
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@sentinelsup/sdk
Advanced tools
Official Node.js SDK for Sentinel — real-time fraud detection, VPN/residential-proxy/antidetect-browser detection in under 40ms.
Official Node.js SDK for Sentinel — real-time fraud detection that flags VPNs, residential proxies, antidetect browsers, and AI bots in under 40 ms.
npm install @sentinelsup/sdk
Zero dependencies. Works on Node 14+, Bun, Deno, Cloudflare Workers, and Vercel Edge (wherever fetch exists).
const Sentinel = require('@sentinelsup/sdk');
const sentinel = new Sentinel({ apiKey: process.env.SENTINEL_KEY });
const result = await sentinel.evaluate({
token: req.body.sentinelToken // from the frontend SDK
});
if (result.isSuspicious) {
return res.status(403).json({ error: 'blocked' });
}
// Safe — let the request through
Get a free API key (no credit card) at sntlhq.com/signup.
{
isSuspicious: boolean, // combined network + device verdict
details: {
ip: '45.33.32.156',
cc: 'US',
vpn: false,
proxied: true, // residential proxy detected
dch: false, // datacenter
anon: false,
service: 'BrightData'
},
deviceIntel: { // null unless you pass fingerprintEventId
visitorId: 'abc123...',
browserTampering: true, // antidetect browser detected
botDetected: false,
incognito: false,
virtualMachine: false,
emulator: false
}
}
Add the client-side SDK to your frontend so Sentinel can collect the token:
<script async src="https://fp.sntlhq.com/agent"></script>
Read the token from the rendered form field and send it to your backend:
const token = document.querySelector('input[name="monocle"]').value;
fetch('/checkout', { method: 'POST', body: JSON.stringify({ sentinelToken: token }) });
const Sentinel = require('@sentinelsup/sdk');
const stripe = require('stripe')(process.env.STRIPE_KEY);
const sentinel = new Sentinel({ apiKey: process.env.SENTINEL_KEY });
app.post('/checkout', async (req, res) => {
const { isSuspicious } = await sentinel.evaluate({ token: req.body.sentinelToken });
if (isSuspicious) return res.status(403).json({ error: 'declined' });
const intent = await stripe.paymentIntents.create({ /* ... */ });
res.json({ clientSecret: intent.client_secret });
});
app.post('/auth/google', async (req, res) => {
const { credential, sentinelToken } = req.body;
const ticket = await googleClient.verifyIdToken({ idToken: credential });
const result = await sentinel.evaluate({ token: sentinelToken });
if (result.isSuspicious) return res.status(403).json({ error: 'signup_blocked' });
await createUser(ticket.getPayload().email, result.deviceIntel?.visitorId);
});
shouldBlock// Only block when we see both residential proxy AND browser tampering
const blocked = await sentinel.shouldBlock(
{ token },
r => r.details.proxied && r.deviceIntel?.browserTampering
);
new Sentinel({ apiKey, endpoint?, timeoutMs? })| Option | Type | Default | Description |
|---|---|---|---|
apiKey | string | required | Your key starting with sk_live_ |
endpoint | string | https://sntlhq.com | Override base URL |
timeoutMs | number | 5000 | Per-request timeout |
sentinel.evaluate({ token, fingerprintEventId? })Returns EvaluateResult. Throws SentinelError on network/API failure — the error carries .status and .body.
sentinel.shouldBlock({ token, fingerprintEventId? }, predicate?)Convenience: runs evaluate() and returns a boolean. Default predicate is r => r.isSuspicious. Pass your own to build custom policies.
Free tier: 1,000 requests/hour per API key. No monthly cap, no credit card. Upgrade at sntlhq.com when you need more.
Full types ship with the package. Importing Sentinel gives you the class plus EvaluateResult, DeviceIntel, EvaluateDetails, and SentinelError types.
import Sentinel, { EvaluateResult } from '@sentinelsup/sdk';
MIT © Sentinel Edge Networks LTD
FAQs
Official Node.js SDK for Maskbreak — evaluate SDK-backed visits for network and device fraud signals, or look up limited public IP intelligence.
The npm package @sentinelsup/sdk receives a total of 331 weekly downloads. As such, @sentinelsup/sdk popularity was classified as not popular.
We found that @sentinelsup/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.