npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

ars-facebook-auth

v1.0.1

Published

Lightweight Facebook authentication library for Node.js

Readme

🔐 ars-facebook-auth

Lightweight Facebook access token verification for Node.js and TypeScript

Validate a Facebook user access token, confirm that it belongs to your app, and receive a normalized user profile through one typed function.

npm version License: MIT TypeScript Node.js


Contents

✨ Features

  • Validates Facebook user access tokens
  • Confirms that a token was issued for your Facebook app
  • Generates appsecret_proof using your app secret
  • Fetches the user's ID, name, email, and profile picture
  • Normalizes missing profile fields to null
  • Supports custom Facebook Graph API versions
  • Provides TypeScript types with no runtime dependencies

📦 Installation

npm install ars-facebook-auth
import { verifyFacebookToken } from 'ars-facebook-auth';

const profile = await verifyFacebookToken(accessToken, {
  appId: process.env.FACEBOOK_APP_ID!,
  appSecret: process.env.FACEBOOK_APP_SECRET!,
});

console.log(profile);

Example response:

{
  id: '123456789',
  name: 'Jane Doe',
  email: '[email protected]',
  picture: 'https://platform-lookaside.fbsbx.com/...'
}

ars-facebook-auth has no NestJS dependency. You can wrap it in an injectable service and keep your Facebook credentials in server-side configuration.

import { Injectable } from '@nestjs/common';
import { ConfigService } from '@nestjs/config';
import {
  verifyFacebookToken,
  type FacebookProfile,
} from 'ars-facebook-auth';

@Injectable()
export class FacebookAuthService {
  constructor(private readonly configService: ConfigService) {}

  verify(accessToken: string): Promise<FacebookProfile> {
    return verifyFacebookToken(accessToken, {
      appId: this.configService.getOrThrow<string>('FACEBOOK_APP_ID'),
      appSecret: this.configService.getOrThrow<string>('FACEBOOK_APP_SECRET'),
    });
  }
}

🧰 API reference

verifyFacebookToken(accessToken, options)

Validates the supplied access token and returns its associated Facebook profile. The function rejects with an Error if validation or profile fetching fails.

function verifyFacebookToken(
  accessToken: string,
  options: FacebookAuthOptions,
): Promise<FacebookProfile>;

Configuration

  • appId — Facebook app ID. Required.
  • appSecret — Facebook app secret. Required.
  • graphVersion — Facebook Graph API version. Optional; defaults to v19.0.
type FacebookAuthOptions = {
  appId: string;
  appSecret: string;
  graphVersion?: string;
};

Returned profile

type FacebookProfile = {
  id: string;
  name: string | null;
  email: string | null;
  picture: string | null;
};

[!NOTE] email may be null because Facebook does not always return it. Other unavailable optional profile fields are also normalized to null.

🛟 Error handling

import { verifyFacebookToken } from 'ars-facebook-auth';

try {
  const profile = await verifyFacebookToken(accessToken, {
    appId: process.env.FACEBOOK_APP_ID!,
    appSecret: process.env.FACEBOOK_APP_SECRET!,
  });

  console.log(profile);
} catch (error: unknown) {
  const message =
    error instanceof Error ? error.message : 'Facebook authentication failed';

  console.error(message);
}

Errors are thrown when required values are missing, a token is invalid, a token belongs to another app, or Facebook profile retrieval fails.

✅ Requirements

  • Node.js 18 or later with the global fetch API available
  • A Facebook app ID and app secret
  • A Facebook user access token issued for the configured app

🛡️ Security

[!WARNING] FACEBOOK_APP_SECRET must never be exposed to frontend or client-side code.

  • Call this package only from a trusted server environment.
  • Store app credentials in environment variables or a secrets manager.
  • Never commit app credentials or access tokens to source control.
  • Treat user access tokens as sensitive data and avoid logging them.

📄 License

Released under the MIT License © 2026 A R S.