npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@rolino/contracts

v0.13.1

Published

Versioned public API contracts for Rolino

Downloads

1,557

Readme

@rolino/contracts

Facebook Page video update

The Page video release adds VIDEO to Facebook delivery options. Earlier clients reject that value. After the coordinated release is published, update the installed SDK, CLI, or local MCP package; update contracts too if imported directly. Restart local MCP and update pinned launch versions. Hosted MCP updates with the server. See package upgrade instructions.

The package includes strict shared backlink prospecting schemas for bounded targets, discoveries, prospects, score evidence, stages, public contacts, outreach drafts, and exact-link verification. The independent backlinks:read, backlinks:write, and backlinks:contacts capabilities do not widen existing credentials.

Zod schemas and TypeScript types for Rolino's versioned public API. This package contains transport-safe DTOs only; it must not depend on Prisma, Next.js, auth providers, or server implementation details.

Storage-management contracts add the independent optional storage:read and media:delete capabilities, exact workspace usage, bounded project or workspace media lists, and confirmation-bound cleanup preview, execute, and status DTOs. Cleanup selections contain at most 500 candidates. Public DTOs omit storage keys, provider errors, credentials, and internal queue records. Workspace media items always include their project ID and project name. Media cursors are opaque deployment-time pagination state and are not long-term IDs.

Contract 0.19 covers discovery, identity, capabilities, project reads and idempotent project creation, safe post and calendar reads, idempotent draft writes, and server-confirmed Instagram, TikTok, YouTube, Bluesky, and LinkedIn scheduling and immediate publishing. YouTube additions include explicit draft settings, provider readiness, early scheduled preparation, and typed pending schedule reconciliation. Bluesky additions include 300-grapheme caption overrides, text-only and image readiness, health, scheduling, and publishing. TikTok additions include separately reviewed draft choices, secret-safe account-level delivery options, server-stamped review time, and exact interaction enforcement. LinkedIn additions include a 3,000-character destination override, text, single/multi-image, and single-video readiness, plus a strict member-delivery-options variant that exposes JPEG/PNG and native MP4 limits without credentials. Draft updates are partial, and post reads expose reusable asset IDs plus provider-keyed sanitized settings so future provider variants remain additive. It also adds the exact optional seo:read capability plus bounded read-only opportunity and weekly-report DTOs. These SEO DTOs contain canonical versioned tasks, safe evidence, neutral provenance, separate topic-relevance and action-readiness confidence, and recommended actions. They exclude credentials, provider names, raw responses, provider request IDs, cost data, signal IDs, and integration IDs. The additive task has an exact READY, NEEDS_REVIEW, or REJECTED decision, selected format, unbiased format options for Research, keyword target, exact deliverables, research, safe URLs, evidence, limitations, success metric, and execution boundaries. Accepted opportunities expose READY or NEEDS_REVIEW; a rejected finding has no active task. A Research task selects only RESEARCH_TASK, names no preferred final format, and returns VALIDATED with a complete next task or REJECTED with evidence before any separate draft action. Older stored reports receive a review-only compatibility task when read; their saved snapshots are not changed.

Blog Studio contracts include provider catalog entries, safe publishing destination readiness, delivery-attempt summaries, and exact destination selection for approval, publication, scheduling, and cancellation preview and execution. The independent blog:approve capability binds one immutable revision and reviewed-image snapshot. blog:publish does not grant approval, and blog:write cannot approve or publish. Existing credentials do not gain a new capability. Provider catalog reads require blog:manage. Destination and delivery-attempt reads require blog:read. These DTOs omit draft content, prompts, evidence, secrets, encrypted values, and raw provider responses. A contract type does not make a hidden provider available; the server rollout registry remains authoritative.

Clients must read current setup and article or plan state, resolve missing website, cadence, destination, and access-level choices, poll import and plan jobs, present evidence, create one immutable revision with catalog-backed links, review one generated or approved uploaded image and its alt text, stop when approval or publication scope is missing, use confirmation-bound and idempotent approval before publication, verify live delivery, and restart from approval preview after any content or image change. A queued delivery is not a published delivery.

Project and post DTOs intentionally omit storage credentials, upload sessions, tokens, and other publishing-provider internals.

Every destination reports an explicit deliveryMode (IMMEDIATE or SCHEDULED) and lifecycle stage. For YouTube, immediate delivery preserves the requested Public, Unlisted, or Private visibility and never creates a schedule. Scheduled delivery requires Public visibility; Rolino uploads the video privately first, and CONFIRMING_SCHEDULE means the upload is complete while YouTube acknowledges the requested future publish time.

Contract support does not imply that a deployment enabled YouTube, Bluesky, or LinkedIn, or completed Google/YouTube review. Servers remain authoritative for provider gates, readiness, confirmation, and reconciliation. Operators should follow the YouTube operations guide and Bluesky operations guide, and LinkedIn operations guide.

This is a supported transitive dependency of the public SDK, CLI, and MCP packages. Most users should install one of those entry points rather than installing contracts directly.

Support, security, and license

Stable releases are published only after the maintainer approves the release gate. Report bugs through the Rolino issue tracker and security issues through the repository's security policy.

@rolino/contracts is available under the MIT License.

Website integrations

Umami and Datafast reports and confirmed management, plus confirmed Astro setup, are available through the shared agent operations. See the website integration guide for permissions, inputs, secret handling, and recovery.