{"_id":"@0xshae/glide-gateway","name":"@0xshae/glide-gateway","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@0xshae/glide-gateway","version":"1.0.0","description":"Middleware that verifies World ID and unlocks payments for human-backed agent requests.","main":"dist/lib.js","types":"dist/lib.d.ts","scripts":{"dev":"ts-node-dev --respawn --transpile-only src/index.ts","demo:bot":"npx tsx scripts/demo-bot.ts","demo:human":"npx tsx scripts/demo-human.ts","demo:premium":"npx tsx scripts/demo-premium.ts","build":"tsc","start":"node dist/index.js","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"keywords":["x402","worldid","agentkit","xmtp","agentic","checkout","gateway"],"license":"MIT","dependencies":{"@worldcoin/agentkit":"^0.1.0","@x402/core":"^2.8.0","@x402/evm":"^2.8.0","@x402/express":"^2.8.0","@x402/fetch":"^2.8.0","@xmtp/agent-sdk":"^2.2.0","better-sqlite3":"^11.0.0","dotenv":"^16.4.0","express":"^4.21.0","nanoid":"^3.3.7","viem":"^2.47.6"},"devDependencies":{"@types/better-sqlite3":"^7.6.0","@types/express":"^5.0.0","@types/node":"^22.0.0","ts-node-dev":"^2.0.0","typescript":"^5.7.0"},"gitHead":"e23c4d396f1a888870294625c04b9c0b16e43c4a","_id":"@0xshae/glide-gateway@1.0.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-HEadke4MJrJGNwj4X69EdJVruU0Pb5l37H0VB4keCNkAJ/CxzNBcNhWP8/V5tbuIl3N/BRI/diap3MsiK1FJaw==","shasum":"0b878167f7336971ce0c0c46f4aa9084a11edc25","tarball":"https://registry.npmjs.org/@0xshae/glide-gateway/-/glide-gateway-1.0.0.tgz","fileCount":30,"unpackedSize":63865,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD0MN6pzc/7x8IbscJJ9GCUId7vcGc2DdMGIE/5gkWYJwIgZlv/kQvwvss3xv/P5Tb3sglGCXGza7plxdmZY9CzhJs="}]},"_npmUser":{"name":"0xshae","email":"shagun.prasad28@gmail.com"},"directories":{},"maintainers":[{"name":"0xshae","email":"shagun.prasad28@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/glide-gateway_1.0.0_1774802446908_0.3104917473757991"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-29T16:40:46.748Z","1.0.0":"2026-03-29T16:40:47.061Z","modified":"2026-03-29T16:40:47.312Z"},"maintainers":[{"name":"0xshae","email":"shagun.prasad28@gmail.com"}],"description":"Middleware that verifies World ID and unlocks payments for human-backed agent requests.","keywords":["x402","worldid","agentkit","xmtp","agentic","checkout","gateway"],"license":"MIT","readme":"# GLIDE — Human-Aware API Gateway\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Stack: World ID + x402 + XMTP](https://img.shields.io/badge/Stack-World%20ID%20+%20x402%20+%20XMTP-blueviolet)](https://world.org/)\n\n**Middleware that verifies World ID and unlocks payments for human-backed agent requests.**\n\nThe internet wasn't built for machines. APIs can't tell if a request comes from a real human or a bot. Glide sits in front of any API and enforces a 3-tier access model based on **proof of humanity** — powered by World ID, x402 payments, and XMTP audit receipts.\n\n---\n\n## Table of Contents\n- [Problem Statement](#problem-statement)\n- [How It Works (3-Tier Model)](#how-it-works)\n- [Technological Stack](#technological-stack)\n- [Architecture & File Structure](#architecture--file-structure)\n- [Technical Deep Dive — Middleware](#technical-deep-dive--middleware)\n- [Audit System — XMTP & Revocation](#audit-system--xmtp--revocation)\n- [Integration Guide](#integration-guide)\n- [Known Issues & Workarounds](#known-issues--workarounds)\n\n---\n\n## The Problem Statement\nIn the agentic economy, APIs are flooded by autonomous agents. Traditional \"Pay-Per-API\" models create a \"Bot Tax\" for humans: you shouldn't have to pay for every single request once you've proven you're a human person. Simultaneously, bots should pay to prevent spam and resource exhaustion.\n\n**Glide solves this by:**\n1. **Granting free, high-speed access** to verified humans (World ID).\n2. **Enforcing on-chain settlement** for unverified bot traffic (x402).\n3. **Offering \"Instant Premium\" access** for humans who also pay for extra features.\n\n---\n\n## How It Works\nGlide enforces a 3-Tier Access Model directly at the middleware layer:\n\n| Tier | Requirement | Priority | Cost | UX Effect |\n| :--- | :--- | :--- | :--- | :--- |\n| **BOT** | No World ID | Low | **$1.00 USDC** | 2000ms Throttle |\n| **HUMAN** | World ID (Proof of Personhood) | High | **$0.00** | <50ms Latency |\n| **PREMIUM**| World ID + x402 Payment | Instant | **$0.50 USDC**| <10ms + Ultra Quality |\n\n---\n\n## Technological Stack\n- **Identity Layer**: [World ID](https://world.org/world-id) (Zk-Proofs for personhood).\n- **Payment Layer**: [x402 protocol](https://x402.org) (The HTTP-native payment standard).\n- **Network**: [Base Sepolia](https://base.org) (Fast, low-cost L2).\n- **Communication Layer**: [XMTP](https://xmtp.org) (Audit logs & receipts).\n- **Backend**: Node.js, Express, TypeScript, Better-SQLite3.\n- **Frontend**: Next.js 15 (Tailwind CSS, Framer Motion).\n\n---\n\n## Architecture & File Structure\n\n```text\n.\n├── src/\n│   ├── index.ts           # Main Gateway entry (Express + x402 Resource Server)\n│   ├── config.ts          # Environment & Pricing configuration\n│   ├── db.ts              # SQLite layer for transaction persistence\n│   ├── agentkit.ts        # World ID AgentKit hooks & extensions\n│   ├── middleware/\n│   │   └── glide.ts       # THE CORE: 3-tier access control logic\n│   └── services/\n│       └── xmtp.ts        # Fire-and-forget Audit delivery system\n├── glide/                 # Next.js Dashboard & Landing Page\n├── scripts/               # End-to-end demo simulations (Bot/Human/Premium)\n└── README.md              # You are here\n```\n\n---\n\n## Technical Deep Dive — Middleware\n\nThe heart of Glide is the `glideMiddleware` which resolves the access tier before the request even reaches your business logic.\n\n### Tier Resolution Logic\nThe system inspects incoming HTTP headers to determine the request's \"DNA\":\n```typescript\nfunction resolveTier(req: Request): GlideTier {\n  const hasWorldId = !!req.headers[\"x-world-id-proof\"];\n  const hasPaid = !!req.headers[\"x-payment-verified\"];\n\n  if (hasWorldId && hasPaid) return \"premium\";\n  if (hasWorldId)            return \"human\";\n  return \"bot\";\n}\n```\n\n### Policy Enforcement\nOnce the tier is resolved, Glide applies the policy (throtlling, payment gating, or instant passthrough):\n- **Bot Tier**: If no payment is detected, it triggers a 402 Payment Required response via the `@x402/express` server. In demo mode, it applies a `botDelayMs` (default 2s) to simulate resource throttling.\n- **Human Tier**: Bypasses payment requirements entirely if a valid World ID proof is detected.\n\n---\n\n## Audit System — XMTP & Revocation\n\nEvery paid or human-verified transaction generates a structured audit receipt sent via XMTP. This allows human owners to monitor what their autonomous agents are doing in real-time.\n\n### The Payload\nGlide uses `@xmtp/agent-sdk` to deliver JSON payloads:\n```json\n{\n  \"type\": \"AGENT_TRANSACTION\",\n  \"merchant\": \"AgenticStore_v1\",\n  \"cost\": \"1.00\",\n  \"currency\": \"USDC\",\n  \"status\": \"SETTLED\",\n  \"short_code\": \"xJ8-7k2P1\",\n  \"revoke_url\": \"https://gateway.glide.com/revoke?code=xJ8-7k2P1\"\n}\n```\n\n### The Kill Switch\nThe `revoke_url` included in the XMTP message allows a human to instantly revoke an agent's access token stored in Glide's SQLite database. If a token is revoked, the `/premium-data` endpoint will reject all subsequent requests from that agent.\n\n---\n\n## Integration Guide\n\nGlide is designed to be developer-first. You can wrap any existing API endpoint in less than 5 minutes.\n\n1. **Install Glide**:\n   `npm install @0xshae/glide-gateway`\n\n2. **Mount the Middleware**:\n```typescript\nimport { glideMiddleware } from \"@0xshae/glide-gateway\";\n\napp.get(\"/api/ai-generate\", \n  glideMiddleware({ \n    requireWorldId: true, \n    fallback: \"pay\", \n    botDelayMs: 2000 \n  }), \n  (req, res) => {\n    // Your actual business logic reached after identity/payment verification\n    const { glideTier } = req as any;\n    res.json({ message: `Access granted for ${glideTier}` });\n  }\n);\n```\n\n---\n\n## Known Issues & Workarounds\n\n- **Network Support**: The x402 facilitator currently does not support World Sepolia (eip155:4801). \n  - *Workaround*: We use **Base Sepolia** (eip155:84532) for all payment settlements while utilizing World ID for identity.\n- **XMTP Identity**: XMTP delivery requires the `XMTP_RECIPIENT_ADDRESS` to be different from the `XMTP_WALLET_KEY` address to avoid self-messaging loops. \n  - *Fix*: Ensure two distinct wallets are configured in your `.env`.\n- **Latency Simulation**: In our current hackathon build, the \"Bot Delay\" is artificial (setTimeout) to visually demonstrate the difference in quality of service. In production, this would be an actual rate-limiting bucket.\n\n---\n\n### GLIDE: Building the Identity-Aware Web 3.0.\n","readmeFilename":"README.md","_rev":"1-322ed7f52c5dbd5715ce3f8b58ba7fee"}