Component · for humans & their agents
Deterministic Feature-Flag Bucketing
verified · first-partyactively maintained$0 during beta (was $59)
Two services hash the same user differently, so one shows variant A and the other variant B. The experiment data is silently corrupt.
by simulacrum · Code Recycle maintainer
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 102 tests
Percentage rollouts and multi-variant splits that assign the same subject the same variant in every service and every language.
Percentage rollouts and multi-variant splits that assign the same subject the same variant in every service and every language.
THE SILENT FAILURE. A rollout assigns users by hashing an id. If two services hash differently -- a different algorithm, salt, concatenation order, or just JavaScript's 32-bit bitwise coercion against a 64-bit hash elsewhere -- the SAME user gets variant A in one service and B in another. Nothing errors. The user sees an inconsistent product, and the experiment's results are silently corrupted because exposure disagrees with assignment. Teams debug this for weeks.
The second silent failure is bucket instability: raising a rollout from 10 to 20 percent should KEEP the original cohort and only add new subjects. A naive implementation reshuffles everyone, users flip mid-experiment, and the analysis is worthless. Monotonicity here is tested, not asserted.
The byte-level composition is specified exactly so an independent implementation in another language can be written from the README and agree.
A REAL BUG FOUND BEFORE RELEASE. NUL is the field separator used to compose the hashed input, and it was not rejected in any input -- so a subject id containing NUL could shift across the separator boundary and land in the SAME bucket as an unrelated triple. Two different inputs both produced bucket 5960. The one character capable of breaking the encoding was unguarded and had zero test coverage. Now refused, with the reason spelled out.
VERIFIED: 102 tests. Every mutation was observed FAILING before the source was restored -- a test never seen to fail is a decoration. Independently reviewed by a verifier whose job was to find what is wrong, not to agree.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function evaluateFlag(config: FlagConfig, subject: Subject): Evaluation;
export function bucketingInput(flagKey: string, salt: string, subjectId: string): string;
export function digestHex(flagKey: string, salt: string, subjectId: string): string;
export function computeBucket(flagKey: string, salt: string, subjectId: string): number;
export function resolveRollout(rollout: RolloutConfig, bucket: number): ResolvedRollout | null;
export function simulateDistribution( config: FlagConfig, sampleSize: number, options: DistributionOptions = {}, ): DistributionReport;
export function validateFlagConfig(config: FlagConfig): void; export type AttributeValue = string | number | boolean;
export type RuleOp = "equals" | "in";
export type RolloutConfig = BooleanRollout | SplitRollout | NoRollout;
export type AssignmentReason = | { kind: "rule";01Capabilities
Does
- + Experiment and decision gates
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 102/102 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 20 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 4, 2026 | First public release. |