npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@neotales/win-cred

v0.0.0

Published

Windows Credential Manager API for Node, Bun, and Deno.

Readme

@neotales/win-cred

Windows Credential Manager secret storage.

GitHub version

Installation

deno add jsr:@neotales/win-cred
npx jsr add @neotales/win-cred
npm install @neotales/win-cred

Secret Store API

The package root stores opaque secrets by service and account. getSecret() returns bytes and getSecretString() decodes UTF-8.

import {
  getSecret,
  getSecretString,
  isAvailable,
  listSecrets,
  removeSecret,
  saveSecret,
} from "@neotales/win-cred";

if (!isAvailable())
  throw new Error("Credential Manager FFI is unavailable");

saveSecret("myapp", "token", "secret");
saveSecret("myapp", "key", new Uint8Array([0, 255, 1]));

console.log(getSecretString("myapp", "token"));
console.log(getSecret("myapp", "key"));
console.log(listSecrets("myapp").map(({ account }) => account));

removeSecret("myapp", "token");
removeSecret("myapp", "key");

Services and accounts must be non-empty. The root API encodes them into an internal Credential Manager target name, so it lists only records created through this API.

Native API

@neotales/win-cred/ffi exposes raw Credential Manager operations for callers that need native target names, credential types, persistence scopes, or raw credential blobs. Unlike the root API, WinCred does not namespace targets. It is safe to import on unsupported runtimes; call isAvailable() before invoking it.

import {
  CredEnumerateFlags,
  CredPersist,
  CredType,
  CredWriteFlags,
  isAvailable,
  WinCred,
} from "@neotales/win-cred/ffi";

if (!isAvailable())
  throw new Error("Credential Manager FFI is unavailable");

const targetName = "myapp/native-token";
const credentialBlob = new TextEncoder().encode("secret");

WinCred.write({
  flags: 0,
  type: CredType.GENERIC,
  targetName,
  comment: "Native Credential Manager example",
  lastWritten: 0n,
  credentialBlobSize: credentialBlob.length,
  credentialBlob,
  persist: CredPersist.LOCAL_MACHINE,
  attributeCount: 0,
  targetAlias: "",
  userName: "token",
}, CredWriteFlags.NONE);

const credential = WinCred.read(targetName, CredType.GENERIC);
console.log(credential?.userName);
console.log(new TextDecoder().decode(credential?.credentialBlob));

const credentials = WinCred.enumerate("myapp/*", CredEnumerateFlags.NONE);
console.log(credentials.map(({ targetName }) => targetName));

WinCred.delete(targetName, CredType.GENERIC);

WinCred.write, WinCred.read, WinCred.delete, and WinCred.enumerate throw when the OS or runtime FFI backend is unavailable.

Runtime Support

Node.js uses native FFI on Node 26 or later with --experimental-ffi; otherwise install the optional fallback with npm install koffi. Bun uses native FFI. Deno requires --allow-ffi.

Credential writes require an interactive Windows logon session. OpenSSH sessions can fail with Win32 error 1312 (ERROR_NO_SUCH_LOGON_SESSION); validate writes from an interactive RDP or console session.

License

MIT License