npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@heliantheons/aegis-ts

v1.3.3

Published

Aegis Auth SDK - Web 认证 SDK

Readme

@heliantheons/aegis-ts 是给浏览器用的认证 SDK。它把 OAuth 2.1 + PKCE 那一整套封装好,帮你处理登录跳转、回调校验、令牌的生命周期和用户信息读取,跟框架无关——React、Vue 都能用,也不逼你绑定任何框架。它分两层:Auth 是底层纯逻辑(不碰 DOM,适合自己定制存储和 HTTP 客户端),WebAuth 是浏览器封装(把跳转、回调、URL 解析接好,SPA 直接用)。运行时依赖刻意压得很轻,核心只依赖 paseto-ts。

@heliantheons/aegis-ts is a framework-agnostic browser SDK for OAuth 2.1 + PKCE. It handles redirects, callback validation, the token lifecycle, and user info. Two layers: Auth is the pure-logic core (no DOM, pluggable storage/HTTP), WebAuth is the browser wrapper that wires up redirects and URL parsing for SPAs.

安装 / Install

pnpm add @heliantheons/aegis-ts

所有公共 API 都可以从包根入口导入。/web 子路径继续保留,用于兼容旧版本调用方。

All public APIs are available from the package root. The /web subpath remains available for backward compatibility.

import {
  Auth,
  WebAuth,
  AuthError,
  type AuthConfig,
  type WebAuthConfig,
} from "@heliantheons/aegis-ts";

浏览器应用 / Browser applications

import { WebAuth } from "@heliantheons/aegis-ts";

const auth = new WebAuth({
  endpoint: "https://aegis.example.com",
  clientId: "portal",
  redirectUri: `${window.location.origin}/auth/callback`,
});

await auth.authorize({
  audience: "hermes",
  scopes: ["openid", "profile", "offline_access"],
  returnTo: window.location.pathname + window.location.search,
});

在回调路由中完成 code exchange:

const result = await auth.handleRedirectCallback();
if (!result.success) throw new Error(result.error);
window.location.replace(result.redirectTo ?? "/");

获取指定 audience 的 access token。SDK 会在需要时使用 refresh token 更新令牌:

const token = await auth.getAccessToken("hermes");
const response = await fetch("/api/resource", {
  headers: { Authorization: `Bearer ${token}` },
});

自定义集成 / Custom integration

需要替换存储或 HTTP 实现时,可以给 WebAuth 传入适配器,也可以直接使用底层 Auth:

const auth = new WebAuth({
  endpoint: "https://aegis.example.com",
  clientId: "portal",
  redirectUri: `${window.location.origin}/auth/callback`,
  storage: customStorage,
  httpClient: customHTTPClient,
});

浏览器应用属于 OAuth public client,不要把 client_secret 放进前端代码。