Skip to content
Status

Status

Worker-safe bearer-key generation and hashing primitives

Ear Tag is on version 0.0.0. Until 1.0, a minor release can change the public API, so pin the version you test against.

The key is a bearer secret: anyone who obtains it can present it to the system that accepts it. Do not log or persist plaintext keys. Retain the digest and give the plaintext only to its intended recipient. This package does not compare a candidate key with a stored digest or implement credential policy.

hashKey requires Web Crypto’s crypto.subtle.digest. Key length follows Cairn’s raw nanoid sizing behavior. Callers should supply a bounded nonnegative integer rather than untrusted sizing input. Ear Tag does not set expiry, scope, rate limits, or revocation rules.

Ear Tag is MIT licensed. See LICENSE.