npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@blockmoblabs/cryptopay

v0.1.1

Published

CryptoPay crypto payment infrastructure: create payment intents, open the checkout, verify webhooks.

Readme

@blockmoblabs/cryptopay

Take crypto payments in your product. Create a payment against your own customer, order or subscription reference; CryptoPay handles the address, the chain and the confirmations, and posts you a signed webhook carrying that reference back.

Zero dependencies. Node 18+ for the server entry; any modern browser for @blockmoblabs/cryptopay/browser.

npm install @blockmoblabs/cryptopay

Server

import { CryptoPay } from '@blockmoblabs/cryptopay';

const cryptopay = new CryptoPay({
  apiKey: process.env.CRYPTOPAY_API_KEY!,   // cp_test_… or cp_live_…
  baseUrl: process.env.CRYPTOPAY_API_URL,   // only when self-hosting
});

const intent = await cryptopay.createIntent({
  amountUsd: 40,
  customerEmail: '[email protected]',
  customerRef: 'user_8812',
  orderRef: 'ord_5571',
  subscriptionRef: 'sub_221',
  successUrl: 'https://yourapp.com/billing/done',
  metadata: { plan: 'pro' },
  idempotencyKey: 'ord_5571',               // replaying returns the same intent
});

The key decides the merchant and the mode — there is no mode flag to get wrong. cryptopay.mode reports which one you are on.

| Method | What | | --- | --- | | createIntent(input) | Create a payment. Returns checkoutUrl and clientSecret. | | getIntent(id) | Read one payment, including its deposit sessions. | | listIntents(query) | Page through payments; search matches any of your references. | | cancelIntent(id) | Cancel an unpaid payment. Refused once completed. | | verifyWebhook(opts) | Verify and parse a webhook. Throws on anything suspect. |

Non-2xx responses throw CryptoPayError with status and body.

Browser

import { openCheckout, embedCheckout } from '@blockmoblabs/cryptopay/browser';

openCheckout({
  checkoutUrl,                               // from the intent your server created
  onStatus: (status) => console.log(status),
  onSuccess: () => location.assign('/billing/done'),
  onCancel: () => console.log('payer closed the modal'),
});

// or inline, into an element you already have
embedCheckout(document.getElementById('pay')!, { checkoutUrl, onSuccess: () => location.reload() });

Nothing secret lives here: the checkout URL carries the payer's own credential, and the page it opens is served by CryptoPay, so your page never handles an address or an amount. Only messages from the checkout's origin can drive the modal.

Webhooks

Pass the raw body — a re-serialized object will not match the signature.

app.post('/webhooks/cryptopay', express.raw({ type: 'application/json' }), async (req, res) => {
  let event;
  try {
    event = cryptopay.verifyWebhook({
      body: req.body,                         // Buffer, not parsed JSON
      headers: req.headers,
      secret: process.env.CRYPTOPAY_WEBHOOK_SECRET!,
    });
  } catch {
    return res.sendStatus(400);               // never act on an unverified body
  }

  if (await alreadyHandled(event.id)) return res.sendStatus(200);

  if (event.type === 'payment.completed') {
    await credit(event.customer.customerRef!, event.fee!.netUsd, event.customer.orderRef);
  }

  await markHandled(event.id);
  res.sendStatus(200);                        // 2xx stops the retries
});

verifyWebhook checks the HMAC-SHA256 signature over timestamp.eventId.rawBody in constant time and rejects a timestamp outside toleranceMs (default 5 minutes), so a validly signed replay of an old event does not get through. Delivery is at-least-once: dedupe on event.id.

Events: payment.created, payment.detected, payment.confirming, payment.underpaid, payment.completed, payment.expired, payment.failed.

Test mode

A test key runs the whole lifecycle against a simulator — real intents, statuses and webhooks, no chain and no money. The deposit address is cptest_…, deliberately invalid on every network, and the payment confirms on a timer: detected within ~15s and confirmed within ~30s, since the watcher that advances it ticks every 15 seconds. In an automated test, call POST /sessions/:id/recheck (what I have paid does in the checkout) to confirm immediately instead of sleeping.

Going live is one environment variable: the key changes, the code does not.

Fees

$2 flat per successful payment, charged once on completion. It comes off your side — the payer is asked for exactly the invoice amount. On a $40 payment, fee is { grossUsd: 40, feeUsd: 2, netUsd: 38 }.