npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@delegus/http-gateway

v0.1.0

Published

Delegus HTTP gateway: a reverse proxy that checks every request to an ordinary HTTP API (REST, any language) against the caller's delegated authority before forwarding it: the Grant and Proof bound to the exact method and URL, the Action built from the bo

Readme

@delegus/http-gateway

The Delegus check in front of an ordinary HTTP API, in any language. Banks and suppliers run REST; this is @delegus/mcp-gateway for those: every request is checked against the caller's delegated authority before the API sees it, and only an allowed request is forwarded.

agent ──► delegus-http-gateway ──► your API (any language)
               │
               └─ one call to Delegus per request

Run it

DELEGUS_RP_KEY=dk_rp_… npx @delegus/http-gateway \
  --upstream http://api:8080 --public-base-url https://pay.example.com --route-map routes.json
  • --upstream: where your API listens. Keep it on a private network; the gateway protects the API only if it is the only way in.
  • --public-base-url: the gateway's public origin, the one agents sign for. A path here is refused at startup, in words, because agents sign for <origin><request path> and a path would double it.
  • --route-map routes.json: how a request becomes the Action Delegus checks (below). Without it, every request is api:call <METHOD> <canonical URL> and the Grant names the URL patterns.
  • DELEGUS_RP_KEY: a Delegus verify key, from the environment only.

The route map

{ "version": 1, "routes": [
  { "id": "payments.create", "method": "POST", "path": "/payments",
    "action": "commerce:purchase",
    "resource": "payee:{arg:/body/payee}",
    "amount": { "value": "/body/amount", "currency": "/body/currency", "unit": "minor" } },
  { "id": "accounts.read", "method": "GET", "path": "/accounts/{id}", "action": "api:call" }
] }

Templates and JSON pointers are the MCP tool map's, resolved against { body, path: {<param>}, query: {<name>}, url }. A money route becomes commerce:purchase with the amount in minor units (or "unit": "major" with decimals); the Grant then says payee:acme-* up to maxAmount. An api:call route binds the request URL itself (its path parameters are already in it), so the Grant names https://pay.example.com/accounts/*; a resource template on an api:call route is refused. A request matching no route is still checked, as api:call on its URL: nothing passes unchecked except OPTIONS. A body the map cannot apply is refused before Delegus is asked (ARGUMENTS_UNMAPPABLE). The map is served at /delegus-routes.json and named in the Delegus-Routes header on a 401, so the agent builds the same Action (Agent.httpHeaders({ routes }) in @delegus/sdk).

What happens to each request

  • ALLOW: forwarded with the exact bytes that were checked, plus Delegus-Receipt-Id and Delegus-Decision: ALLOW (a client's own copies are dropped); the client gets Delegus-Receipt-Id on the response.
  • DENY: 403 with { error, message, delegus: { decision, reason, receipt_id, receipt_url } }; error is always "DENY", the reason to act on is delegus.reason; the API never sees the request. A Proof signed for another method or URL is PROOF_BINDING_MISMATCH (no receipt: Delegus was not asked). Missing credentials: 401 with Delegus-Verify: required, Delegus-Relying-Party and Delegus-Routes.
  • Delegus unreachable: 403 SERVICE_UNAVAILABLE. It fails closed. A body that is not strict JSON or exceeds the size limit is refused (REQUEST_UNREADABLE).

In-process alternatives

Node APIs can skip the proxy: app.use(delegus.http({ routeMap })) (Express style) or app.addHook("preHandler", fastifyDelegusHttp(delegus, { routeMap })) from @delegus/sdk, the same check without the hop.

Limits

  • The gateway must be the only way in; keep the upstream private.
  • Only what the route map names is bound into the Action; validate other fields in the API.
  • Bodies are read whole (default 1 MiB) so the exact bytes that were checked are the bytes forwarded; it is not a streaming proxy for uploads.