{"_id":"@absolutejs/egress","_rev":"2-8ba8cc5f90b7a3501be0c735bab8f0ed","name":"@absolutejs/egress","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@absolutejs/egress","version":"0.1.0","license":"MIT","_id":"@absolutejs/egress@0.1.0","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"dist":{"shasum":"e525faffec1201701818e4691b048eeae0f427e7","tarball":"https://registry.npmjs.org/@absolutejs/egress/-/egress-0.1.0.tgz","fileCount":8,"integrity":"sha512-f1BS8bRDAW9dne6vThm/UTDyka3fZGeMuvjHiR5yO9dAeROZpZdNsrE+RvPyu+5LuPI/dm4nHu86mDnM7Vqo2g==","signatures":[{"sig":"MEYCIQDuOnV7mJirXmVBrUQACVTN2lNS1Uwof3LCjyj2pgb9gQIhAKT16cPrneTvciv/O4WHyuAMZ4kW12BozXvbKgkSFzy4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":248592},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","shasum":"e525faffec1201701818e4691b048eeae0f427e7","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"scripts":{"test":"bun test","build":"rm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --target=bun --external @sinclair/typebox && tsc -p tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md}\"","typecheck":"tsc --noEmit","check:package":"bun run format && bun run typecheck && bun run test && bun run build"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"_integrity":"sha512-f1BS8bRDAW9dne6vThm/UTDyka3fZGeMuvjHiR5yO9dAeROZpZdNsrE+RvPyu+5LuPI/dm4nHu86mDnM7Vqo2g==","absolutejs":{"manifestContract":2},"repository":{"url":"https://github.com/absolutejs/egress.git","type":"git"},"_npmVersion":"10.8.3","description":"Deny-by-default outbound network policy and credential-safe fetch for AI agents.","directories":{},"_nodeVersion":"24.3.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.5.3","@types/bun":"^1.3.14","typescript":"5.8.3"},"_npmOperationalInternal":{"tmp":"tmp/egress_0.1.0_1784164271516_0.8670007988244868","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@absolutejs/egress","version":"0.2.0","description":"Deny-by-default outbound network policy and credential-safe fetch for AI agents.","type":"module","license":"MIT","repository":{"type":"git","url":"https://github.com/absolutejs/egress.git"},"publishConfig":{"access":"public"},"main":"./dist/index.js","types":"./dist/index.d.ts","absolutejs":{"manifestContract":2},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"scripts":{"format":"prettier --write \"./**/*.{ts,json,md}\"","typecheck":"tsc --noEmit","test":"bun test","build":"rm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --target=bun --external @sinclair/typebox && tsc -p tsconfig.build.json && absolute-manifest emit","check:package":"bun run format && bun run typecheck && bun run test && bun run build"},"dependencies":{"@absolutejs/manifest":"^0.2.0","@sinclair/typebox":"^0.34.0"},"devDependencies":{"@types/bun":"^1.3.14","prettier":"3.5.3","typescript":"5.8.3"},"_id":"@absolutejs/egress@0.2.0","_integrity":"sha512-9asrYqCD2E5icWSpSf8GkFg5+PZKaJ4e88i4N/KAvTGprAdc+5nHbLr+oRcj5F8y2mE5BxYBJurgT7oom8Oj/Q==","_nodeVersion":"24.3.0","_npmVersion":"10.8.3","shasum":"e80ac2b670b0019afc6411c60b37f1ed419d4221","dist":{"integrity":"sha512-9asrYqCD2E5icWSpSf8GkFg5+PZKaJ4e88i4N/KAvTGprAdc+5nHbLr+oRcj5F8y2mE5BxYBJurgT7oom8Oj/Q==","shasum":"e80ac2b670b0019afc6411c60b37f1ed419d4221","tarball":"https://registry.npmjs.org/@absolutejs/egress/-/egress-0.2.0.tgz","fileCount":8,"unpackedSize":252461,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGqlWIaRNpMCGqIdcpFQxZqUdldWNm7sfyM2Wt7kVdwUAiEAizVMk7RitYjFCPPmV8NwGRF3rwJyV38kPZJmKkzKkFM="}]},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"directories":{},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/egress_0.2.0_1784303272189_0.49274596990687414"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-16T01:11:11.337Z","modified":"2026-07-17T15:47:52.549Z","0.1.0":"2026-07-16T01:11:11.700Z","0.2.0":"2026-07-17T15:47:52.347Z"},"license":"MIT","repository":{"type":"git","url":"https://github.com/absolutejs/egress.git"},"description":"Deny-by-default outbound network policy and credential-safe fetch for AI agents.","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"readme":"# @absolutejs/egress\n\nDeny-by-default outbound networking for AI agents. The package authorizes an\nexact HTTPS destination, resolves every address, rejects private/local/reserved\nnetworks, re-runs policy after every redirect, injects credentials only after\nauthorization, bounds response size, and emits audit events.\n\nThe transport is required rather than defaulting to global `fetch`. A production\ntransport must connect to one of `decision.resolution.addresses` while retaining\nthe original hostname for TLS SNI and certificate verification. That closes the\nDNS-rebinding gap between policy resolution and the actual socket connection.\n`createPinnedHttpsTransport()` supplies that production transport. It runs\ninside Bun, pins the authorized address at connection time, preserves the\noriginal hostname for TLS, retries the other authorized addresses, and bounds\nbytes while reading the socket. It does not launch Node or a child process.\n\n```ts\nconst policy = createEgressPolicy({\n  allowedHosts: [\"api.stripe.com\", \"*.githubusercontent.com\"],\n  resolver: resolvePublicDns,\n});\n\nconst agentFetch = createEgressFetch({\n  policy,\n  transport: createPinnedHttpsTransport(),\n  credentials: ({ url }) =>\n    url.hostname === \"api.stripe.com\"\n      ? { authorization: `Bearer ${stripeToken}` }\n      : undefined,\n  audit: writeSecurityEvent,\n});\n```\n\nCaller-supplied `Authorization`, `Cookie`, `Host`, and `Proxy-Authorization`\nheaders are always stripped. Credentials come only from the scoped provider and\nare recomputed for each redirect destination.\n","readmeFilename":"README.md"}