
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
Anonymous authentication. Zero personal data.
DAKU (pronounced DAA KU) means "bandits" in Punjabi. Historically, bandits operated anonymously, often using masks to hide their identity. This library adopts that privacy-first ethos—anonymous cryptographic authentication without personal data.
Stop storing passwords. Stop managing email verifications. Stop worrying about data breaches.
DAKU is a simpler approach to user authentication that keeps both you and your users anonymous. No databases of usernames, no password hashes to secure, no personal information to leak.
// Traditional auth: Store emails, hash passwords, manage resets...
// DAKU: Just verify cryptographic signatures ✨
const publicKey = await verifyAuth(token);
Every traditional authentication system carries risk:
Users authenticate with cryptographic keypairs—like Bitcoin wallets, but for your app:
DAKU uses secp256k1 signatures (same as Bitcoin/Ethereum) with proof-of-work spam protection. Auth tokens expire in 1 minute. Users control their private keys, you just verify signatures.
npm install daku
import { generateKeyPair, createAuth, verifyAuth } from "daku";
// 1. User generates keypair (client-side)
const { privateKey, publicKey } = generateKeyPair();
// 2. Create auth token (client-side)
const token = await createAuth(privateKey);
// 3. Verify auth (server-side)
const publicKey = await verifyAuth(token);
// ✅ Authenticated! publicKey is the unique user ID
generateKeyPair()Create a new identity
const { privateKey, publicKey } = generateKeyPair();
Generates a secp256k1 keypair. The privateKey stays with the user (never share it), the publicKey identifies them to your service.
{ privateKey: string, publicKey: string }getPublicKey(privateKey)Derive the public identity
const publicKey = getPublicKey(privateKey);
Extract the public key from a private key. Useful when users return with their saved privateKey.
publicKey stringgetUsername(publicKey)Make public keys human-readable
const username = await getUsername(publicKey);
// → "happy-ocean-flows-1234"
Public keys are long hex strings. getUsername() converts them into memorable usernames for your UI.
adjective-noun-verb-number[!IMPORTANT]
Never ask users to create usernames. DAKU keeps users anonymous. Display the generated username in your UI, but always identify users by their publicKey in your database.
createAuth(privateKey, pow?)Generate authentication token
const token = await createAuth(privateKey, 2); // pow = difficulty
Creates a signed auth token with timestamp, nonce, signature, and proof-of-work. Send this to your server for verification.
verifyAuth(token, pow?)Verify authentication token
const publicKey = await verifyAuth(token, 2);
if (publicKey) {
// ✅ Valid! User authenticated
console.log(`User ${publicKey} logged in`);
} else {
// ❌ Invalid or expired
}
Verifies the signature, proof-of-work, and timestamp (must be < 1 minute old). Returns the user's publicKey on success.
publicKey string or nullsign(message, privateKey, pow?)Sign any message
const { signature, pow } = await sign("hello world", privateKey, 2);
Create a cryptographic signature for any message with proof-of-work. Lower-level function used by createAuth().
{ signature: string, pow: number }verify(message, signatureData, publicKey, pow?)Verify any signature
const isValid = await verify("hello world", { signature, pow }, publicKey, 2);
Verify a message signature and proof-of-work. Lower-level function used by verifyAuth().
booleanimport express from "express";
import { verifyAuth, getUsername } from "daku";
const app = express();
// Middleware: Verify DAKU auth
const daku =
(powDifficulty = 2) =>
async (req, res, next) => {
const token = req.headers["daku"];
const publicKey = await verifyAuth(token, powDifficulty);
if (!publicKey) {
return res.status(401).json({ error: "Unauthorized" });
}
req.userId = publicKey; // Attach user ID
next();
};
// Protected route
app.post("/api/profile", daku(), async (req, res) => {
const username = await getUsername(req.userId);
res.json({
message: `Welcome, ${username}!`,
userId: req.userId,
});
});
app.listen(3000);
| Traditional Auth | DAKU |
|---|---|
| Manage passwords, hashes, resets | No passwords—just verify signatures |
| Store emails/phones (PII) | Zero personal data collected |
| User databases = security liability | Only store public keys (not sensitive) |
| Slow authentication flows | Instant cryptographic verification |
| GDPR compliance overhead | No PII = simpler compliance |
| Spam = manual moderation/CAPTCHAs | Built-in proof-of-work protection |
Users can reuse one private key across multiple services. Same privateKey → same publicKey → same identity everywhere.
// User's keypair works on yourapp.com AND anotherapp.com
const publicKey = getPublicKey(samePrivateKey);
// → Same publicKey = consistent cross-platform identity
[!WARNING]
Reusing keypairs links user identity across services. This enables seamless cross-app experiences but reduces anonymity between services. For per-app isolation, derive or generate separate keys.
DAKU: The authentication system that doesn't know anything about your users. By design.
FAQs
Leave no trace. Just authenticate.
The npm package daku receives a total of 36 weekly downloads. As such, daku popularity was classified as not popular.
We found that daku demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.