npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@molecule/api-secrets-molecule

v1.0.3

Published

Managed per-app secrets vault + credential-broker seam for molecule.dev-hosted backends

Readme

@molecule/api-secrets-molecule

Auto-generated, AI-first package reference for the molecule.dev ecosystem. It is written to be read by coding agents as much as by people, and is generated from this package's source — edit src/index.ts JSDoc, not this file.

Molecule managed-vault secrets provider for molecule.dev.

Fetches a single app's secrets from molecule.dev's managed, per-app encrypted vault at runtime, caches them with a TTL, serves stale cache on transient failure, and only then falls back to process.env. The bootstrap token + app id are the only secrets that live in the environment. It is also the seam through which credential brokering is delivered with no app-code change.

Quick Start

import { bond } from '@molecule/api-bond'
import { provider } from '@molecule/api-secrets-molecule'

bond('secrets', provider)
// ...then, unchanged: await resolveAll([ ...keys... ]) → syncToEnv → process.env

Type

provider

Installation

npm install @molecule/api-secrets-molecule @molecule/api-bond @molecule/api-i18n @molecule/api-secrets

API

Interfaces

MoleculeSecretsProviderOptions

Options for the molecule managed-vault secrets provider.

interface MoleculeSecretsProviderOptions {
  /**
   * Per-app bootstrap token.
   * Falls back to the `MOLECULE_VAULT_TOKEN` env var.
   */
  token?: string

  /**
   * App identifier the vault scopes secrets to.
   * Falls back to the `MOLECULE_APP_ID` env var.
   */
  appId?: string

  /**
   * Vault base URL.
   * Falls back to the `MOLECULE_VAULT_URL` env var, then
   * `https://api.molecule.dev/v1/vault`.
   */
  vaultUrl?: string

  /**
   * Cache TTL in milliseconds.
   * @default 60000 (1 minute)
   */
  cacheTtl?: number

  /**
   * On fetch failure, serve last-good cached values (stale) before falling
   * back to `process.env`. When `false`, fall back to `process.env` immediately.
   * @default true
   */
  staleWhileError?: boolean
}

Functions

createMoleculeSecretsProvider(options)

Creates a managed-vault secrets provider that fetches a single app's secrets from molecule.dev's vault, caches them for the TTL, serves stale cache on transient failure, and only then falls back to process.env.

function createMoleculeSecretsProvider(options?: MoleculeSecretsProviderOptions): SecretsProvider
  • options — Vault connection options. Falls back to MOLECULE_* env vars.

Returns: A SecretsProvider with get/getMany/set/delete/isAvailable/syncToEnv backed by the molecule vault.

Constants

provider

Default provider instance, created from MOLECULE_* environment variables.

const provider: SecretsProvider

secretsMoleculeSecretDefinitions

Secret definitions required by the molecule.dev vault secrets bond.

const secretsMoleculeSecretDefinitions: SecretDefinition[]

Core Interface

Implements @molecule/api-secrets interface.

Bond Wiring

Setup function to register this provider with the core interface:

import { setProvider } from '@molecule/api-secrets'
import { provider } from '@molecule/api-secrets-molecule'

export function setupSecretsMolecule(): void {
  setProvider(provider)
}

Injection Notes

Requirements

Peer dependencies:

  • @molecule/api-bond ^1.0.1
  • @molecule/api-i18n ^1.0.1
  • @molecule/api-secrets ^1.0.1

Environment Variables

  • MOLECULE_VAULT_TOKEN (required) — molecule.dev vault token
    • Provisioned automatically in molecule.dev sandboxes — manual setup only needed outside the platform.
  • MOLECULE_APP_ID (required) — molecule.dev app ID
    • Provisioned automatically in molecule.dev sandboxes — manual setup only needed outside the platform.
  • MOLECULE_VAULT_URL (optional) — molecule.dev vault URL — default: https://api.molecule.dev/v1/vault
    • Provisioned automatically in molecule.dev sandboxes — manual setup only needed outside the platform.

Runtime Dependencies

  • @molecule/api-bond

  • @molecule/api-i18n

  • @molecule/api-secrets

  • MOLECULE_VAULT_TOKEN / MOLECULE_APP_ID must be in the environment BEFORE this module is imported — the default provider captures them at import time (they are platform-provisioned in molecule.dev deployments, so this normally holds). For late-arriving credentials, wire createMoleculeSecretsProvider({ token, appId }) instead.

  • Without a reachable vault AND no cached values, reads fall back to process.env with a logged warning — provider.isAvailable() at boot tells you which path you're on.