@eridian-ai/loom
v0.8.0
Published
Loom embedded data plane for customer apps
Downloads
503
Readme
@eridian-ai/loom
Mount the Loom data plane inside your own backend so agent-authored dashboards query your database directly — your credentials never leave your infrastructure, and query results never transit Loom's servers.
How it works
Loom's control plane signs every query and mutation as a short-lived Ed25519 capability token. This package verifies those signatures with Loom's public key and executes only what was signed — your endpoint holds the database credentials, Loom holds the private signing key, and neither side can act without the other.
- Reads: the exact SQL text is inside the signed token. Anything else is rejected.
- Writes: tokens carry
table / op / pk column / allowed fields— never raw SQL. Every mutation targets exactly one row by primary key, deletes are soft-deletes, and an audit row (who, what, before/after) is written in the same transaction. - Replay protection: mutation tokens are single-use (nonce-tracked) and expire quickly.
Install
npm install @eridian-ai/loomMount (Next.js example)
// app/api/loom/[[...path]]/route.ts
import { createLoomHandler } from "@eridian-ai/loom/data-plane";
const handler = createLoomHandler({
publicKey: process.env.ERIDIAN_LOOM_PUBLIC_KEY!, // provided during onboarding
databaseUrl: process.env.ERIDIAN_LOOM_DATABASE_URL_RO!, // read-only role
databaseUrlRw: process.env.ERIDIAN_LOOM_DATABASE_URL_RW, // optional writer role
});
export const GET = (req: Request) => handler(req);
export const POST = (req: Request) => handler(req);The handler is a plain (Request) => Promise<Response> function, so any framework that speaks the Fetch API (Express via adapter, Hono, Remix, Fastify, etc.) can mount it.
Single sign-on for the embedded UI
If you embed the Loom app in an iframe, mint a short-lived handoff token for your already-authenticated user so they never see a second login screen:
import { createEmbedToken } from "@eridian-ai/loom/data-plane";
const token = await createEmbedToken({
secret: process.env.ERIDIAN_LOOM_EMBED_SECRET!, // per-connection, from onboarding
connectionId: process.env.ERIDIAN_LOOM_CONNECTION_ID!,
email: user.email,
name: user.name,
});
// iframe src: `${ERIDIAN_LOOM_APP_URL}/embed?connection=${connectionId}&token=${token}`Tokens are HMAC-signed, expire within 5 minutes, and are single-use. Mint them server-side only — never expose the secret to the browser.
The iframe needs no sandbox attribute; Loom isolates dashboard code on its own origin. If you set one anyway, include allow-downloads alongside allow-scripts and allow-same-origin — sandbox flags only narrow as frames nest, so omitting it silently discards CSV and image exports from inside a dashboard.
Database roles
We recommend two dedicated Postgres roles:
- a read-only role (
SELECTon the schemas you want dashboardable — this is the visibility boundary: what this role cannot see, Loom cannot see); - a writer role with
INSERT/UPDATEonly (noDELETE, no DDL), plusINSERTon theloom_auditschema where the audit log lives — in your database, next to your data.
Omit databaseUrlRw to run dashboards read-only.
License
Proprietary — use is governed by your Loom service agreement.
