
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
Lexu MCP server: let Claude and other AI assistants create images, video and music with your lexu.io credits
Create images, video and music with your lexu.io credits from code, the terminal, or an AI assistant.
| Package | What it is |
|---|---|
@lexu/sdk | TypeScript client for the Lexu API v1 |
@lexu/cli | The lexu command |
@lexu/mcp | MCP server for Claude Desktop, Claude Code, Cursor and other MCP clients |
Every generation is charged to your Lexu balance, at the same price as on the website. Each API key also has a monthly credit cap (500 by default, 200 for MCP keys), so a leaked key can only spend that much. Manage keys at https://www.lexu.io/dashboard/settings/api-keys.
npx @lexu/cli login # approve in the browser; no password in the terminal
npx @lexu/cli balance
npx @lexu/cli models --type video
npx @lexu/cli estimate kling-3 --duration 10
npx @lexu/cli generate gpt-image-2.5 "a red perfume bottle on white marble" --aspect-ratio 1:1 --download
npx @lexu/cli generate seedance-2-mini "waves at sunset, slow motion" --duration 5 --yes --json
npx @lexu/cli jobs
npx @lexu/cli job <id> --wait --download --out ./renders
npx @lexu/cli logout # also revokes the key on the server
Before charging, generate shows the price and asks. In scripts, pass --yes. --json prints machine-readable output. In CI, set LEXU_API_KEY instead of logging in.
Model options are passed as flags: --aspect-ratio 9:16 becomes aspect_ratio. lexu models lists each model's options.
Log in once (creates a key with a 200-credit monthly cap):
npx @lexu/mcp login
Claude Desktop (claude_desktop_config.json) or any MCP client:
{
"mcpServers": {
"lexu": { "command": "npx", "args": ["-y", "@lexu/mcp"] }
}
}
Claude Code:
claude mcp add lexu -- npx -y @lexu/mcp
Instead of logging in, you can put a key in the client config: "env": { "LEXU_API_KEY": "lexu_live_..." }.
Tools: get_account, get_balance, list_models, estimate_cost, generate_image, generate_video, generate_music, get_generation, list_generations, plus the product_ad prompt.
Every generate_* tool requires max_credits. The server estimates the request first and refuses it if it costs more, so text injected into a web page or file cannot make the assistant overspend.
import { Lexu } from "@lexu/sdk";
const lexu = new Lexu({ apiKey: process.env.LEXU_API_KEY! });
const { credits } = await lexu.estimate({ model: "veo-3.1-lite", prompt: "…", duration: 8 });
const started = await lexu.generate({ model: "veo-3.1-lite", prompt: "…", duration: 8 });
const done = await lexu.waitForGeneration(started.id);
console.log(done.status, done.output_url);
generate() sends an Idempotency-Key and retries network failures with the same key, so a retry never charges twice. Failed generations are refunded automatically; refunded is then true.
Base URL: https://www.lexu.io/api. Send Authorization: Bearer lexu_live_….
| Method | Path | |
|---|---|---|
| GET | /v1/me | Account and plan |
| GET | /v1/balance | Credits and this key's monthly cap |
| GET | /v1/models | Models, inputs, prices (no key needed) |
| POST | /v1/estimate | Price of a request, no charge |
| POST | /v1/generations | Start; requires Idempotency-Key |
| GET | /v1/generations | History (?limit, ?before) |
| GET | /v1/generations/{id} | Status and a fresh download link |
| GET | /v1/ledger | Balance changes |
| DELETE | /v1/keys/current | Revoke the key used |
Answers are { "data": … } or { "error": { "code", "message" } }.
npm install
npm run build
npm test
The server side lives in the lexu-platform repository: supabase/functions/api-v1 and migration 00053_public_api_keys.sql.
FAQs
Lexu MCP server: let Claude and other AI assistants create images, video and music with your lexu.io credits
The npm package @lexu/mcp receives a total of 46 weekly downloads. As such, @lexu/mcp popularity was classified as not popular.
We found that @lexu/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.