
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@crela/license
Advanced tools
License verification SDK for Crela marketplace tools (Node.js / Electron). Reads JWT from launcher-injected env var or cache file, verifies offline via Ed25519.
License verification SDK for tools on the Crela marketplace.
Mandatory for paid tools: the review pipeline looks for a per-tool marker inside your binary (KO-10), and this SDK is what puts it there and checks the licence at startup.
For Node.js and Electron projects, let the init tool wire everything up:
cd my-tool/
npx @crela/init
It detects your entry point and bundler, fetches the SDK marker via the API, injects verifyOrExit(), and patches your bundler config. After that, just run npm run build.
The SDK never prompts for a licence key. It reads a JWT signed by the Crela launcher — either from the environment variable CRELA_LICENSE_JWT or from a cache file — and verifies it offline against an Ed25519 public key. No network call happens.
Activation, heartbeat and device management are handled entirely by the Crela launcher, so your tool does not need its own licence UI. Your integration is one call:
import { verifyOrExit } from '@crela/license'
verifyOrExit('my-tool', process.env.CRELA_SDK_MARKER!)
If you do not use npx @crela/init, set the variables yourself before building:
# Marker token from the creator dashboard:
export CRELA_SDK_MARKER=CRELA_SDKv2_xxxxxxxxxxxxxx
# Ed25519 public key (64 hex chars) for JWT verification:
export CRELA_LICENSE_PUBKEY_HEX=abcdef...
With esbuild:
esbuild main.ts \
--define:CRELA_SDK_MARKER=\"$CRELA_SDK_MARKER\" \
--define:CRELA_LICENSE_PUBKEY_HEX=\"$CRELA_LICENSE_PUBKEY_HEX\"
With Webpack:
new webpack.DefinePlugin({
CRELA_SDK_MARKER: JSON.stringify(process.env.CRELA_SDK_MARKER),
CRELA_LICENSE_PUBKEY_HEX: JSON.stringify(process.env.CRELA_LICENSE_PUBKEY_HEX),
})
The marker has to survive bundling as a literal string — reading it from a config file at runtime does not satisfy KO-10.
import { verifyOrExit } from '@crela/license'
// In electron main.ts, before app.whenReady():
verifyOrExit('my-tool', CRELA_SDK_MARKER)
app.whenReady().then(createWindow)
On failure: a message on stderr and process.exit(0xC1).
CRELA_DEV_MODE=1 env → isDev=true claims, no verificationCRELA_LICENSE_JWT env → verify token<DATA_LOCAL_DIR>/crela/licenses/<slug>.jwt → verify tokenLicenseError with code NOT_LAUNCHED_FROM_CRELAimport { LicenseVerifier } from '@crela/license'
const verifier = new LicenseVerifier({
toolSlug: 'my-tool',
markerToken: CRELA_SDK_MARKER,
pubkeyHex: CRELA_LICENSE_PUBKEY_HEX,
})
try {
const claims = verifier.verify()
console.log(`Licence valid, exp=${claims.exp}`)
} catch (e) {
console.error(`Licence invalid: ${e.message}`)
process.exit(1)
}
Crela ships a ready-made SDK for Node.js/Electron and for Rust/Tauri. For anything else (.NET, Java, Python, C++, Go) there is no SDK — embed the marker string as a compile-time constant and the review will accept it. Enforcing the licence at runtime is then up to you. See the creator guidelines.
npm test
MIT
FAQs
License verification SDK for Crela marketplace tools (Node.js / Electron). Reads JWT from launcher-injected env var or cache file, verifies offline via Ed25519.
The npm package @crela/license receives a total of 63 weekly downloads. As such, @crela/license popularity was classified as not popular.
We found that @crela/license demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.