{"_id":"@absolutejs/key-transparency","_rev":"2-ed17ea6a05c148710615ed965e237151","name":"@absolutejs/key-transparency","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@absolutejs/key-transparency","version":"0.1.0","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/key-transparency@0.1.0","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/key-transparency","bugs":{"url":"https://github.com/absolutejs/key-transparency/issues"},"dist":{"shasum":"48ac30bb1d0db2cb92327b654b83c0ac97abab7a","tarball":"https://registry.npmjs.org/@absolutejs/key-transparency/-/key-transparency-0.1.0.tgz","fileCount":19,"integrity":"sha512-HF1Pmw+Shh6mn8gmxRhdfOtyMGUsoMs7gHCP+0f9i4cZRuzldWW76lAAZb3ej+KJwEMxKd1kjobCfsspoM7POg==","signatures":[{"sig":"MEUCIQDuK7SBflmFv5LovBXeiOsCKJW0n+yqgMNG9+mqRka53AIgdCy0IB913cN7hjQdZc9CvCmSIQ8xS7Zh6260suSzzAQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":135318},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js","default":"./dist/manifest.js"},"./conformance":{"types":"./dist/conformance.d.ts","import":"./dist/conformance.js","default":"./dist/conformance.js"},"./manifest.json":"./dist/manifest.json"},"gitHead":"2f4c85f4da4097e08ee1e9f85eff90ca8197a02c","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts src/conformance.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md}\"","release":"bun run check:package && npm publish --access public","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\"","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"absolutejs":{"manifestContract":2},"repository":{"url":"git+https://github.com/absolutejs/key-transparency.git","type":"git"},"_npmVersion":"10.9.2","description":"Provider-neutral key transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"^3.9.0","@types/bun":"^1.3.14","typescript":"^5.9.0"},"_npmOperationalInternal":{"tmp":"tmp/key-transparency_0.1.0_1787777836377_0.00731394632922","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@absolutejs/key-transparency","version":"0.2.0","description":"Provider-neutral key transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.","type":"module","license":"Apache-2.0","author":{"name":"Alex Kahn"},"repository":{"type":"git","url":"git+https://github.com/absolutejs/key-transparency.git"},"homepage":"https://github.com/absolutejs/key-transparency","bugs":{"url":"https://github.com/absolutejs/key-transparency/issues"},"main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./conformance":{"types":"./dist/conformance.d.ts","import":"./dist/conformance.js","default":"./dist/conformance.js"},"./certification":{"types":"./dist/certification.d.ts","import":"./dist/certification.js","default":"./dist/certification.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js","default":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"publishConfig":{"access":"public"},"scripts":{"build":"rm -rf dist && bun build src/index.ts src/certification.ts src/conformance.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package","format":"prettier --write \"./**/*.{ts,json,md}\"","format:check":"prettier --check \"./**/*.{ts,json,md}\"","release":"bun run check:package && npm publish --access public","test":"bun test tests/","typecheck":"tsc --noEmit","verify-package":"absolute-manifest verify-package"},"dependencies":{"@absolutejs/manifest":"^0.9.0","@sinclair/typebox":"^0.34.0"},"devDependencies":{"@types/bun":"^1.3.14","prettier":"^3.9.0","typescript":"^5.9.0"},"absolutejs":{"manifestContract":2},"_id":"@absolutejs/key-transparency@0.2.0","gitHead":"82f72092181bbc244f90f70ab808c58647d35932","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-KUK+CTh9c6+EbfbL+0m7+b0RuIwqHiVaKhxgSWuf3t04Feb50UoqhgWitNqlhMQe8FxvqW3htNmJTnP5ENlnnA==","shasum":"f96fcacb3dc2fb0c83474a7a288d696a8c4a8ff4","tarball":"https://registry.npmjs.org/@absolutejs/key-transparency/-/key-transparency-0.2.0.tgz","fileCount":22,"unpackedSize":172930,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFUbsHbHt6VIoGe4SF7Sch8hfc41D2s9y12o9WO6Q5PZAiAknG28TXxiww8AuGeRKKI13XQiko2s0ya6azm+lUt5bQ=="}]},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"directories":{},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/key-transparency_0.2.0_1787778616645_0.1070226947359254"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-26T20:57:16.224Z","modified":"2026-08-26T21:10:16.972Z","0.1.0":"2026-08-26T20:57:16.514Z","0.2.0":"2026-08-26T21:10:16.779Z"},"bugs":{"url":"https://github.com/absolutejs/key-transparency/issues"},"author":{"name":"Alex Kahn"},"license":"Apache-2.0","homepage":"https://github.com/absolutejs/key-transparency","repository":{"type":"git","url":"git+https://github.com/absolutejs/key-transparency.git"},"description":"Provider-neutral key transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"readme":"# `@absolutejs/key-transparency`\n\nProvider-neutral key-transparency contracts, local rollback protection,\nprovider selection, and conformance tools for AbsoluteJS.\n\nThis is an early `0.x` foundation. It does not implement the IETF KEYTRANS\ncryptography and it does not turn an ordinary key directory into a transparency\nlog. Providers must verify the protocol's proofs and signatures before returning\nresults through these contracts.\n\n## Why this is separate from E2EE\n\nMLS protects conversation content, but its Authentication Service binds identities\nto device signature keys. A compromised or malicious Authentication Service can\nissue a valid credential for a ghost device. Key transparency makes those key\nbindings append-only, searchable, monitorable, and capable of exposing inconsistent\nviews.\n\nKeeping `@absolutejs/key-transparency` separate from `@absolutejs/e2ee` prevents\nthe encryption provider or identity authority from silently acting as its own\nindependent verifier.\n\n## Provider boundary\n\nProviders live in `key-transparency-providers` and follow the package pattern\n`@absolutejs/key-transparency-<provider>`. A provider owns draft-specific proof\nparsing and cryptographic verification. This package additionally enforces:\n\n- an exact protocol revision rather than a floating “KEYTRANS compatible” claim;\n- operation, label, value, provider, and tree-head binding for evidence;\n- monotonically increasing locally persisted tree views;\n- compare-and-set persistence so concurrent clients cannot overwrite newer views;\n- explicit contact monitoring, owner monitoring, auditor, privacy, and assurance\n  capabilities;\n- independent audit evidence before an `audited` claim is accepted.\n\nApplications pass opaque, application-derived label bytes. Raw email addresses,\nphone numbers, usernames, and other enumerable identifiers should not cross this\nboundary.\n\n```ts\nimport {\n  createKeyTransparencyClient,\n  createMemoryKeyTransparencyViewStore,\n  selectKeyTransparencyProvider,\n} from \"@absolutejs/key-transparency\";\n\nconst provider = selectKeyTransparencyProvider(providers, {\n  minimumAssurance: \"reviewed\",\n  protocolRevision: \"draft-ietf-keytrans-protocol-05\",\n  requireContactMonitoring: true,\n  requireOwnerMonitoring: true,\n  requireSplitViewDetection: true,\n  roles: [\"client\", \"monitor\"],\n  runtime: \"browser\",\n});\n\nconst client = createKeyTransparencyClient({\n  provider,\n  store: createMemoryKeyTransparencyViewStore(),\n});\n```\n\nThe memory view store is for tests and short-lived demos. Production clients need\ndurable, rollback-resistant storage.\n\n## Version-bound certification\n\nProvider manifests are claims; certification reports are evidence tied to one\nexact provider version, protocol revision, runtime, completion time, scenario\nset, and evidence digest. Production admission should require fresh conformance\nand adversarial claims. Official vectors, cross-implementation behavior, and an\nindependent audit are separate claims and cannot be declared without their\ncorresponding evidence.\n\n## Standards status\n\nThe package currently pins\n`draft-ietf-keytrans-protocol-05` and\n`draft-ietf-keytrans-architecture-09`. Internet-Drafts are works in progress and\ncan change. Providers must publish a new `0.x` version when changing protocol\nrevision; the selector never silently treats revisions as equivalent.\n\n- Protocol: <https://datatracker.ietf.org/doc/draft-ietf-keytrans-protocol/>\n- Architecture: <https://datatracker.ietf.org/doc/draft-ietf-keytrans-architecture/>\n- MLS architecture: <https://www.rfc-editor.org/rfc/rfc9750>\n\nPublic TypeScript contracts use type aliases rather than interfaces.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}