npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

copilot-money-cli

v0.2.0

Published

Unofficial CLI for copilot.money — log in with a browser session and query your account data over GraphQL

Readme

copilot-money-cli

Unofficial command-line tool for copilot.money. Log in with your existing browser session and query your account data over Copilot's GraphQL API from the terminal.

Not affiliated with Copilot. Uses your own credentials against your own account.

How auth works

Copilot's API (https://app.copilot.money/api/graphql) authenticates with a Firebase ID token (Authorization: Bearer <token>). Those tokens expire after ~1 hour, so instead of copying a token repeatedly, this CLI reads the Firebase auth session your browser already stores. That session contains a long-lived refresh token plus the Firebase API key, which the CLI uses to mint fresh ID tokens automatically via Firebase's public securetoken endpoint.

You copy one value from the browser once; the CLI keeps itself logged in.

Install

pnpm install
pnpm build
npm link        # optional: exposes `copilot-money` on your PATH

Or run without linking via pnpm dev -- <command> (e.g. pnpm dev -- accounts).

Log in

Copilot's web app stores its Firebase session in IndexedDB (not localStorage), so grab it from there:

  1. Open https://app.copilot.money and sign in.

  2. Open DevTools (Cmd-Opt-I), Console tab.

  3. Paste this, run it, then copy the JSON it prints:

    (async () => {
      const db = await new Promise((ok, no) => {
        const r = indexedDB.open("firebaseLocalStorageDb");
        r.onsuccess = () => ok(r.result);
        r.onerror = () => no(r.error);
      });
      const all = await new Promise((ok, no) => {
        const r = db
          .transaction("firebaseLocalStorage", "readonly")
          .objectStore("firebaseLocalStorage")
          .getAll();
        r.onsuccess = () => ok(r.result);
        r.onerror = () => no(r.error);
      });
      const e = all.find((x) => x.fbase_key?.startsWith("firebase:authUser"));
      console.log(JSON.stringify(e.value));
    })();
  4. Select and copy that printed JSON (Cmd-C).

  5. Run copilot-money login and press Enter to confirm; it reads the JSON straight from your clipboard (no pasting into the terminal):

    copilot-money login

Non-interactive alternatives (handy for scripts, or if clipboard read is unavailable):

pbpaste | copilot-money login            # pipe the copied JSON (macOS)
copilot-money login --file session.json  # read from a file, then delete it

Credentials are stored at ~/.config/copilot-money-cli/credentials.json (directory 0700, file 0600). Run copilot-money logout to remove them.

Security note: that file holds your refresh token, so treat it like a password. It grants ongoing access to your Copilot account until you revoke the session (change your Copilot password / sign out everywhere).

Commands

All data commands print JSON to stdout, so they pipe cleanly into jq.

| Command | Description | | ---------------------------- | ---------------------------------------------------------------------------- | | copilot-money login | Store the browser session (--file <path> to read from a file) | | copilot-money logout | Remove stored credentials | | copilot-money whoami | Show the logged-in account and token status | | copilot-money accounts | List accounts and balances (--type filter, repeatable) | | copilot-money transactions | List transactions (filters below) | | copilot-money summary | Transaction totals: count, income, spent, net (same server filters) | | copilot-money categories | List categories and child categories | | copilot-money networth | Net worth history (--timeframe) | | copilot-money holdings | Investment holdings and securities | | copilot-money introspect | Dump the live GraphQL schema (disabled in prod; see docs/schema.md) | | copilot-money query [q] | Run any GraphQL operation (inline, --file, or stdin; --variables <json>) |

transactions flags

  • -n, --first <count> max to return (default 50; all in range with --from/--to)
  • --account <id> (client-side) · --category <id> · --tag <id> · --type <type> (all repeatable)
  • --reviewed / --unreviewed · --recurring / --one-time
  • --from <YYYY-MM-DD> / --to <YYYY-MM-DD> (inclusive, client-side)
  • --sort DATE|AMOUNT · --dir ASC|DESC · --edges (raw single page)

Valid enum values are shown in --help. See docs/schema.md for what the API does and does not support server-side (e.g. account/date filtering is client-side because the server has no filter for them; summary therefore has no --account or date range).

Examples

# Account balances
copilot-money accounts | jq '.[] | {name, balance}'

# Credit-card accounts only
copilot-money accounts --type CREDIT

# Income transactions in the first half of 2026
copilot-money transactions --type INCOME --from 2026-01-01 --to 2026-06-30 > income.json

# 200 most recent for one account, newest first
copilot-money transactions --account <accountId> -n 200

# Spend totals for a category
copilot-money summary --category <categoryId>

# Net worth over the last year
copilot-money networth --timeframe ONE_YEAR

# Run a custom query (strip @client fields — see docs/schema.md)
copilot-money query 'query { user { id termsStatus } }'

Notes on custom queries

The built-in queries mirror Copilot's own Apollo operations but omit all @client fields (computed in the browser and rejected by the server). If you write your own via copilot-money query, strip any @client fields (e.g. Account identifierId/status, Transaction datetime, Networth total). Introspection is disabled in production, so docs/schema.md documents the recovered types, enums, and filter behavior.

Development

pnpm dev -- <command>   # run from source via tsx
pnpm typecheck
pnpm test               # node:test, no build step
pnpm build              # emit dist/