npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@zanii/subject

v0.1.1

Published

Per-subject auditability: end users hold their own key and independently verify what agents did on their account — a pseudonymous, platform-scoped subject_tag receipt slice — without seeing anyone else's.

Readme

@zanii/subject

Per-subject auditability. A platform registers agents with Zanii; its millions of end users are the data subjects those agents act on. This package gives every end user their own key and their own independently verifiable slice of the ledger — what agents did on my account — without seeing anyone else's.

Owner-scoped views can't do this: an end user isn't an agent or an owner, and data subjects appear elsewhere only as salted, deliberately unqueryable commitments.

How it works. The platform stamps a pseudonymous, platform-scoped subject_tag on each receipt (a signature-covered SPEC §3 field). The end user — holding their own did:key the platform never sees — computes the same tag, pulls their slice from GET /v1/subjects/{tag}, and verifies every receipt offline: signature, delegation chain, scope, and tag match. Trust the maths, not the platform.

  • The same user gets a different tag on every platform — no cross-platform linkage.
  • A tag can't be reversed to an identity; receipts about other subjects aren't enumerable.
  • Field-level payload disclosure composes with @zanii/redact (the subject sees their fields, nothing else — payloads are off-ledger hashes).
npm install @zanii/subject @zanii/core

Platform side — stamp the tag

import { subjectTag } from '@zanii/subject';

const tag = subjectTag(endUser.did, 'platform.example.com');
await agent.record({ target: 'feed.rank', payload, subjectTag: tag }); // SDK ≥0.4.0

End-user side — audit your own slice

import { subjectIdentity, fetchMyHistory, signSubjectClaim, verifySubjectClaim } from '@zanii/subject';

const me = subjectIdentity();                       // your key — the platform never holds it
const history = await fetchMyHistory(me.did, 'platform.example.com');
history.verified;                                    // every receipt checked offline
history.receipts.map((r) => r.receipt.target);       // what agents did on YOUR account

// prove "this is my slice" to an app (sig by your key + the tag derives from your DID):
const claim = signSubjectClaim({ platform: 'platform.example.com', subjectDid: me.did, ts }, me.privateKey);
verifySubjectClaim(claim); // true

Honest limit: the slice is only as complete as the platform's stamping — a platform that omits subject_tag hides that receipt from the subject's view (never from the log itself). Systematic omission is detectable via reconciliation and consent receipts; per-subject auditability is verifiable, not magic.

Changelog

  • 0.1.0 — initial release: subjectTag, subjectIdentity, signSubjectClaim/verifySubjectClaim, fetchSubjectHistory/fetchMyHistory.

License

Apache-2.0.