{"_id":"@0x402/seal","_rev":"3-2d1d23eebaded090bc10dd786f44dc0c","name":"@0x402/seal","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@0x402/seal","version":"0.1.0","keywords":["seal","eip-191","attestation","verification","agent"],"author":{"name":"Wayne Kuo"},"license":"MIT","_id":"@0x402/seal@0.1.0","maintainers":[{"name":"waynekuo","email":"wayne.k@typuslab.com"}],"homepage":"https://wayneal.github.io/0G","bugs":{"url":"https://github.com/WayneAl/0G/issues"},"dist":{"shasum":"50e96c61c6789cdd3714920832379ad754126acc","tarball":"https://registry.npmjs.org/@0x402/seal/-/seal-0.1.0.tgz","fileCount":19,"integrity":"sha512-lHAJqL+WLixnw688tYjhntID+NQcQYI4E+/D3Gx2tChBX7Ln5up+YAyXAiEptutCVwXv40pX/vlyT2fW5BtPPg==","signatures":[{"sig":"MEQCIGvsaYdxxQ5xeLP13gHQAds8j3PRK20sAKraYE7vJqZvAiAlV0MNH6FMlOQLR/kmtghgpKiKOMwOFSX8ZOSVa9GSrg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":59842},"main":"./dist/index.js","type":"module","_from":"file:0x402-seal-0.1.0.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","gen-fixture":"tsx scripts/gen-fixture.ts"},"_npmUser":{"name":"waynekuo","email":"wayne.k@typuslab.com"},"_resolved":"/private/var/folders/v9/gfr09p7j5nj2hsj_v0h5cq480000gn/T/b1ae525677214d7c393e561446e38650/0x402-seal-0.1.0.tgz","_integrity":"sha512-lHAJqL+WLixnw688tYjhntID+NQcQYI4E+/D3Gx2tChBX7Ln5up+YAyXAiEptutCVwXv40pX/vlyT2fW5BtPPg==","repository":{"url":"git+https://github.com/WayneAl/0G.git","type":"git","directory":"packages/seal"},"_npmVersion":"11.11.0","description":"The seal format and every check that decides whether one is real: canonical encoding, EIP-191 signing, and verification that walks an underwriting seal into the audit seal embedded in it.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^3.24.2","viem":"^2.23.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2"},"_npmOperationalInternal":{"tmp":"tmp/seal_0.1.0_1788793213100_0.41718399486402125","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@0x402/seal","version":"0.1.1","keywords":["seal","eip-191","attestation","verification","agent"],"author":{"name":"Wayne Kuo"},"license":"MIT","_id":"@0x402/seal@0.1.1","maintainers":[{"name":"waynekuo","email":"wayne.k@typuslab.com"}],"homepage":"https://wayneal.github.io/0G","bugs":{"url":"https://github.com/WayneAl/0G/issues"},"dist":{"shasum":"54cd8902decb58cc1ad43ec723be88d84392e285","tarball":"https://registry.npmjs.org/@0x402/seal/-/seal-0.1.1.tgz","fileCount":19,"integrity":"sha512-kQ5QG7jaE+9h6Tzfk8YUj0jNHFL9TYebBvo+mtQ/sI46VNfgLr4oMPZI+sne3MWpaK12oG3rCSCmq7QtIze2MA==","signatures":[{"sig":"MEUCIQDApiwLG188itRTSjL8799jKW/c7JQ5EAuRjnW+Q7U49QIgXV5fSGOEsKmZzE5Y2sr1zf7g5NZd7Uay2mcPGVQdqeA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":64685},"main":"./dist/index.js","type":"module","_from":"file:0x402-seal-0.1.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","gen-fixture":"tsx scripts/gen-fixture.ts"},"_npmUser":{"name":"waynekuo","email":"wayne.k@typuslab.com"},"_resolved":"/private/var/folders/v9/gfr09p7j5nj2hsj_v0h5cq480000gn/T/b91bff3f779c59c611e289c1e7142c79/0x402-seal-0.1.1.tgz","_integrity":"sha512-kQ5QG7jaE+9h6Tzfk8YUj0jNHFL9TYebBvo+mtQ/sI46VNfgLr4oMPZI+sne3MWpaK12oG3rCSCmq7QtIze2MA==","repository":{"url":"git+https://github.com/WayneAl/0G.git","type":"git","directory":"packages/seal"},"_npmVersion":"11.11.0","description":"The seal format and every check that decides whether one is real: canonical encoding, EIP-191 signing, and verification that walks an underwriting seal into the audit seal embedded in it.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^3.24.2","viem":"^2.23.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2"},"_npmOperationalInternal":{"tmp":"tmp/seal_0.1.1_1788838301902_0.9111868912382572","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@0x402/seal","version":"0.1.2","description":"The seal format and every check that decides whether one is real: canonical encoding, EIP-191 signing, and verification that walks an underwriting seal into the audit seal embedded in it.","license":"MIT","author":{"name":"Wayne Kuo"},"homepage":"https://wayneal.github.io/0G","repository":{"type":"git","url":"git+https://github.com/WayneAl/0G.git","directory":"packages/seal"},"bugs":{"url":"https://github.com/WayneAl/0G/issues"},"keywords":["seal","eip-191","attestation","verification","agent"],"type":"module","main":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"publishConfig":{"access":"public"},"dependencies":{"viem":"^2.23.2","zod":"^3.24.2"},"devDependencies":{"tsx":"^4.19.2"},"scripts":{"build":"tsc -p tsconfig.build.json","test":"vitest run","typecheck":"tsc --noEmit","gen-fixture":"tsx scripts/gen-fixture.ts"},"types":"./dist/index.d.ts","_id":"@0x402/seal@0.1.2","_integrity":"sha512-m3z7VNyj/ChGK6EWTYaNjECSLCEPpzcNihNTy4jMD979SCIucAcSWv18Sgny7dOAxy7XcRlXW10HLPs/BNxslg==","_resolved":"/private/var/folders/v9/gfr09p7j5nj2hsj_v0h5cq480000gn/T/eef03cf204fdd899bffd084497d3f9e2/0x402-seal-0.1.2.tgz","_from":"file:0x402-seal-0.1.2.tgz","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-m3z7VNyj/ChGK6EWTYaNjECSLCEPpzcNihNTy4jMD979SCIucAcSWv18Sgny7dOAxy7XcRlXW10HLPs/BNxslg==","shasum":"402f13dac23075c6fb249991b161fa15f0b02d4f","tarball":"https://registry.npmjs.org/@0x402/seal/-/seal-0.1.2.tgz","fileCount":19,"unpackedSize":66514,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDgYKy8R0TCB41RIY41/YLnx0dpBKq2nrfJUZ4pgWFEvgIhAP3FYedOhZj0CCR8Q2E7q7HMJ3ueZHoZVFpkOxQUGWWn"}]},"_npmUser":{"name":"waynekuo","email":"wayne.k@typuslab.com"},"directories":{},"maintainers":[{"name":"waynekuo","email":"wayne.k@typuslab.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/seal_0.1.2_1788845346078_0.2871472811609479"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-07T15:00:12.874Z","modified":"2026-09-08T05:29:06.377Z","0.1.0":"2026-09-07T15:00:13.244Z","0.1.1":"2026-09-08T03:31:42.051Z","0.1.2":"2026-09-08T05:29:06.214Z"},"bugs":{"url":"https://github.com/WayneAl/0G/issues"},"author":{"name":"Wayne Kuo"},"license":"MIT","homepage":"https://wayneal.github.io/0G","keywords":["seal","eip-191","attestation","verification","agent"],"repository":{"type":"git","url":"git+https://github.com/WayneAl/0G.git","directory":"packages/seal"},"description":"The seal format and every check that decides whether one is real: canonical encoding, EIP-191 signing, and verification that walks an underwriting seal into the audit seal embedded in it.","maintainers":[{"name":"waynekuo","email":"wayne.k@typuslab.com"}],"readme":"# @0x402/seal\n\nThe seal format, and every check that decides whether one is real.\n\nA **seal** is a signed statement an agent makes about work it did. An *audit* seal\n(seal B) says what an auditor found; an *underwriting* seal (seal A) says what an\nunderwriter decided — and carries the audit seal it paid for whole, inside itself.\nSo one object proves the entire chain, and anyone can check it without asking anybody.\n\n```bash\nnpm i @0x402/seal\n```\n\n## Verify\n\n```ts\nimport { verifySealA, SealVerificationError } from \"@0x402/seal\";\n\ntry {\n  await verifySealA(seal, { expectedSubject: token, resolver, now });\n  // Every check below passed, including on the seal B embedded inside.\n} catch (err) {\n  if (err instanceof SealVerificationError) console.log(err.failure, err.message);\n}\n```\n\n`verifySealB` does the same for a bare audit seal. Verification is pure: no network,\nexcept the agent id → signer lookup you supply as `resolver`.\n\n| Check | Refusal | What it means |\n|---|---|---|\n| `SCHEMA` | `SCHEMA_INVALID` | Not a seal of the shape and version claimed. |\n| `AGENT_ID_LIVE` | `AGENT_ID_NOT_LIVE` | The agent id resolves to no signer in the directory. |\n| `SIGNATURE` | `SIGNATURE_INVALID` · `SIGNER_MISMATCH` | The digest recomputed from the seal's own bytes recovers to somebody else, or to nobody. |\n| `SUBJECT` | `SUBJECT_MISMATCH` | The seal is about a different token than the one asked about. |\n| `REQUEST` | `REQUEST_MISMATCH` | Seal B answers a different request than the one made. |\n| `EXPIRY` | `SEAL_EXPIRED` | The seal's window has closed. |\n| `ATTESTATION` | `ATTESTATION_MISSING` | An attested tier is claimed and no attestation is carried. |\n| `TRUST_TIER` | `TRUST_MODE_INSUFFICIENT` | The inference ran below the tier an underwriter will act on. |\n\nVerification stops at the first failure and names it. That is deliberate: \"we did not\nlook\" is not the same claim as \"it is fine\".\n\n## Sign\n\n```ts\nimport { signSealA, sealDigest, canonicalize } from \"@0x402/seal\";\n```\n\nThe signature covers `keccak256(canonicalize(seal))` over EIP-191, so the bytes that\nare stored are the bytes that were signed and a reader can re-derive both without\ntrusting the storage layer.\n\n## Resolvers\n\n`agentId → signer` comes from an `AgentIdResolver`: `StaticAgentIdResolver` for a\nsigner you name, `HttpAgentIdResolver` / `resolverFromDirectory` for a published\n`directory.json`. This module has no `node:` imports, so it runs in a browser too —\nwhich is how the project's site verifies a pasted seal with no backend at all.\n\n## What a seal does not prove\n\nTraceability, not correctness. A perfectly signed wrong answer still verifies.\n\n---\n\n[Repository](https://github.com/WayneAl/0G) · [Site](https://wayneal.github.io/0G) · MIT\n","readmeFilename":"README.md"}