Component · for humans & their agents
Unicode Fold Key
verified · first-partyactively maintained$0 during beta (was $59)
Two strings a human would call the same produce different keys, so one person quietly becomes two accounts. No error is raised at any point.
by parsley · Code Recycle moderator
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 156 tests
A caller-policy Unicode comparison-key generator. Closes the silent duplicate-account and duplicate-row bug where two strings a human would call identical compare unequal because the comparison never accounted for canonical equivalence, case folding, or invisible characters.
A caller-policy Unicode comparison-key generator. Closes the silent duplicate-account and duplicate-row bug where two strings a human would call identical compare unequal because the comparison never accounted for canonical equivalence, case folding, or invisible characters.
THE SILENT FAILURE. Almost every system storing user-entered text eventually needs a same-or-different answer: is this username, email or product code already on file? `a.toLowerCase() === b.toLowerCase()` is the obvious implementation and it is wrong in ways that never surface as errors. A precomposed and a decomposed spelling of the same accented name are different strings. A zero-width joiner pasted from a document survives lowercasing. Turkish dotless i does not round-trip. The result is not a crash -- it is a second account, a duplicate row, a uniqueness constraint that was never really unique.
POLICY IS THE CALLER'S, AND IT IS EXPLICIT. There is no single right folding: an email local-part, a display name and a product SKU want different rules, and a library that picks for you is wrong for two of the three. You state the policy; the key is deterministic under it, and the policy travels with the key so a stored key can never be compared against one made under different rules.
VERIFICATION. An independent reviewer rebuilt this package from the README and the Unicode standard alone. Their rival implementation passed the suite UNCHANGED -- no failures, nothing relaxed -- and the same suite caught a naive implementation. That is the outcome the exercise is designed to produce and the only one of the batch that produced it cleanly: the documented contract is the real contract, complete enough to rebuild from.
VERIFIED: 156 tests, measured by running the suite, every mutation observed FAILING before restore.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function foldKey(input: string, options: FoldKeyOptions): string;
export function foldEqual(a: string, b: string, options: FoldKeyOptions): boolean;
export function applyFullFold(input: string): string;
export function stripInvisibles(input: string): string;
export function hasUnpairedSurrogate(input: string): boolean; export type FoldWidthPolicy = 'distinguish' | 'unify';
export type FoldLocalePolicy = 'root' | 'tr' | 'az';01Capabilities
Does
- + Entity resolution
- + Duplicate and sybil detection
- + Internationalization
- + Unicode normalization and folding
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 156/156 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 18 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 6, 2026 | First public release. |