npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@crvouga/mockingbird-service-turnstile

v1.1.0

Published

Deterministic Cloudflare Turnstile Siteverify token validation.

Readme

@crvouga/mockingbird-service-turnstile

Local emulators. Real API contracts. Part of Mockingbird.

WIP Cloudflare Turnstile server-side Siteverify emulator. It never solves or issues real challenges.

Install

bun add @crvouga/mockingbird-service-turnstile

Usage

import { createRuntime } from "@crvouga/mockingbird-service-turnstile"

const turnstile = createRuntime()
const { token } = await turnstile.instance().issue({
  hostname: "app.example.test", action: "signup",
}).json()
const result = await turnstile.fetch(new Request("http://turnstile.test/turnstile/v0/siteverify", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({ secret: "mock_secret", response: token }),
}))
console.log(await result.json()) // success, challenge_ts, hostname, action, cdata

Run mockingbird-turnstile serve --port 12126, then override the consumer's Siteverify URL with http://localhost:12126/turnstile/v0/siteverify. Keep the real Cloudflare origin in production. There is no universal consumer environment variable for this override. Send synthetic secret: mock_secret; configure additional sites with sites.

Contract

POST /turnstile/v0/siteverify accepts JSON or URL-encoded form fields secret, response, optional remoteip and UUID idempotency_key. Valid tokens return HTTP 200 and success: true with metadata. Rejection is HTTP 200 with success: false and error-codes, not a transport exception. Missing/invalid secrets, missing/invalid tokens, malformed bodies and expired/used tokens retain their documented error codes.

Tokens expire at five minutes on the emulator clock and are consumed once. Matching idempotency key retries replay the original response; other retries return timeout-or-duplicate. Wrong secrets do not consume a valid token. Applications must independently check the returned hostname/action. Remote IP is accepted, not used for actual bot detection.

Controls

  • POST /__admin/issue: issue a synthetic token; accepts siteKey (default mock_site), hostname, action, cdata. Defaults are for local testing only.
  • Constructor tokens and shared /__admin/state/tokens: seed token expiry/use state.
  • GET /__admin/attempts: metadata-only verification attempts, without secret/token bodies.
  • Shared clock, Timeline, reset, state, faults and request journal are available. Reset restores constructor sites/tokens; namespaces are isolated by header or /__admin/ns/{namespace}. Body secrets do not select namespaces. adminPrefix relocates the control tree.

Presets: internal_error (HTTP 200 verification rejection), rate_limited (scripted 429), server_error (503), connection_drop. Generic fault rules add deterministic latency. Transport presets are test controls, not claims about normal Siteverify status codes. No webhooks.

Tests use raw fetch (the requested client), JSON/form success, expiry boundary/replay, idempotency, malformed input, namespace/reset isolation, redacted journals and served HTTP timeouts/fail-closed behavior. Property tests validate Siteverify and detect divergence. bun scripts/parity.ts needs TURNSTILE_TEST_SECRET set to one of Cloudflare's documented public dummy keys; production keys are refused. It compares success/error envelopes in JSON and form modes, not production token issuance or private metadata.

Deliberately not modelled

Browser widget/script, bot detection, real challenges/tokens, multipart encoding, production token signing, IP reputation, hostname policy administration and enterprise metadata. Idempotency cache retention and conflicting/in-flight key policies are deterministic local stand-ins; only identical retry behavior is covered by the public contract evidence.

API

  • TurnstileAPI: FetchAPI with fetch, reset, issue, and site/token/attempt collections.
  • createRuntime: shared emulator contract plus token issuance/attempt inspection.
  • TURNSTILE_NAMESPACE: service name.
  • TURNSTILE_PRESETS: named failure controls.
  • document, operationIds, supportedOperationIds: generated OpenAPI metadata.
  • createServer, serveTarget, DEFAULT_PORT from ./server: Node HTTP/CLI serving, default port 12126.

Public types include Site, Token, TurnstileAPIOptions, OperationId and SupportedOperationId.