{"_id":"@absolutejs/secure-messaging-federation","_rev":"4-3d2bd479c6941d492a2c248732909cd2","name":"@absolutejs/secure-messaging-federation","dist-tags":{"latest":"0.1.0"},"versions":{"0.0.1":{"name":"@absolutejs/secure-messaging-federation","version":"0.0.1","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/secure-messaging-federation@0.0.1","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/secure-messaging-federation","bugs":{"url":"https://github.com/absolutejs/secure-messaging-federation/issues"},"dist":{"shasum":"c6f16791477a37e860c68fb867dff6b45bea99b6","tarball":"https://registry.npmjs.org/@absolutejs/secure-messaging-federation/-/secure-messaging-federation-0.0.1.tgz","fileCount":19,"integrity":"sha512-e37LwZKE/+QnQtPWdoHvOYFMmc0urlkuYOTpMXBYpIfxsDYMzdm9dhfrnUUtpcYCs6OycdXFqrvv7BAVjZqBHg==","signatures":[{"sig":"MEUCIQDxxAYegGpK9A62FyAg8J66W6QBTAjlE3OiLaJnNjRHxQIgd+Vyq+zDLHNUQLQv5W8lUmTlOgEUU65w1Z4hrApWPXM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":84495},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js","default":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"gitHead":"592bbd940f6a405fe30cf77ba38bb9ffa00275ff","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md}\"","release":"bun run check:package && npm publish --access public","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\"","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"absolutejs":{"manifestContract":2},"repository":{"url":"git+https://github.com/absolutejs/secure-messaging-federation.git","type":"git"},"_npmVersion":"10.9.2","description":"Provider-neutral, downgrade-resistant secure messaging federation for AbsoluteJS.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"^3.9.0","@types/bun":"^1.3.14","typescript":"^5.9.0"},"_npmOperationalInternal":{"tmp":"tmp/secure-messaging-federation_0.0.1_1787798554392_0.9491765259148519","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@absolutejs/secure-messaging-federation","version":"0.0.2","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/secure-messaging-federation@0.0.2","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/secure-messaging-federation","bugs":{"url":"https://github.com/absolutejs/secure-messaging-federation/issues"},"dist":{"shasum":"2a7eaa57618e59b7448156439a93d19c3e077bcc","tarball":"https://registry.npmjs.org/@absolutejs/secure-messaging-federation/-/secure-messaging-federation-0.0.2.tgz","fileCount":19,"integrity":"sha512-ULx4F6qwIpI3G08985Q2X+lk6nBbB5vtf8mhUcXLSeUUQSS8MY0S5dGunq340iIoLaxrB8ywXp1iqO80/kozwQ==","signatures":[{"sig":"MEUCIQDYXdGiqeLl7PuK17jQdGPzM16Z7IYJI/nuZdadGPDhWAIgZJJcd6LQ+fz7C7/I+f5NAADrHE4EJY5BOf+otxoFJQ4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":85226},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js","default":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"gitHead":"e3f4c79bdfc173dafbe091622b908d51977f188a","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md}\"","release":"bun run check:package && npm publish --access public","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\"","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"absolutejs":{"manifestContract":2},"repository":{"url":"git+https://github.com/absolutejs/secure-messaging-federation.git","type":"git"},"_npmVersion":"10.9.2","description":"Provider-neutral, downgrade-resistant secure messaging federation for AbsoluteJS.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"^3.9.0","@types/bun":"^1.3.14","typescript":"^5.9.0"},"_npmOperationalInternal":{"tmp":"tmp/secure-messaging-federation_0.0.2_1787798781269_0.7117179504657583","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"name":"@absolutejs/secure-messaging-federation","version":"0.0.3","author":{"name":"Alex Kahn"},"license":"Apache-2.0","_id":"@absolutejs/secure-messaging-federation@0.0.3","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"homepage":"https://github.com/absolutejs/secure-messaging-federation","bugs":{"url":"https://github.com/absolutejs/secure-messaging-federation/issues"},"dist":{"shasum":"e57e3204b43d2bc1d9bd3b75ef35fa97970c5264","tarball":"https://registry.npmjs.org/@absolutejs/secure-messaging-federation/-/secure-messaging-federation-0.0.3.tgz","fileCount":19,"integrity":"sha512-cimtY5EfwwW8adjFsemxZ8DybmYbDFM3GwgxpxSIQJVtckT8ABjk8p1XGYpGRBDyXVXU35HgcsaBoiQzzQgtjw==","signatures":[{"sig":"MEYCIQCaK48o/boHRR5wdGahj8FOgjUaDU1KUddegj85Ci72EAIhAOasCoVfqmRJhQiVLmPjj34IO5cRr8f5o8FdNu+tWsqi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":85533},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js","default":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"gitHead":"c8df42cf840f982a809ce6e5e175cc2c63b2b803","scripts":{"test":"bun test tests/","build":"rm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit","format":"prettier --write \"./**/*.{ts,json,md}\"","release":"bun run check:package && npm publish --access public","typecheck":"tsc --noEmit","format:check":"prettier --check \"./**/*.{ts,json,md}\"","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package","verify-package":"absolute-manifest verify-package"},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"absolutejs":{"manifestContract":2},"repository":{"url":"git+https://github.com/absolutejs/secure-messaging-federation.git","type":"git"},"_npmVersion":"10.9.2","description":"Provider-neutral, downgrade-resistant secure messaging federation for AbsoluteJS.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@sinclair/typebox":"^0.34.0","@absolutejs/manifest":"^0.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"^3.9.0","@types/bun":"^1.3.14","typescript":"^5.9.0"},"_npmOperationalInternal":{"tmp":"tmp/secure-messaging-federation_0.0.3_1787799387214_0.8086863789404244","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@absolutejs/secure-messaging-federation","version":"0.1.0","description":"Provider-neutral, downgrade-resistant secure messaging federation for AbsoluteJS.","type":"module","license":"Apache-2.0","author":{"name":"Alex Kahn"},"repository":{"type":"git","url":"git+https://github.com/absolutejs/secure-messaging-federation.git"},"homepage":"https://github.com/absolutejs/secure-messaging-federation","bugs":{"url":"https://github.com/absolutejs/secure-messaging-federation/issues"},"main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./manifest":{"types":"./dist/manifest.d.ts","import":"./dist/manifest.js","default":"./dist/manifest.js"},"./manifest.json":"./dist/manifest.json"},"publishConfig":{"access":"public"},"scripts":{"build":"rm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit","check:package":"bun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package","format":"prettier --write \"./**/*.{ts,json,md}\"","format:check":"prettier --check \"./**/*.{ts,json,md}\"","release":"bun run check:package && npm publish --access public","test":"bun test tests/","typecheck":"tsc --noEmit","verify-package":"absolute-manifest verify-package"},"dependencies":{"@absolutejs/manifest":"^0.9.0","@sinclair/typebox":"^0.34.0"},"devDependencies":{"@types/bun":"^1.3.14","prettier":"^3.9.0","typescript":"^5.9.0"},"absolutejs":{"manifestContract":2},"_id":"@absolutejs/secure-messaging-federation@0.1.0","gitHead":"31fc92c10da11a40aaf6f71da06b035572d2eaf6","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-Yx/w8sxwE2fsn/w1hOT6S8ElpcB+VAiiKyZjFNC4eKkJ307Q3YMDx7An//lLR9txxFKHbN23UHLtMjnvJK5CVw==","shasum":"1fce9bd7d7769c9fcd12840f7fafea835e4c748e","tarball":"https://registry.npmjs.org/@absolutejs/secure-messaging-federation/-/secure-messaging-federation-0.1.0.tgz","fileCount":20,"unpackedSize":101840,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCaG6BFEW4MvG/uIwE4FfzQNSK7wLsB7YCfVAPd7NBOGwIhAN1aZflyEVPL1NYM5IaM8UCCMzeFH/OMgqSq9U+O4I6I"}]},"_npmUser":{"name":"alexkahndev","email":"alexkahn2019@gmail.com"},"directories":{},"maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/secure-messaging-federation_0.1.0_1787799798446_0.9379341020652503"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-27T02:42:34.218Z","modified":"2026-08-27T03:03:18.796Z","0.0.1":"2026-08-27T02:42:34.523Z","0.0.2":"2026-08-27T02:46:21.423Z","0.0.3":"2026-08-27T02:56:27.398Z","0.1.0":"2026-08-27T03:03:18.591Z"},"bugs":{"url":"https://github.com/absolutejs/secure-messaging-federation/issues"},"author":{"name":"Alex Kahn"},"license":"Apache-2.0","homepage":"https://github.com/absolutejs/secure-messaging-federation","repository":{"type":"git","url":"git+https://github.com/absolutejs/secure-messaging-federation.git"},"description":"Provider-neutral, downgrade-resistant secure messaging federation for AbsoluteJS.","maintainers":[{"name":"alexkahndev","email":"alexkahn2019@gmail.com"}],"readme":"# `@absolutejs/secure-messaging-federation`\n\nProvider-neutral secure messaging federation for AbsoluteJS. The stable core\nkeeps domain authentication, transports, and abuse-evidence cryptography behind\ninterchangeable contracts while enforcing one downgrade-resistant API.\n\nThe first release provides:\n\n- exact bilateral profile matching; profiles bind the federation protocol and\n  revision, E2EE protocol, content types, feature set, frame limit, and explicit\n  `strict-e2ee` or `managed-recovery` security mode;\n- transcript hashes over both offers and mutual domain signatures before a\n  session becomes active;\n- signed opaque envelopes bound to that transcript, with expiry, clock-skew,\n  size, local-domain, route, and durable replay checks;\n- strict bounded wire codecs and explicit transport acknowledgement, allowing a\n  delivery bridge to acknowledge only after durable MLS processing;\n- confidential abuse-evidence contracts that require a concrete user approval\n  or standing-policy mandate and disclose only ciphertext to federation code.\n\nThere is deliberately no plaintext, legacy, or weaker-mode fallback. If peers do\nnot advertise an exactly matching locally preferred profile, negotiation fails.\nManaged recovery also has to name the same recovery authority on both sides.\n\n```ts\nconst transcript = await negotiateFederation({\n  initiatorOffer,\n  responderOffer,\n  preferredProfileIds: [\"abs.mls.strict.v1\"],\n  sessionId: \"random-session-id\",\n  limits,\n  now: Date.now(),\n});\n\n// Each domain signs the exact transcript through a signature provider.\nconst session = await activateFederationSession({\n  initiatorOffer,\n  responderOffer,\n  transcript,\n  initiatorConfirmation,\n  responderConfirmation,\n  signatureProvider,\n  now: Date.now(),\n});\n```\n\n## Standards position\n\nThe IETF MIMI architecture and protocol are active Internet-Drafts, not finished\nstandards. This core therefore does not claim MIMI interoperability. A MIMI\nadapter must identify and pin the exact draft revision, expose it in the\nnegotiated profile, require explicit experimental opt-in, and fail when the peer\ndoes not match. The separation lets AbsoluteJS track MIMI without destabilizing\nthe application API.\n\nThe model follows MLS's authenticated epoch and group-state boundaries from\n[RFC 9420](https://www.rfc-editor.org/rfc/rfc9420.html), the federation roles and\nminimal-provider-access direction in the\n[MIMI architecture draft](https://datatracker.ietf.org/doc/html/draft-ietf-mimi-arch-03),\nand bilateral capability/message-franking work in the\n[MIMI protocol draft](https://datatracker.ietf.org/doc/html/draft-ietf-mimi-protocol-06).\n\n## Abuse and AI safety\n\nEvidence sealing happens at the endpoint. The report object carries sealed bytes\nand bounded metadata, never a plaintext field. `receiver-asserted` means a\nrecipient supplied the evidence and could have fabricated it; only a provider\nthat actually validates a sender-bound cryptographic frank may return `franked`.\nMessage franking in MIMI remains draft work.\n\nAn agent must not infer permission from the content it sees. It must supply either\na phishing-resistant `user-approved` approval ID or an exact `standing-policy`\nmandate ID before evidence can be sealed. Applications should show the recipient,\nreason, messages, destination moderation key, and disclosure scope outside\nmodel-controlled content.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}