npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

sf-perms-lens

v1.2.0

Published

Salesforce Permissions Lens — visual permission inspector for Salesforce users

Downloads

493

Readme

SF Perms Lens

A world-class Node.js CLI + browser UI for inspecting Salesforce user permissions with full source lineage.

Features

| Feature | Details | |---|---| | Permission Lineage | See every permission a user has and exactly which Profile, Perm Set, or PSG grants it | | Object Permissions | Full CRUD/ViewAll/ModifyAll matrix across all assigned objects | | Field-Level Security | Expand any object row to see field-by-field Read/Write access inline | | Graph View | Infinite-canvas force graph: User → Profile/PermSets/PSGs → Permissions. Pan, zoom, save as SVG | | Raw JSON | Full data in Monaco editor with syntax highlighting, folding, and minimap | | AI Sidekick | Chat panel powered by Ollama, Claude, OpenAI, xAI, or Gemini to explain permissions | | Splitter | Drag the pane divider to resize the user list vs content area | | Dark / Light theme | Persisted to localStorage | | Download JSON | One-click export of the full permission payload | | Save SVG | Export the graph as a branded SVG with user/org/profile metadata header |

Requirements

  • Node.js ≥ 18
  • Salesforce CLI (sf) authenticated to the target org

Installation

npm install -g sf-perms-lens

Screenshots

sf-perms-lens-1

sf-perms-lens-2

sf-perms-lens-3

sf-perms-lens-4

sf-perms-lens-5a

sf-perms-lens-5b

sf-perms-lens-6

Usage

# Start — auto-opens browser
sf-perms-lens  -o <org-alias>

# Pre-select a user
sf-perms-lens  -o <org-alias> -u [email protected]

# Custom port, no auto-open
sf-perms-lens  -o <org-alias> -p 8080 --no-open

Options

| Flag | Description | Default | |---|---|---| | -o, --org <alias> | Salesforce org username or alias | required | | -u, --user <email> | Pre-select a user on load | — | | -p, --port <n> | HTTP port | 3579 | | --no-open | Don't auto-open the browser | — |

AI Sidekick

Click the chat bubble icon in the top-right to open the AI Sidekick panel. Click the ⚙️ gear icon to configure your LLM:

| Provider | What you need | |---|---| | Ollama | Running Ollama instance (default: http://localhost:11434). Click "Fetch Models" to auto-discover available models. | | Claude | Anthropic API key (sk-ant-…) | | OpenAI | OpenAI API key (sk-…) | | xAI Grok | xAI API key (xai-…) | | Gemini | Google AI API key (AIza…) |

Settings are saved to localStorage and persist across sessions.

How it works

  1. CLI starts an Express + WebSocket server on the given port
  2. Browser connects via WebSocket — analysis streams status updates in real time
  3. sf CLI is invoked server-side for all SOQL queries — no direct API calls from the browser
  4. Permission fields are discovered dynamically via sf sobject describe and queried in character-length-bounded batches to stay within Salesforce's HTTP 431 limits
  5. Object/field permissions use the profile's owned PermissionSet ID to avoid illegal multi-level relationship traversal in SOQL

Author

Mohan Chinnappan — Licensed under the MIT License.


Support this work

If this tool has helped you, please consider donating to one of Mohan's suggested charities:

  • St. Jude Children's Research Hospital — fighting childhood cancer and other life-threatening diseases. Donate to St. Jude

  • Any charity supporting Developing Countries — organisations providing food, clean water, education, or healthcare to communities in need.

Your generosity makes a real difference. Thank you.