
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@featureflip/node
Advanced tools
Node.js SDK for Featureflip - evaluate feature flags locally with near-zero latency. Built on top of @featureflip/js with Node.js-specific defaults.
Using OpenFeature? See
@featureflip/openfeature-node, the Featureflip provider for the OpenFeature Node.js SDK.
npm install @featureflip/node
import { FeatureflipClient } from '@featureflip/node';
// Blocks until flags are loaded
const client = await FeatureflipClient.create({
sdkKey: 'your-sdk-key',
});
const enabled = client.boolVariation('my-feature', { user_id: '123' }, false);
if (enabled) {
console.log('Feature is enabled!');
}
await client.close();
Or, obtain a handle synchronously and wait manually:
const client = FeatureflipClient.get({ sdkKey: 'your-sdk-key' });
await client.waitForInitialization();
Singleton by construction.
FeatureflipClient.get()is the only way to obtain a client — the public constructor was removed in v2.0. Callingget()more than once with the same SDK key returns handles pointing at one shared underlying client. The factory is refcounted, so closing a handle only shuts down the shared core when the last handle is closed. This makes the SDK safe to call from per-request handlers and DI containers without leaking SSE connections.
const client = await FeatureflipClient.create({
sdkKey: 'your-sdk-key',
baseUrl: 'https://eval.featureflip.io', // Evaluation API URL (default)
streaming: true, // Use SSE for real-time updates (default)
pollInterval: 30000, // Polling interval in ms if streaming=false
flushInterval: 30000, // Event flush interval in ms
flushBatchSize: 100, // Events per batch
initTimeout: 10000, // Max ms to wait for initialization
maxStreamRetries: 5, // SSE retries before falling back to polling
});
const context = { user_id: '123', email: 'user@example.com' };
// Boolean flag
const enabled = client.boolVariation('feature-key', context, false);
// String flag
const tier = client.stringVariation('pricing-tier', context, 'free');
// Number flag
const limit = client.numberVariation('rate-limit', context, 100);
// JSON flag
const config = client.jsonVariation('ui-config', context, { theme: 'light' });
const detail = client.variationDetail('feature-key', { user_id: '123' }, false);
console.log(detail.value); // The evaluated value
console.log(detail.reason); // "RuleMatch", "Fallthrough", "FlagDisabled", etc.
console.log(detail.ruleId); // Rule ID if reason is "RuleMatch"
// Track custom events
client.track('checkout-completed', { user_id: '123' }, { total: 99.99 });
// Record an identify event for analytics (does not affect flag evaluation)
client.identify({ user_id: '123', email: 'user@example.com', plan: 'pro' });
// Force flush pending events
await client.flush();
Use forTesting() to create a client with predetermined flag values -- no network calls.
const client = FeatureflipClient.forTesting({
'my-feature': true,
'pricing-tier': 'pro',
});
client.boolVariation('my-feature', {}, false); // true
client.stringVariation('pricing-tier', {}, 'free'); // 'pro'
forTesting() factory for deterministic unit testshttp module for SSE and HTTPApache-2.0
FAQs
Node.js server SDK for Featureflip
The npm package @featureflip/node receives a total of 34 weekly downloads. As such, @featureflip/node popularity was classified as not popular.
We found that @featureflip/node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.