{"_id":"@25xcodes/llmfeed-signer","_rev":"5-dcd5d96add83a5a86f98f9cc52913539","name":"@25xcodes/llmfeed-signer","dist-tags":{"latest":"1.2.0"},"versions":{"1.0.0":{"name":"@25xcodes/llmfeed-signer","version":"1.0.0","keywords":["llmfeed","webmcp","mcp","ed25519","signing","cryptography","ai-agents","cli"],"author":"","license":"MIT","_id":"@25xcodes/llmfeed-signer@1.0.0","maintainers":[{"name":"25xcodes","email":"kiarash@25x.codes"}],"homepage":"https://github.com/kiarashplusplus/webmcp-tooling-suite#readme","bugs":{"url":"https://github.com/kiarashplusplus/webmcp-tooling-suite/issues"},"bin":{"llmfeed-sign":"bin/llmfeed-sign.js"},"dist":{"shasum":"c8ebc825ed12648a30e03b5e48449e7d271873a3","tarball":"https://registry.npmjs.org/@25xcodes/llmfeed-signer/-/llmfeed-signer-1.0.0.tgz","fileCount":15,"integrity":"sha512-P1arHAhBx/GXsSQNstIOpNiyocV5/pe6ZeABC2eBO9W9y73mRehEPzMaZ0GTl3wUlgkx/mM7oBjrHc0n3TGmdw==","signatures":[{"sig":"MEQCIBRVInYQ5ztmoWR9OuPp45V/FVZf7Nqk1hdffAGxYdDxAiALSP3Dq8dGplw9dqRJyBYEWNyem1CSIw171YwWOoX8WQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@25xcodes%2fllmfeed-signer@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":234089},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"ab21a5f75c70eeb31f321247c41a15b8b32f2525","scripts":{"dev":"tsup --watch","test":"node --test dist/*.test.js","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"25xcodes","email":"kiarash@25x.codes"},"repository":{"url":"git+https://github.com/kiarashplusplus/webmcp-tooling-suite.git","type":"git","directory":"packages/signer"},"_npmVersion":"10.8.2","description":"Ed25519 key generation and LLMFeed signing tool for the WebMCP ecosystem","directories":{},"_nodeVersion":"20.19.6","_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","typescript":"^5.8.3","@types/node":"^22.15.21"},"_npmOperationalInternal":{"tmp":"tmp/llmfeed-signer_1.0.0_1764879456960_0.7542826170230237","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@25xcodes/llmfeed-signer","version":"1.0.1","keywords":["llmfeed","webmcp","mcp","ed25519","signing","cryptography","ai-agents","cli"],"author":"","license":"MIT","_id":"@25xcodes/llmfeed-signer@1.0.1","maintainers":[{"name":"25xcodes","email":"kiarash@25x.codes"}],"homepage":"https://github.com/kiarashplusplus/webmcp-tooling-suite#readme","bugs":{"url":"https://github.com/kiarashplusplus/webmcp-tooling-suite/issues"},"bin":{"llmfeed-sign":"bin/llmfeed-sign.js"},"dist":{"shasum":"29be6255a40962e7bb6f58c80a0783b9d39786e1","tarball":"https://registry.npmjs.org/@25xcodes/llmfeed-signer/-/llmfeed-signer-1.0.1.tgz","fileCount":15,"integrity":"sha512-S5TG5QwGqURXEbFPrwILvbffzj1z5QuUQl5yoNcxaN+6UBFlcLNsXNqEtmTZiFpZSFmkymF43C4ONCa/eCdYrQ==","signatures":[{"sig":"MEUCIQDL+q7M1xWnqZT926SuQymO5N6lMYeAbxRroQAzgRVGXwIgMAMc2JZLVuGmfQwqtUZbAjMlpGFN6ohNDuD7kWAmoyk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@25xcodes%2fllmfeed-signer@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":234125},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"913711bc23cdd5a489c6936c07b186e4b9547b30","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"25xcodes","email":"kiarash@25x.codes"},"repository":{"url":"git+https://github.com/kiarashplusplus/webmcp-tooling-suite.git","type":"git","directory":"packages/signer"},"_npmVersion":"10.8.2","description":"Ed25519 key generation and LLMFeed signing tool for the WebMCP ecosystem","directories":{},"_nodeVersion":"20.19.6","_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^1.0.0","typescript":"^5.8.3","@types/node":"^22.15.21"},"_npmOperationalInternal":{"tmp":"tmp/llmfeed-signer_1.0.1_1764928963299_0.7070257122912542","host":"s3://npm-registry-packages-npm-production"}},"1.1.6":{"name":"@25xcodes/llmfeed-signer","version":"1.1.6","keywords":["llmfeed","webmcp","mcp","ed25519","signing","cryptography","ai-agents","cli"],"author":"","license":"MIT","_id":"@25xcodes/llmfeed-signer@1.1.6","maintainers":[{"name":"25xcodes","email":"kiarash@25x.codes"}],"homepage":"https://github.com/kiarashplusplus/webmcp-tooling-suite#readme","bugs":{"url":"https://github.com/kiarashplusplus/webmcp-tooling-suite/issues"},"bin":{"llmfeed-sign":"bin/llmfeed-sign.js"},"dist":{"shasum":"485f603b009bb161cbf1dca94ca12c09f498db53","tarball":"https://registry.npmjs.org/@25xcodes/llmfeed-signer/-/llmfeed-signer-1.1.6.tgz","fileCount":15,"integrity":"sha512-5CnQW1/VsYXzvXTXpbElzc236eqHEc3GWfsw/Aax8lm7JdqsydFhF94XsBiPeeBwMkOUHtOIKUe/A2A/trRpCA==","signatures":[{"sig":"MEUCIHg2PsczS/7XZCDuJc0d1tHs9sammVSkMiZyzPUdr9kMAiEAj6twK4vSfHWPc/tn38ZKqDDUU5xdxjT0eHSSLw/EEe0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@25xcodes%2fllmfeed-signer@1.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":239422},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"bba5ad6825733882894d97bc2a29df542887ec4f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"25xcodes","email":"kiarash@25x.codes"},"repository":{"url":"git+https://github.com/kiarashplusplus/webmcp-tooling-suite.git","type":"git","directory":"packages/signer"},"_npmVersion":"10.8.2","description":"Ed25519 key generation and LLMFeed signing tool for the WebMCP ecosystem","directories":{},"_nodeVersion":"20.19.6","_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^4.0.0","typescript":"^5.8.3","@types/node":"^22.15.21","@vitest/coverage-v8":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/llmfeed-signer_1.1.6_1764933192963_0.22354965904271618","host":"s3://npm-registry-packages-npm-production"}},"1.1.7":{"name":"@25xcodes/llmfeed-signer","version":"1.1.7","keywords":["llmfeed","webmcp","mcp","ed25519","signing","cryptography","ai-agents","cli"],"author":"","license":"MIT","_id":"@25xcodes/llmfeed-signer@1.1.7","maintainers":[{"name":"25xcodes","email":"kiarash@25x.codes"}],"homepage":"https://github.com/kiarashplusplus/webmcp-tooling-suite#readme","bugs":{"url":"https://github.com/kiarashplusplus/webmcp-tooling-suite/issues"},"bin":{"llmfeed-sign":"bin/llmfeed-sign.js"},"dist":{"shasum":"46f36b823661cb5c869e0c78e5cb41012856efe2","tarball":"https://registry.npmjs.org/@25xcodes/llmfeed-signer/-/llmfeed-signer-1.1.7.tgz","fileCount":15,"integrity":"sha512-k4mFm8uwrExc9RqQce8IcOFMy5GwLgJbxSaNRDlViCaNJgCKL3SiYywibaD+fGQBbd7lYLRun267K1uBWX1iZA==","signatures":[{"sig":"MEUCIQCV+eveVX3k8xTv5FrRcXoOIMV5n6TP/zah+qEaP7kgmwIga62cuURaxmRhK2U1HDcviSrbrM3GpqVmzD9jBJvAxvk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@25xcodes%2fllmfeed-signer@1.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":239417},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"ce001248d2f1dbaacba3fcb9ce8c52f7aeb41ab4","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"25xcodes","email":"kiarash@25x.codes"},"repository":{"url":"git+https://github.com/kiarashplusplus/webmcp-tooling-suite.git","type":"git","directory":"packages/signer"},"_npmVersion":"10.8.2","description":"Ed25519 key generation and LLMFeed signing tool for the WebMCP ecosystem","directories":{},"_nodeVersion":"20.19.6","_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","vitest":"^4.0.0","typescript":"^5.8.3","@types/node":"^22.15.21","@vitest/coverage-v8":"^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/llmfeed-signer_1.1.7_1764938641879_0.27474897101658646","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@25xcodes/llmfeed-signer","version":"1.2.0","description":"Ed25519 key generation and LLMFeed signing tool for the WebMCP ecosystem","type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"bin":{"llmfeed-sign":"bin/llmfeed-sign.js"},"scripts":{"build":"tsup","dev":"tsup --watch","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest"},"keywords":["llmfeed","webmcp","mcp","ed25519","signing","cryptography","ai-agents","cli"],"author":"","license":"MIT","repository":{"type":"git","url":"git+https://github.com/kiarashplusplus/webmcp-tooling-suite.git","directory":"packages/signer"},"engines":{"node":">=18.0.0"},"devDependencies":{"@types/node":"^22.15.21","@vitest/coverage-v8":"^4.0.0","tsup":"^8.5.0","typescript":"^5.8.3","vitest":"^4.0.0"},"_id":"@25xcodes/llmfeed-signer@1.2.0","gitHead":"06b246443edf450eb842ec3e38e47b339debb92e","bugs":{"url":"https://github.com/kiarashplusplus/webmcp-tooling-suite/issues"},"homepage":"https://github.com/kiarashplusplus/webmcp-tooling-suite#readme","_nodeVersion":"20.19.6","_npmVersion":"10.8.2","dist":{"integrity":"sha512-WaMXlECS9kIGSJec1epE1qRU13ye/VvVc/BCwR96KV6Cqe/3Kx/HWkTSRuokaOrKEAQF8wbSFZhLIIPR1vETig==","shasum":"7f571c347a507ea09bc385aa6f306f82395cbdfd","tarball":"https://registry.npmjs.org/@25xcodes/llmfeed-signer/-/llmfeed-signer-1.2.0.tgz","fileCount":15,"unpackedSize":239417,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@25xcodes%2fllmfeed-signer@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDKzvRwRByE+bglMCb2NQcFFGHMbWKbGDY5MXRMy214xwIgFuoqRrQwzpqZrCZLC+Z1MWEtWBNStTdUOmioqSbm7oY="}]},"_npmUser":{"name":"25xcodes","email":"kiarash@25x.codes"},"directories":{},"maintainers":[{"name":"25xcodes","email":"kiarash@25x.codes"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/llmfeed-signer_1.2.0_1764957253456_0.4792434003255148"},"_hasShrinkwrap":false}},"time":{"created":"2025-12-04T20:17:36.857Z","modified":"2025-12-05T17:54:13.955Z","1.0.0":"2025-12-04T20:17:37.104Z","1.0.1":"2025-12-05T10:02:43.443Z","1.1.6":"2025-12-05T11:13:13.135Z","1.1.7":"2025-12-05T12:44:02.037Z","1.2.0":"2025-12-05T17:54:13.607Z"},"bugs":{"url":"https://github.com/kiarashplusplus/webmcp-tooling-suite/issues"},"license":"MIT","homepage":"https://github.com/kiarashplusplus/webmcp-tooling-suite#readme","keywords":["llmfeed","webmcp","mcp","ed25519","signing","cryptography","ai-agents","cli"],"repository":{"type":"git","url":"git+https://github.com/kiarashplusplus/webmcp-tooling-suite.git","directory":"packages/signer"},"description":"Ed25519 key generation and LLMFeed signing tool for the WebMCP ecosystem","maintainers":[{"name":"25xcodes","email":"kiarash@25x.codes"}],"readme":"# @25xcodes/llmfeed-signer\n\nEd25519 key generation and LLMFeed signing tool for the WebMCP ecosystem.\n\n## Installation\n\n```bash\nnpm install @25xcodes/llmfeed-signer\n```\n\nOr use directly with npx:\n\n```bash\nnpx @25xcodes/llmfeed-signer keygen\n```\n\n## CLI Usage\n\n### Generate Keypair\n\nGenerate a new Ed25519 keypair for feed signing:\n\n```bash\n# Generate keys in ./keys directory\nllmfeed-sign keygen\n\n# Custom output directory and name\nllmfeed-sign keygen --output ./my-keys --name mysite\n```\n\nThis creates:\n- `mysite.private.pem` - Private key (keep secret!)\n- `mysite.public.pem` - Public key (publish to your server)\n- `mysite.private.base64` - Base64 key for environment variables\n\n### Sign a Feed\n\nSign an LLMFeed JSON file:\n\n```bash\n# Basic signing\nllmfeed-sign sign mcp.llmfeed.json --key ./keys/mysite.private.pem\n\n# With public key URL (recommended)\nllmfeed-sign sign mcp.llmfeed.json \\\n  --key ./keys/mysite.private.pem \\\n  --public-url https://example.com/.well-known/public.pem\n\n# Sign specific blocks only\nllmfeed-sign sign feed.json \\\n  --key private.pem \\\n  --blocks metadata,capabilities,agent_guidance\n\n# Modify in place\nllmfeed-sign sign feed.json --key private.pem --in-place\n```\n\n### Verify a Signature\n\nVerify a signed feed:\n\n```bash\n# With local public key\nllmfeed-sign verify signed.json --key ./keys/mysite.public.pem\n\n# Auto-fetch from public_key_hint in feed\nllmfeed-sign verify signed.json\n\n# JSON output for scripting\nllmfeed-sign verify signed.json --json\n```\n\n## Library Usage\n\n```typescript\nimport {\n  generateKeyPair,\n  signFeed,\n  verifyFeed,\n} from '@25xcodes/llmfeed-signer'\n\n// Generate keypair\nconst keyPair = await generateKeyPair()\nconsole.log(keyPair.publicKeyPem)  // PEM for publishing\nconsole.log(keyPair.privateKey)    // Base64 for env vars\n\n// Sign a feed\nconst feed = {\n  feed_type: 'mcp',\n  metadata: {\n    title: 'My API',\n    origin: 'https://example.com',\n    description: 'My awesome API'\n  },\n  capabilities: [/* ... */]\n}\n\nconst signed = await signFeed(feed, keyPair.privateKey, {\n  publicKeyUrl: 'https://example.com/.well-known/public.pem',\n  signedBlocks: ['metadata', 'capabilities'],\n  trustLevel: 'self-signed'\n})\n\nconsole.log(signed.feed)           // Feed with trust & signature blocks\nconsole.log(signed.signature)      // Base64 Ed25519 signature\nconsole.log(signed.payloadHash)    // SHA-256 of canonical payload\n\n// Verify a feed\nconst result = await verifyFeed(signed.feed, keyPair.publicKey)\nconsole.log(result.valid)          // true\nconsole.log(result.signedBlocks)   // ['metadata', 'capabilities']\n```\n\n## CI/CD Integration\n\n### GitHub Actions\n\n```yaml\nname: Sign LLMFeed\n\non:\n  push:\n    paths:\n      - 'mcp.llmfeed.json'\n\njobs:\n  sign:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      \n      - name: Setup Node.js\n        uses: actions/setup-node@v4\n        with:\n          node-version: '20'\n      \n      - name: Sign feed\n        env:\n          MCP_PRIVATE_KEY: ${{ secrets.MCP_PRIVATE_KEY }}\n        run: |\n          npx @25xcodes/llmfeed-signer sign mcp.llmfeed.json \\\n            --key <(echo \"$MCP_PRIVATE_KEY\") \\\n            --public-url https://example.com/.well-known/public.pem \\\n            --in-place\n      \n      - name: Commit signed feed\n        run: |\n          git config user.name \"github-actions[bot]\"\n          git config user.email \"github-actions[bot]@users.noreply.github.com\"\n          git add mcp.llmfeed.json\n          git commit -m \"chore: re-sign LLMFeed\" || exit 0\n          git push\n```\n\n### Cloudflare Workers\n\n```typescript\n// Sign at request time\nimport { signFeed } from '@25xcodes/llmfeed-signer'\n\nexport default {\n  async fetch(request: Request, env: Env) {\n    const manifest = buildManifest()\n    \n    const signed = await signFeed(manifest, env.MCP_PRIVATE_KEY, {\n      publicKeyUrl: 'https://example.com/.well-known/public.pem'\n    })\n    \n    return new Response(JSON.stringify(signed.feed, null, 2), {\n      headers: { 'Content-Type': 'application/json' }\n    })\n  }\n}\n```\n\n## Security Notes\n\n1. **Never commit private keys** - Use environment variables or secrets management\n2. **Rotate keys periodically** - Generate new keypairs and update signatures\n3. **Verify before trusting** - Always verify signatures before consuming feed data\n4. **Use HTTPS** - Host public keys only over HTTPS\n\n## API Reference\n\n### `generateKeyPair(): Promise<KeyPair>`\n\nGenerate a new Ed25519 keypair.\n\n### `signFeed(feed, privateKey, options?): Promise<SignedFeed>`\n\nSign an LLMFeed with Ed25519.\n\nOptions:\n- `signedBlocks?: string[]` - Blocks to include (default: all except trust/signature)\n- `publicKeyUrl?: string` - URL for public_key_hint\n- `trustLevel?: string` - Trust level descriptor\n- `addTimestamp?: boolean` - Add created_at (default: true)\n\n### `verifyFeed(feed, publicKey): Promise<VerificationResult>`\n\nVerify a signed feed's signature.\n\n### `deepSortObject(obj): unknown`\n\nDeep sort object keys for canonical JSON.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}