@key-warden/protect
v1.0.1
Published
Key-Warden Protect CLI - obfuscate, seal, embed-key, watermark and verify a build for licensed distribution. Obfuscation is mandatory. Local, source never leaves your machine.
Maintainers
Readme
@key-warden/protect
The Key-Warden Protect CLI - a local, build-time tool that hardens a build for licensed distribution. Your source never leaves your machine.
It does four things and has one command that runs them all:
- obfuscate - mandatory. Runs
javascript-obfuscator(shipped as a dependency of this CLI) over your built JS. A build is not protected without it, so it cannot be turned off - only strengthened. - seal - encrypt your licensed file(s) with your product's content key (AES-256-GCM). They only run once Key-Warden hands the key to a valid, activated licence.
- embed-key - write your vendor public key into the build for offline token verification.
- watermark - stamp the build with a unique id.
- check - confirm all of the above are present before you publish (this is
"verify a protected build", run locally - nothing is uploaded). It fails if
any shippable
.jswas not obfuscated, and exits non-zero so you can gate CI.
build runs them in order obfuscate → seal → embed-key → watermark → check,
so your code is obfuscated first and then encrypted.
Quick start
npx @key-warden/protect init # writes kw-protect.json - edit it
export KW_CONTENT_KEY=<base64 key> # from vendor console -> Protect your code -> Reveal key
npx @key-warden/protect build # obfuscate -> seal -> embed-key -> watermark -> checkShip the produced *.sealed files plus dist/kw-public-key.txt. At runtime,
decrypt with @key-warden/sdk:
const kw = require('@key-warden/sdk');
const res = await kw.validate(licence, { apimKey, clientKey, machineId });
const key = kw.unlockFromToken(res.token, machineId); // machine-bound content key
const code = kw.unseal(sealedBlob, key); // your decrypted (obfuscated) filekw-protect.json
{
"product": "your-product-code",
"seal": ["dist/licensed"],
"publicKey": "BASE64_VENDOR_PUBLIC_KEY",
"obfuscate": { "include": ["dist"] },
"out": "dist"
}seal- a list of files or folders (folders are sealed recursively).publicKey- your vendor public key (base64, 32 bytes). Not a secret.- The content key is never in the config - it comes from
KW_CONTENT_KEY. obfuscate.include- the built JS to obfuscate (default["dist"]). Obfuscation always runs; addobfuscate.optionsto strengthen it (any javascript-obfuscator option). There is no switch to disable it.
Commands
| Command | What it does |
|---|---|
| init | scaffold kw-protect.json |
| build | obfuscate → seal → embed-key → watermark → check |
| obfuscate | obfuscate your built JS (mandatory) |
| seal | seal the configured files |
| embed-key | write the public key into the build |
| watermark | stamp a build id |
| check | verify the build is protected (CI-friendly exit code) |
One dependency - javascript-obfuscator (obfuscation is not optional).
Everything else uses Node's built-in crypto.
Licence
MIT.
