{"_id":"@absuitecore/capkit","_rev":"14-6f16e3bfa49d1cf411d6a422410725f1","name":"@absuitecore/capkit","dist-tags":{"latest":"1.8.1"},"versions":{"1.0.0":{"name":"@absuitecore/capkit","version":"1.0.0","keywords":["capability-token","jwt","authorization","ai-agents","audit-log"],"license":"MIT","_id":"@absuitecore/capkit@1.0.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"15d80741fbe5f3b1a67cdf0c41ad428c68130d2e","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.0.0.tgz","fileCount":37,"integrity":"sha512-P4y5z6WNk3COperVWRD+Hbe/8/M2J6rXEBfAPzSvymmB48oqwDF3zyhSX/tZPj6L8iTqqBrRhZ+OUuDY6FFUDg==","signatures":[{"sig":"MEYCIQDQPCS8y0MBmCbeTIjn5uLUp+luBIEBKNRpCzQWttk+igIhAM/qUHsLvDH/f2h08r24FV9oufEDXjw4hwSzvWE36guI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":175853},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.0.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/a7e410ef4b2797751d49f2219b83f912/absuitecore-capkit-1.0.0.tgz","_integrity":"sha512-P4y5z6WNk3COperVWRD+Hbe/8/M2J6rXEBfAPzSvymmB48oqwDF3zyhSX/tZPj6L8iTqqBrRhZ+OUuDY6FFUDg==","deprecated":"Security: POST /auth/token/validate accepted a requiredScope field and silently ignored it, returning valid:true for scopes the token did not hold. Fixed in 1.1.1 — please upgrade.","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Capability tokens, JWT validation, tamper-evident audit and verifiable execution traces for AI agents.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.0.0_1785297888600_0.039457708527041335","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@absuitecore/capkit","version":"1.1.0","keywords":["capability-token","jwt","authorization","ai-agents","audit-log"],"license":"MIT","_id":"@absuitecore/capkit@1.1.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"f07f17b86e169d944801285d6a0186b1f9a0c29d","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.1.0.tgz","fileCount":37,"integrity":"sha512-0uJvScUZNFeBHkLLtGoF1+YzBeYPmMFyxKUnPyYCf+0Wqz+cd6esRikFleHKS8nt6Si4b5ZheRvAI6Zl/CLx4A==","signatures":[{"sig":"MEUCIG0B4S6hX6d33/SWQ+H8ZwVE/xKNArV1v9d7GwWt47X5AiEAxoi3uOFJFh8rKh5lbRt1v9by4SCoboM5Rv3op3UQmyo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":180717},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.1.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/4362559ff54cf280bccce00d027b9ae3/absuitecore-capkit-1.1.0.tgz","_integrity":"sha512-0uJvScUZNFeBHkLLtGoF1+YzBeYPmMFyxKUnPyYCf+0Wqz+cd6esRikFleHKS8nt6Si4b5ZheRvAI6Zl/CLx4A==","deprecated":"Security: POST /auth/token/validate accepted a requiredScope field and silently ignored it, returning valid:true for scopes the token did not hold. Fixed in 1.1.1 — please upgrade.","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Capability tokens, JWT validation, tamper-evident audit and verifiable execution traces for AI agents.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.1.0_1785317360739_0.08031815527890407","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@absuitecore/capkit","version":"1.1.1","keywords":["capability-token","jwt","authorization","ai-agents","audit-log"],"license":"MIT","_id":"@absuitecore/capkit@1.1.1","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"080346559961173a9f17bbbf3e843c25571a6c1c","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.1.1.tgz","fileCount":37,"integrity":"sha512-LKQq1l14a861uEx4obpsRVecTRHLUsuEGEg1fRh1+FcaSgevroXHqXK3Xn8Fnu9OjQ8if3SDdz6D1quRr3xfww==","signatures":[{"sig":"MEQCIByJSEwdK8y4PeQOOoxMTbIFqxYWqf9HW7a/+CCiOTTeAiAkCtlDiuzR1fEda0PoI5UsTc4hYJQC7l9kfsaYEe2Fow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":183400},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.1.1.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/89acffc924b16d2f52c192a904358445/absuitecore-capkit-1.1.1.tgz","_integrity":"sha512-LKQq1l14a861uEx4obpsRVecTRHLUsuEGEg1fRh1+FcaSgevroXHqXK3Xn8Fnu9OjQ8if3SDdz6D1quRr3xfww==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Capability tokens, JWT validation, tamper-evident audit and verifiable execution traces for AI agents.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.1.1_1785318634097_0.9694589793538357","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@absuitecore/capkit","version":"1.1.2","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.1.2","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"d662a15f49082ce7613b2b6566765a2aaa81b6e8","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.1.2.tgz","fileCount":37,"integrity":"sha512-gnh3pg2YzPbXI0+OKUL0+bR6uBlaYqC9XleOpZnxOUXMnPW2C12dzNFhZDrRBXWBpa/OkuuyVrn3xMVvnkrIVg==","signatures":[{"sig":"MEQCIC1RjJFbuwD7oSMzIUACWqQU6cNvgzsaH5E7l9SW0LyKAiB5uvnnpirolB+RnZrePLtObuCqTrSJbaBRXXqAJbmilA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":183546},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.1.2.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/5051cb307e4cd79393f1911a3f2f9e61/absuitecore-capkit-1.1.2.tgz","_integrity":"sha512-gnh3pg2YzPbXI0+OKUL0+bR6uBlaYqC9XleOpZnxOUXMnPW2C12dzNFhZDrRBXWBpa/OkuuyVrn3xMVvnkrIVg==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.1.2_1785320179919_0.5500736310676129","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@absuitecore/capkit","version":"1.2.0","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.2.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"e8e06613dc93b73d5206421e0a553ddb4fbd30a1","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.2.0.tgz","fileCount":53,"integrity":"sha512-zgbsRUEF4CWFMpCxOOzZA5rFpcxgQ+OH0I4YqKvW6BAOrFfu0IhZByQhqAA2WXs3locSrRyqFXUvp0LXqca0kQ==","signatures":[{"sig":"MEQCIFtpiu/tgJCIJHHZg63oOHIVN6ijfgT9ISuCLESz6XsBAiBWSdb94XgQzXUm20WgValg+R2+zraENv/YTrEB0lS/TQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":437674},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.2.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/d24c2aec3793f130bea44460b7cf0581/absuitecore-capkit-1.2.0.tgz","_integrity":"sha512-zgbsRUEF4CWFMpCxOOzZA5rFpcxgQ+OH0I4YqKvW6BAOrFfu0IhZByQhqAA2WXs3locSrRyqFXUvp0LXqca0kQ==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.2.0_1785669559388_0.671079006650606","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@absuitecore/capkit","version":"1.3.0","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.3.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"e19af8a546e293c511143c03f8b12f7a1b5a2ec3","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.3.0.tgz","fileCount":53,"integrity":"sha512-vZ2V8Cz8uwFVVhAdP9CC1YjxM+H28xiZJDBPCJ3Dxfmf59yekauBuTU0PTAjT3s7dhOvXe6yMHlTqBoPBUZoyw==","signatures":[{"sig":"MEQCIGuJujVGqQqxu1ufCVTuCgk8/vSqume60xgT9zpE7zd4AiBMR5H/DrkjhjfUsDeM4f1Vv9UTp5Bt8eh48VyNBwdr8A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":442765},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.3.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/c1774b5f47e717608dd5a24867ae27b5/absuitecore-capkit-1.3.0.tgz","_integrity":"sha512-vZ2V8Cz8uwFVVhAdP9CC1YjxM+H28xiZJDBPCJ3Dxfmf59yekauBuTU0PTAjT3s7dhOvXe6yMHlTqBoPBUZoyw==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.3.0_1785682583675_0.797187476800534","host":"s3://npm-registry-packages-npm-production"}},"1.3.1":{"name":"@absuitecore/capkit","version":"1.3.1","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.3.1","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"3b9d7e80299f16032360d263029f238471fe2559","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.3.1.tgz","fileCount":53,"integrity":"sha512-AfkQtvwP1nH6Qmxsb+Jslk/1SZ10atOF9s/fxVQ+kwHmxxrwlwl2qpZ9ef5NHEXeS3L028XfIXsRHhyc5QM71A==","signatures":[{"sig":"MEUCIH8P7s+2Y6dQNOEKvuzC26ZDKLaVsdB7X0njfqe75jYbAiEA2EnPrHFqMddXIg54hu2u1uEk7rSZd/nZBS9wP1MaHcQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":445580},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.3.1.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/a9ce1fe9e75c2be19503f84e77e62475/absuitecore-capkit-1.3.1.tgz","_integrity":"sha512-AfkQtvwP1nH6Qmxsb+Jslk/1SZ10atOF9s/fxVQ+kwHmxxrwlwl2qpZ9ef5NHEXeS3L028XfIXsRHhyc5QM71A==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.3.1_1785684233705_0.27219540931195874","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@absuitecore/capkit","version":"1.4.0","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.4.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"a101a1fd327153ed2dd47d733460802ffe957601","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.4.0.tgz","fileCount":53,"integrity":"sha512-JLLLLPrvfse17bdc6kifvi1UPWLEdU4J1iZ4HtzZAZuA1kMr8pbyfnJBn01S0RyWVk7rLEe1ULxQ0osKXWBfQw==","signatures":[{"sig":"MEUCIQC+rF4GP9PqgQy3wqaxQL9RH1VLlkMnzbbombiv0VUnJgIgdIWlh2+oxel5o8BbR4rmW9uEinCejlYdNle+X4JqFR8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":458942},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.4.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/a4b74da89e8336795e68494517d2612e/absuitecore-capkit-1.4.0.tgz","_integrity":"sha512-JLLLLPrvfse17bdc6kifvi1UPWLEdU4J1iZ4HtzZAZuA1kMr8pbyfnJBn01S0RyWVk7rLEe1ULxQ0osKXWBfQw==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.4.0_1785700452090_0.38248961729910635","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@absuitecore/capkit","version":"1.5.0","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.5.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"419020238ee3043aec6c1d3e932f349ef19bc6bc","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.5.0.tgz","fileCount":55,"integrity":"sha512-AR6CPBNiLeAA9aTKp7QvlBKOWMBgp4Hn4sKCjiL/37I9Mzj6Ocg2gaENVVS7XKiQmc4ck3s3gvZsfMAjZrAJhg==","signatures":[{"sig":"MEYCIQCCcgrsRRNfCFfY6QdKQuPBD7pGYI01N1fzvCmyjQsDNQIhAPlvITLzqXDjBsf/WQd5TvBk8ZUNOcANdsvQuOWAa+oa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":471305},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.5.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/e7df97760eb3ce47528ebc8a524fe998/absuitecore-capkit-1.5.0.tgz","_integrity":"sha512-AR6CPBNiLeAA9aTKp7QvlBKOWMBgp4Hn4sKCjiL/37I9Mzj6Ocg2gaENVVS7XKiQmc4ck3s3gvZsfMAjZrAJhg==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.5.0_1785719309153_0.38712888380203125","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@absuitecore/capkit","version":"1.6.0","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.6.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"456be82fe377d8be5adfc3551bb2bb5d0dd19644","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.6.0.tgz","fileCount":57,"integrity":"sha512-DJa/uyvsrd3KZHOvFgySPcuHxdfQmAM7gXy0kgXMAesBgtoBq1/+8TAobT0pFNhZXdZs5fLaLfcnX/hOZ88cYA==","signatures":[{"sig":"MEYCIQCM2W5GTicA3Ypp2e+Ab19FOCi1JwBMX7hoP4LB4YKd0AIhAPxYphq1xT2FDZIuICvcDUKJRx6KOPZAUdjBWIJUhqrO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":490895},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.6.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/7ed0ac1fc5e26b6b11f1310ea4346961/absuitecore-capkit-1.6.0.tgz","_integrity":"sha512-DJa/uyvsrd3KZHOvFgySPcuHxdfQmAM7gXy0kgXMAesBgtoBq1/+8TAobT0pFNhZXdZs5fLaLfcnX/hOZ88cYA==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.6.0_1785725932836_0.4671340746308683","host":"s3://npm-registry-packages-npm-production"}},"1.7.0":{"name":"@absuitecore/capkit","version":"1.7.0","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.7.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"cea06de0464fe450fcc461ff69160f45446de18a","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.7.0.tgz","fileCount":57,"integrity":"sha512-1U44Z8GKGvuSA3jZ56QFA1/Jfqcl/w7KDG8h6hzswFczaV9uYUWA4PovNoJ0BK+EG5IOk1GAEwKPP0INo+uMyQ==","signatures":[{"sig":"MEYCIQCBIEBv2SDujgsgXn+3/Oqou9XCjDk3eeEa94dIC3kinwIhAMD9HgWGu7JLqXK3sSLUUGqVGyHQJleR8ptHq5DmHEBt","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":492557},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.7.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/3b2477be6e64e4452285fbba9debc3e7/absuitecore-capkit-1.7.0.tgz","_integrity":"sha512-1U44Z8GKGvuSA3jZ56QFA1/Jfqcl/w7KDG8h6hzswFczaV9uYUWA4PovNoJ0BK+EG5IOk1GAEwKPP0INo+uMyQ==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.7.0_1785726754225_0.6739760441922542","host":"s3://npm-registry-packages-npm-production"}},"1.7.1":{"name":"@absuitecore/capkit","version":"1.7.1","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"license":"MIT","_id":"@absuitecore/capkit@1.7.1","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"a783ad5b3eb3e1d73663ab95bb20c9cf11b644d5","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.7.1.tgz","fileCount":57,"integrity":"sha512-2Khvi1Yn6Xz2HOI925EYWGETCQYDsXcCQPSFV1Qu3AXe3py5gFG1h6CxoSaFx5M9TzRVAmehBGhhGGnDwWmPow==","signatures":[{"sig":"MEUCIQDfRf54ee1FR8gJ6TWmG9cFsLIJD1Gj0tEtZlps2mTJuAIgXLF4xs/8MXnb3YTiRlQhN974Mh8pR3jw5tTEP2QANI0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":492936},"main":"dist/index.js","_from":"file:absuitecore-capkit-1.7.1.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/def4845def3b69dc48f41f3dd81c157d/absuitecore-capkit-1.7.1.tgz","_integrity":"sha512-2Khvi1Yn6Xz2HOI925EYWGETCQYDsXcCQPSFV1Qu3AXe3py5gFG1h6CxoSaFx5M9TzRVAmehBGhhGGnDwWmPow==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/capkit"},"_npmVersion":"10.9.8","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/capkit_1.7.1_1785736579309_0.4598765366010078","host":"s3://npm-registry-packages-npm-production"}},"1.8.1":{"name":"@absuitecore/capkit","version":"1.8.1","description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"dependencies":{"express":"^4.18.0","undici":"^8.9.0"},"devDependencies":{"@types/express":"^4.17.21","@types/node":"^22.0.0","tsx":"^4.21.0","typescript":"^5.0.0"},"engines":{"node":">=22.5.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/iamGodofall/ABSuite-core.git","directory":"packages/capkit"},"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"scripts":{"build":"tsc -p tsconfig.json","start":"node dist/server.js","dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/capkit"},"_id":"@absuitecore/capkit@1.8.1","_integrity":"sha512-M5JB/ImDLgFOn1QMfJwdcrckZfw/XGoPv3EbfL2Em7LI3+/3J97bqNVZK32btOyI8JCZtyYpQhh6ayHD20RqPw==","_resolved":"/tmp/69d10c92c2d49798fb797b4fecb42909/absuitecore-capkit-1.8.1.tgz","_from":"file:absuitecore-capkit-1.8.1.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-M5JB/ImDLgFOn1QMfJwdcrckZfw/XGoPv3EbfL2Em7LI3+/3J97bqNVZK32btOyI8JCZtyYpQhh6ayHD20RqPw==","shasum":"cbe0bc689e1383d2803769439412789fe62ede0b","tarball":"https://registry.npmjs.org/@absuitecore/capkit/-/capkit-1.8.1.tgz","fileCount":57,"unpackedSize":499623,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2fcapkit@1.8.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCVkwX3HYyf7GdB9oIc8gqd1DubelW39KgTwA3jkI6a+QIgfXr2FaWXLBLMLwVzUTJ32YYCq0LrATi002lnKT1CmA0="}]},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"directories":{},"maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/capkit_1.8.1_1785741117329_0.8684685915739194"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-29T04:04:48.407Z","modified":"2026-08-03T07:11:57.830Z","1.0.0":"2026-07-29T04:04:48.792Z","1.1.0":"2026-07-29T09:29:20.892Z","1.1.1":"2026-07-29T09:50:34.247Z","1.1.2":"2026-07-29T10:16:20.118Z","1.2.0":"2026-08-02T11:19:19.544Z","1.3.0":"2026-08-02T14:56:23.888Z","1.3.1":"2026-08-02T15:23:53.903Z","1.4.0":"2026-08-02T19:54:12.226Z","1.5.0":"2026-08-03T01:08:29.316Z","1.6.0":"2026-08-03T02:58:53.029Z","1.7.0":"2026-08-03T03:12:34.574Z","1.7.1":"2026-08-03T05:56:19.486Z","1.8.1":"2026-08-03T07:11:57.459Z"},"bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"license":"MIT","homepage":"https://github.com/iamGodofall/ABSuite-core#readme","keywords":["capability-token","execution-trace","tamper-evident","ed25519","provenance","audit-log","authorization","jwt","ai-agents","ai-governance"],"repository":{"type":"git","url":"git+https://github.com/iamGodofall/ABSuite-core.git","directory":"packages/capkit"},"description":"Ed25519-signed, hash-chained execution traces and capability tokens for AI agents — prove what an agent was allowed to do and what it actually did.","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"readme":"# @absuitecore/capkit\n\n**Scoped, expiring, auditable credentials for AI agents. Stop handing your agents your root API key.**\n\n[![MIT License](https://img.shields.io/badge/license-MIT-7C3AED)](https://github.com/iamGodofall/ABSuite-core/blob/main/LICENSE)\n\nMost agent deployments authenticate with a long-lived API key that has full\naccount access. CapKit replaces that with capability tokens: narrow, expiring,\nrevocable grants, with a tamper-evident record of everything they were used for.\n\n```bash\nnpm install @absuitecore/capkit\n```\n\n## Capability tokens\n\n```typescript\nimport { CapabilityToken } from '@absuitecore/capkit'\n\nconst created = CapabilityToken.create({\n  sub: 'agent-001',\n  scope: ['read:users', 'write:tasks'],\n  expiresIn: '8h',\n}, process.env.CAPKIT_HMAC_SECRET!)\n\nconst result = CapabilityToken.validate(created.token, secret, {\n  requiredScope: 'write:tasks',\n})\n\nif (!result.valid) {\n  // 'TOKEN_MISSING' | 'TOKEN_MALFORMED' | 'TOKEN_INVALID' | 'TOKEN_EXPIRED'\n  // | 'TOKEN_NOT_ACTIVE' | 'TOKEN_AUDIENCE_MISMATCH' | 'TOKEN_REVOKED'\n  // | 'CAPABILITY_INSUFFICIENT'\n  throw new Error(result.error)\n}\n```\n\nScopes match segment-wise: `read:*` grants `read:users` but never\n`read:users:delete`. Tokens are HS256 JWTs signed with `node:crypto` — no\nthird-party JWT dependency on the security-critical path, and `alg: none`\ndowngrades and tampered payloads are rejected.\n\n## Guarding a route\n\n```typescript\nimport express from 'express'\nimport { capabilityGuard, revocationStoreFromEnv } from '@absuitecore/capkit'\n\nconst requireCapability = capabilityGuard({ revocations: revocationStoreFromEnv() })\n\napp.post('/tasks', requireCapability('write:tasks'), handler)\n```\n\nReturns `401` for a missing or invalid token, `403` for insufficient scope. If\nthe revocation store is unreachable it returns `503` rather than failing open.\n\n## Verifiable execution\n\nEvery real action can produce a signed, hash-chained trace. Signatures are\n**Ed25519**, so an auditor can verify your records holding only a public key —\nwithout also being able to forge them.\n\n```typescript\nimport { TraceStore, SigningKey, verifyTrace, getStorage } from '@absuitecore/capkit'\n\nconst traces = new TraceStore(getStorage(), new SigningKey(process.env.CAPKIT_TRACE_PRIVATE_KEY))\n\nconst trace = traces.record({\n  subject: 'agent-001',\n  scope: ['write:tasks'],\n  module: 'my-service',\n  action: 'http:POST https://api.example.com/sync',\n  input,          // hashed here and discarded — pass `inputHash` if you hashed it yourself\n  output,\n  outcome: 'success',\n})\n\n// Anyone holding the public key can check it — no ABSuite credentials needed.\nverifyTrace(trace, publicKeyPem)  // { valid: true, contentIntact: true, signatureValid: true }\n\ntraces.verifyChain(publicKeyPem)  // names the sequence number of any broken record\n```\n\nPayloads are **hashed, never stored**, so a trace proves what happened without\nretaining your customers' data. `startedAt` defaults to now, `steps` to none,\nand `durationMs` is derived when you supply both timestamps — a default is only\never taken where the library already knows the answer.\n\n## Tamper-evident audit log\n\n```typescript\nimport { AuditLog } from '@absuitecore/capkit'\n\nconst audit = new AuditLog('/data/audit.jsonl')\naudit.record({ subject: 'agent-001', action: 'POST /tasks', resource: '/tasks', result: 'allow' })\n\naudit.verifyChain()  // { valid: false, brokenAt: 3, reason: 'Entry content does not match its hash' }\n```\n\nEditing or deleting a historical entry breaks every subsequent link, and the\nverifier names the first record that fails.\n\n## Human approvals, bound to what actually ran\n\nAn approval is tied to a **hash of the payload**, not to a request id. Every\nfield it binds — subject, module, action, inputHash — is also on the finished\nexecution record, so *\"was this approved?\"* is answerable from the record alone,\nwith no approval id written onto it.\n\n```typescript\nimport { ApprovalRegistry, Storage } from '@absuitecore/capkit'\n\nconst approvals = new ApprovalRegistry(new Storage('/data/absuite.db'))\n\nconst request = approvals.request({\n  action: { subject: 'agent:payments', module: 'payments',\n            action: 'approve_batch', inputHash },     // the hash of what will run\n  context: 'batch B-1 is over the human-approval threshold',\n  policyRef: 'payments.batch-approval', policyVersion: '1',\n  requestedBy: 'ops:alice',\n})\n\napprovals.decide(request.id, {\n  decision: 'GRANTED', decidedBy: 'ops:bob',\n  basis: 'CFO confirmed the batch against the ledger.',   // required, never optional\n})\n```\n\nAn approval granted for one input does not cover a different one. The requester\nmay not decide, and a decision with no stated basis is refused — recorded\nreasoning is the only part of an approval that helps anybody six months later.\n\n**Signed versus named.** A decision signed with an enrolled key reads `PROVEN`; a\ndecision attributed by a name the operator supplied reads `ASSERTED`, and says\nso. Set `ABSUITE_REQUIRE_SIGNED_APPROVALS=true` to make that a gate rather than a\nlabel — an `ASSERTED` decision then turns Governance `FAILED` on a record whose\npolicy demanded a person. **Set it if you rely on approvals for a regulated\nobligation.**\n\n## Watch — findings, and how much of the record they cover\n\n```typescript\nimport { Watch } from '@absuitecore/capkit'\n\nconst watch = new Watch(storage, traces, approvals, { publicKeyPem })\n\nwatch.coverage()   // everRun: false — nothing has looked yet, and it says so\nwatch.sweep()\n\nwatch.notices()    // CHAIN_BROKEN, UNAPPROVED_EXECUTION, DENIED_BUT_SUCCEEDED, …\nwatch.coverage()   // everRun, sweeps, highWaterSeq, behind, and why\n```\n\n`coverage()` exists because **an empty notice list means two opposite things** —\n*we looked and found none*, or *nothing has ever looked* — and those must not\nappear identical. Before the first sweep it says exactly which one you have:\n\n> This watch has never run. There are no notices because nothing has looked,\n> which is not the same as nothing being wrong.\n\nAfter a sweep it stops making that excuse and tells you how far it got, including\nhow many records it has not reached yet.\n\n## Multi-tenancy, metering and quotas\n\n```typescript\nimport { Storage, TenantService } from '@absuitecore/capkit'\n\nconst tenancy = new TenantService(new Storage('/data/absuite.db'))\nconst tenant = tenancy.tenants.create('Acme Corp', 'team')\n// tenant.apiKey is returned exactly once and stored only as a SHA-256 hash.\n\ntenancy.consume(tenant, 'validations')\ntenancy.usageReport(tenant)  // usage, quotas, and which limits are being approached\n```\n\n## Configuration\n\n| Variable | Purpose |\n|---|---|\n| `CAPKIT_HMAC_SECRET` | Token signing secret. Required in production (32+ chars). |\n| `CAPKIT_ADMIN_KEY` | Bootstrap key for issuing the first token. |\n| `CAPKIT_AUDIENCE` | Optional audience enforced at validation. |\n| `ABSUITE_DB_PATH` | SQLite database. Enables durable revocation, tenancy and traces. |\n| `CAPKIT_TRACE_PRIVATE_KEY` | Ed25519 PEM for signing traces. Generated ephemerally if unset. |\n| `ABSUITE_REQUIRE_SIGNED_APPROVALS` | `true` makes an unsigned (`ASSERTED`) approval fail rather than pass with a label. Off by default; the server says which mode it is in at boot, both ways. |\n\nGenerate secrets with `openssl rand -hex 32`, and a trace keypair with\n`SigningKey.createPair()` — it hands back the key to sign with plus both PEMs,\nthe public one to give auditors and the private one for your secret manager.\n`SigningKey.generate()` returns the PEMs alone and remains supported.\n\n## Where an outbound request is going\n\nThree services in this suite take a URL from a caller and fetch it. Rather than\nthree copies of one address table — the drift this project keeps catching in\nitself — classification lives here, and so does the fetch that uses it:\n\n```ts\nimport { guardedFetch } from '@absuitecore/capkit';\n\nconst response = await guardedFetch(url, init, {\n  refuse: ['link-local'],   // your policy; metadata endpoints are always refused\n  allow: allowedHosts,      // hosts an operator named explicitly\n  verb: 'call',             // used in the error: \"Refusing to call …\"\n});\n```\n\n`guardedFetch` follows redirects itself, because `fetch` follows them without\nasking again — a permitted host answering `302 Location:\nhttp://169.254.169.254/…` was demonstrated to reach the metadata service past a\nguard that had classified hop one correctly. Against a redirect, checking only\nthe caller's URL is not partial protection; it is none. Every hop is classified,\n`Authorization` and `Cookie` are dropped when the origin changes, and a\n`BlockedTargetError` names which hop failed.\n\n`allow` and `only` are different questions, and the difference is load-bearing.\n`allow` exempts a host from the range check; `only` restricts **every hop** to a\nlist and refuses anything else. Passing an allowlist as `allow` restricts the\nfirst request and nothing after it.\n\n**Known metadata endpoints are refused whatever your `refuse` list says.** They\nare not a range: `169.254.169.254` is link-local, `100.100.100.200` is\ncarrier-grade NAT, and AWS serves IMDS over IPv6 at `fd00:ec2::254`, which is\nunique-local — a range services that call their own infrastructure allow on\npurpose. `allowMetadata: true` overrides it, and a host allowlist deliberately\ndoes not.\n\nThe classifier is exported on its own for callers that need to decide before\nfetching:\n\n```ts\nimport { resolveRanges, inAnyRange } from '@absuitecore/capkit';\n\nconst blocked = inAnyRange(await resolveRanges(url.hostname), ['link-local']);\nif (blocked) throw new Error(`Refusing to call ${url.hostname}: it is ${blocked.why}.`);\n```\n\n`resolveRanges` returns every address a hostname resolves to, each tagged\n`loopback | private | link-local | carrier-grade-nat | unique-local |\nunspecified | public`, with a `why` string naming the specific thing that\nmatched — `169.254.169.254` is described as the metadata service, `fe80::1` is\nnot. It returns `undefined` for a name that will not resolve, because reporting a\nDNS outage as a security event teaches operators to ignore security events.\n\nAddresses are compared numerically, not as text. `new URL()` re-serialises IPv6\nto its shortest form, so `[::ffff:169.254.169.254]` arrives as\n`::ffff:a9fe:a9fe`; a pattern looking for a dotted quad sees none and calls it\npublic. IPv4-mapped, IPv4-compatible and NAT64-embedded forms all classify as\nthe IPv4 address they reach.\n\n**It classifies and does not decide.** There is no `isAllowed()`, because\n`webhook.send` posts to third parties and must refuse private ranges, while\nedge-run and quickbench exist to call your own internal services. A shared\ndecision would have had to pick a side and be wrong somewhere.\n\n## Known limitations\n\n- Only one signing key is active at a time; rotating `CAPKIT_HMAC_SECRET`\n  invalidates existing tokens.\n- `guardedFetch` pins the connection to the address it classified, which closes\n  DNS rebinding. `resolveRanges` on its own does not — a caller that resolves and\n  then hands the hostname to `fetch` is resolving twice, which is the window.\n- SQLite is single-node. The `Storage` and `RevocationStore` interfaces exist so\n  a Postgres or Redis backend drops in without callers changing.\n\n## One token, every service\n\n`@absuitecore/edge-run` (scheduling), `@absuitecore/quickbench` (benchmarking),\n`@absuitecore/connector-starter` (integrations) and `@absuitecore/trust`\n(evidence) all import `capabilityGuard` from this package, so one token works\nacross the suite and revoking it at CapKit locks it out everywhere.\n\n---\n\n## Part of ABSuite\n\n**The black box for AI systems** — record what happened, prove it happened,\npreserve the evidence.\n\n| | |\n|---|---|\n| Source | <https://github.com/iamGodofall/ABSuite-core> |\n| Verify a trace in your browser | <https://iamgodofall.github.io/ABSuite-core/verify.html> |\n| Getting started | [GETTING-STARTED.md](https://github.com/iamGodofall/ABSuite-core/blob/main/GETTING-STARTED.md) |\n| Reporting a vulnerability | [SECURITY.md](https://github.com/iamGodofall/ABSuite-core/blob/main/SECURITY.md) — never a public issue |\n| What this project refuses to build | [PRINCIPLES.md](https://github.com/iamGodofall/ABSuite-core/blob/main/PRINCIPLES.md) |\n\nPublished from CI with a signed Sigstore provenance attestation — check it with\n`npm audit signatures` rather than taking our word for it.\n\nMIT licensed.\n","readmeFilename":"README.md"}