Socket
Socket
Sign inDemoInstall

@xrplf/secret-numbers

Package Overview
Dependencies
11
Maintainers
6
Versions
3
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

    @xrplf/secret-numbers

Generate XRPL Accounts with a number-based secret: 8 chunks of 6 digits


Version published
Weekly downloads
1.3K
increased by11.24%
Maintainers
6
Install size
4.03 MB
Created
Weekly downloads
 

Readme

Source

XRPL Secret Numbers npm version

For more background information, please read the proposed Standard.

A tool to convert Secret Numbers to the widely used Family Seed s... format is available here

A bundled version of this lib is available at NPM (build/xrplf-secret-numbers-latest.js), CDN: https://cdn.jsdelivr.net/npm/@xrplf/secret-numbers. You can access the library as xrplf_secret_numbers. Sample: https://jsfiddle.net/WietseWind/uo1zy0q7/

Generate XRPL Accounts with a number-based secret: 8 chunks of 6 digits.

The common formats for XRPL account secrets are (at the time of writing this, July 2019):

  • Family Seed, eg. sh1HiK7SwjS1VxFdXi7qeMHRedrYX
  • Mnemonic, eg. car banana apple road ...

These formats are prone to typo's and not that user friendly. Using numbers means it's language (spoken, written) agnostic as well. They may be especially intimidating for the public that's relatively new to cryptocurrencies / blockchain technology.

This library encodes the entropy to generate accounts into 8 chunks of 6 digits, of which 5 digits are 1/8th of the entropy, and a 6th digit contains a checksum allowing realtime typo detection.

A secret now looks like:
554872 394230 209376 323698
140250 387423 652803 258676

For compatibility with existing clients, this library supports exporting the family seed for a generated / entered "Secret Number"-set as well.

API

The typescript code to use resides in ./src/ and the compiled js in ./dist/ of the package. See the ./samples/ folder for some simple JS samples.

Generating a new account:
const {Account} = require('@xrplf/secret-numbers')
const account = new Account()
Importing an existing account:
const {Account} = require('@xrplf/secret-numbers')
const secret = '399150 474506 009147 088773 432160 282843 253738 605430'
const account = new Account(secret)

Or importing with custom entropy (buffer, 16):

const {Account} = require('@xrplf/secret-numbers')
const entropy = Buffer.from('0123456789ABCDEF0123456789ABCDEF', 'hex')
const account = new Account(entropy)
After generating / importing:

You can fetch the account details (address, secret, etc.) using these methods:

console.log(account.getAddress())
console.log(account.getSecret())
Available methods:
  • getSecret(): Array[8]
  • getSecretString(): string 012345 456789 ...
  • getAddress(): string rXXXXXXXX...
  • getFamilySeed(): string sXXXXXXXX...
  • getKeypair(): Keypair({privateKey, publicKey}
To split/check/encode/decode some more:

There's a Utils export as well:

const {Account, Utils} = require('@xrplf/secret-numbers')

Some Utils methods (that you may want to use in your UI / ... before using the Account constructor):

  • To calculate the 6th decimal for a group of 5 digits:
    calculateChecksum(position: number, value: number): number
  • To check a checksum (either sliced or the 6th char of a string containing numbers:
    checkChecksum(position: number, value: number | string, checksum?: number): Boolean

Development

Run npm run prepublish to clean, lint, test and build. Or just run npm run build, npm run test or npm run lint.

Tests are in ./test/

Credits

This concept is based on an idea by @nbougalis.

Keywords

FAQs

Last updated on 01 Feb 2024

Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc