npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@zafu/protocol

v0.2.0

Published

Versioned, transport-agnostic contract for the zafu_* wallet<->dapp API

Readme

@zafu/protocol

The versioned, transport-agnostic contract for the zafu_* wallet ↔ dapp API - the shared source of truth that the zafu wallet and the @zafu/zid SDK are both checked against.

Most apps want @zafu/zid, not this package directly. Reach for @zafu/protocol when you are building your own client or a non-extension transport and want the typed request/response shapes and the version constant.

Install

npm install @zafu/protocol

What's in it

  • ZAFU_PROTOCOL_VERSION / ZAFU_SUPPORTED_PROTOCOL_VERSIONS - the wire-protocol major(s), negotiated over the ping handshake.
  • Method types - typed request/response shapes for the v1 surface: ping, zafu_sign, zafu_zid_pubkey, zafu_request_capability, zafu_encrypt, zafu_decrypt, zafu_pick_contacts. ZAFU_V1_METHODS lists them; ZafuRequest<M> / ZafuResponse<M> map a method to its shapes.
  • ZafuTransport - the pluggable transport interface. The message shapes say what crosses the wire; a transport says how it gets there (an extension bridge today; a relay or native host tomorrow).
import {
  ZAFU_PROTOCOL_VERSION,
  isZafuError,
  type ZafuTransport,
  type ZafuRequest,
  type ZafuResponse,
} from '@zafu/protocol';

async function zidPubkey(t: ZafuTransport) {
  const resp = await t.request('zafu_zid_pubkey', { type: 'zafu_zid_pubkey' });
  if (isZafuError(resp)) throw new Error(resp.error);
  return resp.pubkey; // hex ed25519, plus resp.pq_pubkey for post-quantum
}

The shapes describe the wire faithfully, including the historical per-method response inconsistencies; a higher-level SDK (@zafu/zid) normalises them into typed-or-throw calls.

Post-quantum

Confidentiality-bearing methods carry an additive post-quantum path (pq_pubkey on zafu_zid_pubkey, recipient_pq on zafu_encrypt) using the hybrid X25519 + ML-KEM-768 KEM from @zafu/pq. Additive: pre-PQ wallets simply omit the fields.

License

MIT