{"_id":"@absolutejs/agent-exchange-provider-conformance","_rev":"4-1678208fb99b5ccb34173a28fb101733","name":"@absolutejs/agent-exchange-provider-conformance","dist-tags":{"latest":"0.3.1"},"versions":{"0.1.0":{"name":"@absolutejs/agent-exchange-provider-conformance","version":"0.1.0","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/agent-exchange-provider-conformance@0.1.0","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/agent-exchange-providers/tree/main/conformance","bugs":{"url":"https://github.com/absolutejs/agent-exchange-providers/issues"},"dist":{"shasum":"63ae5c5156af06f0e5d7814ccb9ef2f88ebca09b","tarball":"https://registry.npmjs.org/@absolutejs/agent-exchange-provider-conformance/-/agent-exchange-provider-conformance-0.1.0.tgz","fileCount":6,"integrity":"sha512-UTx0e5zmyw1MlkTBHQDa3xrjcY3jCarRD80gH5Ln9dTKkfX2zm05SJhmWJ0pyDBJjVedLE1Pa6uqJ3MjNFNL5w==","signatures":[{"sig":"MEUCID670NkMY/C/0a99ywJeG5wFyrPbvnH13oDMhJUOPamOAiEAxM1ddN/RbVkwNX1EnxwRcmi2s+arFmLucZZ5pC8/Yok=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32144},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"21b20bde4dce97a553b28f9711a7ae27ed2c82c6","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser && tsc --project tsconfig.build.json","format":"prettier --write \"./**/*.{ts,json,md}\"","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\""},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"repository":{"url":"git+https://github.com/absolutejs/agent-exchange-providers.git","type":"git","directory":"conformance"},"_npmVersion":"10.9.2","description":"Security capability and DPoP conformance checks for Agent Exchange providers.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.3.14","typescript":"^5.9.0"},"_npmOperationalInternal":{"tmp":"tmp/agent-exchange-provider-conformance_0.1.0_1787742615778_0.06359790696451051","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@absolutejs/agent-exchange-provider-conformance","version":"0.2.0","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/agent-exchange-provider-conformance@0.2.0","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/agent-exchange-providers/tree/main/conformance","bugs":{"url":"https://github.com/absolutejs/agent-exchange-providers/issues"},"dist":{"shasum":"5f8313c6028dc2d0f9192fcf9764d2aa274bda93","tarball":"https://registry.npmjs.org/@absolutejs/agent-exchange-provider-conformance/-/agent-exchange-provider-conformance-0.2.0.tgz","fileCount":8,"integrity":"sha512-nQY5L4JDHBZcx4H2xjkR1oIKvH8s5WJtM4URxvwpFLJAONeUowAzK+qV59HXhaBLCkjYwRxKew3hR2mBnd30GQ==","signatures":[{"sig":"MEUCIQCPcxMPLUYJaMsEC+3VGF98+NSe7fxKSKQzyUIC2c2PUAIgM7vKgFd4B/CdiLOZPN9NRaXBeda8QxdShBYxvZw9aNo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89192},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"d173d243543be34e235a81f82e3d9e1ae45bbb39","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange --external '@absolutejs/agent-exchange/*' && tsc --project tsconfig.build.json && prettier --write --ignore-path /dev/null 'dist/*.d.ts'","format":"prettier --write \"./**/*.{ts,json,md}\"","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\"","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"repository":{"url":"git+https://github.com/absolutejs/agent-exchange-providers.git","type":"git","directory":"conformance"},"_npmVersion":"10.9.2","description":"OAuth, DPoP, and black-box A2A security conformance checks for Agent Exchange providers.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.3.14","typescript":"^5.9.0","@absolutejs/a2a":"^0.3.6","@absolutejs/agent-exchange-a2a":"0.2.0"},"peerDependencies":{"@absolutejs/agent-exchange":">=0.4.4 <0.5"},"_npmOperationalInternal":{"tmp":"tmp/agent-exchange-provider-conformance_0.2.0_1787759216407_0.11047153362986095","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@absolutejs/agent-exchange-provider-conformance","version":"0.3.0","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/agent-exchange-provider-conformance@0.3.0","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/agent-exchange-providers/tree/main/conformance","bugs":{"url":"https://github.com/absolutejs/agent-exchange-providers/issues"},"dist":{"shasum":"17de70aaaa935343239dc0f255d1e04a048d8901","tarball":"https://registry.npmjs.org/@absolutejs/agent-exchange-provider-conformance/-/agent-exchange-provider-conformance-0.3.0.tgz","fileCount":8,"integrity":"sha512-kJLFZvDyd0F5LjXuQkmlrlRxSN1NpTyVDby6pLo1L4VsAzNYKJDvZN5Q2NgHLC8GFNktN3CA4J4vUGzq5zZiAA==","signatures":[{"sig":"MEYCIQCDUfzKGKKfaTmUGFIyG2QLBH6Wym+vJgVxcGVOyouTrQIhAPv7bx3wUdmiw1OzouSzNLV8+5mZetcn7Jq+JuZ2lI8T","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89192},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"gitHead":"05a6e94907aa2c6fe91023f483bfa51b87847429","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange --external '@absolutejs/agent-exchange/*' && tsc --project tsconfig.build.json && prettier --write --ignore-path /dev/null 'dist/*.d.ts'","format":"prettier --write \"./**/*.{ts,json,md}\"","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\"","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"repository":{"url":"git+https://github.com/absolutejs/agent-exchange-providers.git","type":"git","directory":"conformance"},"_npmVersion":"10.9.2","description":"OAuth, DPoP, and black-box A2A security conformance checks for Agent Exchange providers.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.3.14","typescript":"^5.9.0","@absolutejs/a2a":"^0.3.6","@absolutejs/agent-exchange-a2a":"0.3.0"},"peerDependencies":{"@absolutejs/agent-exchange":">=0.5.0 <0.6"},"_npmOperationalInternal":{"tmp":"tmp/agent-exchange-provider-conformance_0.3.0_1787773400613_0.1428161538174766","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@absolutejs/agent-exchange-provider-conformance","version":"0.3.1","description":"OAuth, DPoP, and black-box A2A security conformance checks for Agent Exchange providers.","type":"module","license":"Apache-2.0","author":{"name":"Alex Kahn"},"repository":{"type":"git","url":"git+https://github.com/absolutejs/agent-exchange-providers.git","directory":"conformance"},"homepage":"https://github.com/absolutejs/agent-exchange-providers/tree/main/conformance","bugs":{"url":"https://github.com/absolutejs/agent-exchange-providers/issues"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"publishConfig":{"access":"public"},"scripts":{"build":"rm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange --external '@absolutejs/agent-exchange/*' && tsc --project tsconfig.build.json && prettier --write --ignore-path /dev/null 'dist/*.d.ts'","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build","format":"prettier --write \"./**/*.{ts,json,md}\"","format:check":"prettier --check \"./**/*.{ts,json,md}\"","test":"bun test tests/","typecheck":"tsc --noEmit"},"devDependencies":{"@absolutejs/a2a":"^0.3.6","@absolutejs/agent-exchange-a2a":"0.3.0","@types/bun":"^1.3.14","typescript":"^5.9.0"},"peerDependencies":{"@absolutejs/agent-exchange":">=0.5.0 <0.6"},"_id":"@absolutejs/agent-exchange-provider-conformance@0.3.1","gitHead":"a1255397df6786c4532615ca5db06fa44af36f3f","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-oqYLIRs0cXgZJlDGwBnGqWNGMFsZ9v0FcLT4Z24WQXsDpsz2DFSLOrC0Hk2XWXxodANiBdOh6fRMQSEJpNzIOg==","shasum":"dc3c673307e87122113a6cb5276750d32ace9912","tarball":"https://registry.npmjs.org/@absolutejs/agent-exchange-provider-conformance/-/agent-exchange-provider-conformance-0.3.1.tgz","fileCount":8,"unpackedSize":90546,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGCiqmMsoU+HFG7pMKAcpLJtpA/jXJC30erdP34q8MGkAiAugbAf/ZFvUHMX2True3V2dOQEzX5mi7cC7S25INjTzg=="}]},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"directories":{},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-exchange-provider-conformance_0.3.1_1787871667371_0.0022014852912852767"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-26T11:10:15.661Z","modified":"2026-08-27T23:01:07.706Z","0.1.0":"2026-08-26T11:10:15.927Z","0.2.0":"2026-08-26T15:46:56.547Z","0.3.0":"2026-08-26T19:43:20.760Z","0.3.1":"2026-08-27T23:01:07.538Z"},"bugs":{"url":"https://github.com/absolutejs/agent-exchange-providers/issues"},"author":{"name":"Alex Kahn"},"license":"Apache-2.0","homepage":"https://github.com/absolutejs/agent-exchange-providers/tree/main/conformance","repository":{"type":"git","url":"git+https://github.com/absolutejs/agent-exchange-providers.git","directory":"conformance"},"description":"OAuth, DPoP, and black-box A2A security conformance checks for Agent Exchange providers.","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"readme":"# @absolutejs/agent-exchange-provider-conformance\n\nShared capability checks, cryptographic DPoP verification, and black-box A2A\nsecurity tests for Agent Exchange providers. Provider adapters publish facts;\nthis package decides whether those facts meet the phishing-resistant OAuth\nprofile. A2A servers are exercised over their public protocol boundary without\ndepending on their implementation.\n\nUnknown or unavailable features are failures, not optimistic defaults.\n\n## A2A prepared-profile conformance\n\n`evaluateAgentExchangeA2aConformance()` performs eight active checks:\n\n- Agent Card discovery and same-origin A2A 1.0 JSON-RPC routing;\n- extension parameters, skill media types, and declared authentication;\n- authentication before parsing malformed A2A and preparation requests;\n- distinct preparation and A2A credentials;\n- `A2A-Extensions` negotiation;\n- protected preparation followed by exact-reference execution;\n- raw, hexadecimal, base64, and base64url leakage detection in tasks and\n  receipts; and\n- safe replay rejection or convergence on the original task.\n\nThe suite executes the supplied request. It requires the literal\n`acknowledgeExecution: \"sandbox-only\"` and must never be aimed at production or\nan endpoint that can submit a real credential:\n\n```ts\nimport {\n  assertAgentExchangeA2aConformance,\n  type AgentExchangeA2aConformanceTarget,\n} from \"@absolutejs/agent-exchange-provider-conformance\";\n\nconst target: AgentExchangeA2aConformanceTarget = {\n  acknowledgeExecution: \"sandbox-only\",\n  additionalSensitiveMarkers: [sandboxVerificationCode],\n  a2aHeaders: ({ url }) => a2aTokenFor(url),\n  createRequest: (purpose) => sandboxRequest(purpose),\n  origin: \"https://sandbox-recipient.example\",\n  preparationHeaders: ({ url }) => preparationTokenFor(url),\n};\n\nconst report = await assertAgentExchangeA2aConformance(target);\n```\n\n`createRequest()` receives a purpose identifier and must return a fresh exchange\neach time. The sandbox must use separate audience-bound credentials for the\npreparation and A2A URLs. Put any simulated protected value that is not already\npart of the request—such as a sandbox six-digit code—in\n`additionalSensitiveMarkers`.\n\nThe report demonstrates observable protocol behavior for that sandbox run. It is\nnot a cryptographic audit, production authorization, penetration test, or claim\nthat an email/SMS bearer code is phishing-resistant.\n\n## OAuth provider conformance\n\n`evaluateOAuthProviderConformance()` evaluates declared authorization-code,\nissuer-identification, PAR, S256 PKCE, RAR, resource-indicator, and\nsender-constraint capabilities. `verifyDpopProof()` independently validates the\nES256 proof, public key, method, normalized target URI, timestamp, nonce, and\naccess-token hash. JWT segments must use canonical unpadded base64url encoding;\nalternate strings that decode to the same bytes are rejected so proof identity\ncannot be aliased through unused padding bits.\n","readmeFilename":"README.md"}