# `zappier/accounts` **Package:** `zappier` **Source:** `packages/zappier/src/accounts.ts` **Lines:** 166 ## What this module is Implementation module in `zappier`. The tables below are extracted from the source (signatures + JSDoc). ## Exports `hashPassword`, `verifyPassword`, `base32Encode`, `base32Decode`, `hotp`, `totp`, `verifyTotp`, `generateTotpSecret`, `totpUri`, `PortalSession`, `SessionRepo`, `newSessionToken`, `InMemorySessionRepo` ## Types / interfaces / classes | Kind | Name | |------|------| | interface | `PortalSession` | | interface | `SessionRepo` | | class | `InMemorySessionRepo` | ## Functions | Name | Parameters | Param types (JSDoc) | Returns | Calls (same file / helpers) | |------|------------|---------------------|---------|-----------------------------| | `hashPassword` | `password: string` | — | `unknown` | see Call graph | | | _Format: scrypt:N:r:p::_ | | | | | `verifyPassword` | `password: string, stored: string` | — | `unknown` | see Call graph | | `base32Encode` | `buf: Buffer` | — | `unknown` | see Call graph | | `base32Decode` | `s: string` | — | `unknown` | see Call graph | | `hotp` | `secret: string, counter: number, digits = 6` | — | `unknown` | see Call graph | | `totp` | `secret: string, atMs: number, stepSec = 30, digits = 6` | — | `unknown` | see Call graph | | `verifyTotp` | `secret: string, code: string, atMs: number, window = 1,` | — | `unknown` | see Call graph | | `generateTotpSecret` | `(none)` | — | `unknown` | see Call graph | | | _160-bit secret, base32 without padding (authenticator-app standard)._ | | | | | `totpUri` | `secret: string, email: string, issuer = 'Zappier'` | — | `unknown` | see Call graph | | | _160-bit secret, base32 without padding (authenticator-app standard)._ | | | | | `newSessionToken` | `(none)` | — | `unknown` | see Call graph | | | _Returns the session, or undefined when unknown or expired at nowMs._ | | | | ## Methods (class / object) | Name | Parameters | |------|------------| | `create` | `customerId: string, ttlMs: number` | | `get` | `token: string, nowMs?: number` | | `delete` | `token: string` | | `create` | `customerId: string, ttlMs: number` | | `get` | `token: string, nowMs = Date.now(` | | `delete` | `token: string` | ## What it imports / requires - `crypto` ## Call graph (identifiers invoked) `hashing`, `secrets`, `hashPassword`, `randomBytes`, `scryptSync`, `toString`, `verifyPassword`, `split`, `from`, `timingSafeEqual`, `base32`, `base32Encode`, `base32Decode`, `toUpperCase`, `replace`, `indexOf`, `push`, `hotp`, `alloc`, `writeBigUInt64BE`, `createHmac`, `update`, `digest`, `padStart`, `totp`, `floor`, `verifyTotp`, `test`, `padding`, `generateTotpSecret`, `totpUri`, `encodeURIComponent`, `create`, `get`, `delete`, `newSessionToken`, `now`, `set` Each identifier is a call site in this file. Follow the import list to see the defining module; open that module’s MD for parameter and return types. ## Return values (how to read this) - HTTP route handlers return Express `res.json(...)` bodies (see route docs). - Zapier `perform` functions return a **single object** (creates) or an **array** (triggers/searches). - Pricing functions return integer **cents** on `Quote.totalCents`.