
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@dropthis/node
Advanced tools
Official Node.js SDK for dropthis -- the publish layer between AI and the internet. One API call in, one URL out.
npm install @dropthis/node
import { Dropthis } from "@dropthis/node";
const dropthis = new Dropthis({ apiKey: "sk_..." });
const { data, error } = await dropthis.drops.publish("<h1>Hello</h1>");
console.log(data.url); // https://abc123.dropthis.app
const { data } = await dropthis.drops.publish("<h1>Launch page</h1>");
const { data } = await dropthis.drops.publish("./report.html");
const { data } = await dropthis.drops.publish("./dist");
const { data } = await dropthis.drops.publish("./dist", {
title: "Q4 Report",
visibility: "unlisted",
password: "s3cret",
expiresAt: "2026-12-31T00:00:00Z",
});
const created = await dropthis.drops.publish("./dist", { title: "v1" });
const updated = await dropthis.drops.updateContent(created.data.id, "./dist-v2", {
ifRevision: created.data.revision,
});
await dropthis.drops.updateSettings("drop_abc123", { title: "New title" });
The drops.publish() and drops.updateContent() methods accept:
"<h1>Hello</h1>" (auto-detected as inline content)"./report.html" (local file)"./dist" (local directory, bundled)["./dist", "./extra.css"] (multi-path bundle)new URL("https://example.com/page") (source fetch)new Uint8Array(...) (raw bytes){ kind: "content", content: "...", contentType?: "text/html", path?: "page.html" }{ kind: "source_url", sourceUrl: "https://example.com/page" }{ kind: "files", files: [{ path, content?, contentBase64?, bytes?, contentType? }], entry? }Drop settings (title, visibility, password, noindex, expiresAt, slug, metadata) go in the second options argument, not in the input object.
All inputs are uploaded through staged presigned URLs. The SDK handles this transparently.
// Inline content with explicit MIME type
await dropthis.drops.publish({
kind: "content",
content: "<h1>Hello</h1>",
contentType: "text/html",
});
// Fetch and re-publish a remote URL
await dropthis.drops.publish({
kind: "source_url",
sourceUrl: "https://example.com/report",
});
// Multi-file bundle with explicit entry point
await dropthis.drops.publish(
{
kind: "files",
files: [
{ path: "index.html", content: "<h1>Hello</h1>" },
{ path: "style.css", content: "body { margin: 0; }" },
],
entry: "index.html",
},
{ title: "My Site" },
);
prepare() resolves and validates the input locally, returning the prepared request object without making any API calls. It throws PublishInputError on invalid input (e.g. missing file).
import { Dropthis, PublishInputError } from "@dropthis/node";
try {
const prepared = await dropthis.prepare("./dist");
console.log("Ready to publish:", prepared.kind);
} catch (e) {
if (e instanceof PublishInputError) {
console.error("Bad input:", e.message);
}
}
All methods return DropthisResult<T> -- either { data: T, error: null, headers } or { data: null, error, headers }. API errors never throw; check error before using data.
const result = await dropthis.drops.get("drop_abc123");
if (result.error) {
console.error(result.error.code, result.error.message);
// Also available: error.statusCode, error.requestId, error.suggestion,
// error.retryable, error.param, error.currentRevision
} else {
console.log(result.data);
}
Local input validation errors (e.g. file_not_found) are also returned as { error: { code: "file_not_found", ... } } rather than thrown -- except for prepare(), which throws PublishInputError.
const dropthis = new Dropthis({
apiKey: "sk_...", // Required. Defaults to DROPTHIS_API_KEY env var.
baseUrl: "https://...", // Override API base URL.
timeoutMs: 30_000, // Request timeout in milliseconds (default: 30s).
uploadTimeoutMs: 120_000, // Timeout for signed-PUT file uploads (default: 120s).
fetch: customFetch, // Custom fetch implementation.
});
You can also pass just the API key as a string:
const dropthis = new Dropthis("sk_...");
await dropthis.drops.list({ limit: 20 });
await dropthis.drops.get("drop_abc123");
await dropthis.drops.updateSettings("drop_abc123", { title: "Updated" });
await dropthis.drops.delete("drop_abc123");
List results support auto-pagination:
const page = await dropthis.drops.list();
const allDrops = await page.data.autoPagingToArray({ limit: 100 });
// Or iterate
for await (const drop of page.data) {
console.log(drop.url);
}
To change a drop's content, use
client.drops.updateContent(dropId, newInput).drops.updateSettings()is for settings only (title, visibility, password, noindex, expiresAt, slug, metadata).
await dropthis.deployments.list("drop_abc123");
await dropthis.deployments.get("drop_abc123", "dep_xyz789");
Low-level upload session management. Most users should use publish() instead.
await dropthis.uploads.create({
schemaVersion: 1,
files: [{ path: "index.html", contentType: "text/html", sizeBytes: 1024 }],
});
await dropthis.uploads.get("upl_abc123");
await dropthis.uploads.complete("upl_abc123", { files: {} });
await dropthis.uploads.cancel("upl_abc123");
await dropthis.auth.requestEmailOtp({ email: "you@example.com" });
await dropthis.auth.verifyEmailOtp({ email: "you@example.com", code: "123456" });
await dropthis.auth.logout();
await dropthis.apiKeys.create({ label: "CI" });
await dropthis.apiKeys.list();
await dropthis.apiKeys.delete("key_abc123");
await dropthis.account.get();
await dropthis.account.update({ displayName: "Jane Doe" });
await dropthis.account.delete();
Use the fs-free entry point for Cloudflare Workers and other edge runtimes. It does not import node:fs, node:path, or node:crypto.
import { DropthisEdge } from "@dropthis/node/edge";
const dropthis = new DropthisEdge({ apiKey: env.DROPTHIS_API_KEY });
const { data, error } = await dropthis.drops.publish("<h1>Hello from the edge</h1>");
DropthisEdge accepts the in-memory subset of PublishInput: inline strings, Uint8Array, URL, and the explicit { kind: "content" }, { kind: "source_url" }, and { kind: "files" } forms. Local file paths and string[] path arrays are not supported (no filesystem on the edge).
DropthisEdge exposes the drop lifecycle through drops.publish(input, options?), drops.updateContent(dropId, input, options?), drops.updateSettings, drops.get, drops.list, and drops.delete, plus the deployments, account, and apiKeys resource accessors — the same surface as the Node client.
Key types exported from the package:
import type {
DropthisClientOptions,
DropthisResult,
DropthisErrorResponse,
DropResponse,
DropDeploymentResponse,
DropOptions,
PrepareOptions,
RequestControls,
PublishOptions,
PublishInput,
PublishFileInput,
ListPage,
CreateUploadSessionRequest,
CreateUploadSessionResponse,
} from "@dropthis/node";
For AI coding agents (Cursor, Claude Code, Windsurf, etc.), install the dropthis-skills package:
npx skills add dropthis-dev/dropthis-skills
FAQs
Official Node.js SDK for dropthis — the publish layer between AI and the internet. One call in, one URL out.
The npm package @dropthis/node receives a total of 51 weekly downloads. As such, @dropthis/node popularity was classified as not popular.
We found that @dropthis/node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.