npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@nordio/server-kit

v0.8.0

Published

The shared library every MCP server reuses — so no server hand-rolls plumbing (guideline hard rule 12).

Readme

@nordio/server-kit

The shared library every MCP server reuses — so no server hand-rolls plumbing (guideline hard rule 12).

What exists today

  • createMcpServer(opts) — build a client-agnostic server from ToolDef[] (title, agent-written description, Zod inputSchema, annotations, handler with { mock, log } context, error-to-isError wrapping, automatic per-call instrumentation with duration + redacted args), optional ResourceDef[] (<domain>://reference manuals — query syntax, field maps, examples) and optional PromptDef[] (registered canonical workflows, e.g. monthly_review)
  • Typed annotation vocabulary: readOnlyLocal · readOnlyExternal · writeCreate · writeUpdate · writeDelete · writeIrreversible — semantics reasoned once, one-liner per tool
  • runStdio(server) — stdio transport (local dev via .mcp.json, .mcpb packaging)
  • createHttpApp(makeServer) — Streamable HTTP via Express (remote/Vercel; stateless, fresh server+transport per request; add OAuth middleware in front of POST /mcp before production)
  • createLogger() — structured JSON logging to stderr with redaction by key AND by value-shape (long opaque strings under innocent keys), and child loggers
  • Cache — volatility-aware caching ({ immutable } → cache hard · { ttlMs } → expire · {} → no-cache), hit/miss/entries metrics, injectable clock (ported from bankingMCP's TtlCache)
  • FileTokenStore — per-account AES-256-GCM encrypted token store under the state dir (§2c; key in a 0600 keyfile), get/set/delete/list, account names hashed; TokenStore interface
  • generatePkce · runLoopbackOAuth · exchangeCode · refreshTokens — OAuth 2.1 Authorization-Code + PKCE loopback for local tools (the gmail-cli/banking pattern, generalized)
  • Ledger — append-only JSONL audit ledger (§2c): record/recent (for undo), seen (idempotent re-runs), hashPayload, redactForModel (LLM-safe reads) — the write-safety core

Planned (not yet implemented — don't reference these as available)

  • Multi-tenant / remote auth — per-client consent + fail-closed OAuth middleware in front of POST /mcp (the commercial / service-operation tier; the local oauth + FileTokenStore above cover the single-user default)
  • OS-keychain token store — Keychain/DPAPI/libsecret backing, stronger than the file+0600 baseline
  • Correlation ids end-to-end
  • Entitlement checks (for the optional commercialization layer)
  • Out-of-band approval for irreversible remote writes (the local Ledger + --confirm covers the CLI/local path)
  • Log forwarding to the client (capabilities: {logging} + sendLoggingMessage) — port from bankingMCP

Distribution

Published to public npm as @nordio/server-kit on every factory tag (release.yml). Consumers npm install @nordio/server-kit (no registry config) and depend on a version range — Dependabot delivers updates as PRs. Vendoring into the project's own workspace remains an option for fully self-contained scaffolds. Improvements flow back to the factory, not into forks.