
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@crela/license
Advanced tools
License verification SDK for Crela marketplace tools (Node.js / Electron). Reads JWT from launcher-injected env var or cache file, verifies offline via Ed25519.
License verification SDK for tools on the Crela marketplace.
Mandatory for paid tools: the review pipeline looks for a per-tool marker inside your binary (KO-10), and this SDK is what puts it there and checks the licence at startup.
For Node.js and Electron projects, let the init tool wire everything up:
cd my-tool/
npx @crela/init
It detects your entry point and bundler, fetches the SDK marker via the API, injects verifyOrExit(), and patches your bundler config. After that, just run npm run build.
The SDK never prompts for a licence key. It reads a JWT signed by the Crela launcher — either from the environment variable CRELA_LICENSE_JWT or from a cache file — and verifies it offline against an Ed25519 public key. No network call happens.
Activation, heartbeat and device management are handled entirely by the Crela launcher, so your tool does not need its own licence UI. Your integration is one call:
import { verifyOrExit } from '@crela/license'
verifyOrExit('my-tool', process.env.CRELA_SDK_MARKER!)
If you do not use npx @crela/init, set the variables yourself before building:
# Marker token from the creator dashboard:
export CRELA_SDK_MARKER=CRELA_SDKv2_xxxxxxxxxxxxxx
# Ed25519 public key (64 hex chars) for JWT verification:
export CRELA_LICENSE_PUBKEY_HEX=abcdef...
With esbuild:
esbuild main.ts \
--define:CRELA_SDK_MARKER=\"$CRELA_SDK_MARKER\" \
--define:CRELA_LICENSE_PUBKEY_HEX=\"$CRELA_LICENSE_PUBKEY_HEX\"
With Webpack:
new webpack.DefinePlugin({
CRELA_SDK_MARKER: JSON.stringify(process.env.CRELA_SDK_MARKER),
CRELA_LICENSE_PUBKEY_HEX: JSON.stringify(process.env.CRELA_LICENSE_PUBKEY_HEX),
})
The marker has to survive bundling as a literal string — reading it from a config file at runtime does not satisfy KO-10.
import { verifyOrExit } from '@crela/license'
// In electron main.ts, before app.whenReady():
verifyOrExit('my-tool', CRELA_SDK_MARKER)
app.whenReady().then(createWindow)
On failure: a message on stderr and process.exit(0xC1).
CRELA_DEV_MODE=1 env → isDev=true claims, no verificationCRELA_LICENSE_JWT env → verify token<DATA_LOCAL_DIR>/crela/licenses/<slug>.jwt → verify tokenLicenseError with code NOT_LAUNCHED_FROM_CRELAimport { LicenseVerifier } from '@crela/license'
const verifier = new LicenseVerifier({
toolSlug: 'my-tool',
markerToken: CRELA_SDK_MARKER,
pubkeyHex: CRELA_LICENSE_PUBKEY_HEX,
})
try {
const claims = verifier.verify()
console.log(`Licence valid, exp=${claims.exp}`)
} catch (e) {
console.error(`Licence invalid: ${e.message}`)
process.exit(1)
}
Crela ships a ready-made SDK for Node.js/Electron and for Rust/Tauri. For anything else (.NET, Java, Python, C++, Go) there is no SDK — embed the marker string as a compile-time constant and the review will accept it. Enforcing the licence at runtime is then up to you. See the creator guidelines.
npm test
MIT
FAQs
License verification SDK for Crela marketplace tools (Node.js / Electron). Reads JWT from launcher-injected env var or cache file, verifies offline via Ed25519.
The npm package @crela/license receives a total of 20 weekly downloads. As such, @crela/license popularity was classified as not popular.
We found that @crela/license demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.