npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@crela/license

v1.0.2

Published

License verification SDK for Crela marketplace tools (Node.js / Electron). Reads JWT from launcher-injected env var or cache file, verifies offline via Ed25519.

Readme

@crela/license (Node.js / Electron)

License verification SDK for tools on the Crela marketplace.

Mandatory for paid tools: the review pipeline looks for a per-tool marker inside your binary (KO-10), and this SDK is what puts it there and checks the licence at startup.

Quick start

For Node.js and Electron projects, let the init tool wire everything up:

cd my-tool/
npx @crela/init

It detects your entry point and bundler, fetches the SDK marker via the API, injects verifyOrExit(), and patches your bundler config. After that, just run npm run build.

How it works

The SDK never prompts for a licence key. It reads a JWT signed by the Crela launcher — either from the environment variable CRELA_LICENSE_JWT or from a cache file — and verifies it offline against an Ed25519 public key. No network call happens.

Activation, heartbeat and device management are handled entirely by the Crela launcher, so your tool does not need its own licence UI. Your integration is one call:

import { verifyOrExit } from '@crela/license'

verifyOrExit('my-tool', process.env.CRELA_SDK_MARKER!)

Manual build-time setup

If you do not use npx @crela/init, set the variables yourself before building:

# Marker token from the creator dashboard:
export CRELA_SDK_MARKER=CRELA_SDKv2_xxxxxxxxxxxxxx

# Ed25519 public key (64 hex chars) for JWT verification:
export CRELA_LICENSE_PUBKEY_HEX=abcdef...

With esbuild:

esbuild main.ts \
  --define:CRELA_SDK_MARKER=\"$CRELA_SDK_MARKER\" \
  --define:CRELA_LICENSE_PUBKEY_HEX=\"$CRELA_LICENSE_PUBKEY_HEX\"

With Webpack:

new webpack.DefinePlugin({
  CRELA_SDK_MARKER: JSON.stringify(process.env.CRELA_SDK_MARKER),
  CRELA_LICENSE_PUBKEY_HEX: JSON.stringify(process.env.CRELA_LICENSE_PUBKEY_HEX),
})

The marker has to survive bundling as a literal string — reading it from a config file at runtime does not satisfy KO-10.

Usage

import { verifyOrExit } from '@crela/license'

// In electron main.ts, before app.whenReady():
verifyOrExit('my-tool', CRELA_SDK_MARKER)

app.whenReady().then(createWindow)

On failure: a message on stderr and process.exit(0xC1).

Verification order

  1. CRELA_DEV_MODE=1 env → isDev=true claims, no verification
  2. CRELA_LICENSE_JWT env → verify token
  3. Cache file <DATA_LOCAL_DIR>/crela/licenses/<slug>.jwt → verify token
  4. Nothing found → LicenseError with code NOT_LAUNCHED_FROM_CRELA

Advanced

import { LicenseVerifier } from '@crela/license'

const verifier = new LicenseVerifier({
  toolSlug: 'my-tool',
  markerToken: CRELA_SDK_MARKER,
  pubkeyHex: CRELA_LICENSE_PUBKEY_HEX,
})

try {
  const claims = verifier.verify()
  console.log(`Licence valid, exp=${claims.exp}`)
} catch (e) {
  console.error(`Licence invalid: ${e.message}`)
  process.exit(1)
}

Other languages

Crela ships a ready-made SDK for Node.js/Electron and for Rust/Tauri. For anything else (.NET, Java, Python, C++, Go) there is no SDK — embed the marker string as a compile-time constant and the review will accept it. Enforcing the licence at runtime is then up to you. See the creator guidelines.

Tests

npm test

Licence

MIT