# @securenative/sdk

Latest version **1.11.7** (published 2020-07-28) · MIT license · 0 weekly downloads

## Install

```sh
npm install @securenative/sdk
pnpm add @securenative/sdk
yarn add @securenative/sdk
bun add @securenative/sdk
```

## Health

**Score 25/100 (F)** — status: abandoned.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.11.7 |
| Published | 2020-07-28 |
| First published | 2019-05-26 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 10 |
| Unpacked size | 126.5 KB |
| Known vulnerabilities | 0 (+3 in 3 direct dependencies) |
| Install scripts | no |
| GitHub stars | 1 |
| Author | SecureNative |
| Maintainers | alexivsn |
| Keywords | securenative, sdk, agent, security-platform |

## Links

- npm: https://www.npmjs.com/package/@securenative/sdk
- Repository: https://github.com/securenative/securenative-node
- Homepage: https://github.com/securenative/securenative-node#readme
- Issues: https://github.com/securenative/securenative-node/issues
- npm.io page: https://npm.io/package/@securenative/sdk

## Dependencies (10)

- [ip](https://npm.io/package/ip.md) ^1.1.5
- [pino](https://npm.io/package/pino.md) ^5.13.2
- [uuid](https://npm.io/package/uuid.md) ^3.3.2
- [cookie](https://npm.io/package/cookie.md) ^0.3.1
- [shimmer](https://npm.io/package/shimmer.md) ^1.2.1
- [cls-hooked](https://npm.io/package/cls-hooked.md) ^4.2.2
- [node-fetch](https://npm.io/package/node-fetch.md) ^2.6.0
- [pino-pretty](https://npm.io/package/pino-pretty.md) ^3.2.1
- [futoin-ipset](https://npm.io/package/futoin-ipset.md) ^1.3.4
- [require-in-the-middle](https://npm.io/package/require-in-the-middle.md) ^5.0.3

## Alternatives

- [mobx-react](https://npm.io/package/mobx-react.md) — 2.8M weekly downloads
- [rc-tree](https://npm.io/package/rc-tree.md) — 2.6M weekly downloads
- [@react-oauth/google](https://npm.io/package/@react-oauth/google.md) — 1.3M weekly downloads
- [@wagmi/connectors](https://npm.io/package/@wagmi/connectors.md) — 877.0K weekly downloads
- [vee-validate](https://npm.io/package/vee-validate.md) — 836.4K weekly downloads

## Recent versions

- 1.11.7 (latest) — 2020-07-28
- 1.11.6 — 2020-07-20
- 1.11.5 — 2020-06-02
- 1.11.4 — 2020-05-20
- 1.11.3 — 2020-05-20
- 1.11.2 — 2020-05-20
- 1.11.1 — 2020-05-20
- 1.11.0 — 2020-05-19
- 1.10.0 — 2020-05-19
- 1.9.17 — 2020-05-17
- 1.9.16 — 2020-05-14
- 1.9.15 — 2020-05-14
- 1.9.13 — 2020-05-14
- 1.9.12 — 2020-05-14
- 1.9.11 — 2020-05-14
- … 38 more at https://npm.io/package/@securenative/sdk/versions

## README

<p align="center">
  <a href="https://www.securenative.com"><img src="https://user-images.githubusercontent.com/45174009/77826512-f023ed80-7120-11ea-80e0-58aacde0a84e.png" alt="SecureNative Logo"/></a>
</p>

<p align="center">
  <b>A Cloud-Native Security Monitoring and Protection for Modern Applications</b>
</p>
<p align="center">
  <a href="https://github.com/securenative/securenative-node">
    <img alt="Github Actions" src="https://github.com/securenative/securenative-node/workflows/Build/badge.svg">
  </a>
  <a href="https://codecov.io/gh/securenative/securenative-node">
    <img src="https://codecov.io/gh/securenative/securenative-node/branch/master/graph/badge.svg" />
  </a>
  <a href="https://badge.fury.io/js/%40securenative%2Fsdk">
    <img src="https://badge.fury.io/js/%40securenative%2Fsdk.svg" alt="npm version" height="20">
  </a>
  <a href="https://github.com/semantic-release/semantic-release">
    <img src="https://img.shields.io/badge/%20%20%F0%9F%93%A6%F0%9F%9A%80-semantic--release-e10079.svg" alt="npm version">
  </a>
</p>
<p align="center">
  <a href="https://docs.securenative.com">Documentation</a> |
  <a href="https://docs.securenative.com/quick-start">Quick Start</a> |
  <a href="https://blog.securenative.com">Blog</a> |
  <a href="">Chat with us on Slack!</a>
</p>
<hr/>

[SecureNative](https://www.securenative.com/) performs user monitoring by analyzing user interactions with your application and various factors such as network, devices, locations and access patterns to stop and prevent account takeover attacks.

## Install the SDK

Navigate to your application project folder and enter:

```bash
npm i @securenative/sdk
```

Verify that `@securenative/sdk` appears in your package to your `package.json`.

## Initialize the SDK

To get your *API KEY*, login to your SecureNative account and go to project settings page:

```js
import { SecureNative, EventTypes } from "@securenative/sdk";
or;
const { SecureNative, EventTypes } = require("@securenative/sdk"); // if your using ES5
``` 

### Option 1: Initialize via Config file
SecureNative can automatically load your config from *securenative.json* that you can add to your application folder.

```shell script
cat > securenative.json <<EOF
{
  "SECURENATIVE_APP_NAME": "YOUR_APPLICATION_NAME",
  "SECURENATIVE_API_KEY": "YOUR_API_KEY"
}
EOF
```

### Option 2: Initialize via config options

```java
SecureNative.init({ apiKey: "Your API_KEY" });
```

## Getting SecureNative instance
Once initialized, sdk will create a singleton instance which you can get: 
```java
const secureNative = SecureNative.getInstance();
```

## Tracking events

Once the SDK has been initialized, tracking requests sent through the SDK
instance. Make sure you build event with the EventBuilder:


```js
import { SecureNative, EventTypes, contextFromRequest } from "@securenative/sdk";

secureNative.track({
  event: EventTypes.LOG_IN,
  userId: '1234',
  userTraits: {
    name: 'Your Name',
    email: 'name@gmail.com',
    phone: '+1234567890'
  },
  context: contextFromRequest(req)
});
``` 

If you don't have acess to request object you can construct the context manually:

```js
secureNative.track({
  event: EventTypes.LOG_IN,
  userId: '1234',
  userTraits: {
    name: 'Your Name',
    email: 'name@gmail.com',
    phone: '+1234567890'
  },
  context: {
    ip: '10.0.0.0',
    clientToken: 'Token from client',
    headers: {
      "user-agent": 'Mozilla/5.0 (iPad; U; CPU OS 3_2_1 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Mobile/7B405"'
    }
  }
});
``` 

## Verify events
```js

  const verifyResult = await secureNative.verify({
    event: EventTypes.LOG_IN,
    userId: '1234',
    userTraits: {
      name: 'Your Name',
      email: 'name@gmail.com',
      phone: '+1234567890'
    },
    context: contextFromRequest(req)
  })

  verifyResult.riskLevel // Low, Medium, High
  verifyResult.score  // Risk score: 0 -1 (0 - Very Low, 1 - Very High)
  verifyResult.triggers // ["TOR", "New IP", "New City"]
}
```

## Configuration

| Option                          | Type    | Optional | Default Value                             | Description                                       |
| ------------------------------- | ------- | -------- | ----------------------------------------- | ------------------------------------------------- |
| SECURENATIVE_API_KEY            | string  | false    | none                                      | SecureNative api key                              |
| SECURENATIVE_APP_NAME           | string  | false    | package.json                              | Name of application source                        |
| SECURENATIVE_API_URL            | string  | true     | https://api.securenative.com/v1/collector | Default api base address                          |
| SECURENATIVE_INTERVAL           | number  | true     | 1000                                      | Default interval for SDK to try to persist events |                |
| SECURENATIVE_MAX_EVENTS         | number  | true     | 1000                                      | Max in-memory events queue                        |
| SECURENATIVE_TIMEOUT            | number  | true     | 1500                                      | API call timeout in ms                            |
| SECURENATIVE_AUTO_SEND          | Boolean | true     | true                                      | Should api auto send the events                   |
| SECURENATIVE_DISABLE            | Boolean | true     | true                                      | Allow to disable agent functionality              |
| SECURENATIVE_LOG_LEVEL          | string | true     | fatal                                     | Displays debug info to stdout                     |

## Compatibility

This agent is compatible with Node.js 8 and higher.

For other compatibility related information, please visit [the compatibility page](https://docs.securenative.com/nodejs/compatibility/).

## Documentation

For more details, please visit documentation page, available on [docs.securenative.com](https://docs.securenative.com/agent/nodejs).

---
_Source: https://npm.io/package/@securenative/sdk · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
