# macOS (Apple Silicon)\ncurl -fsSL -o workos-emulate https://github.com/workos/emulate/releases/latest/download/workos-emulate-darwin-arm64\nchmod +x workos-emulate\n\n# macOS (Intel)\ncurl -fsSL -o workos-emulate https://github.com/workos/emulate/releases/latest/download/workos-emulate-darwin-x64\nchmod +x workos-emulate\n\n# Linux with glibc (x64)\ncurl -fsSL -o workos-emulate https://github.com/workos/emulate/releases/latest/download/workos-emulate-linux-x64\nchmod +x workos-emulate\n\n# Linux with glibc (arm64)\ncurl -fsSL -o workos-emulate https://github.com/workos/emulate/releases/latest/download/workos-emulate-linux-arm64\nchmod +x workos-emulate\n\n# Alpine Linux / musl (x64)\ncurl -fsSL -o workos-emulate https://github.com/workos/emulate/releases/latest/download/workos-emulate-linux-x64-musl\nchmod +x workos-emulate\n\n# Alpine Linux / musl (arm64)\ncurl -fsSL -o workos-emulate https://github.com/workos/emulate/releases/latest/download/workos-emulate-linux-arm64-musl\nchmod +x workos-emulate\n```\n\nOn Windows, download `workos-emulate-windows-x64.exe` or `workos-emulate-windows-arm64.exe` from\nthe [latest release](https://github.com/workos/emulate/releases/latest) and run it directly (there\nis no Homebrew path for Windows).\n\nEach release also ships a `checksums.txt` with the SHA-256 of every binary.\n\n### npm\n\nFor JavaScript projects (or one-off runs via npx):\n\n```bash\nnpm install --save-dev @workos/emulate\n\n# or run without installing\nnpx @workos/emulate\n```\n\n### Docker\n\nA container image is published to the GitHub Container Registry with each release.\nStable releases are tagged `:latest` and `:<version>`; prereleases are tagged `:beta`\nand `:<version>`.\n\n```bash\ndocker run --rm -p 4100:4100 ghcr.io/workos/emulate\n```\n\nWith `docker-compose.yml`:\n\n```yaml\nservices:\n  workos-emulate:\n    image: ghcr.io/workos/emulate:latest\n    ports:\n      - '4100:4100'\n    # Mount a seed config file (optional)\n    volumes:\n      - ./workos-emulate.config.yaml:/app/workos-emulate.config.yaml:ro\n```\n\nThe image binds to `0.0.0.0` so the emulator is reachable from the host or other\ncontainers. The seed config is auto-detected from the working directory (`/app`);\nmount it at `/app/workos-emulate.config.yaml` (or `.yml` / `.json`).\n\n## CLI\n\n```bash\nworkos-emulate\nworkos-emulate --port 9100 --json\nworkos-emulate --seed workos-emulate.config.yaml\nworkos-emulate --interactive          # serve login pages for E2E browser testing\nworkos-emulate --interactive-password # ...and ask a user who has a password for it\nworkos-emulate --signing-key ci-key.pem --issuer https://api.workos.com  # stable JWKS and iss\nworkos-emulate --redirect-hosts app.example.test  # allow a non-localhost redirect_uri\nworkos-emulate --version\n```\n\nThe emulator defaults to `http://localhost:4100` and the API key `sk_test_default`.\nUse `GET /health` for readiness checks.\n\nIn an interactive terminal, the CLI checks for new stable releases without delaying startup. npm\ninstallations follow the npm registry; Homebrew and direct-download installations follow GitHub\nReleases after their checksums are available. Set `NO_UPDATE_NOTIFIER=1` or\n`WORKOS_EMULATE_DISABLE_UPDATE_CHECK=1` to disable the check. JSON output, CI, and non-interactive\ninvocations never perform it.\n\n## Using from Any Language\n\nThe emulator is a plain HTTP server, so any language can use it — just point your WorkOS SDK's base URL at the emulator instead of `https://api.workos.com`.\n\nStart the emulator in the background (or in a separate terminal):\n\n```bash\nworkos-emulate --port 4100 --seed workos-emulate.config.yaml\n```\n\n### Python\n\n```python\nimport workos\n\nworkos.api_key = \"sk_test_default\"\nworkos.base_url = \"http://localhost:4100\"  # ← emulator\n\n# Use the SDK as normal — requests hit the emulator\nuser = workos.client.user_management.create_user(email=\"alice@example.com\")\n\n# Add an error hook at runtime to test failure handling\nimport requests\n\nrequests.post(\"http://localhost:4100/_emulate/hooks\", json={\n    \"method\": \"POST\",\n    \"path\": \"/user_management/users\",\n    \"status\": 422,\n    \"body\": {\"message\": \"Validation failed\", \"code\": \"unprocessable_entity\"},\n})\n\n# Now this call returns a 422 — test your error handling\ntry:\n    workos.client.user_management.create_user(email=\"bob@example.com\")\nexcept Exception as e:\n    print(f\"Handled error: {e}\")\n```\n\n### PHP\n\n```php\nuse WorkOS\\WorkOS;\n\n$workos = new WorkOS('sk_test_default');\n$workos->setApiBaseUrl('http://localhost:4100'); // ← emulator\n\n// Use the SDK as normal\n$user = $workos->userManagement->createUser(['email' => 'alice@example.com']);\n\n// Add an error hook at runtime\n$ch = curl_init('http://localhost:4100/_emulate/hooks');\ncurl_setopt_array($ch, [\n    CURLOPT_POST => true,\n    CURLOPT_HTTPHEADER => ['Content-Type: application/json'],\n    CURLOPT_POSTFIELDS => json_encode([\n        'method' => 'POST',\n        'path' => '/user_management/users',\n        'status' => 500,\n    ]),\n    CURLOPT_RETURNTRANSFER => true,\n]);\ncurl_exec($ch);\ncurl_close($ch);\n\n// Now user creation returns a 500 — test your error handling\ntry {\n    $workos->userManagement->createUser(['email' => 'bob@example.com']);\n} catch (\\Exception $e) {\n    echo \"Handled error: \" . $e->getMessage();\n}\n```\n\nThe same pattern works for any language with a WorkOS SDK (Ruby, Go, Java, etc.) — override the base URL and use the `/_emulate/hooks` HTTP API to manage error hooks from your test setup.\n\n## Programmatic API (Node.js)\n\n```ts\nimport { createEmulator } from '@workos/emulate';\n\nconst emulator = await createEmulator({\n  port: 0,\n  seed: {\n    users: [{ email: 'test@example.com', password: 'secret' }],\n  },\n});\n\nconst res = await fetch(`${emulator.url}/user_management/users`, {\n  headers: { Authorization: `Bearer ${emulator.apiKey}` },\n});\n\nemulator.reset();\nawait emulator.close();\n```\n\n### ⚠️ Important: EventBus Reset Limitation\n\nThe `reset()` method clears all data and re-seeds from the original config, but **route-level authentication events will not work after reset**. This is because Hono's router cannot be modified after it's built, so the EventBus cannot be re-registered with the collection hooks.\n\nThis limitation is acceptable for test scenarios where `reset()` is primarily used to clean up state between tests, but it means:\n\n- After calling `reset()`, authentication events (`authentication.*_succeeded`, `authentication.*_failed`) will not be emitted\n- Resource lifecycle events (user.created, organization.created, etc.) will still work\n- If you need authentication events after reset, you must create a new emulator instance\n\n```ts\nconst emulator = await createEmulator({ port: 0 });\n\n// First run: authentication events work\nawait fetch(`${emulator.url}/user_management/authenticate`, {\n  method: 'POST',\n  headers: { 'Content-Type': 'application/json' },\n  body: JSON.stringify({ grant_type: 'password', email: 'test@example.com', password: 'secret' }),\n});\n// authentication.password_succeeded webhook is delivered\n\nemulator.reset();\n\n// Second run: authentication events DO NOT work\nawait fetch(`${emulator.url}/user_management/authenticate`, {\n  method: 'POST',\n  headers: { 'Content-Type': 'application/json' },\n  body: JSON.stringify({ grant_type: 'password', email: 'test@example.com', password: 'secret' }),\n});\n// NO authentication.password_succeeded webhook is delivered\n\n// Solution: create a new emulator instance if you need authentication events\nawait emulator.close();\nconst newEmulator = await createEmulator({ port: 0 });\n```\n\n## Seed Data\n\nCreate `workos-emulate.config.yaml` in the current directory or pass `--seed <path>`.\n\n```yaml\nusers:\n  - email: alice@acme.com\n    first_name: Alice\n    password: test123\n    email_verified: true\n\norganizations:\n  - name: Acme Corp\n    domains:\n      - domain: acme.com\n        state: verified\n    # Minted into the `entitlements` claim of access tokens scoped to this organization.\n    entitlements: [audit-logs, sso]\n\nroles:\n  - slug: admin\n    name: Admin\n    permissions: [posts:read, posts:write]\n  - slug: document-editor\n    name: Document Editor\n    permissions: [documents:read]\n    resource_type_slug: document # optional; defaults to organization\n\npermissions:\n  - slug: posts:read\n    name: Read Posts\n  - slug: posts:write\n    name: Write Posts\n  - slug: documents:read\n    name: Read Documents\n    resource_type_slug: document # optional; defaults to organization\n```\n\n### Pinning organization and user ids\n\nBoth `organizations` and `users` accept an optional `id`. Pin it to match what your real\nWorkOS environment emits, so a backend whose database already references a real org or user id\nlines up with the emulator — and stays stable across restarts, which otherwise mint a fresh id\neach time the seed re-runs. Omit it and an id is generated as before.\n\n```yaml\norganizations:\n  - id: org_01ABC... # optional; generated if omitted\n    name: Acme Corp\n\nusers:\n  - id: user_01XYZ... # optional; generated if omitted\n    email: alice@acme.com\n    password: test123\n```\n\nA pinned id must be a non-empty string, and ids must be unique within `organizations` and\nwithin `users` (a duplicate would silently overwrite the earlier record in the store). The\npinned id is what the API, login tokens, and webhooks report for that resource.\n\nFor OAuth-based logins (`authorization_code`, `refresh_token`, `device_code`), the authenticate\nresponse omits `authentication_method` by default: the hosted authorize flow carries no provider\ninformation, and the spec's `authentication_method` enum has no generic `OAuth` value — only\nprovider-specific ones like `GoogleOAuth`. Set `oauth_provider` on a seeded user to have the\nresponse report a concrete, spec-valid provider. (Password, Magic Auth, and SSO logins already\nreport their own method and need no configuration.)\n\n```yaml\nusers:\n  - email: alice@acme.com\n    oauth_provider: GoogleOAuth # reported as authentication_method for this user's OAuth logins\n    oauth_idp_id: 108872335 # the user's id at the provider; generated if omitted\n```\n\n### Linked OAuth identities\n\n`oauth_provider` also links an OAuth identity, so the user is reported by\n`GET /user_management/users/{id}/identities` — a bare array of `{idp_id, type, provider}`, which is\nwhat the SDKs' `getUserIdentities` deserializes:\n\n```json\n[{ \"idp_id\": \"108872335\", \"type\": \"OAuth\", \"provider\": \"GoogleOAuth\" }]\n```\n\nCompleting a login through an OAuth `connection` (`GoogleOAuth`, `MicrosoftOAuth`, `GitHubOAuth`,\n`AppleOAuth`) links one too, carrying the profile's `idp_id`. SAML connections do not: the spec's\nidentity `provider` enum is OAuth-only. A second login through the same provider is the same link,\nnot another one.\n\nA JWT template reads the same fact as `user.identities` — a provider→`idp_id` map, `null` for every\nprovider the user has not linked, so `{{ user.identities.GoogleOAuth }}` renders the id and an\nunlinked provider renders a claim the emulator drops.\n\n### Seeded MFA factors\n\nSet `totp: true` on a user to enroll a TOTP authentication factor at boot, exactly as\n`POST /user_management/users/{id}/auth_factors` would:\n\n```yaml\nusers:\n  - email: alice@acme.com\n    password: test123\n    email_verified: true\n    totp: true # enrolls a TOTP factor; password sign-ins answer with mfa_challenge\n```\n\nThe factor is reported by `GET /user_management/users/{id}/auth_factors`, and a password\nsign-in for the user returns the spec's `mfa_challenge` step (a `pending_authentication_token`\nplus an `authentication_challenge`) instead of a session, completed with the\n`urn:workos:oauth:grant-type:mfa-totp` grant — so MFA administration and step-up login flows\nneed no post-boot enrollment calls that in-memory state would lose on restart.\n\n### Pipes connected accounts\n\n`GET|POST|PUT|DELETE /user_management/users/{id}/connected_accounts/{slug}` serve a user's\n[connected accounts](https://workos.com/docs/reference/pipes/connected-account). Seed them\nwith `connectedAccounts`, referencing a user by email (the same join key memberships use)\nand, for an org-scoped connection, an organization by name:\n\n```yaml\nusers:\n  - email: alice@acme.com\norganizations:\n  - name: Acme Corp\nconnectedAccounts:\n  - email: alice@acme.com\n    provider: github # the slug requests address\n    scopes: [repo, user:email]\n  - email: alice@acme.com\n    provider: slack\n    organization: Acme Corp # scoped to that organization's id\n    state: needs_reauthorization # defaults to connected\n```\n\nAccounts are keyed by (user, provider, organization scope). `POST` imports an account from\nOAuth tokens under exactly that key — an omitted `state` is derived from the token combination\n(an expired access token with no refresh token is `needs_reauthorization`) — and answers `409`\nfor a duplicate. On every other verb `organization_id` is a filter, as in the API: omitted, a\nuser's lone account for the provider resolves whatever its scope, and several (one provider\ninstalled in two organizations) answer `409` until one is named. `DELETE` disconnects by\nremoving the account and its stored tokens, so a later import is a fresh `201`. State changes\nemit the spec's `pipes.connected_account.connected` / `reauthorization_needed` /\n`disconnected` events, including for seeded accounts.\n\n`POST /data-integrations/{slug}/token` (the SDK's `pipes.getAccessToken`) resolves the account\nthe same way and returns its access token with its scopes and expiry. Missing accounts return\n`not_installed`; accounts in `needs_reauthorization` return that. A `connected` account always\nyields a token: an imported one is returned verbatim while it is unexpired, and otherwise the\nemulator — which never contacts the real provider — mints a `di_mock_…` token in its place: an\nexpiring one when a refresh token was imported (the emulated refresh), a non-expiring one for\na seeded account, which is never given credentials. An expired token with no refresh token\nflips the account to `needs_reauthorization`, emitting its event, as a failed refresh would.\nThe emulator cannot see a provider revoke a grant, so to exercise a reauthorization flow, set\n`state: needs_reauthorization` on the account — on import, with `PUT`, or in the seed — and\nreconnect it with a `PUT` carrying the new token.\n\n### Machine-to-Machine (M2M) Applications\n\nSeed M2M Connect Applications so a service has a known `client_id` / client secret pair on\nstartup — ideal for `docker compose up` style local development where credentials must exist\nbefore any dashboard interaction.\n\n```yaml\norganizations:\n  - name: Acme Corp\n\nconnectApplications:\n  - name: Backend Service\n    type: m2m # default; use `oauth` for an OAuth app\n    organization: Acme Corp # required for m2m; owning org, by name\n    scopes: [posts:read, posts:write]\n    client_id: client_local_backend # optional; generated if omitted\n    client_secret: secret_local_backend # optional; generated if omitted\n    audience: https://api.acme.example # optional; the token `aud` claim, defaults to client_id\n\n  - name: Partner App\n    type: oauth\n    is_first_party: false # optional, oauth only; a third-party app needs `organization`\n    organization: Acme Corp\n    uses_pkce: true # optional, oauth only; reported on the app, not enforced\n```\n\nEach seeded application is provisioned with a client secret. Pin `client_secret` to bake a known\nvalue into a service's environment; otherwise one is generated. The application is then available\nthrough the full Connect Applications surface:\n\n| Method   | Path                                       | Notes                                                 |\n| -------- | ------------------------------------------ | ----------------------------------------------------- |\n| `GET`    | `/connect/applications`                    | Filters on `organization_id` and `registration_types` |\n| `POST`   | `/connect/applications`                    |                                                       |\n| `GET`    | `/connect/applications/:id`                | `:id` is the application ID **or** the client ID      |\n| `PUT`    | `/connect/applications/:id`                | `name`, `description`, `scopes`, `redirect_uris`      |\n| `DELETE` | `/connect/applications/:id`                | Cascades secrets and in-flight Connect logins         |\n| `GET`    | `/connect/applications/:id/client_secrets` | A bare array; never includes the plaintext            |\n| `POST`   | `/connect/applications/:id/client_secrets` | The one response carrying the plaintext, as `secret`  |\n| `DELETE` | `/connect/client_secrets/:id`              |                                                       |\n\n`registration_types` defaults to `authenticated`, as production does — nothing in the emulator\nperforms dynamic client registration, so an unfiltered list shows every application it can create.\nA secret's `last_used_at` is stamped when a token exchange actually succeeds, not merely when the\nsecret is presented.\n\n#### Token exchange (`client_credentials`)\n\nA service swaps its seeded `client_id` + `client_secret` for a scoped access token at\n`POST /oauth2/token`, exactly as in production:\n\n```bash\ncurl -s http://localhost:4100/oauth2/token \\\n  -H \"Content-Type: application/x-www-form-urlencoded\" \\\n  -d grant_type=client_credentials \\\n  -d client_id=client_local_backend \\\n  -d client_secret=secret_local_backend\n# (client credentials may also be sent via HTTP Basic auth)\n```\n\n```json\n{\n  \"access_token\": \"eyJ...\",\n  \"token_type\": \"Bearer\",\n  \"expires_in\": 3600,\n  \"scope\": \"posts:read posts:write\"\n}\n```\n\nThe `access_token` is an RS256 JWT signed with the same key the emulator publishes at\n`GET /sso/jwks/:client_id` (and `GET /oauth2/jwks`), so a consumer validating with JWKS — e.g.\n`jose` — verifies it with no emulator-specific shims. Its claims:\n\n| Claim    | Value                                                  |\n| -------- | ------------------------------------------------------ |\n| `iss`    | the emulator base URL (e.g. `http://localhost:4100`)   |\n| `aud`    | the app's `audience` if set, otherwise the `client_id` |\n| `sub`    | the requesting `client_id`                             |\n| `jti`    | a unique token identifier (ULID)                       |\n| `scope`  | granted scopes, space-delimited                        |\n| `org_id` | the application's owning organization                  |\n\nThe claim set mirrors a production M2M token, because the SDKs parse it: scopes are a\nspace-delimited `scope` **string** (not an array, and not `scp`), and `jti` is always present —\nthe WorkOS SDKs reject an M2M token that lacks it, however well-signed.\n\n> **Set `audience` on the seeded application.** In production `aud` is your environment's client\n> ID, which is _not_ the M2M application's `client_id` — and the SDKs default the expected\n> audience to the environment client ID. The emulator has no environment-level client ID to fall\n> back on, so it uses the requesting `client_id`. Pin `audience` to the value your real WorkOS\n> environment emits and a consumer that validates `aud` accepts emulator tokens unchanged.\n\nA request may narrow to a subset of the application's scopes via `-d scope=\"posts:read\"`;\nrequesting a scope the application does not have returns `400 invalid_scope`, so scope-based\nauthorization can be exercised locally. Unknown credentials return `401 invalid_client`, and an\n`oauth`-type application returns `400 unauthorized_client`.\n\n### Standalone Connect\n\nBridge your application's own login to Connect with an OAuth application and an emulator-only\n`connectApplications[].login_url` (the stand-in for the login page configured in the WorkOS dashboard):\n\n```yaml\nconnectApplications:\n  - name: Standalone App\n    type: oauth\n    client_id: client_local_standalone\n    client_secret: secret_local_standalone\n    login_url: http://localhost:3000/login\n    redirect_uris: [http://localhost:3000/callback]\n    scopes: [profile, email]\n```\n\n1. Send the browser to\n   `http://localhost:4100/oauth2/authorize?client_id=client_local_standalone&response_type=code&redirect_uri=http%3A%2F%2Flocalhost%3A3000%2Fcallback&state=my-state`.\n   The emulator redirects to `login_url` with a fresh `external_auth_id` valid for ten minutes.\n2. Authenticate the user in your application, then call from your backend:\n\n   ```bash\n   curl -s http://localhost:4100/authkit/oauth2/complete \\\n     -H \"Authorization: Bearer sk_test_default\" \\\n     -H \"Content-Type: application/json\" \\\n     -d '{\"external_auth_id\":\"ext_auth_FROM_LOGIN_URL\",\"user\":{\"id\":\"user_12345\",\"email\":\"marcelina.davis@example.com\"}}'\n   ```\n\n   This creates or updates the AuthKit user by `external_id = user.id`, marks their email verified,\n   emits `user.created` or `user.updated`, and returns `{\"redirect_uri\":\"...\"}`. Optional `name`,\n   `first_name`, `last_name`, and `metadata` update when supplied; omitted fields are preserved.\n\n3. Redirect the browser to that returned URL (`GET /oauth2/authorize/complete`). It is single-use\n   and redirects to the original client callback with `code` and the original `state`.\n4. Exchange the code at `POST /oauth2/token` with `grant_type=authorization_code`, `code`, the exact\n   original `redirect_uri`, `client_id`, and `client_secret` (form-encoded or JSON; Basic credentials\n   also work). Codes expire after ten minutes and are consumed on exchange. The response contains\n   an access token, `token_type`, `expires_in`, and `scope`. Its JWT `sub` is the AuthKit user ID;\n   `aud` is the application's `audience`, falling back to its `client_id`.\n\nReusing a completed ID returns `400 external_auth_session_already_completed`; unknown or expired IDs\nreturn `404 not_found`. Missing required fields return `422`, malformed email returns `400 invalid_email`,\nand an email owned by another user returns `400 email_not_available` (including on updates). A failed\nvalidation does not consume the session. Browser redemption of an incomplete or already redeemed ID\nreturns `404`.\n\n`login_url` can also be set on `POST /connect/applications`, but is not included in API application\nresponses. Both browser destinations must pass the emulator's redirect-host policy (localhost by\ndefault; configure `--redirect-hosts` for other hosts). When `redirect_uris` is non-empty, the callback\nmust also match an entry exactly.\n\n**Deliberate limitations:** no PKCE, refresh tokens, ID tokens, or consent UI. `user_consent_options`\nis ignored; the `email_change_not_allowed` policy is not modeled. The authorize request's `scope`\nis not tracked: tokens default to the application's configured scopes, optionally narrowed by `scope`\nat token exchange. The emulator's completion URL uses `/oauth2/authorize/complete?external_auth_id=...`,\nnot production's AuthKit-domain `/oauth/authorize/complete?state=...`; always follow the returned URL\nrather than constructing it. This is a local testing flow, not a replacement authentication service.\n\n### Client API tokens\n\n`POST /client/token` mints the short-lived token the Client GraphQL API expects, scoped to an\norganization and a user:\n\n```bash\ncurl -X POST http://localhost:4100/client/token \\\n  -H \"Authorization: Bearer sk_test_ci_key\" -H \"Content-Type: application/json\" \\\n  -d '{\"organization_id\":\"org_01K...\",\"user_id\":\"user_01K...\"}'\n```\n\nUnknown ids return `404`. The token is signed with the emulator key, so it verifies against\n`/sso/jwks`, and carries `sub`, `org_id`, and `aud: client` with a five-minute expiry. The spec\ndocuments only the `{ token }` response, so those claims are an emulator convention — and the\nemulator does not serve the Client GraphQL API itself, so nothing consumes the token.\n\n### API Keys\n\nSeed organization- or user-owned API keys. Each seeded key is created as an `api_key` resource\n**and** registered in the auth allow-list, so the value authenticates requests to the emulator.\n\n```yaml\norganizations:\n  - name: Acme Corp\n\napiKeys:\n  - name: CI Key\n    organization: Acme Corp # owner org, by name (or use `user_id`)\n    value: sk_test_ci_key # optional; must start with `sk_` and be unique; generated if omitted\n    permissions: [posts:read, posts:write]\n    # expires_at: 2030-01-01T00:00:00.000Z   # optional; never expires if omitted\n```\n\n```bash\n# The seeded value authenticates requests:\ncurl http://localhost:4100/connect/applications -H \"Authorization: Bearer sk_test_ci_key\"\n```\n\nValidate a key the way the SDKs do — `POST /api_keys/validations` with the key in `value`:\n\n```bash\ncurl -X POST http://localhost:4100/api_keys/validations \\\n  -H \"Authorization: Bearer sk_test_ci_key\" -H \"Content-Type: application/json\" \\\n  -d '{\"value\":\"sk_test_ci_key\"}'\n```\n\n```json\n{\n  \"api_key\": {\n    \"object\": \"api_key\",\n    \"id\": \"api_key_01K...\",\n    \"name\": \"CI Key\",\n    \"owner\": { \"type\": \"organization\", \"id\": \"org_01K...\" },\n    \"obfuscated_value\": \"sk_..._key\",\n    \"permissions\": [\"posts:read\", \"posts:write\"],\n    \"last_used_at\": null,\n    \"expires_at\": null,\n    \"created_at\": \"2026-01-15T12:00:00.000Z\",\n    \"updated_at\": \"2026-01-15T12:00:00.000Z\"\n  }\n}\n```\n\nA valid key returns the whole `api_key` object — `permissions` included, so permission-based\nauthorization can be exercised locally. An invalid, expired, or unknown key is `200` with\n`{\"api_key\": null}`, not an error — matching production and what the SDKs read. The raw value is\nnever echoed back; only `obfuscated_value`.\n\nThe `organization` (or the org supplied via `user_id`) must reference a seeded organization;\nan unresolved name fails fast at startup. A key seeded with an already-past `expires_at` is still\ncreated as a resource but does **not** authenticate, and deleting a key via `DELETE /api_keys/:id`\nstops it authenticating immediately — matching production.\n\n`apiKeys` also accepts the legacy auth allow-list map form (`{ sk_xxx: { environment } }`), which\nonly registers values for authentication without creating resources. A map-form value authenticates\nrequests but has no `api_key` resource behind it, so validating one returns `{\"api_key\": null}` —\nuse the array form for keys your code validates.\n\n### Directory Sync\n\nProduction connects a directory through the dashboard or Admin Portal — there is no\ncreate-directory endpoint — so the `directories` seed key is how one comes into existence at\nall. A directory joins its organization by name, the same way `connections` do, and its users\njoin the directory's own groups by name.\n\n```yaml\norganizations:\n  - name: Acme Corp\n\ndirectories:\n  - name: Acme Okta\n    organization: Acme Corp\n    type: okta scim v2.0\n    domain: acme.com\n    groups:\n      # Object form maps the group to an organization role, the way a directory's role\n      # assignments do in the dashboard. A bare string declares a group with no mapping.\n      - name: Admins\n        role: admin\n      - name: Engineering\n        role: member\n      - Contractors\n    users:\n      - email: dev@acme.com\n        first_name: Dev\n        last_name: Eloper\n        groups:\n          - Engineering\n```\n\nA user in several mapped groups takes the first in declaration order, the emulator's\nstand-in for the dashboard's role-assignment priority; a user's own `role` overrides the\nmapping. The resolved role is set on the directory user and, where `users` and\n`memberships` already put that person in the organization, on their organization\nmembership — which is what an app reads, and where production puts it too.\n\nA membership matching a seeded directory user reports `directory_managed: true`, whether or\nnot a role mapped. Where two directories in one organization map the same person, the first\nin declaration order keeps the role.\n\n`DELETE /directories/:id` clears `directory_managed` only once no directory in the\norganization still lists that person. While one does, the membership stays managed, and the\nfirst surviving directory that maps a role takes the role over. A membership no directory\never claimed is left alone, so an application-owned membership survives an unrelated\ndirectory being deleted.\n\nSeeding a directory creates no AuthKit user and no organization membership: seed `users`\nand `memberships` for those.\n\n`state` defaults to `linked` and `type` to `generic scim v2.0`. Seeding emits `dsync.activated`\nfor a `linked` directory, plus `dsync.group.created` and `dsync.user.created`, all queryable at\n`GET /events`. They are not delivered to a seeded webhook endpoint, which registers after them —\nas with every other seeded resource. `DELETE /directories/:id` emits `dsync.deleted`, which is\ndelivered.\n\n### Feature Flags\n\nProduction has no create-flag endpoint — flags are made in the dashboard — so the `featureFlags`\nseed key is how a flag comes into existence at all. Targets join to `users` by email and to\n`organizations` by name, the same way memberships do; an entry naming neither fails at startup.\n\n```yaml\nusers:\n  - email: alice@acme.com\n    password: test123\n    email_verified: true\n  - email: bob@acme.com\n    password: test123\n    email_verified: true\n\norganizations:\n  - name: Acme Corp\n    memberships:\n      - email: alice@acme.com\n      - email: bob@acme.com\n  - name: Other Inc\n\nfeatureFlags:\n  # On for everyone: nothing matches a target, so default_value decides.\n  - slug: new-billing\n    name: New Billing\n    default_value: true\n\n  # Off by default, on for exactly the listed targets.\n  - slug: beta-dashboard\n    name: Beta Dashboard\n    description: The rebuilt analytics dashboard\n    tags: [ui, beta]\n    owner:\n      email: jane@acme.com\n      first_name: Jane\n      last_name: Doe\n    targets:\n      users: [alice@acme.com]\n      organizations: [Acme Corp]\n\n  # Targeted at an organization Alice is not a member of.\n  - slug: partner-portal\n    targets:\n      organizations: [Other Inc]\n\n  # Built but not switched on in this environment: off for everyone, targets included.\n  - slug: unreleased\n    id: flag_01PINNEDUNRELEASED\n    enabled: false\n    default_value: true\n    targets:\n      users: [alice@acme.com]\n```\n\nSigning Alice in against that config gives `feature_flags: [\"new-billing\", \"beta-dashboard\"]`;\nBob gets `[\"new-billing\", \"beta-dashboard\"]` too via Acme Corp, but would lose `beta-dashboard`\nif the organization target were removed. `partner-portal` is off for both, and `unreleased` is\noff for everyone until something enables it.\n\nA flag is on for a resource when it is `enabled` **and** either a target names that resource or\n`default_value` is true. Targeting is additive, as it is in production: `POST\n/feature-flags/{slug}/targets/{resourceId}` carries no body, so a target can turn a flag on but\nnever off. Flags also accept an optional `id` to pin (`flag_01ABC…`). Slugs must be URL-safe, since\nevery route addresses a flag by slug in the path.\n\nThree surfaces read the result, and all three resolve through the same rule:\n\n- **The `feature_flags` access-token claim** — the slugs on for the signed-in user, re-resolved at\n  every mint (refresh grants included), so a toggle lands in the next token. Scoped to the\n  session's organization: a flag targeted at some _other_ org the user belongs to is not in the\n  claim. Omitted rather than minted as `[]` when nothing is on.\n- **The list endpoints an SDK polls** — `GET /user_management/users/{id}/feature-flags` and\n  `GET /organizations/{id}/feature-flags`. Both return a paginated list of whole `feature_flag`\n  objects, and both list only the flags that are on. The user endpoint includes flags from every\n  organization the user is an _active_ member of, as production documents — a `pending` or\n  `inactive` membership grants nothing, matching the status check `authenticate` applies before\n  scoping a session to an organization.\n\n```ts\nconst { data } = await workos.featureFlags.listUserFeatureFlags({ userId: user.id });\nconst enabled = new Set(data.map((flag) => flag.slug));\n// ...or the organization-scoped equivalent\nawait workos.featureFlags.listOrganizationFeatureFlags({ organizationId: org.id });\n```\n\n- **The SDK runtime client** — `workos.featureFlags.createRuntimeClient()` does not use either\n  list endpoint. It polls `GET /sdk/feature-flags`, which is **not in the WorkOS OpenAPI spec**;\n  the emulator implements it anyway, because without it the runtime client never leaves its\n  bootstrap state. The response is a bare slug-keyed map of every flag and its targets, and the\n  client evaluates locally, so `isEnabled` answers without a round trip:\n\n```ts\nconst flags = workos.featureFlags.createRuntimeClient({ pollingIntervalMs: 5_000 });\nawait flags.waitUntilReady();\nflags.isEnabled('beta-dashboard', { userId: user.id, organizationId: org.id });\nflags.on('change', ({ key, current }) => console.log(key, current));\n```\n\nAll three apply the same rule — a disabled flag is off for everyone; otherwise a matching enabled\ntarget wins; otherwise `default_value` — so for one resource they agree. They are scoped\ndifferently on purpose, and that is the one case where they legitimately differ: the token claim\ncovers the user plus the session's organization, while the user list endpoint covers the user plus\n_every_ organization they are an active member of. A user in two organizations can therefore have a flag in the\nlist endpoint that is absent from a token scoped to the other organization. Production scopes them\nthe same way.\n\nToggling at runtime works too. The verbs match the spec: `PUT /feature-flags/{slug}/enable` and\n`/disable`, `POST /feature-flags/{slug}/targets/{resourceId}` and its `DELETE`. The emulator also\naccepts `POST` on enable/disable and `PUT` on target creation, for callers written against its\nearlier shape — those aliases are **emulator-only**, and production rejects them, so do not rely\non them in code you intend to run against real WorkOS. Changes emit `flag.updated`; adding or\nremoving a target emits `flag.rule_updated`, carrying the flag's `access_type`, its configured\ntargets, and the previous rule state.\n\n`flag.rule_updated` names the API key that made the request as its `actor` when that key has a\nrecord behind it (an array-form `apiKeys` entry, or a key created over the API); a map-form key\nauthenticates but has no record, so the actor falls back to the emulator's placeholder key. The\ncollection-level `flag.created` / `flag.updated` / `flag.deleted` events run without request\ncontext and always report the placeholder. Flags are not environment-scoped, so every flag event\nreports `environment_test`. Deleting a user or organization removes its flag targets.\n\n### Agent Auth\n\nAgent blueprints, the tokens minted from them, and the resulting instances and sessions are all\nimplemented (`/agents/blueprints`, `/agents/instances`, `/agents/sessions`). Blueprints can be\ncreated over the API or seeded; instances and sessions only ever come into being by minting.\n`permissions` and `invocable_by.role_slugs` name seeded `permissions` and `roles` by slug, and\n`invocable_by.organizations` names `organizations` by name, the same join feature-flag targets use.\nA seeded blueprint is validated the way `POST /agents/blueprints` validates a body: `description`\nis a non-empty string or omitted, and `session_settings` is either omitted (production's 3600 /\n300 / 3600 second defaults) or given with all three values.\n\n```yaml\npermissions:\n  - slug: crm:read\n    name: Read CRM\n  - slug: email:send\n    name: Send email\n\nroles:\n  - slug: manager\n    name: Manager\n    permissions: [crm:read, email:send]\n  - slug: member\n    name: Member\n    permissions: [crm:read]\n\norganizations:\n  - name: Acme Corp\n    memberships:\n      - email: alice@acme.com\n        role: manager\n\nagentBlueprints:\n  - name: Prospecting Agent\n    description: Finds and qualifies sales prospects.\n    permissions: [crm:read, email:send]\n    invocable_by:\n      role_slugs: [manager]\n      organizations: [Acme Corp]\n    session_settings:\n      max_age_seconds: 3600\n      access_token_ttl_seconds: 300\n      refresh_token_ttl_seconds: 3600\n```\n\n`POST /agents/blueprints/{id}/tokens` accepts the four grant types production does:\n\n- **`user_delegated`** takes a user access token minted by the emulator (any `authenticate` or\n  `/oauth2/token` grant). The token only identifies the user and organization: the session behind\n  its `sid` must still be live, the user must be an active member of the organization, the\n  organization and the member's role must be allowed by `invocable_by`, and the login must be\n  younger than `max_age_seconds`. The granted permissions are the blueprint's `permissions`\n  intersected with what the member's role currently grants — recomputed at every mint and refresh,\n  so a role change lands in the next token.\n- **`autonomous`** takes an `organization_id` and grants the whole blueprint ceiling.\n- **`agent_delegated`** exchanges an agent access token for a new session on the same instance.\n  Chains are self-only (a token from another blueprint is `invalid_agent_access_token`), at most 32\n  deep, and anchored at the root: no hop may outlive the root session's `created_at +\nmax_age_seconds`.\n- **`refresh`** rotates the refresh token. Each is single-use, and a refresh never extends the\n  session past its chain root's max-age window.\n\nAccess tokens are RS256 JWTs signed with the emulator key and `typ: at+jwt`, so the same JWKS a\nbackend already uses for user tokens validates them. Claims follow production: `sub` is the agent\ninstance id, `sub_profile: ai_agent`, `sid` is the session id, plus `org_id`, `permissions`,\n`intent: { text }` when supplied, `act: { sub: <user id>, sub_profile: user }` for delegated\nsessions, and `auth_time` from the delegating login. `aud` is the `workos-emulate` placeholder,\nsince nothing at the API-key-authenticated token endpoint names a client.\n`POST .../tokens/validate` checks the signature, the session (revoked, expired, or torn down), and\nfor delegated chains that the backing user session is still live.\n\nRevoking a session (`POST /agents/sessions/{id}/revoke`, or revoking or logging out of the user\nsession it was delegated from) cascades to every session chained from it. Deleting an instance\nrevokes its live sessions first, and deleting a blueprint tears down its instances. The resources\nagents hang off cascade the same way: deleting an organization tears down every instance in it,\ndeleting a membership or its user tears down the instances delegated from it, deactivating a\nmembership revokes their sessions (the instance survives for a reactivation), and deleting a\npermission removes it from every blueprint ceiling that named it. Session `status` is derived at\nread time from `revoked_at` and `expires_at`; revoking touches only live sessions, so an\nalready-expired one stays `expired` with a null `revoked_at` while its live descendants are\nstill revoked. The seven `agent.*` events fire through the same webhook and `/events` plumbing\nas everything else.\n\nErrors use production's stable codes: `invalid_request` (400) for a malformed body;\n`permission_not_found`, `role_not_found`, `organization_not_found` (422) and `name_already_in_use`\n(409) on blueprint create and update; and at mint time `invalid_user_access_token`,\n`invalid_agent_access_token`, `invalid_refresh_token`, `session_revoked`, `session_expired`,\n`user_session_ended`, `max_age_exceeded`, `chain_depth_exceeded` (400) and\n`user_not_member_of_organization`, `organization_not_invocable`, `role_not_invocable` (403).\n\nAgent Registration (`/agents/registrations`, claim attempts, credential validation) is not\nimplemented.\n\n## Widgets\n\n`POST /widgets/token` mints the session token the `@workos-inc/widgets` components authenticate\nwith, as the SDKs' `widgets.getToken()` calls it. The requested scopes are minted under the\n`permissions` claim and the token expires in an hour — the two claims the widget client reads to\ndecide whether it may render and when to refresh.\n\nThe components never call the public REST API; they call a private `/_widgets/*` surface. The\nemulator serves the routes the org-scope `<ApiKeys>` widget uses, as a translation layer over the\nsame store the public API-key routes use — so a key created in the widget authenticates requests,\nand a key created through `POST /organizations/{id}/api_keys` (or seeded) shows up in the widget:\n\n| Method   | Path                                      |\n| -------- | ----------------------------------------- |\n| `GET`    | `/_widgets/ApiKeys/organization-api-keys` |\n| `POST`   | `/_widgets/ApiKeys/organization-api-keys` |\n| `DELETE` | `/_widgets/ApiKeys/{apiKeyId}`            |\n| `POST`   | `/_widgets/ApiKeys/{apiKeyId}/expire`     |\n| `GET`    | `/_widgets/ApiKeys/permissions`           |\n\nPoint the widgets provider at the emulator and hand it a token minted with the\n`widgets:api-keys:manage` scope:\n\n```tsx\n<WorkOsWidgets apiHostname=\"localhost\" port={4100} https={false}>\n  <ApiKeys authToken={token} />\n</WorkOsWidgets>\n```\n\n`/_widgets/*` requests authenticate with the widget token, not an API key, and the organization is\nthe token's `org_id`: keys are only ever listed, created, revoked, or expired within it, and another\norganization's key is a `404`. A missing, expired, or otherwise invalid token — or one minted\nwithout the widget's scope — is a `403`, the status the widget client treats as a token problem: it\nrefetches the token once, then renders its expired-session or incorrect-permissions state.\n`GET /_widgets/ApiKeys/permissions` serves the environment's permissions (seeded, or created via\n`POST /authorization/permissions`), which is what fills the create dialog's checklist.\n\nNot implemented yet: the `scope=\"user\"` variant (`/_widgets/UserApiKeys/*`) and the other widgets'\n`/_widgets/*` routes.\n\n## Testing Your Login Flow End-to-End\n\nThe emulator implements the full [workos.com/docs](https://workos.com/docs) login story: every resource creation and authentication outcome fires a signed webhook, with event names and payload shapes generated from the WorkOS OpenAPI spec. You can run your app's entire login flow — hosted authorize, callback, token exchange, webhook handling — against the emulator without touching the real API.\n\n### 1. Register a webhook endpoint\n\nSeed it (an empty `events` list subscribes to everything):\n\n```yaml\nwebhookEndpoints:\n  - endpoint_url: http://localhost:5005/webhooks\n    secret: whsec_test # optional; generated if omitted\n    events: []\n```\n\nPin `secret` when your consumer verifies signatures: the API masks an endpoint's secret after\ncreation, so a generated one can't be recovered for the consumer's environment.\n\nOr register at runtime:\n\n```bash\ncurl -X POST http://localhost:4100/webhook_endpoints \\\n  -H \"Authorization: Bearer sk_test_default\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"endpoint_url\":\"http://localhost:5005/webhooks\",\"secret\":\"whsec_test\",\"events\":[]}'\n```\n\n### 2. Walk the login flow\n\nPoint your SDK's base URL at the emulator and follow the AuthKit quickstart exactly as documented:\n\n1. **Create a user** — `POST /user_management/users` → a `user.created` webhook arrives.\n2. **Redirect to AuthKit** — send the browser to `GET /user_management/authorize?redirect_uri=...&state=...`. By default the emulator immediately redirects back to your callback with a `code`; with `--interactive` it serves a real login page first.\n3. **Exchange the code** — your callback calls `POST /user_management/authenticate` with `grant_type=authorization_code`. You get back the user, `access_token`, and `refresh_token` — and `session.created` plus `authentication.oauth_succeeded` webhooks arrive (`authentication.password_succeeded` instead, when the [interactive password page](#requiring-a-password) checked the login, or the event of the gate that page cleared last).\n4. **Other methods work the same way** — password, Magic Auth, email verification, MFA, and SSO logins all emit their spec-named `authentication.*_succeeded` events; failed attempts emit `authentication.*_failed` with an `error: { code, message }` object.\n\nCodes that WorkOS would deliver by email are delivered to you in the webhook payload instead: `magic_auth.created` carries the Magic Auth `code`, `password_reset.created` carries the reset `password_reset_token` (and the `password_reset_url` built around it), and `email_verification.created` carries the verification `code`. Your test can drive the whole flow from webhooks alone — see `src/e2e.spec.ts` for a complete worked example.\n\n### 3. Verify signatures\n\nWebhooks are signed exactly like production WorkOS: `WorkOS-Signature: t=<timestamp>, v1=<hmac>` where the HMAC-SHA256 is computed over `\"{timestamp}.{body}\"` with the endpoint's secret. The official SDKs' `webhooks.constructEvent` verifies them unchanged.\n\n### Organization-scoped sessions\n\nEvery fresh login resolves an organization the way production does, so tokens carry the claims your authorization code reads:\n\n- **One active membership** — selected implicitly. The response returns `organization_id` and the access token carries `org_id`, `role`, `roles`, and `permissions`.\n- **No memberships** — `organization_id` is `null` and the token carries no `org_id`. Nothing is invented.\n- **Several active memberships** — a `403` asking the client to choose, exactly as WorkOS does:\n\n```json\n{\n  \"code\": \"organization_selection_required\",\n  \"message\": \"The user must choose an organization to finish their authentication.\",\n  \"pending_authentication_token\": \"pending_...\",\n  \"organizations\": [\n    { \"id\": \"org_...\", \"name\": \"Alpha Corp\" },\n    { \"id\": \"org_...\", \"name\": \"Beta Corp\" }\n  ],\n  \"user\": { \"object\": \"user\", \"id\": \"user_...\", \"email\": \"member@example.com\" }\n}\n```\n\nFinish the sign-in by exchanging that token for a session scoped to the chosen organization — the emulator rejects an organization the user is not an active member of with `organization_membership_not_found`:\n\n```bash\ncurl -X POST http://localhost:4100/user_management/authenticate \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"grant_type\":\"urn:workos:oauth:grant-type:organization-selection\",\"pending_authentication_token\":\"pending_...\",\"organization_id\":\"org_...\"}'\n```\n\nOnly `active` memberships count — an unaccepted invitation or a deactivated member is never selected. Passing `invitation_token` to the `authorization_code`, `password`, or Magic Auth grants accepts the invitation as part of the login, joining the user to the invited organization and scoping the session to it, so there is no selection step; a token that is unknown, expired, or already used is rejected with `invitation_invalid`, and one addressed to somebody else with `invitation_cannot_be_used_for_email`. Once a session exists, only an explicit `organization_id` on a refresh (`switchToOrganization`) moves it between organizations.\n\n### Email verification gates the password grant\n\nA password sign-in by a user whose `email_verified` is `false` does not return a session. Production answers `email_verification_required`, and that response is what sends the user to a verification screen — so the emulator does too:\n\n```json\n{\n  \"code\": \"email_verification_required\",\n  \"message\": \"Email ownership must be verified before authentication.\",\n  \"pending_authentication_token\": \"pending_...\",\n  \"email_verification_id\": \"email_verification_...\",\n  \"email\": \"bob@example.com\"\n}\n```\n\nThe gate creates an email verification, so the code arrives on the `email_verification.created` webhook like every other emailed code. Finish the sign-in with the token and the code — exactly what the SDKs' `authenticateWithEmailVerification` sends:\n\n```bash\ncurl -X POST http://localhost:4100/user_management/authenticate \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"grant_type\":\"urn:workos:oauth:grant-type:email-verification:code\",\"pending_authentication_token\":\"pending_...\",\"code\":\"123456\"}'\n```\n\nThe resulting session records the method that was gated (`password`), not the verification step. Driving the grant with `user_id` instead of a pending token still works, and that session reports `unknown` — there is no primary method to recover. Fixtures that sign in with a password want `email_verified: true`, in a seed file or on `POST /user_management/users`.\n\n### SSO logins produce a session\n\nA code from `GET /sso/authorize` redeems at `POST /user_management/authenticate` with `grant_type=authorization_code`, so an app that sends people straight to their IdP with `sso.getAuthorizationUrl` and finishes at AuthKit's callback gets a real session — one whose `auth_method` is `sso`, so authorization code that hides password management for federated users can be exercised. `POST /sso/token` still redeems the same code for a bare profile and access token, which is the standalone SSO product and creates no session; a code is spent by whichever endpoint gets it first.\n\nThe session is scoped to the connection's organization. A profile with no user-management account yet gets one, verified — the IdP asserted the address — the way AuthKit provisions on a first SSO login.\n\nAs with `/user_management/authorize`, `/sso/authorize` is public and signs in whoever `login_hint` names: there is no IdP here to prove an identity with, and inventing a profile for any address is what lets a test drive an SSO login at all. Both endpoints will therefore hand out a session for any account you ask them for. That is the emulator being a test double, not an authorization server — do not point anything at it that you would not also let sign in as your users.\n\n### Refresh tokens always rotate\n\nThe emulator issues a new refresh token on every refresh and invalidates the one you presented, so replaying it returns `{\"error\": \"invalid_grant\", \"error_description\": \"Invalid refresh token.\"}`. WorkOS documents that refresh tokens _may_ be rotated after use, so production is free to hand back the same token and leave it valid. The emulator always takes the stricter path: a client that forgets to store the newly returned `refresh_token` fails locally instead of in production.\n\n### Authentication failure shapes\n\n`POST /user_management/authenticate` does not use one error shape for every failure. Which shape you get depends on the failure, not only on the grant: any malformed request is OAuth-shaped, and among credential failures three grants are OAuth-shaped and the rest plain.\n\n| Failure                                                          | Body                                                                  | Node SDK raises           |\n| ---------------------------------------------------------------- | --------------------------------------------------------------------- | ------------------------- |\n| Malformed request — missing or unrecognized parameter, any grant | `{\"error\": \"invalid_request\", \"error_description\": \"…\"}`              | `OauthException`          |\n| `authorization_code` — unknown, expired, bad verifier, user gone | `{\"error\": \"invalid_grant\", \"error_description\": \"…\"}`                | `OauthException`          |\n| `refresh_token` — unknown, expired, rotated, or user deleted     | `{\"error\": \"invalid_grant\", \"error_description\": \"…\"}`                | `OauthException`          |\n| Device code — pending, expired, unknown, or user deleted         | `{\"error\": \"authorization_pending\\|expired_token\\|invalid_grant\", …}` | `OauthException`          |\n| `password` — wrong password                                      | `{\"code\": \"invalid_credentials\", \"message\": \"…\"}` (400)               | `GenericServerException`  |\n| Magic Auth — wrong or expired code                               | `{\"code\": \"invalid_one_time_code\\|one_time_code_expired\", …}`         | `GenericServerException`  |\n| Step-up (MFA, org selection, email verification)                 | `{\"code\": \"…\", \"message\": \"…\"}` (403)                                 | `AuthenticationException` |\n\n`password` is an RFC 6749 grant, but production fails its credentials with the plain shape, so the emulator does too — while a `password` request that omits a parameter still answers `invalid_request` OAuth-style. Both halves come from the spec, whose authenticate 400 lists `invalid_request` and `invalid_grant` only as `{error, error_description}` and `invalid_credentials` and the one-time-code errors only as `{code, message}`. An unrecognized `grant_type` is reported as `invalid_request` rather than `unsupported_grant_type`, which the spec gives to `/sso/token` alone.\n\n`/sso/token` is OAuth-shaped throughout, matching its spec definition.\n\n### Magic Auth doubles as sign-up\n\n`POST /user_management/magic_auth` creates the user when the email has none, so a sign-up flow needs no separate `POST /user_management/users` first. Production does the same at code-creation time rather than at authenticate: the 201 already carries a `user_id`, the user is immediately listable with `email_verified: false`, and the email it sends uses the \"Sign up\" template.\n\nRedeeming a Magic Auth code sets `email_verified` to `true`, matching the live authenticate response for the same flow. This applies to **any** user who was not already verified, not only ones the endpoint just created, so a fixture seeded `email_verified: false` comes back verified after its first Magic Auth login.\n\nAn email is resolved case-insensitively (`User@x.test` and `user@x.test` are the same account, stored under whichever case created it), and one that could only be a typo is rejected rather than turned into an account nothing can reach. `POST /user_management/users` applies both — so it answers 409 for an address that differs from an existing one only in case, rather than creating a second account no lookup can tell apart from the first.\n\nEvery lookup by email is case-insensitive, not just Magic Auth's, so an account created by a Magic Auth sign-up is reachable by whatever casing the caller has: the password grant, `login_hint` on the authorize endpoints, `POST /user_management/password_reset`, the `email` filter on `GET /user_management/users` and `GET /user_management/invitations`, accepting an invitation, the `user_id` on SSO authentication events, the profile `/sso/authorize` resolves from a `login_hint`, and the email a seeded organization membership joins its user by. Seeded `users` are held to the same uniqueness the API enforces — two entries differing only in case are a config error, since a seed was otherwise the one way left to produce the pair of accounts no lookup can tell apart.\n\nA field named `email` must be a string wherever it is accepted. A number or object is a `400` (`422` on `POST /user_management/users` and `POST /user_management/invitations`, which keep those routes' validation shape) naming the type, distinct from the `email is required` reported for one that is genuinely absent — which includes an explicit `null`, since that is how a JSON body spells absence. Addresses are trimmed before they are stored or compared, so a padded copy of an address finds the account written under it.\n\nThe typo guard applies wherever an address is written rather than looked up: both routes that create users, `POST /user_management/invitations` (acceptance resolves the recipient by email, so a typo is an invitation that is spent without enrolling anyone), and seeded `users`, `invitations`, and organization `memberships`. Read paths are left alone — an address that resolves to nothing is still a `404` you can act on, not a validation error.\n\n### Emitted events\n\nAuthentication events carry the spec payload `{ type, status, user_id, email, ip_address, user_agent }` (plus `error` on failures and `sso` details on SSO events).\n\n| Trigger                                | Events                                                                                                   |\n| -------------------------------------- | -------------------------------------------------------------------------------------------------------- |\n| Login success (per method)             | `authentication.{oauth,password,magic_auth,email_verification,mfa,sso}_succeeded`                        |\n| Login failure (bad/expired credential) | `authentication.{oauth,password,magic_auth,email_verification,mfa,sso}_failed`                           |\n| Sessions                               | `session.created`, `session.revoked`                                                                     |\n| Users                                  | `user.created`, `user.updated`, `user.deleted`                                                           |\n| Login-flow resources                   | `magic_auth.created`, `email_verification.created`, `password_reset.created`, `password_reset.succeeded` |\n| Organizations & domains                | `organization.*`, `organization_domain.*` (incl. `organization_domain.verified`)                         |\n| Memberships & invitations              | `organization_membership.*`, `invitation.{created,accepted,revoked,resent}`                              |\n| Connections                            | `connection.activated`, `connection.deactivated`, `connection.deleted`                                   |\n| Directory Sync                         | `dsync.activated`, `dsync.deleted`, `dsync.user.*`, `dsync.group.*`                                      |\n| Roles & permissions                    | `role.*`, `organization_role.*`, `permission.*`                                                          |\n| API keys & feature flags               | `api_key.{created,updated,revoked}`, `flag.{created,updated,deleted}`                                    |\n\nThe full catalog (including names the emulator never emits, like `authentication.passkey_*` and `vault.*`) lives in `src/workos/generated/events.ts`, generated from the [`@workos/openapi-spec`](https://www.npmjs.com/package/@workos/openapi-spec) package.\n\nAll events are also queryable at `GET /events` (filter with `?events[]=user.created`, or repeated `?events=`, which is what the Go SDK sends).\n\n### Caveats\n\n- Delivery is fire-and-forget with a 5-second timeout and no retries — poll your receiver in tests rather than asserting immediately.\n- Resources defined in a seed file record events (visible at `GET /events`) but are not delivered to webhook endpoints from the same seed file — endpoints are registered last, mirroring real WorkOS, where pre-existing data never replays. Register endpoints via the API if you want deliveries for setup data.\n- Seeding a directory user into a group emits `dsync.group.user_added`. Removing that membership emits `dsync.group.user_removed`. There is still no HTTP route to mutate a directory; production connects one in the dashboard.\n\n## JWT Templates (custom claims)\n\nA JWT template adds your own claims to every access token the emulator mints, so authorization\ncode that reads a custom claim runs against the emulator unchanged. Seed it to have the claims\npresent from the first sign-in, with no setup call:\n\n```yaml\njwtTemplate:\n  content: >-\n    {\"urn:myapp:name\": \"{{ user.first_name }} {{ user.last_name }}\",\n     \"urn:myapp:tenant\": \"{{ organization.metadata.tenant_id }}\",\n     \"urn:myapp:role\": \"{{ organization_membership.role }}\"}\n```\n\nOr set it at runtime, matching the WorkOS API — `content` is a template string that renders to a\nJSON object:\n\n```bash\ncurl -X PUT http://localhost:4100/user_management/jwt_template \\\n  -H \"Authorization: Bearer sk_test_default\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"content\": \"{\\\"urn:myapp:tenant\\\": \\\"{{ organization.metadata.tenant_id }}\\\"}\"}'\n```\n\nEither way the rendered claims land in the token:\n\n```json\n{\n  \"sub\": \"user_01...\",\n  \"org_id\": \"org_01...\",\n  \"role\": \"admin\",\n  \"urn:myapp:name\": \"Alice Smith\",\n  \"urn:myapp:tenant\": \"tenant_123\"\n}\n```\n\n### Template syntax\n\nWorkOS uses a small interpolation syntax, not full Liquid. The emulator implements that subset:\n\n| Form                                    | Meaning                                                |\n| --------------------------------------- | ------------------------------------------------------ |\n| `{{ user.email }}`                      | Interpolate a value by dotted path                     |\n| `{{ user.nickname \\|\\| user.email }}`   | Fallback chain; the first non-null value wins          |\n| `{{ user.nickname \\|\\| 'anonymous' }}`  | Single-quoted literal as the last resort               |\n| `\"{{ user.first_name }} {{ user.id }}\"` | Concatenation inside a JSON string; null becomes `\"\"`  |\n| `{\"meta\": {{ user.metadata }}}`         | A whole object or array, interpolated outside a string |\n| `organization.domains.0.domain`         | Array index as a path segment                          |\n\nFilters, conditionals, and loops are not part of the syntax and are not supported.\n\nAvailable variables are `user.*`, `organization.*`, and `organization_membership.*`. `organization`\nand `organization_membership` are only populated for an org-scoped session; in a session with no\norganization they resolve to null, so use a fallback if a claim must always be present.\n\nTemplates apply to AuthKit session tokens — every grant on `POST /user_management/authenticate`,\nincluding `refresh_token`, so claims survive a refresh. They do not apply to M2M\n(`client_credentials`) tokens, widget tokens, or the profile-based `POST /sso/token`, none of which\nresolve a user and membership to render against.\n\n### What is rejected\n\nTemplates are validated when set — over the API, and at startup for a seeded one, so a bad template\nfails the boot rather than the first sign-in. `--validate-config` checks it too.\n\n- **Reserved claims.** A template may not set `iss`, `sub`, `exp`, `iat`, `nbf`, or `jti`. Note that\n  `aud`, `sid`, `org_id`, `role`, `roles`, and `permissions` are _not_ reserved: a template may\n  deliberately override those, and the rendered value wins over what the emulator resolved.\n- **Unknown variables.** An unrecognized root (`{{ usr.email }}`) is a typo and is rejected. A path\n  _below_ a known root that the emulator does not model resolves to null instead — including\n  `organization.allow_profiles_outside_organization` and\n  `organization_membership.custom_attributes`, which the emulator has no data for and will not\n  invent.\n- **Anything that is not a JSON object** with at least one key.\n\nWorkOS caps rendered claims at 3072 bytes, because the session cookie carrying them has to fit in a\nbrowser. That depends on the data, so it is enforced when the token is signed: a template that\nrenders too large fails the authenticate call with a 422 naming the size, rather than quietly\nhanding back a token missing its claims. Nothing is persisted when that happens — no session, no\nrefresh token, no bumped `last_sign_in_at` — with one exception: a login that passed\n`invitation_token` has already consumed the invitation by then, and the membership it created\nstands. Retrying with the same token returns `invitation_invalid`, so fix the template and re-seed\nrather than replaying the login.\n\n> Earlier versions accepted a `custom_claims` object on this endpoint and stored it without ever\n> putting it in a token. That field is gone; `content` is what works. Sending `custom_claims` now\n> returns a 422 pointing at `content`.\n\n## Stable Signing Key and Issuer\n\nBy default the emulator generates an RSA keypair at startup and builds `iss` from its own URL. That\nis fine for a single run, but it means a restart invalidates every token already issued and changes\nthe published JWKS — and the issuer moves with the port.\n\nPin either or both to make tokens outlive a restart:\n\n```bash\n# Generate a key once and keep it with your test fixtures\nopenssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out ci-key.pem\n\nworkos-emulate \\\n  --signing-key ci-key.pem \\\n  --kid ci_key \\\n  --issuer https://api.workos.com\n```\n\nEach flag has an environment equivalent — `WORKOS_EMULATE_SIGNING_KEY`, `WORKOS_EMULATE_KID`,\n`WORKOS_EMULATE_ISSUER` — so a compose file can set them once. Flags win over the environment.\n\nProgrammatically:\n\n```ts\nconst emulator = await createEmulator({\n  signingKey: { privateKey: readFileSync('ci-key.pem', 'utf-8'), kid: 'ci_key' },\n  issuer: 'https://api.workos.com',\n});\n```\n\nWhat this buys you:\n\n- **JWKS stable across restarts.** `/sso/jwks/:client_id` publishes the same key every boot, so a\n  token minted before a restart still verifies after it. Without a pinned key, a verifier that\n  cached the JWKS must refetch.\n- **A constant `iss`.** A verifier comparing `iss` against a hardcoded string needs no test-only\n  branch. It must still fetch JWKS from the emulator — pinning the issuer does not make WorkOS's\n  real keys apply.\n- **One key across several emulators**, or tokens pre-signed offline with the same key the emulator\n  verifies.\n\n`--issuer` is the base the client id hangs off, not the whole claim. An AuthKit access token from\n`/user_management/authenticate` carries `iss` of `{issuer}/user_management/{client_id}`, which is\nwhat production mints — so `--issuer https://api.workos.com` with a client of `client_123` gives\n`https://api.workos.com/user_management/client_123`. The M2M, SSO and widget tokens carry","readmeFilename":"README.md"}