
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@usesentinel/express
Advanced tools
Sentinel middleware for Express - Track your API requests automatically
Sentinel middleware for Express - Track your API requests automatically.
npm install @usesentinel/express
# or
yarn add @usesentinel/express
# or
pnpm add @usesentinel/express
Simply add the middleware to your Express app:
import express from "express";
import { sentinel } from "@usesentinel/express";
const app = express();
// Add body parser middleware before sentinel
app.use(express.json());
app.use(express.urlencoded({ extended: true }));
// Add Sentinel middleware
app.use(sentinel()); // That's it!
app.get("/", (req, res) => {
res.json({ message: "Hello World" });
});
app.listen(3000);
The SDK automatically reads from environment variables:
SENTINEL_API_KEY (required) - Your Sentinel API keyYou can also pass options directly:
app.use(
sentinel({
apiKey: "sk_...", // Optional if SENTINEL_API_KEY is set
batchSize: 50, // Optional, default 50
flushInterval: 5000, // Optional, default 5000ms
excludePaths: ["/health", "/metrics"], // Optional
})
);
You can track sub-operations within a request (like database queries, external API calls, etc.):
import { registerStep } from "@usesentinel/express";
app.get("/users", async (req, res) => {
if (!req.sentinel) {
return res.status(500).json({ error: "Sentinel not initialized" });
}
// Track a database query
const endDbStep = registerStep(req.sentinel.requestId, "db_query", {
table: "users",
operation: "SELECT",
});
const users = await db.query("SELECT * FROM users");
endDbStep(); // Step completes here
// Track an external API call
const endApiStep = registerStep(req.sentinel.requestId, "external_api_call", {
service: "payment_gateway",
});
const payment = await fetch("https://api.payment.com/charge", {
method: "POST",
body: JSON.stringify({ amount: 100 }),
});
endApiStep?.();
res.json(users);
});
The steps will be automatically included in the event sent to Sentinel, allowing you to see which parts of your request took the longest.
You can set userId for a request to track user behavior:
import { setUserId } from "@usesentinel/express";
app.get("/users", async (req, res) => {
// Get user from your auth system
const user = await getCurrentUser();
// Identify the user making the request
if (req.sentinel) {
setUserId(req.sentinel.requestId, user.id);
}
res.json(users);
});
The userId will be automatically included in the event sent to Sentinel.
The middleware automatically:
Events are batched and sent automatically, so there's minimal performance impact. Failed requests are automatically retried with exponential backoff (up to 3 retries by default).
express.json() or express.urlencoded()) before the Sentinel middleware so that request bodies can be captured.sentinel property to the Express Request object, which contains the request context including requestId.FAQs
Sentinel middleware for Express - Track your API requests automatically
We found that @usesentinel/express demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.