
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Anonymous authentication. Zero personal data.
DAKU (pronounced DAA KU) means "bandits" in Punjabi. Historically, bandits operated anonymously, often using masks to hide their identity. This library adopts that privacy-first ethos—anonymous cryptographic authentication without personal data.
Stop storing passwords. Stop managing email verifications. Stop worrying about data breaches.
DAKU is a simpler approach to user authentication that keeps both you and your users anonymous. No databases of usernames, no password hashes to secure, no personal information to leak.
// Traditional auth: Store emails, hash passwords, manage resets...
// DAKU: Just verify cryptographic signatures ✨
const publicKey = await verifyAuth(token);
Every traditional authentication system carries risk:
Users authenticate with cryptographic keypairs—like Bitcoin wallets, but for your app:
DAKU uses secp256k1 signatures (same as Bitcoin/Ethereum) with proof-of-work spam protection. Auth tokens expire in 1 minute. Users control their private keys, you just verify signatures.
npm install daku
import { generateKeyPair, createAuth, verifyAuth } from "daku";
// 1. User generates keypair (client-side)
const { privateKey, publicKey } = generateKeyPair();
// 2. Create auth token (client-side)
const token = await createAuth(privateKey);
// 3. Verify auth (server-side)
const publicKey = await verifyAuth(token);
// ✅ Authenticated! publicKey is the unique user ID
generateKeyPair()Create a new identity
const { privateKey, publicKey } = generateKeyPair();
Generates a secp256k1 keypair. The privateKey stays with the user (never share it), the publicKey identifies them to your service.
{ privateKey: string, publicKey: string }getPublicKey(privateKey)Derive the public identity
const publicKey = getPublicKey(privateKey);
Extract the public key from a private key. Useful when users return with their saved privateKey.
publicKey stringgetUsername(publicKey)Make public keys human-readable
const username = await getUsername(publicKey);
// → "happy-ocean-flows-1234"
Public keys are long hex strings. getUsername() converts them into memorable usernames for your UI.
adjective-noun-verb-number[!IMPORTANT]
Never ask users to create usernames. DAKU keeps users anonymous. Display the generated username in your UI, but always identify users by their publicKey in your database.
createAuth(privateKey, pow?)Generate authentication token
const token = await createAuth(privateKey, 2); // pow = difficulty
Creates a signed auth token with timestamp, nonce, signature, and proof-of-work. Send this to your server for verification.
verifyAuth(token, pow?)Verify authentication token
const publicKey = await verifyAuth(token, 2);
if (publicKey) {
// ✅ Valid! User authenticated
console.log(`User ${publicKey} logged in`);
} else {
// ❌ Invalid or expired
}
Verifies the signature, proof-of-work, and timestamp (must be < 1 minute old). Returns the user's publicKey on success.
publicKey string or nullsign(message, privateKey, pow?)Sign any message
const { signature, pow } = await sign("hello world", privateKey, 2);
Create a cryptographic signature for any message with proof-of-work. Lower-level function used by createAuth().
{ signature: string, pow: number }verify(message, signatureData, publicKey, pow?)Verify any signature
const isValid = await verify("hello world", { signature, pow }, publicKey, 2);
Verify a message signature and proof-of-work. Lower-level function used by verifyAuth().
booleanimport express from "express";
import { verifyAuth, getUsername } from "daku";
const app = express();
// Middleware: Verify DAKU auth
const daku =
(powDifficulty = 2) =>
async (req, res, next) => {
const token = req.headers["daku"];
const publicKey = await verifyAuth(token, powDifficulty);
if (!publicKey) {
return res.status(401).json({ error: "Unauthorized" });
}
req.userId = publicKey; // Attach user ID
next();
};
// Protected route
app.post("/api/profile", daku(), async (req, res) => {
const username = await getUsername(req.userId);
res.json({
message: `Welcome, ${username}!`,
userId: req.userId,
});
});
app.listen(3000);
| Traditional Auth | DAKU |
|---|---|
| Manage passwords, hashes, resets | No passwords—just verify signatures |
| Store emails/phones (PII) | Zero personal data collected |
| User databases = security liability | Only store public keys (not sensitive) |
| Slow authentication flows | Instant cryptographic verification |
| GDPR compliance overhead | No PII = simpler compliance |
| Spam = manual moderation/CAPTCHAs | Built-in proof-of-work protection |
Users can reuse one private key across multiple services. Same privateKey → same publicKey → same identity everywhere.
// User's keypair works on yourapp.com AND anotherapp.com
const publicKey = getPublicKey(samePrivateKey);
// → Same publicKey = consistent cross-platform identity
[!WARNING]
Reusing keypairs links user identity across services. This enables seamless cross-app experiences but reduces anonymity between services. For per-app isolation, derive or generate separate keys.
DAKU: The authentication system that doesn't know anything about your users. By design.
FAQs
Leave no trace. Just authenticate.
The npm package daku receives a total of 26 weekly downloads. As such, daku popularity was classified as not popular.
We found that daku demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.