npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@zephytiju/juntai-typescript-sdk

v3.8.0

Published

Aggregate generated TypeScript clients for Console-facing Juntai services

Readme

Juntai TypeScript SDK

@zephytiju/juntai-typescript-sdk is the single aggregate npm package for generated clients of Console-facing Juntai services. It consumes reviewed, immutable, service-owned OpenAPI artifacts and publishes all approved clients under collision-free full-service-ID subpaths.

npm install @zephytiju/juntai-typescript-sdk
import { createClient as createDefinitionClient } from "@zephytiju/juntai-typescript-sdk/services/axiom.definition";
import { createClient as createOperationsClient } from "@zephytiju/juntai-typescript-sdk/services/axiom.operations";
import { createClient } from "@zephytiju/juntai-typescript-sdk/services/platform.application-metadata";
import { createClient as createAccountClient } from "@zephytiju/juntai-typescript-sdk/services/platform.account";
import { createClient as createBlueprintClient } from "@zephytiju/juntai-typescript-sdk/services/platform.blueprint";
import { createClient as createIamClient } from "@zephytiju/juntai-typescript-sdk/services/platform.iam";
import { createClient as createVanguDeploymentClient } from "@zephytiju/juntai-typescript-sdk/services/platform.vangu-deployment";
import { createClient as createUsageCostClient } from "@zephytiju/juntai-typescript-sdk/services/juntai.usage-cost";
import { createClient as createPrismCompositionClient } from "@zephytiju/juntai-typescript-sdk/services/prism.composition";
import { createClient as createPrismBuildClient } from "@zephytiju/juntai-typescript-sdk/services/prism.build";
import { createClient as createLatticeOntologyClient } from "@zephytiju/juntai-typescript-sdk/services/lattice.ontology";
import { createClient as createLatticeGenerationClient } from "@zephytiju/juntai-typescript-sdk/services/lattice.runtime-generation";

All imports resolve from this one aggregate dependency; there are no service-specific npm packages. Account exposes opaque Account/v1, AccountProfile/v1, integration-binding, stable-error, authorization-action, idempotency, and concurrency contracts. Application Metadata includes the exact application-documentation discovery contract, Blueprint exposes only the Console-facing Blueprint Service API, IAM exposes the exact same-origin account and immutable-application administration contract, and Vangu Deployment exposes authorized target inspection plus immutable PREVIEW, APPLY, and REMOVE execution control.

Axiom Definition exposes generated pipeline creation and discovery, revision history, validation, readiness, release, and release-search contracts. Axiom Operations exposes generated execution and production-activity discovery, import validation and submission, checkpoint inspection, source-gap search, redrive, and waiver contracts. Both clients preserve the owning services' required tenant, request, authorization, idempotency, cursor, and stable-error types without handwritten Axiom DTOs.

Prism Composition exposes Operating System and UI-page authoring, exact revisions, layout-variant application, and Ready for release. Prism Build exposes build creation, lookup, pagination, and deliberate retry for exact Ready-for-release revisions with [email protected]; historical [email protected] requests and receipts remain supported. Inject context.fetch and the reviewed same-origin gateway base URL for each service. Draft mutations preserve If-Match; commands preserve Idempotency-Key. After an ambiguous response, recover by the existing operation identity instead of automatically replaying the command. A successful build confirms publication and association; application sealing and deployment remain with Application Metadata and Vangu.

Version 3.8.0 adds resolveBuildSubmission from Build Service 1.3.0. Pass the original Idempotency-Key header and exact application_id path value to recover {build, identityExpiresAt} without a request body or query. SUBMISSION_NOT_FOUND is point-in-time absence; SUBMISSION_IDENTITY_EXPIRED is unresolved recovery. Neither permits automatic create/retry or payload matching. Preserve a scoped local identity before submitting, and keep it out of URLs and telemetry. The returned BuildView is authoritative under current application/build read access.

Version 3.7.0 pins Composition and Build Service 1.2.0. getUiPageDraft accepts includeAuthoring: true with blueprintAssetId, blueprintVersionId, and targetSlotId for an unplaced candidate, or instanceId for one saved instance; omitting selectors projects the current instances. Candidate discovery requires no prior binding fingerprint. The generated projection includes typed declarations, original Schema definitions (including boolean schemas), preset digests and explicit default absence. Save optional LayoutNodeInput.splitAllocation with version 1 and positive child-ID shares totaling 1000000; exact template validation and persistence belong to Composition. Allocated snapshots require Builder 1.2.0. Authorization, stale ETag, incompatible metadata and oversize errors remain visible to callers.

IAM consumers inject the session-aware fetch supplied by ConsolePageContext; the client neither owns credentials nor calls a protected origin directly:

const iam = createIamClient({
  baseUrl: "/",
  fetch: context.fetch,
});

const account = createAccountClient({
  baseUrl: "/",
  fetch: context.fetch,
});

Lattice consumers

The package exposes latticeOntology and latticeRuntimeGeneration root namespaces, also available under clients["lattice.ontology"] and clients["lattice.runtime-generation"]. Their full service subpaths expose generated operations, types, and isolated factories from LatticeModelConfigurationService 0.4.0 and LatticeRuntimeGenerationService 0.1.0. sources/openapi.lock.json records each exact source revision, OpenAPI SHA-256, and output digest.

import { latticeOntology, latticeRuntimeGeneration } from "@zephytiju/juntai-typescript-sdk";

// Use the same-origin gateway paths reviewed for the host Console deployment.
const ontology = latticeOntology.createClient({ baseUrl: ontologyGatewayPath, fetch: context.fetch });
const generation = latticeRuntimeGeneration.createClient({ baseUrl: generationGatewayPath, fetch: context.fetch });
// Source selection is read-only and does not create an import plan.
const source = await latticeOntology.readBlueprintSource({
  client: ontology,
  path: { asset_id: assetId, version_id: exactVersionId },
  query: { limit: 50 },
});
if (source.data) {
  const selected = await latticeOntology.readBlueprintDefinition({
    client: ontology,
    path: { asset_id: assetId, version_id: exactVersionId, definition_id: definitionId },
    query: { expected_digest: source.data.source_digest },
  });
}
const preview = await latticeOntology.previewDefinitions({
  client: ontology,
  body: { bundle_id: bundleId, bundle_revision: revision, definition_ids: selectedDefinitionIds },
});
const operation = await latticeRuntimeGeneration.getGenerationOperation({
  client: generation,
  headers: { "X-Juntai-Application-ID": applicationId },
  path: { generation_operation_id: operationId },
});

Version 3.6.0 adds listBundleVersions, listDefinitionVersions, readBlueprintSource, and readBlueprintDefinition. Revision pages retain the first page’s through_revision on continuation; exact source pages retain source_digest as expected_digest. Source browsing returns bounded summaries; full definition reads preserve code authorization. Stale, missing, and denied reads remain typed errors. Blueprint discovery and exact resolution use the existing platform.blueprint contract.

Pass each factory instance through the operation's client option. Relative gateway paths work in the browser; server adapters use an absolute URL. Console owns session-aware fetch and rejects protected cross-origin calls. The SDK supplies neither session credentials nor gateway registration. Operations use the exact released flat names and snake_case request properties. Authoring commands preserve body expected_bundle_revision and idempotency_key; generation requires application scope and preserves exact reference versions, including Object version "1". Cancellation forwards If-Match when supplied, and evidence reads require expected_digest. Inspect returned data, error, response, and ETag; an accepted generation remains queued until authoritative lookup reports a terminal status. After an ambiguous command, recover using its existing identity instead of automatically replaying it.

npm run check:consumer installs a packed release into a clean directory, checks ESM exports and TypeScript declarations, bundles it for the browser without Node shims or runtime dependencies, and runs Chromium against explicit same-origin HTTP adapter fixtures. It exercises read-only source selection, digest-pinned pagination, exact definitions, authoring, preview/release, generation lookup/cancellation/evidence, pagination, session/correlation forwarding, denial, stale revision, expiry, cancellation, isolation, and lost-response recovery. These are SDK contract fixtures; service deployment and end-to-end LatticeConsole acceptance remain with their owning tasks. Run npx --no-install playwright install --with-deps chromium before local verification. --tarball <path> tests an already downloaded release; publication CI runs this against the integrity-verified public npm tarball.

The withdrawn unscoped [email protected] publication is historical metadata only. Do not install it or treat it as target release evidence.

The repository has one package manifest, one canonical multi-source lock, one generated tree, one distribution directory, one changelog, one tarball, and one release pipeline. It never publishes service-specific packages or partial releases.

Releases authenticate to npm through Trusted Publishing with GitHub OIDC. Because the source repository is private and npm accepts Sigstore provenance only from public GitHub repositories, npm Sigstore provenance is disabled. The published tarball still carries dist/release-manifest.json and sources/openapi.lock.json, which pin every service-owned OpenAPI release, source commit, artifact digest, and generated output digest.

Onboarding

An owning service contributes a reviewed sources/registrations/<service-id>.json that pins its immutable OpenAPI artifact, source commit, release, generator profile, export namespace, and compatibility classification. Run:

npm ci
npm run fetch:artifacts
npm run resolve
npm run generate
npm run sync:exports
npm run verify

Generation reads only sources/openapi.lock.json, creates a clean temporary source tree, verifies every output digest, and transactionally replaces the checked-in tree. CI regenerates twice and requires byte-identical output and a clean Git diff.

Boundary

Browser code calls an owning backend service through its module in this package. Configuration Registry, Artifact Registry, Registry metadata contracts, OCI workflows, and Juntai Query Engine are backend-only and are deliberately rejected by onboarding and packaging checks. Owning backend services use the Python distributions juntai-configuration-client and juntai-artifact-client; neither is an npm dependency or TypeScript surface.