npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@0xdivyanshh/tab-sdk

v0.1.1

Published

Client for the Tab gateway: agent credit on Hedera. Ten verbs, two of which spend.

Readme

@0xdivyanshh/tab-sdk

Tier 3 · PUBLISHED to npm · thin HTTP client · browser-safe

The TypeScript client every other surface is built on: agentkit-plugin, mcp, cli, dashboard, and both demo agents.

Thin on purpose

boundaries.json forbids @hiero-ledger/sdk, ioredis and drizzle-orm here. This package speaks HTTP to the gateway and nothing else.

That constraint carries the product claim. The agent holds no key and signs nothing — so the library it installs should not even be able to sign. If the SDK bundled the Hedera SDK, the claim would rest on us not having used it. This way it rests on a check anyone can run.

Browser-safe matters too: apps/web imports this, and a browser bundle must not be able to reach a signing path or a database driver.

Surface

spend · quote · balance · ceiling · receipts · register

The same five verbs appear in the Agent Kit plugin and the MCP server. Define them once here.

Contents

| File | Holds | |---|---| | src/client.ts | constructor, auth, retry, timeouts | | src/spend.ts | the spend call, including the refusal shape | | src/quote.ts | pre-flight quote without reserving | | src/state.ts | balance, ceiling, available, pending holds, window countdown | | src/receipts.ts | receipt history and the SSE stream the dashboard consumes | | src/errors.ts | typed errors — refusal, unavailable, invalid | | src/types.ts | re-exported from @0xdivyanshh/tab-protocol. One definition, not two |

Invariants

  • A refusal is a value, not an exception. spend() returns a discriminated result carrying the rule that fired. Throwing on refusal pushes every consumer into try/catch and makes the Refusals view harder to build — and refusal is the demo, so it deserves a first-class type. Throw only for transport and protocol failures.
  • Amounts cross the wire as decimal strings, parsed to MicroUsdc on the way in. bigint does not survive JSON.stringify.
  • Types are re-exported from @0xdivyanshh/tab-protocol, never redefined. A second copy will drift.
  • Retries are safe. spend carries an idempotency key so a network retry cannot double-spend.
  • No key material in the constructor. If the SDK ever accepts a private key, the whole claim is gone.

Publishing

Versioned with changesets. Once an agent depends on this, breaking changes cost someone a redeploy — so treat exports as a contract from the first release.