npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@allowly-ai/cli

v0.1.2

Published

Command-line setup tool for Allowly workspaces

Readme

Allowly CLI

Command-line setup tool for Allowly workspaces.

Use it after a human creates an account and verifies email. Billing is not required for setup or the first successful runtime check; later new checks require a payment method. allowly login opens the dashboard, asks the signed-in owner to approve CLI access, then stores a local CLI credential in ~/.allowly/config.json with owner-only permissions.

After approval, the saved CLI credential can ask the app's AI drafting service for a local setup file:

allowly init --ai "Allow listing calendar events and require confirmation before deleting events."

This only writes allowly.setup.json. Review it first; the existing actions apply and policies apply commands create workspace resources.

Install the public npm package:

npm install -g @allowly-ai/cli

Then:

allowly login
allowly init --ai "Allow listing calendar events and confirm before deleting events."
allowly actions apply allowly.setup.json
allowly policies apply allowly.setup.json
allowly keys create --write-env .env.local --var ALLOWLY_API_KEY
allowly setup guide
allowly check --authorization-id auth_... --action web.search --runtime-env .env.local

Use allowly init --use-case email-agent instead when you want a built-in seed rather than AI drafting.

allowly login talks to the dashboard app for browser approval and stores the public API URL returned by Allowly for setup calls. Use --app-url for local app development and --api-url only when you need to override the API URL written to the local CLI config.

Optional use-case seeds

allowly init --list-use-cases
allowly init --use-case email-agent
allowly init --use-case browser-agent
allowly init --use-case client-intelligence
allowly init --use-case hr-ops
allowly init --use-case mcp-guardrails
allowly init --use-case no-code-automation
allowly init --manual

Use-case seeds are optional. If you already know your actions, create them first, then group them into policies per agent.

CLI credentials can configure actions, policies, setup status, and runtime-key creation. They cannot call /v1/check, access billing, manage users, or change passwords.

Runtime API keys are shown once. Write them to local env files or a secret manager; do not paste them into logs, tickets, or chat transcripts.

Use --write-env for local env-file output. --env-file is intentionally not documented because recent Node versions reserve that flag for Node itself.

allowly check is a runtime helper. It requires a runtime API key from --api-key, ALLOWLY_API_KEY, or --runtime-env; it does not use the CLI setup credential. Receipt signing still happens server-side in the Allowly API.

The command prints the runtime response unchanged. Signed receipts carry a schema_version; alg and key_id are signed top-level fields, and signature is the unpadded base64url string. Use an Allowly SDK verifier for offline verification.