npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@nsec/server

v0.4.0

Published

Zero-knowledge REST API and Web Dashboard server for NullSec / ZVault

Readme

@nsec/server

npm version License: MIT TypeScript

Zero-Knowledge REST API Server & Client-Side Decrypted Web Dashboard for NullSec / ZVault

Overview • Installation & Running • Architecture • Security & Access Control • Database Adapters • API Routes


Overview

@nsec/server is the backend orchestration and zero-knowledge synchronization service for NullSec (zVault). Built on top of Hono, it provides:

  • Zero-Knowledge Architecture: All secrets stored and exchanged are encrypted on the client side with AES-256-GCM. The server never holds or receives private keys or plaintext secrets.
  • Cryptographic Request Authentication: Validates Ed25519 digital signatures on incoming requests with anti-replay protection.
  • Built-in Web Dashboard: Client-side single-page application that decrypts secrets directly in the browser using the WebCrypto API.
  • Modern Storage Engine: Native SQLite support using Node.js built-in node:sqlite (zero compilation/native node-gyp dependencies), plus Cloudflare D1 and in-memory test adapters.
  • Access Control & BOLA Protection: Strict Broken Object Level Authorization checks ensuring users can only read or mutate projects and environments they are explicitly granted access to.

Installation & Running

1. Run with npx / CLI

The package provides three executable CLI aliases: nsec-server, nullsec-server, and zvault-server.

# Start server with default port 4000
npx @nsec/server

# Custom port, host, and persistent SQLite database
PORT=8080 HOST=0.0.0.0 DATABASE_PATH=/var/data/nullsec.db npx @nsec/server

2. Global Installation

npm install -g @nsec/server
nsec-server

3. Docker Deployment

docker run -d \
  -p 4000:4000 \
  -v /var/nullsec-data:/data \
  -e DATABASE_PATH=/data/nullsec.db \
  ghcr.io/chamesh2019/nsec-server:latest

Architecture

                  ┌──────────────────────────────────────────────┐
                  │              Incoming Request                │
                  │   Headers: X-NullSec-Signature, Timestamp    │
                  └───────────────────────┬──────────────────────┘
                                          │
                                          ▼
                       ┌─────────────────────────────────────┐
                       │      Authentication Middleware      │
                       │   - Anti-Replay Sliding Window      │
                       │   - Ed25519 Signature Verification  │
                       │   - Resolve Authenticated User      │
                       └──────────────────┬──────────────────┘
                                          │
                                          ▼
                       ┌─────────────────────────────────────┐
                       │     Project & BOLA Authorization    │
                       │   - Verify Project Membership       │
                       │   - Check Environment Role Perms    │
                       └──────────────────┬──────────────────┘
                                          │
                        ┌─────────────────┴─────────────────┐
                        ▼                                   ▼
             ┌─────────────────────┐             ┌─────────────────────┐
             │ REST API Endpoints  │             │ Web Admin Dashboard │
             │  /api/v1/projects   │             │   Client-side SPA   │
             │  /api/v1/secrets    │             │   In-browser crypto │
             └──────────┬──────────┘             └─────────────────────┘
                        │
                        ▼
             ┌─────────────────────┐
             │  Database Adapter   │
             │ (node:sqlite / D1)  │
             └─────────────────────┘

Security & Access Control

  1. Anti-Replay Attack Protection: All requests are timestamped. Signatures are verified and cached in a sliding time window (5-minute drift ceiling). Replayed requests with previously observed signatures are rejected immediately.
  2. First-User Bootstrap: The first user to register on a new instance automatically receives the admin server role. Subsequent registrations require a single-use signed invite token generated by an administrator.
  3. Environment-Level Scoping: Project members can be granted access to specific environments (e.g. ['development'] vs ['development', 'staging', 'production']) with read or admin permissions.
  4. Hardened HTTP Headers: Uses Hono secureHeaders (X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Cross-Origin-Opener-Policy: same-origin).

Database Adapters

@nsec/server abstracts all persistence behind the DatabaseAdapter interface:

import { startServer, SqliteDatabaseAdapter, MemoryDatabaseAdapter } from '@nsec/server';

// 1. Persistent production storage using Node 22+ built-in node:sqlite
const db = new SqliteDatabaseAdapter('./data/nullsec.sqlite');
await startServer({ port: 4000, db });

// 2. Ephemeral in-memory database for testing
const testDb = new MemoryDatabaseAdapter();
await startServer({ port: 0, db: testDb });

API Routes Summary

| Method | Path | Description | |---|---|---| | GET | /health | Healthcheck and service version | | GET | / | Web Dashboard SPA entry point | | POST | /api/v1/auth/register | Register user identity (Ed25519 & RSA public keys) | | POST | /api/v1/auth/rotate-keys | Cryptographically rotate identity public keys | | GET | /api/v1/users | List users on server (admin only) | | PATCH | /api/v1/users/:id/role | Update user server role (admin only) | | POST | /api/v1/invites | Create invite token (admin only) | | GET | /api/v1/invites | List active invite tokens | | DELETE | /api/v1/invites/:id | Revoke invite token | | POST | /api/v1/projects | Create a new project | | GET | /api/v1/projects/:id | Get project details (members only) | | POST | /api/v1/projects/:id/members | Add member and upload user-specific wrapped key | | GET | /api/v1/projects/:id/environments/:env/secrets | Fetch encrypted payload & caller envelope key | | PUT | /api/v1/projects/:id/environments/:env/secrets | Upload updated encrypted ciphertext | | POST | /api/v1/projects/:id/tokens | Create CI/CD service token |


License

MIT © NullSec / zVault Contributors