npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@1ecomm/app-bridge

v0.2.0

Published

Framework-agnostic client SDK a 1ecomm app imports to talk to the platform host (App Bridge protocol): signed context, session tokens, scope-enforced API access, resize/toast/modal/navigate.

Readme

@1ecomm/app-bridge

The client SDK for building embedded apps on the 1ecomm commerce platform. It runs inside your app's sandboxed iframe and speaks a versioned, origin-validated postMessage protocol to the platform host, which holds your signed installation context and proxies scope-enforced API calls.

Zero dependencies, framework-agnostic, ~2 kB. Works with any stack that renders a page — React, Angular, Vue, or plain HTML.

Install

npm install @1ecomm/app-bridge

Quickstart

import { createAppBridge } from '@1ecomm/app-bridge';

const bridge = createAppBridge({ hostOrigin: 'https://developer.1ecomm.com' });

// Signed context: who installed you, where you're mounted, what you're granted.
const ctx = await bridge.getContext(); // { installationId, appId, siteId, accountId, userId, surfaceKey, grantedScopes, locale? }

// Scope-enforced platform data — the host attaches your session token.
const products = await bridge.apiFetch('/products', { query: { limit: '20' } });

// Writes take a JSON body.
await bridge.apiFetch(`/products/${id}/metafields/myapp/rating`, {
  method: 'PUT',
  body: { value: 5 },
});

// Host UI affordances.
bridge.resize(document.body.scrollHeight); // keep the iframe fitted
bridge.toast('Saved');
await bridge.modal({ title: 'Delete?', message: 'This cannot be undone.', variant: 'danger' });
bridge.navigate('/studio/apps'); // in-app host paths only

How it works

  • Handshake. The SDK announces ready; the host answers with your signed AppBridgeContext. getContext() resolves then (or immediately once received).
  • Origin validation. Every inbound message is checked against hostOrigin and the protocol channel/version; anything else is dropped.
  • Nonce-matched requests. Every call is a promise matched to a host response by request id, with a timeout (timeoutMs, default 10 s).
  • Scopes are server-enforced. apiFetch is proxied with your installation's session token; calls outside your granted scopes return a 403 naming the missing scope. Never store platform cookies or tokens yourself — the bridge is the only credential path you need.
  • Cleanup. Call destroy() when your surface unmounts to detach the listener and reject in-flight requests.

API

| Member | Purpose | | --- | --- | | createAppBridge(options) | Create a bridge. hostOrigin is required; window/host/generateId are injectable for tests. | | bridge.getContext() | Resolves with the signed AppBridgeContext after the host handshake. | | bridge.getSessionToken() | Exchange the context for a scoped session token (for calling the platform API directly). | | bridge.apiFetch(path, init?) | Proxied, scope-enforced API call. init: { method?, query?, body? }. | | bridge.resize(height) | Fit the host iframe to your content. | | bridge.navigate(path) | Ask the host to navigate (in-app paths only). | | bridge.toast(text) / bridge.modal(options) | Host-rendered notifications and dialogs. | | bridge.destroy() | Detach listeners, reject pending requests. |

Docs

Full platform documentation — manifest reference, scopes and events catalogs, review rules, and the Studio IDE — lives at developer.1ecomm.com/docs.

License

MIT © Digitrend