npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@expo/snapback-expo-custody

v0.1.29

Published

First-party native iOS and Android auth custody for Snapback Expo applications. Experimental; custody grades are adapter-reported.

Readme

@expo/snapback-expo-custody

Experimental first-party native ordinary-bearer auth custody for Snapback Expo applications. The package provides native compare-and-replace adapters backed by iOS Keychain or Android DataStore plus Android Keystore AES-GCM. Custody grades are reported by the selected adapter; in v1, both OS adapters declare only single-runtime.

Both native provider tuples ship in the qualified thirteen-package closure beginning with 0.1.24. The first qualified publication was governed by the custody first-publish gate, whose ceremony record lives in LLP 0041.

| OS | Adapter-reported grade | Source/publication posture | | --- | --- | --- | | iOS | single-runtime | Published (0.1.24+). Share-sheet-extension evidence only; the built NSE and simctl push service-stage invocation remain nonclaims. | | Android | single-runtime | Published (0.1.24+). |

The separate Phase-2 receipts and closure records live in the both-OS Phase-2 close-out and the iOS extension-refusal close-out. The package is a native module and therefore requires an Expo development/production build; it is not available in Expo Go.

import { createNativeAuthCustodyStorage } from '@expo/snapback-expo-custody';

const storage = createNativeAuthCustodyStorage();
const grade = await storage.platformGrade();

The Expo config plugin installs the mandatory Android custody-file backup and device-transfer exclusions. It is not applied automatically: list @expo/snapback-expo-custody explicitly in the app's Expo plugins array.

The Android carrier retires a permanently invalidated Keystore alias before it reports the typed custody-absent diagnostic, so a later fresh write can create a new key. JavaScript fakes cover that restart contract; only the LLP 0263 emulator/device probes can establish real Keystore invalidation, AEAD, backup, and OEM process-name behavior. A resolved Android process name different from the application package fails closed as a secondary-process single-runtime refusal. If every process-identity mechanism fails, custody also fails closed before I/O with reason process-identity-unresolved. This is deliberate: single-runtime identity is a security boundary under LLP 0258 D3, not an optional diagnostic.

This is an optional add-on, not a dependency of the @expo/snapback umbrella.

Documentation outside a checkout

A running Snapback server serves the Guide compiled into that exact build. These links use the first default development port; use the origin printed by snapback dev or snapback start if yours differs.

  • Read first: the start packets — the budgeted per-template first read (LLP 0259).
  • Read password auth and custody for the ordinary bootstrap path and current platform limits.
  • Look up (do not linear-read) the capability index before assuming an OS custody grade is available.
  • Run snapback guide or snapback guide <query> to browse or search the embedded Guide.
  • Run snapback mcp for the same build-bound corpus as read-only MCP resources, starting at snapback-guide://manifest.