npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

shein-cart

v0.1.1

Published

See what is in a shared SHEIN cart from the terminal, or open it in any browser

Downloads

234

Readme

shein-cart

Someone shares their SHEIN cart with you and what you get is a onelink.shein.com URL that only really works inside the SHEIN app. On a phone without the app it falls through to the mobile site. On a laptop it drops you on the SHEIN homepage and the cart is nowhere.

This takes that link and shows you the cart: every item with its photo, colour and size, price, discount, stock, and a link to the product page. It also gives you the plain m.shein.com URL that opens the same cart in any browser, so you can send that one instead.

There's a site at https://cart-viewer.ibrahimwithi.com and a CLI.

CLI

npx shein-cart "https://onelink.shein.com/51/xxxxxxxx?shc=2_xxxxxxxxxxx"

Needs Node 18+. Paste the whole message if that's what you have, it finds the link in it. Piping works too: pbpaste | shein-cart.

shein-cart -c EGP "https://onelink.shein.com/51/..."      # prices in another currency
shein-cart --link "https://onelink.shein.com/51/..."      # only the browser link
shein-cart --open "https://onelink.shein.com/51/..."      # and open it
shein-cart --json "https://onelink.shein.com/51/..."      # the cart as JSON

What the link actually does

I traced it because the redirect chain isn't obvious from a browser. The onelink page is a bit of HTML with a script that tries the app deeplink and falls back to api-shein.shein.com/h5/sharejump/appjump. That page has the cart's group_id embedded twice (in the deeplink and in a shareInfo JSON) and, on a phone, forwards to m.shein.com/cart/share/landing. With a desktop user agent it forwards to the homepage instead, which is the whole problem.

The landing page loads the items with one POST to m.shein.com/bff-api/order/cart/share/landing. All that call checks is that an armorUuid cookie is there and shaped like the ones m.shein.com hands out, a timestamp and 50 hex characters, so this mints one instead of fetching a page for it. No login, no app headers, no risk tokens.

Heads up

  • It's SHEIN's private endpoint. When they change it this breaks and src/shein.js gets patched.
  • Prices are guest prices and SHEIN reprices per request, so the total moves by a dollar or two between runs. A currency is a header away (-c EGP), but each site only offers some and quietly answers in its own when asked for one it lacks. EGP exists on the global site alone, so the website, which cannot reach the global site (below), shows USD and says so; the CLI run from Egypt gets EGP. Language is the site's, not yours.
  • The share payload has no quantities. You get each item and its variant, not how many.
  • SHEIN runs one site per region and a cart shared from the global site is only visible on some of them. The global site is also geo-routed at the CDN, so from Europe or the US a request to it lands on a regional site that shows an empty cart. This asks the link's own site first and then the regional ones that can see global carts (au, ar, mx). The output says which site answered, and that site's prices and language are what you get.
  • None of this works from a static page: the endpoints send no CORS headers and the cookie belongs to m.shein.com. That's why the site is a Worker.

The site

A Cloudflare Worker. public/index.html is served as a static asset, worker/index.js answers the API, and both sit on src/shein.js, which is plain fetch and runs unchanged in Node.

npm install
npm run dev       # http://localhost:8787
npm run deploy    # the route in wrangler.toml is my hostname, change it

/api/cart?link=…&currency=EGP returns the cart as JSON, /api/resolve?link=… just the ids and the browser link, and /go?link=… is a 302 to that link so it works behind a bookmark.

Tests

npm test covers the link parsing and the payload normalisation. The network path I check by hand against a real link.

License

MIT