{"_id":"@a-identity/trust-guard","_rev":"2-4864d5aaf8211f985675145a24e910e5","name":"@a-identity/trust-guard","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@a-identity/trust-guard","version":"0.1.0","keywords":["a-identity","agent","trust","reputation","erc-8004","kya","x402","risk","guard","okx"],"author":{"name":"A-Identity"},"license":"MIT","_id":"@a-identity/trust-guard@0.1.0","maintainers":[{"name":"0xmericeth","email":"cintosunmeric@gmail.com"}],"homepage":"https://a-identity.xyz","bugs":{"url":"https://github.com/getA-Identity/A-Identity/issues"},"dist":{"shasum":"cff2266fb4a1e8a6993f7f58478031001da8c72d","tarball":"https://registry.npmjs.org/@a-identity/trust-guard/-/trust-guard-0.1.0.tgz","fileCount":4,"integrity":"sha512-aCBY5lRjst50SiKTt6t7rtPsVyx64y24kd6oka1uP7zpTH9s6pKy49ZB0yJjllkWCsFw0xrgVoI3GvwvnTf4Tw==","signatures":[{"sig":"MEQCIBpLXS375LOv9sNweGnSogHHr+vJG8v8M1f4ChoVE4c0AiBwGT9J7VIETZdXlaivHAixicihMVQps6q7EUaUEwfRAA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14225},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f61acd6eff705bb4e0aaacb9d7b659d9fef112dd","scripts":{"test":"tsc -p tsconfig.test.json && node --test dist-test/index.test.js","build":"tsc","prepare":"tsc","prepublishOnly":"tsc"},"_npmUser":{"name":"0xmericeth","email":"cintosunmeric@gmail.com"},"repository":{"url":"git+https://github.com/getA-Identity/A-Identity.git","type":"git","directory":"trust-guard"},"_npmVersion":"11.12.1","description":"One-line trust guard: verify an AI agent (ERC-8004 identity + KYA + 0-1000 reputation + Sybil + risk) before you pay or hire it. Throws on DENY.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/trust-guard_0.1.0_1785419427028_0.7632018192075836","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"_id":"@a-identity/trust-guard@0.2.0","bugs":{"url":"https://github.com/getA-Identity/A-Identity/issues"},"dist":{"shasum":"8ef84ca3a8b6566915f548e5d0d9febf12b06b51","tarball":"https://registry.npmjs.org/@a-identity/trust-guard/-/trust-guard-0.2.0.tgz","fileCount":6,"integrity":"sha512-pdTBC37/pn20Dv78FZ5tiVvLcaQ7p2o3w0V3DRQqUK2AE0tT5gZGLpRjj8vASmsZxcaaUmemRGRrDsD6oF32+w==","signatures":[{"sig":"MEYCIQDRYG7vv3klfknZH6cC4V7qSLZq/ZD4to5qesQihu8HkwIhAI46XIRlOmJxJqiwgNMXjq0EBo1J/sPVgLaAP236FNH5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDCMP8qdxU+rKj4pnoH9lJm46Py6BGmcLok/q2HJCtx7gIhAKmwjWdFlq2Ejf6RNrd3hNyI4afWdrBE/ZwGbmzkcfQ9"}],"unpackedSize":31302},"main":"./dist/index.js","name":"@a-identity/trust-guard","type":"module","types":"./dist/index.d.ts","author":{"name":"A-Identity"},"engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./algorand":{"types":"./dist/algorand.d.ts","import":"./dist/algorand.js"}},"gitHead":"78aa726a7364868335c049ff18a2d27b74a7ff56","license":"MIT","scripts":{"test":"tsc -p tsconfig.test.json && node --test dist-test/index.test.js dist-test/algorand.test.js","build":"tsc","prepare":"tsc","prepublishOnly":"tsc"},"version":"0.2.0","_npmUser":{"name":"0xmericeth","email":"cintosunmeric@gmail.com"},"homepage":"https://a-identity.xyz","keywords":["a-identity","agent","trust","reputation","erc-8004","kya","x402","risk","guard","okx","algorand","usdc"],"repository":{"url":"git+https://github.com/getA-Identity/A-Identity.git","type":"git","directory":"trust-guard"},"_npmVersion":"11.12.1","description":"One-line trust guard: verify an AI agent (ERC-8004 identity + KYA + 0-1000 reputation + Sybil + risk) before you pay or hire it. Throws on DENY. Pays per call over x402 on X Layer or Algorand.","directories":{},"maintainers":[{"name":"0xmericeth","email":"cintosunmeric@gmail.com"}],"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"algosdk":"^3.7.0","typescript":"^5.9.3"},"peerDependencies":{"algosdk":"^3.7.0"},"peerDependenciesMeta":{"algosdk":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/trust-guard_0.2.0_1789242292090_0.1681821414041733"}}},"time":{"created":"2026-07-30T13:50:26.582Z","modified":"2026-09-12T19:44:52.343Z","0.1.0":"2026-07-30T13:50:27.174Z","0.2.0":"2026-09-12T19:44:52.174Z"},"bugs":{"url":"https://github.com/getA-Identity/A-Identity/issues"},"author":{"name":"A-Identity"},"license":"MIT","homepage":"https://a-identity.xyz","keywords":["a-identity","agent","trust","reputation","erc-8004","kya","x402","risk","guard","okx","algorand","usdc"],"repository":{"url":"git+https://github.com/getA-Identity/A-Identity.git","type":"git","directory":"trust-guard"},"description":"One-line trust guard: verify an AI agent (ERC-8004 identity + KYA + 0-1000 reputation + Sybil + risk) before you pay or hire it. Throws on DENY. Pays per call over x402 on X Layer or Algorand.","maintainers":[{"name":"0xmericeth","email":"cintosunmeric@gmail.com"}],"readme":"# @a-identity/trust-guard\n\nOne line of code that stops your AI agent from paying a counterparty it should not trust.\n\nAgents are starting to hire and pay other agents at machine speed. `trust-guard` puts a\nverification gate in front of that payment: it calls the live **A-Identity Trust Oracle**\n(ERC-8004 on-chain identity + KYA + a deterministic 0-1000 reputation + a Sybil check) and\n**throws if the verdict is DENY**, so a revoked, Sybil, or unverified counterparty never gets paid.\n\n```bash\nnpm install @a-identity/trust-guard\n```\n\n```ts\nimport { guard, TrustDenyError } from '@a-identity/trust-guard'\n\ntry {\n  // Verify before you pay. Throws if the counterparty is DENY.\n  await guard(counterpartyAgentId, { txContext: { amountUsd: 500, kind: 'payment' } })\n  await payAgent(counterpartyAgentId, 500) // only runs if the guard passed\n} catch (e) {\n  if (e instanceof TrustDenyError) {\n    console.warn('Blocked:', e.verdict.decision, e.verdict.reasons)\n    return // do not pay\n  }\n  throw e\n}\n```\n\n## Verdicts\n\n`guard()` runs `risk_check` and returns an `ALLOW` / `WARN` verdict, or throws `TrustDenyError`\non `DENY`. Block warnings too by widening `denyOn`:\n\n```ts\nawait guard(id, { denyOn: ['DENY', 'WARN'] }) // stricter: throw on WARN as well\n```\n\n## The full client\n\n```ts\nimport { TrustGuard } from '@a-identity/trust-guard'\n\nconst oracle = new TrustGuard() // X Layer rail, https://a-identity-asp.onrender.com\n\nawait oracle.verify(id)        // ERC-8004 identity + KYA status\nawait oracle.reputation(id)    // 0-1000 score (+ its on-chain attestation, if published)\nawait oracle.riskCheck(id, tx) // ALLOW / WARN / DENY\nawait oracle.passport(id)      // identity + reputation + KYA + risk in one call\nawait oracle.guard(id, opts)   // the gate: throws on DENY\n```\n\n## Two rails\n\nEvery call is paid per request over x402. Pick where the money moves:\n\n| Rail | Settles in | verify | reputation | risk_check | passport | batch audit |\n| --- | --- | --- | --- | --- | --- | --- |\n| `xlayer` (default) | USDT0 on X Layer mainnet | $0.001 | $0.002 | $0.005 | $0.01 | n/a |\n| `algorand` | USDC on Algorand mainnet | $0.01 | $0.02 | $0.05 | $0.10 | $0.04 per agent, up to 50 |\n\nThe live price is always the one in the 402 challenge; the table is a convenience.\n\n### Paying on Algorand from your own account\n\n```bash\nnpm install @a-identity/trust-guard algosdk\n```\n\n```ts\nimport { TrustGuard } from '@a-identity/trust-guard'\nimport { algorandPayer, SpendCapError } from '@a-identity/trust-guard/algorand'\n\nconst oracle = new TrustGuard({\n  rail: 'algorand',\n  onPaymentRequired: algorandPayer({\n    mnemonic: process.env.AGENT_MNEMONIC!, // the agent's own account, opted in to USDC\n    maxUsdPerCall: 0.1,                    // refuses anything pricier, before signing\n  }),\n})\n\nawait oracle.guard(counterpartyId) // pays 0.05 USDC for the verdict, throws on DENY\n```\n\nWhat the payer signs, and nothing more: one USDC transfer of exactly the quoted amount to the\nquoted payTo, with fee zero, grouped with an unsigned fee-payer transaction the GoPlausible\nfacilitator signs and pays for. The account needs USDC and no ALGO for fees, and the key never\nleaves your process. A challenge above `maxUsdPerCall` (default 0.25), for any asset other\nthan native Circle USDC, or on an unknown network is refused before anything is signed.\n\nThe oracle produces its answer before it submits your payment and releases it only once the\ntransfer is confirmed on-chain, so a check that fails costs you nothing.\n\n### Auditing a shortlist\n\n```ts\nconst audit = await oracle.batchAudit(['#12', '#907', '#4411'], { amountUsd: 250 })\naudit.summary            // { ALLOW: 2, WARN: 0, DENY: 1 }\naudit.results[2].reasons // why #4411 was refused\n```\n\nOne paid call, up to 50 agents, $0.04 each. Raise `maxUsdPerCall` to cover the list (50 agents\nis $2.00).\n\n### From an MCP client\n\n`@a-identity/trust-mcp` wraps this package as an MCP server your agent runs with its own\naccount:\n\n```bash\nclaude mcp add a-identity-trust -e A_IDENTITY_ALGORAND_MNEMONIC=\"...\" -- npx -y @a-identity/trust-mcp\n```\n\n## Paying on X Layer\n\nThe X Layer rail settles through OKX. If a call returns HTTP 402, the guard invokes your\n`onPaymentRequired` payer and retries; without one it throws `PaymentRequiredError` carrying the\nchallenge. Wire your OKX Agentic Wallet (or any x402 client) to sign the payment:\n\n```ts\nconst oracle = new TrustGuard({\n  onPaymentRequired: async (challenge, { resource }) => {\n    const header = await myWallet.payX402(challenge) // your x402 signer\n    return { 'X-PAYMENT': header }                   // headers to retry with\n  },\n})\n```\n\n## Notes\n\n- The core import has zero runtime dependencies and uses the global `fetch` (Node >= 18, Deno,\n  Bun, browsers); inject `opts.fetch` for other runtimes or tests. Only\n  `@a-identity/trust-guard/algorand` needs `algosdk`.\n- Point `baseUrl` at your own instance if you self-host the oracle.\n- Verify first. Pay at machine speed.\n\nMIT\n","readmeFilename":"README.md"}