NakodaX

Developers

Command-line tools for protected work.

nkx-upload encrypts large video and audio recordings on your computer before it uploads them. nkx handles protected source code in CI builds and developer change sessions. Every release is signed, so you can check what you download.

A command-line tool can do what a browser cannot: read a 5 GB recording from disk, lock it on your own machine, and resume if the connection drops.

For Document Protection

nkx-upload: encrypted upload for large recordings

The browser upload in NakodaX box stops at 500 MB. nkx-upload takes video and audio files of up to 5 GB, encrypts each one on your computer, and uploads it to your box drive. Once uploaded, a recording plays and shares like any other protected document, and you decide who can open it and for how long. It runs on macOS, Windows 10 and 11, and Linux.

macOS and Linux
curl -fsSL https://box.nakodax.com/install.sh | sh
Windows (PowerShell)
powershell -ExecutionPolicy ByPass -c "irm https://box.nakodax.com/install.ps1 | iex"
Homebrew
brew install nakodax/tap/nkx-upload
Scoop
scoop bucket add nakodax https://github.com/nakodax/scoop-bucket
scoop install nakodax/nkx-upload
Sign in once, then upload
nkx-upload login
nkx-upload upload "board meeting.mov"

Sign-in happens in your own browser, so the tool never sees your password. Full commands, supported file types and troubleshooting are in the nkx-upload README on GitHub.

Locked before it leaves

Each file is encrypted with AES-256 on your computer before any part of it is uploaded, and it stays encrypted in storage.

A sign-in that can only upload

The command-line sign-in can add recordings to your drive. It cannot open, download, share or delete anything, and it ends after 30 days.

Picks up where it stopped

If your connection drops, the upload pauses and continues when the network returns, for up to an hour.

For Source Protection

nkx: build and change protected source code

nkx is the command-line tool for Source Protection. In a CI build it decrypts the protected files your compiler needs and re-encrypts the compiled output afterwards. For a developer it unlocks protected code for an approved change session and reseals it when the session ends. It is a single binary with no Python or Node.js install. Your Source Console shows the exact command and credentials for each setup on its Connect page.

Homebrew (macOS and Linux)
brew install nakodax/tap/nkx

Other platforms

Download the binary for macOS, Linux or Windows, on x64 or arm64, from the latest release. Each release includes a checksum file and signatures.

To run the protected software itself, use the runtime SDK. For Node.js that is @nakodax/runtime.

nkx commands

nkx register
Set up credentials for a protected repository from a Register Token.
nkx materialize
In CI, decrypt the protected files into a folder ahead of your own compiler.
nkx rehook
In CI, re-encrypt compiled TypeScript or JavaScript output after your build.
nkx unlock
Decrypt this release's protected files for local editing in an approved change session.
nkx reseal
Re-encrypt the files and remove the plaintext, ending the session.
nkx unlock-mock
Decrypt one file's mock stub so you can edit it by hand.
nkx reseal-mock
Re-encrypt one file's hand-edited mock stub.
nkx status
Show whether the repository is protected or unlocked.

Check what you downloaded

Every release file of both tools is signed with Sigstore cosign, and every release has a SHA256SUMS file for a plain checksum. The install scripts check the download against it before installing. The exact verification command is in each release’s notes and README.

Answers

Developer tool questions

How do I upload a video larger than 500 MB to NakodaX box?
Install nkx-upload, run nkx-upload login once, then run nkx-upload upload with the file name. The browser upload stops at 500 MB. nkx-upload takes recordings of up to 5 GB.
Is nkx-upload free?
It is free to install and use with a NakodaX box account. Each file you upload counts toward your plan, the same as an upload in the browser.
Can NakodaX see my recording?
No. The file is encrypted on your computer before it is uploaded, and it stays encrypted in storage. Only you and the people you share it with in box can play it.
Can someone who steals my nkx-upload sign-in read my files?
No. A command-line sign-in can only upload. It cannot open, download or share anything. If you think one has been exposed, end it in box under Settings, then Profile, and it stops working straight away.
Which operating systems do the tools support?
nkx-upload runs on macOS (Apple silicon and Intel), Windows 10 and 11 (64-bit), and Linux on x64 and arm64. nkx is published for macOS, Linux and Windows on x64 and arm64.
What does nkx do?
nkx is the command-line tool for NakodaX Source Protection. In a CI build it decrypts the protected files your compiler needs and re-encrypts the compiled output. For a developer it unlocks protected code for an approved change session and reseals it afterwards. To run the protected software itself, use the runtime SDK.
Do I need Python or Node.js to run nkx?
No. nkx is a single binary with no dependencies.
How do I know a download is genuine?
Compare it with the release's SHA256SUMS file, or verify its Sigstore cosign signature using the command in the release notes.

Need help setting up a tool?

Tell us what you are trying to protect and where it runs, and we will point you to the right setup.