npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@bipsync/apiclient

v2.0.0

Published

Bipsync API Client

Readme

Installation

Examples

Getting the latest notes

example.js

run it

using the OAuth client credentials grant to authenticate

When running reports locally OAuth can be used to authenticate:

using the OAuth device code grant to authenticate

When running reports locally OAuth can be used to authenticate:

How it works

On first run, the API client will:

  1. Prompt the user once for two intermediate DCR OAuth client IDs — one for production (.com) and one for internal/staging (.io) — and cache them at the top level of ~/.bipsyncapi under intermediateClients as { production, staging }
  2. Prompt the user to select which environment (production or staging) applies to the current API hostname, and cache that choice per API hostname as intermediateClientKey ("production" or "staging"); the actual client ID is resolved at request time via the top-level intermediateClients map, so updates to the global IDs propagate to every host automatically
  3. Use the resolved intermediate client to request an OAuth token with the oauth:dcr scope via the device authorization flow
  4. The user will be prompted to complete authorization in their browser
  5. Once authorized, fetch the list of available scopes
  6. Use the oauth:dcr-scoped token to register a new OAuth client with the required scopes via Dynamic Client Registration (RFC 7591)
  7. Cache the newly registered client per API hostname in ~/.bipsyncapi
  8. Prompt for team ID and cache it per API hostname after successful authentication
  9. Use the cached client + credentials to obtain an access token with all available scopes plus the team-specific scope
  10. Use this access token to make authenticated API requests

On subsequent runs:

  • The cached intermediate client selection (intermediateClientKey), registered client, and team ID are reused; the intermediate client ID itself is re-resolved each run from the top-level intermediateClients map
  • To change the intermediate client IDs for production or staging, delete the top-level intermediateClients map in ~/.bipsyncapi; you'll be prompted to re-enter both on next run
  • To change which environment a given API hostname uses, edit or delete the cached intermediateClientKey field under the hostname in ~/.bipsyncapi
  • To change the cached team ID, edit or delete the teamId field under the hostname in ~/.bipsyncapi
  • If the available scopes change in the main app, a new client will be registered via the device / DCR flow

The user approving the device code must have the OAuth Dynamic Client Registration permission enabled in the Can Access section of their Access tab in the admin app.