New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@everframe/identity

Package Overview
Dependencies
Maintainers
2
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@everframe/identity

Mint Everframe identity tokens from any runtime — one handler that works as a Next route, a Cloudflare Worker, an Edge function or a Node server.

latest
Source
npmnpm
Version
0.3.0
Version published
Maintainers
2
Created
Source

@everframe/identity

Mint Everframe identity tokens from any runtime.

One createIdentityHandler call returns a standard (Request) => Promise<Response> — which is simultaneously a Next App Router handler, a Cloudflare Worker, a Vercel/Netlify Edge function, a Supabase Edge Function and a Deno/Bun handler.

// app/api/everframe-identity/route.ts
import { createIdentityHandler } from '@everframe/identity';

const handler = createIdentityHandler({
  secret: process.env.EVERFRAME_IDENTITY_SECRET!,
  projectId: process.env.EVERFRAME_PROJECT_ID!,
  resolveUser: async (req) => {
    const user = await getSessionUser(req);   // cookie, bearer, anything
    return user ? { id: user.id, email: user.email, name: user.name } : null;
  },
});

// Export for BOTH verbs. A cross-origin request carrying `Authorization` is
// ALWAYS preflighted with an OPTIONS request first — exporting only GET lets
// Next answer that preflight itself with a bare `Allow` header, so the
// handler's CORS headers (see "Cross-origin" below) never reach the browser
// and recognition silently stops working for every cross-origin caller.
export { handler as GET, handler as OPTIONS };

Then point the SDK at it:

<EverframeProvider
  config={{ apiKey }}
  identity={{ endpoint: '/api/everframe-identity', key: user?.id }}
>

resolveUser receives the Request. Cookies are one implementation; a bearer token is another:

resolveUser: (req) => verifyAccessToken(req.headers.get('authorization'))

On the client, headers is re-invoked on every mint, so a rotating access token is never captured stale:

identity={{
  endpoint: 'https://api.example.com/everframe-identity',
  key: user?.id,
  headers: async () => ({ Authorization: `Bearer ${await getAccessToken()}` }),
}}

Cross-origin

Pass allowedOrigins to answer preflights and echo matched origins. Absent, the handler is same-origin only. '*' throws — a wildcard origin on an endpoint that returns identity tokens would expose them to any site.

createIdentityHandler({ …, allowedOrigins: ['https://app.example.com'] })

Node

import { toNodeHandler } from '@everframe/identity/node';
const nodeHandler = (req, res) => void toNodeHandler(handler)(req, res);

// Register for BOTH verbs — or use app.all(...) — for the same reason as the
// Next example above: a cross-origin request carrying `Authorization` is
// ALWAYS preflighted with OPTIONS first. Registering only `.get(...)` means
// Express answers OPTIONS with a 404 before it ever reaches the handler, so
// its CORS headers never appear and recognition silently stops working for
// every cross-origin caller.
app.get('/api/everframe-identity', nodeHandler);
app.options('/api/everframe-identity', nodeHandler);

Responses

CaseResponse
User resolves200 { token, expiresAt } (expiresAt is ms epoch)
Nobody signed in200 { token: null }
user.id empty or >255 chars200 { token: null, reason: 'subject_too_long' }
resolveUser throws500, empty body

Every response carries Cache-Control: no-store. A signed-out user is a normal state, not an error — all token: null cases read as "anonymous" to the SDK.

Licence

MIT

Keywords

everframe

FAQs

Package last updated on 25 Sep 2026

Related posts