Sign In

@fetchproxy/protocol

Package Overview
Dependencies
Maintainers
1
Versions
44
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@fetchproxy/protocol

WebSocket frame types + runtime validators for fetchproxy.

latest
Source
npmnpm
Version
2.1.0
Version published
Maintainers
1
Created
Source

@fetchproxy/protocol

Wire-protocol types, runtime validators, and crypto wrappers for the fetchproxy WebSocket protocol.

Internal-ish: most users want @fetchproxy/server instead. @fetchproxy/server re-exports the few protocol types MCP authors typically need (Capability, FetchInit); pull this package in directly only if you're building your own bridge endpoint (alternate server, test harness, custom extension).

See:

  • Top-level README — what fetchproxy is.
  • docs/PROTOCOL.md — full wire-format reference (frames, handshake, crypto).

Install

npm install @fetchproxy/protocol

What's in here

ModuleExportsPurpose
framesPROTOCOL_VERSION, Capability, KNOWN_CAPABILITIES, all …Frame types, FetchInit, ReadCookiesInit, InnerFrame union, StoragePointerDecl, IndexedDbScopeDecl, CaptureHeaderDeclStatic + runtime descriptions of every frame on the wire.
validatevalidateFrame, validateInnerFrame, ProtocolError, HOSTNAME_REDefensive JSON validators with no third-party dependencies. Reject prototype-pollution attempts, malformed base64, unknown ops/capabilities, bad hostnames.
cryptoRawKeyPair, generateX25519, generateEd25519, ecdhX25519, hkdfSha256, ed25519Sign, ed25519Verify, aesGcmSeal, aesGcmOpen, sha256Thin async wrappers around WebCrypto subtle. Used by both server and extension.
mcp-idgenerateMcpId, parseMcpId, isValidMcpId, McpIdPartsPer-process <serverName>:<version>:<rand> ids.
pair-codederivePairCode, derivePairCodeFromIdsDeterministic 6-digit SAS code from X25519 pubkey(s) (SHA256[0..3] mod 1_000_000, formatted XXX-XXX).
sealsealInnerFrame, openEncryptedFrameAES-256-GCM encrypt/decrypt of inner JSON payloads keyed by sessionKey.
encodingtoB64, fromB64, toHex, concatBytesShared base64/hex helpers.
json-pointerevalJsonPointer, isValidJsonPointer, matchesDeclaredKey, undeclaredKeysJSON-pointer evaluation + glob matching for storage-pointer extraction.

Stability

All exports are part of the published surface and follow semver:

  • Major bumps signal wire-incompatible changes (new required fields, removed fields, semantic shifts).
  • Minor bumps add fields or accepted values additively.
  • Patch bumps are pure fixes.

0.2.0 was a wire-incompatible jump from 0.1.x (singular domain: stringdomains: string[]; added capabilities; added op discriminator on inner request/response).

License

MIT.

FAQs

Package last updated on 09 Aug 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts