
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@nacre.work/api
Advanced tools
The REST API and authorization service of Nacre — a self-hosted knowledge index where search returns exactly what the caller is permitted to see.
You probably want the container, not this package. A running installation is
the API, the MCP server, a worker, a parser sidecar, Postgres, Qdrant and Redis;
docker compose --profile minimal up brings all of it up from a clean clone.
This package is on the registry because the MCP server depends on it and because
an installation that assembles its own processes has to be able to install it.
@nacre.work/sdk.@nacre.work/cli.@nacre.work/mcp.Documents and ingest (JSON, a URL, or multipart/form-data including PDF),
hybrid search with metadata filters, layers and workspaces, grants, users,
groups and service accounts, OAuth consent and connection ceilings, embedding
providers and layer reindexing gated on recall, the access log as JSON, JSONL or
CSV, and /health, /ready and /metrics.
The contract is normative and comes first:
docs/openapi.yaml.
404, never 403, for anything invisible — same status and same wording
for "no such object" and "not yours", so nobody can map an installation by
probing it.
write does not imply read. admin implies both.
/ready refuses while the database schema is behind the image, which is what
keeps a rolling upgrade from replacing working pods with pods that answer every
request with an error. It stays ready when the schema is ahead, which is the
normal middle of that same upgrade.
Apache 2.0. Configuration, the permission model and the operator documentation: github.com/nacre-work/nacre.
FAQs
Nacre REST API and authorization service
The npm package @nacre.work/api receives a total of 13 weekly downloads. As such, @nacre.work/api popularity was classified as not popular.
We found that @nacre.work/api demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.