Installation
npm install @alexify/kerberospnpm add @alexify/kerberosyarn add @alexify/kerberosRequires Node.js ≥ 18 (or any modern browser through a bundler). The package is CommonJS; both require('@alexify/kerberos') and import { Kerberos } from '@alexify/kerberos' (via Node/bundler ESM interop) work — the examples throughout these docs use import.
Bundle size
Zero runtime dependencies. Measured with pnpm size (esbuild browser bundle, fully minified with identifier mangling, then gzipped):
| Entry | min | min+gzip |
|---|---|---|
@alexify/kerberos (main entry, query planner included) | 93.6 KB | 25.1 KB |
@alexify/kerberos/relations (opt-in ReBAC resolver) | 57.2 KB | 15.1 KB |
The /relations and /tests subpaths are only bundled if you import them. Optional tooling (jsep, zod, ajv, @sinclair/typebox, @opentelemetry/api) is never included — you install what you use.
Browser usage
The package ships two entrypoints: a Node.js entry (index.js, uses node:crypto / node:perf_hooks directly) and a browser entry (browser.js) declared via the package.json browser field and the browser condition in exports. Browser bundlers pick the browser build automatically — no configuration needed for webpack 5, Vite, esbuild (platform: 'browser'), Parcel or Bun. Rollup users need @rollup/plugin-node-resolve with browser: true.
The browser build contains zero Node.js builtins — the only platform-specific code (generateCallId, getNow) is swapped to a browser implementation backed by globalThis.crypto.randomUUID and globalThis.performance.
Notes
- In insecure contexts (plain HTTP), where
crypto.randomUUIDis unavailable, call IDs fall back to aMath.random-based pseudo UUID. Call IDs are correlation identifiers, not security tokens, so this is safe. - The package is CommonJS, so browser usage requires a bundler (no bare
<script>tag). - Node.js itself ignores the
browserfield entirely — server-side usage (with or without a bundler) always resolves the Node entry.