npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@quietflow/runtime-client

v0.1.4

Published

Read approved company data from inside a Quiet Flow app — one call that works under `qf dev` and deployed, without the app ever holding a credential.

Readme

@quietflow/runtime-client

How an app published to Quiet Flow reads company data. One function, one shape of answer, and the same code whether the app is running under qf dev on the builder's machine or deployed for the whole company.

npm install @quietflow/runtime-client
import { readCompanyData } from "@quietflow/runtime-client";

app.get("/accounts", async (request, response) => {
  const answer = await readCompanyData(request, {
    capability: "crm.read",
    operation: "list_accounts",
  });
  response.json(answer);
});

Pass the incoming request through — it is how Quiet Flow knows which employee is asking — and name a capability and an operation. Both of those names are printed together on Company data in Quiet Flow, under the account you are reading from, and list_company_systems says the same pair to an assistant (#622). Write them exactly as they are given: an operation name taken off an IT screen is the provider's own name for the action, which is a different string and is refused. Where the app's manifest declared more than one place it reads that kind of data from, add as: "acquired-customers" to say which. An operation may declare safe scalar inputs, such as parameters: { withinDays: 14 }. These are named and bounded by the connector; they are not filters. There is no field list, row predicate, or query, because Quiet Flow builds the real request from what the Data Owner approved.

The answer is { status, records, page, scope }. status is ok, denied, provider_unavailable, or unavailable; on anything but ok there is a message already written for the person using the app — show it as it is. While nobody has approved real access yet, qf dev serves invented rows in the real shape and marks the answer sample: true, so the app can say so on screen. When answer.page.hasMore is true, call again with page: { cursor: answer.page.cursor }; the cursor is opaque and must be reused, not constructed.

What it does

  • Chooses its own authentication. Under qf dev it uses the run's dev session; deployed it uses the identity file the platform mounts. App code never branches on the difference.
  • Re-reads the app's identity on every call. The platform rotates it; nothing here caches it, so nothing here expires an hour in.
  • Forwards who is asking. Deployed, the gateway's signed context is required — a request without one is refused with a sentence, never sent unauthenticated.
  • Rejects redirects and incomplete answers. The app's identity is sent only to the configured broker endpoint, and a rolling upgrade cannot turn a partial response into a value the app was promised was complete.

What it does not do

  • Run in a browser. It refuses with a sentence. Ask from server-side code and send the result to the page.
  • Write anything. This is a read client.
  • Accept a query. Safe operation parameters and broker-issued page cursors are supported; fields, filters, expansions, and queries are not, and an extra property on the call never reaches the wire.
  • Hold a credential. There is no token to configure, copy, or leak.