
Security News
White House Authorizes Private Companies to Conduct Offensive Cyber Operations
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.
@memberjunction/credentials
Advanced tools
MemberJunction: Credential Engine - secure credential management with caching, encryption, and audit logging.
Secure credential management engine for MemberJunction. Provides centralized storage, retrieval, validation, and audit logging of credentials with automatic field-level encryption and JSON Schema validation.
The @memberjunction/credentials package manages the full credential lifecycle: storing encrypted values, resolving credentials by name or ID, validating against JSON Schema constraints, and logging every access for audit compliance.
graph TD
A["CredentialEngine<br/>(Singleton)"] --> B["Credential Types<br/>(Schema Definitions)"]
A --> C["Credentials<br/>(Encrypted Values)"]
A --> D["Credential Categories<br/>(Organization)"]
A --> E["Audit Log<br/>(Access Tracking)"]
A --> F["Ajv Validator<br/>(JSON Schema)"]
G["Consumer Code"] --> A
G -->|"getCredential()"| H["ResolvedCredential<T>"]
G -->|"storeCredential()"| C
G -->|"validateCredential()"| I["ValidationResult"]
style A fill:#2d6a9f,stroke:#1a4971,color:#fff
style B fill:#7c5295,stroke:#563a6b,color:#fff
style C fill:#2d8659,stroke:#1a5c3a,color:#fff
style D fill:#b8762f,stroke:#8a5722,color:#fff
style E fill:#b8762f,stroke:#8a5722,color:#fff
style F fill:#7c5295,stroke:#563a6b,color:#fff
style H fill:#2d8659,stroke:#1a5c3a,color:#fff
style I fill:#2d8659,stroke:#1a5c3a,color:#fff
npm install @memberjunction/credentials
import { CredentialEngine, APIKeyCredentialValues } from '@memberjunction/credentials';
// Initialize at application startup
await CredentialEngine.Instance.Config(false, contextUser);
// Retrieve a credential with typed values
const cred = await CredentialEngine.Instance.getCredential<APIKeyCredentialValues>(
'OpenAI',
{ contextUser, subsystem: 'AIService' }
);
// Use the decrypted values
console.log(cred.values.apiKey); // Strongly typed as string
flowchart TD
A["getCredential(name, options)"] --> B{directValues<br/>provided?}
B -->|Yes| C["Return direct values<br/>source: request"]
B -->|No| D{credentialId<br/>provided?}
D -->|Yes| E["Lookup by ID"]
D -->|No| F["Lookup by name"]
E --> G["Parse & return values<br/>source: database"]
F --> G
G --> H["Log access to Audit Log"]
H --> I["Update LastUsedAt"]
style A fill:#2d6a9f,stroke:#1a4971,color:#fff
style C fill:#2d8659,stroke:#1a5c3a,color:#fff
style G fill:#2d8659,stroke:#1a5c3a,color:#fff
style H fill:#b8762f,stroke:#8a5722,color:#fff
Resolution priority:
directValues in options (bypasses database, useful for testing)credentialId in options (specific credential lookup)credentialName parameter (most common usage)| Type | Interface | Fields |
|---|---|---|
| API Key | APIKeyCredentialValues | apiKey |
| API Key with Endpoint | APIKeyWithEndpointCredentialValues | apiKey, endpoint |
| OAuth2 Client Credentials | OAuth2ClientCredentialValues | clientId, clientSecret, tokenUrl, scope |
| Basic Auth | BasicAuthCredentialValues | username, password |
| Azure Service Principal | AzureServicePrincipalCredentialValues | tenantId, clientId, clientSecret |
| AWS IAM | AWSIAMCredentialValues | accessKeyId, secretAccessKey, region |
| Database Connection | DatabaseConnectionCredentialValues | host, port, database, username, password |
| Twilio | TwilioCredentialValues | accountSid, authToken |
const credential = await CredentialEngine.Instance.storeCredential(
'API Key', // Credential type name
'OpenAI Production', // Credential name
{ apiKey: 'sk-...' }, // Values (encrypted on save)
{
isDefault: true,
description: 'Production OpenAI API key',
expiresAt: new Date('2025-12-31')
},
contextUser
);
The engine validates credential values against the FieldSchema defined on each Credential Type using Ajv. Supported constraints include required, const, enum, format, pattern, minLength/maxLength, and minimum/maximum.
Default and const values are auto-populated before validation, and validation errors produce clear, human-readable messages.
Every credential operation (Decrypt, Create, Update, Validate) is logged to the Audit Logs entity with:
Values field uses MJ field-level encryptioncontextUserExpiresAt field enforces credential rotation| Package | Purpose |
|---|---|
@memberjunction/core | Base engine, metadata, entity system |
@memberjunction/global | Global state management |
@memberjunction/core-entities | Credential entity types |
ajv | JSON Schema validation |
ajv-formats | Format validators (uri, email, date) |
ISC
FAQs
MemberJunction: Credential Engine - secure credential management with caching, encryption, and audit logging.
We found that @memberjunction/credentials demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 11 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.