npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

envelopa

v0.3.0

Published

Headless TypeScript library for end-to-end encrypted document storage

Readme

envelopa

Headless TypeScript library for building applications that store documents with end-to-end encryption.

Envelopa implements vault lifecycle, cryptographic envelopes, password-based key derivation, password rotation, and interoperable serialization. It does not provide authentication, databases, sync, networking, UI, or account management — those belong in your application layer.

Requirements

  • Node.js >= 20 (or a modern browser with Web Crypto API)
  • ESM ("type": "module")

Development

From the monorepo root:

pnpm install
pnpm build
pnpm test:browser

The first run downloads Chromium via Playwright automatically (pretest:browser). If you see Executable doesn't exist, run manually:

pnpm --filter envelopa exec playwright install chromium

Install

npm install envelopa @envelopa/argon2

@envelopa/argon2 is required at runtime. Envelopa keeps the KDF in a separate package so the core stays runtime-neutral.

Quickstart

import { argon2id } from '@envelopa/argon2';
import {
  createVault,
  unlockVault,
  encodeVaultHeader,
  decodeVaultHeader,
  envelopeToJson,
  envelopeFromJson,
} from 'envelopa';

const kdfProvider = argon2id();
const password = 'user-chosen-password';

// Create a vault
const { header, session } = await createVault({
  password,
  kdfProvider,
});

// Persist the vault header (CBOR bytes — not plain JSON)
const headerBytes = encodeVaultHeader(header);
const headerB64 = Buffer.from(headerBytes).toString('base64url');

// Seal a document
const envelope = await session.seal({
  documentId: 'note_123',
  data: new TextEncoder().encode('secret content'),
  context: { type: 'note' },
});

const envelopeJson = envelopeToJson(envelope);
session.destroy();

// --- later, in another session ---

const storedHeader = decodeVaultHeader(Buffer.from(headerB64, 'base64url'));
const unlocked = await unlockVault({
  password,
  header: storedHeader,
  kdfProvider,
});

const plaintext = await unlocked.open(envelopeFromJson(envelopeJson));
console.log(new TextDecoder().decode(plaintext));

unlocked.destroy();

Text helpers

For UTF-8 string content, use the envelopa/text subpath:

import { sealText, openText } from 'envelopa/text';

const envelope = await sealText(session, {
  documentId: 'note_123',
  text: '# Hello\n\nMarkdown here.',
});

const text = await openText(session, envelope);

API surface

| Subpath | Exports | | ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | | envelopa | createVault, unlockVault, encodeVaultHeader, decodeVaultHeader, encodeEnvelope, decodeEnvelope, envelopeToJson, envelopeFromJson, error types | | envelopa/text | sealText, openText | | envelopa/crypto | WebCryptoProvider, CryptoProvider type | | envelopa/testing | DeterministicCryptoProvider (tests only — unsafe for production) |

VaultSession exposes seal, open, rotatePassword, and destroy. The concrete implementation is not exported.

Persistence

| Artifact | Format | Functions | | ------------------ | ---------------------------------- | ----------------------------------------- | | Vault header | Canonical CBOR bytes | encodeVaultHeader / decodeVaultHeader | | Encrypted envelope | JSON (base64url for binary fields) | envelopeToJson / envelopeFromJson |

The in-memory VaultHeader type contains Uint8Array fields. Encode explicitly before storing in a database or file.

See docs/serialization.md for format details and persistence patterns.

Documentation

Security scope

Protects against:

  • Compromised database or storage provider (data at rest)
  • Network interception of encrypted envelopes
  • Malicious modification of persisted envelopes
  • Offline password guessing (mitigated by Argon2id)

Does not protect against:

  • Compromised client device or malicious JavaScript in your app origin
  • Keyloggers or password theft
  • Plaintext exposure while the vault session is unlocked
  • Rollback attacks without external trusted versioning

See docs/architecture.md for a threat model summary. A formal threat model document is planned for 1.0.

Stability

0.3.0 completes protocol v1 test vectors, adds docs/protocol-v1.md, and migrates the repository to envelopa-dev/envelopa. The cryptographic protocol is versioned (version: 1), but the API may evolve before 1.0.0.

Specifications

Public documentation: docs/ (architecture, serialization, protocol v1).

License

MIT