
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@everframe/identity
Advanced tools
Mint Everframe identity tokens from any runtime — one handler that works as a Next route, a Cloudflare Worker, an Edge function or a Node server.
Mint Everframe identity tokens from any runtime.
One createIdentityHandler call returns a standard
(Request) => Promise<Response> — which is simultaneously a Next App Router
handler, a Cloudflare Worker, a Vercel/Netlify Edge function, a Supabase Edge
Function and a Deno/Bun handler.
// app/api/everframe-identity/route.ts
import { createIdentityHandler } from '@everframe/identity';
const handler = createIdentityHandler({
secret: process.env.EVERFRAME_IDENTITY_SECRET!,
projectId: process.env.EVERFRAME_PROJECT_ID!,
resolveUser: async (req) => {
const user = await getSessionUser(req); // cookie, bearer, anything
return user ? { id: user.id, email: user.email, name: user.name } : null;
},
});
// Export for BOTH verbs. A cross-origin request carrying `Authorization` is
// ALWAYS preflighted with an OPTIONS request first — exporting only GET lets
// Next answer that preflight itself with a bare `Allow` header, so the
// handler's CORS headers (see "Cross-origin" below) never reach the browser
// and recognition silently stops working for every cross-origin caller.
export { handler as GET, handler as OPTIONS };
Then point the SDK at it:
<EverframeProvider
config={{ apiKey }}
identity={{ endpoint: '/api/everframe-identity', key: user?.id }}
>
resolveUser receives the Request. Cookies are one implementation; a bearer
token is another:
resolveUser: (req) => verifyAccessToken(req.headers.get('authorization'))
On the client, headers is re-invoked on every mint, so a rotating access
token is never captured stale:
identity={{
endpoint: 'https://api.example.com/everframe-identity',
key: user?.id,
headers: async () => ({ Authorization: `Bearer ${await getAccessToken()}` }),
}}
Pass allowedOrigins to answer preflights and echo matched origins. Absent, the
handler is same-origin only. '*' throws — a wildcard origin on an endpoint
that returns identity tokens would expose them to any site.
createIdentityHandler({ …, allowedOrigins: ['https://app.example.com'] })
import { toNodeHandler } from '@everframe/identity/node';
const nodeHandler = (req, res) => void toNodeHandler(handler)(req, res);
// Register for BOTH verbs — or use app.all(...) — for the same reason as the
// Next example above: a cross-origin request carrying `Authorization` is
// ALWAYS preflighted with OPTIONS first. Registering only `.get(...)` means
// Express answers OPTIONS with a 404 before it ever reaches the handler, so
// its CORS headers never appear and recognition silently stops working for
// every cross-origin caller.
app.get('/api/everframe-identity', nodeHandler);
app.options('/api/everframe-identity', nodeHandler);
| Case | Response |
|---|---|
| User resolves | 200 { token, expiresAt } (expiresAt is ms epoch) |
| Nobody signed in | 200 { token: null } |
user.id empty or >255 chars | 200 { token: null, reason: 'subject_too_long' } |
resolveUser throws | 500, empty body |
Every response carries Cache-Control: no-store. A signed-out user is a normal
state, not an error — all token: null cases read as "anonymous" to the SDK.
MIT
FAQs
Mint Everframe identity tokens from any runtime — one handler that works as a Next route, a Cloudflare Worker, an Edge function or a Node server.
We found that @everframe/identity demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.