Zero-Storage Authentication Client SDK - The server knows absolutely nothing about your users.
Client-side JavaScript SDK for CryptoLogin - Zero-Knowledge-Inspired Passwordless Authentication.
Stop storing password hashes. With CryptoLogin, the server only stores encrypted challenges. The master secret is used once at registration, then forgotten. At login, no secret ever crosses the network.
CryptoLogin uses a challenge-response mechanism inspired by Zero-Knowledge principles. The server never stores your secret. Your secret never leaves your device.
´´´bash npm install cryptologin-client
import { createClient, deriveUserId } from "cryptologin-client";
// Initialize
const client = createClient({
baseURL: "https://your-api.com/api/v1",
});
// Register
const userId = await deriveUserId("your-master-secret-min-32-chars.");
await client.register(userId);
// Login
const session = await client.login(userId, "your-master-secret-min-32-chars.");
console.log("Authenticated:", session.authenticated);| Feature | Traditional Auth | CryptoLogin |
|---|---|---|
| Password storage | Hashed on server | Never stored |
| Database breach impact | Credentials exposed | Nothing to steal |
| "Forgot Password" | Email reset | Impossible by design |
| User sovereignty | Low | Absolute |
CryptoLogin uses a Zero-Storage Authentication model:
- Client-side derivation: The
user_idis derived frommaster_secretusing PBKDF2-SHA512 (100,000 iterations) - Challenge-Response: Server generates encrypted challenges using AES-256-GCM
- Local decryption: Client decrypts challenges locally -
master_secretNEVER leaves the browser - No server secrets: Server stores only encrypted tokens, not passwords or secrets
- Key Derivation: PBKDF2-SHA512 (100,000 iterations)
- Encryption: AES-256-GCM
- Hashing: SHA-256
CryptoLogin is NOT for everyone:
- ❌ No "Forgot Password" flow (server knows nothing)
- ❌ If user loses
master_secret, account is permanently locked - ✅ Absolute data sovereignty
- ✅ Zero server-side secrets to steal
- ✅ Immune to database breaches
This is a deliberate design choice, not a bug.
- 🔐 Passwordless Authentication - No email, no password required
- 🛡️ Zero-Knowledge-Inspired - Your secret never leaves your browser
- ⚡ Web Crypto API - Uses native browser cryptography
- 📦 Lightweight - ~3KB minified
- 🔧 TypeScript Support - Full type definitions included
- 🌐 Universal - Works in browsers and Node.js
npm install cryptologin-client
# or
yarn add cryptologin-client
# or
pnpm add cryptologin-client📖 API Documentation
API Reference
| Option | Type | Default | Description |
|---|---|---|---|
| baseURL | string | Required | Your CryptoLogin API URL |
| timeout | number | 10000 | Timeout in milliseconds |
| onError | function | null | Error callback |
createClient(options)
Creates a new CryptoLogin client.
const client = createClient({
baseURL: "https://api.example.com/v1", // Required
timeout: 30000, // Optional, default: 30000ms
});deriveUserId(masterSecret)
Derives a unique user ID from the master secret. Minimum 32 characters required.
const userId = await deriveUserId("my-super-secret-passphrase-1234567890");
// Returns: 64-character hex stringclient.register(userId)
Registers a new user with the server.
const result = await client.register(userId);
// Returns: { success: true, userId: '...' }
});client.login(userId, masterSecret)
Authenticates the user using challenge-response.
const session = await client.login(userId, masterSecret);
// Returns: { authenticated: true, sessionId: '...' }client.logout()
Logs out the current user.
await client.logout();Session Management
import { saveSession, loadSession, clearSession } from "cryptologin-client";
// Save session after login
saveSession(session);
// Load existing session
const session = loadSession();
// Clear session (logout)
clearSession();🧪 Development & Testing
# Install dependencies
npm install
# Run tests
npm test
# Run tests with coverage
npm run test:coverage
# Watch mode
npm test -- --watch📦 Publishing
npm version patch # or minor/major
npm publish🤝 Contributing
Contributions are welcome! Please read our Contributing Guide for details.
MIT © erabytse
. Server SDK (Python): cryptologin on PyPI
. Website: cryptologin-website
Reinventing Authentication. One Secret at a Time.
A quiet rebellion against digital waste.