
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@domainkits/sdk
Advanced tools
TypeScript client for the DomainKits REST API. Search expiring, newly registered, aged, active, deleted and marketplace domains, plus WHOIS, DNS, Certificate Transparency and trends.
TypeScript client for the DomainKits REST API.
DomainKits is one API with a shared key across every endpoint. This SDK covers all of them — six domain search types, WHOIS, DNS, reverse nameserver, Certificate Transparency, safety, trends and bulk download — with typed parameters and responses, automatic paging, and structured quota errors.
The REST API is for Premium and Platinum accounts; unauthenticated requests are rejected with 401. Keys start with dk_ and come from domainkits.com.
If you want a no-key way to explore the same data from an AI client, use @domainkits/mcp instead, which has a guest tier.
npm install @domainkits/sdk
import { DomainKits } from '@domainkits/sdk';
const dk = new DomainKits(process.env.DOMAINKITS_API_KEY!);
const { data, total } = await dk.expired.list({
keyword: 'clinic',
tld: 'com',
length: '5-10',
no_number: true,
no_hyphen: true,
});
console.log(`${total} matches`);
for (const d of data) {
console.log(d.domain, d.age, d.status);
}
A single request returns at most 500 results. paginate walks the whole result set for you:
for await (const domain of dk.expired.paginate({ keyword: 'clinic', tld: 'com' })) {
console.log(domain.domain);
}
It stops when the result set is exhausted. Break out of the loop whenever you have enough — no further requests are made.
export pulls up to 50,000 rows as CSV in one request:
const csv = await dk.expired.export({ tld: 'com', status: 'pending_delete' });
This runs on a separate, much smaller quota — 10 per day and 100 per month on Premium, 3 and 9 during the trial. It is for occasional bulk pulls, not for a scheduled job. The export also returns fewer columns than paged mode: registered_date is the year only, and age is omitted.
50,000 is a cap, not a promise of completeness — browsing .com matched 4,847,613 expiring domains on 27 July 2026, so an unfiltered export returns the first 50,000. Narrow the query if you need the result set to fit.
| Method | What it searches |
|---|---|
dk.expired | Domains in the deletion cycle: expired, redemption, pending delete |
dk.nrds | Newly registered domains, last 60 days |
dk.aged | Domains with 5 to 20+ years of registration history |
dk.active | Currently registered domains |
dk.deleted | Dropped domains (requires keyword) |
dk.market | Domains listed for sale on marketplaces |
Each has list, paginate and export, and its own parameter and result types — an expired result carries status, an NRD result carries expiry_date, a market result carries marketplace.
await dk.whois('example.com');
await dk.dns('example.com');
await dk.safety('example.com');
await dk.nsReverse({ ns: 'ns1.example.com', tld: 'com' });
await dk.tldCheck({ prefix: 'yourbrand' });
await dk.typosquat({ domain: 'example.com' });
await dk.ipLookup('8.8.8.8');
await dk.registrar('godaddy');
await dk.statusGuide('clientHold');
await dk.monitorChanges({ tld: 'com', reason: 'transfer' });
await dk.ctSubdomains('example.com');
await dk.ctCerts({ domain: 'example.com' });
await dk.ctSearch({ keyword: 'example' });
await dk.tldTrends('newly', { tld: 'com' });
await dk.keywordTrends('hot');
await dk.usage();
await dk.searchStatus();
gTLDs only for the domain search endpoints. The index covers generic TLDs — .com, .net, .org, .info, .biz, .xyz, .online, .site, .top, .club, .live, .app, .dev and others. Country-code TLDs are not indexed: a query for .de, .io, .co or .us returns an empty result set, not an error.
whois, dns, safety, ipLookup and the Certificate Transparency endpoints work on any domain, ccTLDs included.
No PII. Responses contain no personal data. WHOIS results are limited to registrar, dates, status codes and nameservers; registrant names, emails, addresses and phone numbers are not returned.
import { RateLimitError, AuthError, DomainKitsError } from '@domainkits/sdk';
try {
await dk.expired.export({ tld: 'com' });
} catch (error) {
if (error instanceof RateLimitError) {
console.log(`Quota exhausted. Retry in ${error.retryAfterMs}ms`);
console.log(error.rateLimit);
} else if (error instanceof AuthError) {
console.log('Key rejected — check your plan tier');
} else if (error instanceof DomainKitsError) {
console.log(error.status, error.message);
}
}
Every error carries the x-ratelimit-limit, x-ratelimit-remaining and x-ratelimit-reset values as a parsed rateLimit object. RateLimitError.retryAfterMs tells you how long until the window resets.
429 and 5xx responses are retried automatically — twice by default, waiting until the rate-limit window resets when that is under two minutes. Set maxRetries: 0 to handle it yourself.
const dk = new DomainKits({
apiKey: process.env.DOMAINKITS_API_KEY!,
timeoutMs: 60_000,
maxRetries: 2,
baseUrl: 'https://premium-api.domainkits.com/api/v1',
});
Call usage() for the live picture on your account — every endpoint reports its own per-minute, daily and monthly allowance alongside what you have already spent.
Daily quotas reset at 00:00 UTC, monthly quotas on the 1st. Current limits: domainkits.com/dev/api-docs.
FAQs
TypeScript client for the DomainKits REST API. Search expiring, newly registered, aged, active, deleted and marketplace domains, plus WHOIS, DNS, Certificate Transparency and trends.
The npm package @domainkits/sdk receives a total of 33 weekly downloads. As such, @domainkits/sdk popularity was classified as not popular.
We found that @domainkits/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.