{"_id":"@aethyrai/ssi-verify","_rev":"4-55c3cba913ada986170471294ce763a9","name":"@aethyrai/ssi-verify","dist-tags":{"latest":"0.4.0"},"versions":{"0.1.1":{"name":"@aethyrai/ssi-verify","version":"0.1.1","license":"MIT","_id":"@aethyrai/ssi-verify@0.1.1","maintainers":[{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"}],"homepage":"https://github.com/aethyrai/ssi-verify#readme","bugs":{"url":"https://github.com/aethyrai/ssi-verify/issues"},"dist":{"shasum":"f93e3cb70d27dc3b7391cceeeb284da5bd966db1","tarball":"https://registry.npmjs.org/@aethyrai/ssi-verify/-/ssi-verify-0.1.1.tgz","fileCount":7,"integrity":"sha512-yuYXMVJwwVSHtuzQo8JTqz0DJJN2Xm8/9y4JOTT81SQKZ1cTT8wVP94obYql2IeKpTTuz6pTwgM10uk2UcLtSQ==","signatures":[{"sig":"MEQCIGRct35gjLOeFZohG0G4coztM2FZuuRG1Zfg8CqfHnxOAiBagW5jjaxHIPGnF+ywGld1o5RWwQnmK1Z6hWEgBLykMA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":18477},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a1ac06418e9681c946463ce57cbefc92718ecf27","scripts":{"lint":"npx @biomejs/biome check .","test":"vitest run","build":"tsc","lint:fix":"npx @biomejs/biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"},"repository":{"url":"git+https://github.com/aethyrai/ssi-verify.git","type":"git"},"_npmVersion":"11.7.0","description":"Lightweight SSI credential and signature verification","directories":{},"_nodeVersion":"22.19.0","dependencies":{"@noble/hashes":"^1.7.2","@noble/post-quantum":"^0.5.4"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@biomejs/biome":"^1.9.0"},"_npmOperationalInternal":{"tmp":"tmp/ssi-verify_0.1.1_1774423095189_0.6134150882351184","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@aethyrai/ssi-verify","version":"0.2.0","license":"MIT","_id":"@aethyrai/ssi-verify@0.2.0","maintainers":[{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"}],"homepage":"https://github.com/aethyrai/ssi-verify#readme","bugs":{"url":"https://github.com/aethyrai/ssi-verify/issues"},"dist":{"shasum":"ba04b1b227a17374c296690b7c59be664c8f358b","tarball":"https://registry.npmjs.org/@aethyrai/ssi-verify/-/ssi-verify-0.2.0.tgz","fileCount":7,"integrity":"sha512-QnO6uC4ltn0cF6kHizJnhhrevxvNJq0EEF1yaTD4w2rFV/mLlfxBF8JUy7QKqclmjU1LNVG0XopM8H9PL0YEPA==","signatures":[{"sig":"MEQCIG7GZdSboNAyhPlL3CILnz/FuFGWwJNRCKTkPwoDBLbSAiBgsGfVy7+/oo+5saYO113M+/pUVcs23wW19s2IGbLa1Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21748},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"2450b32bdf7e8d1f0aca152e408ebe89ae63c3a0","scripts":{"lint":"npx @biomejs/biome check .","test":"vitest run","build":"tsc","lint:fix":"npx @biomejs/biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"},"repository":{"url":"git+https://github.com/aethyrai/ssi-verify.git","type":"git"},"_npmVersion":"11.7.0","description":"Lightweight SSI credential and signature verification","directories":{},"_nodeVersion":"22.19.0","dependencies":{"@noble/hashes":"^1.7.2","@noble/post-quantum":"^0.5.4"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@biomejs/biome":"^1.9.0"},"_npmOperationalInternal":{"tmp":"tmp/ssi-verify_0.2.0_1774428205975_0.7346216216440284","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aethyrai/ssi-verify","version":"0.3.0","license":"MIT","_id":"@aethyrai/ssi-verify@0.3.0","maintainers":[{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"}],"homepage":"https://github.com/aethyrai/ssi-verify#readme","bugs":{"url":"https://github.com/aethyrai/ssi-verify/issues"},"dist":{"shasum":"05cb8093b21094237f4fe382d532c59d5c75cc6e","tarball":"https://registry.npmjs.org/@aethyrai/ssi-verify/-/ssi-verify-0.3.0.tgz","fileCount":7,"integrity":"sha512-+YEH2Bc6ii2Hj84DN3CJChRNRbuJgxjZb3gYlb8aOSglqs1uT2ziyM7zoDQVA6jP5jtMIP5jJbPq3vUOgJEzqA==","signatures":[{"sig":"MEQCIAqQ+ohyv0QmKzi3ouosa7WFVLAQnTgfgOi2urq75uXYAiA/g1s6FumcYr45z76zhQgb1cStrxuYFnzDM+7gpFtErA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28728},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20.19.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7b823660492b75c4f93db87e1230b5bca29998f9","scripts":{"lint":"npx @biomejs/biome check .","test":"vitest run","build":"tsc","lint:fix":"npx @biomejs/biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"},"repository":{"url":"git+https://github.com/aethyrai/ssi-verify.git","type":"git"},"_npmVersion":"11.7.0","description":"Lightweight SSI credential and signature verification","directories":{},"_nodeVersion":"22.19.0","dependencies":{"@noble/hashes":"^1.7.2","@noble/post-quantum":"^0.5.4"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@biomejs/biome":"^1.9.0"},"_npmOperationalInternal":{"tmp":"tmp/ssi-verify_0.3.0_1774494158520_0.41986347793334833","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@aethyrai/ssi-verify","version":"0.4.0","description":"Lightweight SSI credential and signature verification","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest","lint":"npx @biomejs/biome check .","lint:fix":"npx @biomejs/biome check --write ."},"dependencies":{"@noble/post-quantum":"^0.5.4","@noble/hashes":"^1.7.2"},"devDependencies":{"@biomejs/biome":"^1.9.0","typescript":"^5.7.0","vitest":"^3.0.0"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/aethyrai/ssi-verify.git"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"engines":{"node":">=20.19.0"},"gitHead":"e3668122fb82157c86c4ebd6560c3fcea11eaea0","_id":"@aethyrai/ssi-verify@0.4.0","bugs":{"url":"https://github.com/aethyrai/ssi-verify/issues"},"homepage":"https://github.com/aethyrai/ssi-verify#readme","_nodeVersion":"22.19.0","_npmVersion":"11.7.0","dist":{"integrity":"sha512-UhS9G0+4b8INQ78Lb/uxIcxjMLQh6iZ+YhDsYbR5EkEbNBDfgJqgJ8UYFdOJH+X718Rb1jJow9dJcj5c3nXORA==","shasum":"e573075ff34506a17e5b16a7f710e4cb3e917225","tarball":"https://registry.npmjs.org/@aethyrai/ssi-verify/-/ssi-verify-0.4.0.tgz","fileCount":7,"unpackedSize":28746,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGYsro4dihMKJB/eCmkXAjrjvPyIcDO0KxcoHQ3/Gba4AiBgXNYu0OlsQHfhp5YnhxEb0R0TKjHedCX8uSw2IFiqng=="}]},"_npmUser":{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"},"directories":{},"maintainers":[{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ssi-verify_0.4.0_1774541447894_0.28381174795793096"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-25T07:18:15.026Z","modified":"2026-03-26T16:10:48.198Z","0.1.1":"2026-03-25T07:18:15.326Z","0.2.0":"2026-03-25T08:43:26.119Z","0.3.0":"2026-03-26T03:02:38.686Z","0.4.0":"2026-03-26T16:10:48.083Z"},"bugs":{"url":"https://github.com/aethyrai/ssi-verify/issues"},"license":"MIT","homepage":"https://github.com/aethyrai/ssi-verify#readme","repository":{"type":"git","url":"git+https://github.com/aethyrai/ssi-verify.git"},"description":"Lightweight SSI credential and signature verification","maintainers":[{"name":"thehermetist","email":"dvallejos@aethyrresearch.com"}],"readme":"# @aethyrai/ssi-verify\n\nVerify AI agent identity. Lightweight, embeddable, post-quantum.\n\n## Why This Exists\n\nAutonomous agents are about to walk the streets. They'll book hotel rooms, sign contracts, access medical records, make purchases, and interact with systems on behalf of real people and companies. Every system they touch needs to answer the same question: **who is this agent, who sent it, and what is it allowed to do?**\n\nToday there's no answer. 93% of agent deployments use shared API keys. 68% of organizations can't tell agent actions apart from human activity. No major agent framework provides per-agent cryptographic identity. When an agent misbehaves, there's no way to trace it back to a responsible party without taking everyone else down with it.\n\nThat's not a technical inconvenience. It's a blocker for agents operating in the real world. Without verifiable identity, autonomous agents can't be trusted, regulated, or insured.\n\n## What This Library Does\n\nThis is the verification side. When an agent presents a credential to your service, `ssi-verify` checks three things:\n\n1. **Is the credential authentic?** — cryptographic signature verification (ML-DSA-65, post-quantum)\n2. **Is it still valid?** — expiry checking\n3. **Is the agent authorized?** — capability matching against what the credential grants\n\nNo network calls. No Aethyr account needed. No API keys. Just math running locally in your service. Install from npm and verify.\n\nThe credential itself is issued by Aethyr — the trust authority. Think of Aethyr as the DMV for AI agents. The agent gets a license. Your service checks the license. This library is the scanner at the door.\n\n## Install\n\n```bash\nnpm install @aethyrai/ssi-verify\n```\n\n## Usage\n\n```typescript\nimport {\n  verifyCredential,\n  verifyAction,\n  verify,\n  matchCapability,\n  parseDID,\n} from '@aethyrai/ssi-verify';\n\n// An agent presents a credential to your service.\n// Verify it against Aethyr's public key.\nconst result = verifyCredential(credential, issuerPublicKey);\nif (!result.valid) {\n  console.error('Credential invalid:', result.reason);\n}\n\n// Check what the agent is allowed to do\nmatchCapability('tool:hubspot_*', 'tool:hubspot_create_contact'); // true\nmatchCapability('tool:hubspot_*', 'tool:jobtread_list');          // false\n\n// Verify a signed action\nconst actionResult = verifyAction(signedAction, signerPublicKey);\n\n// Raw ML-DSA-65 signature verification\nconst valid = verify(publicKey, data, signature);\n\n// Parse an agent's DID\nconst parsed = parseDID('did:aethyr:agent:abc123');\n// { namespace: 'agent', identifier: 'abc123' }\n```\n\n## How It Works\n\n```\n┌──────────┐         ┌──────────┐         ┌──────────────┐\n│  Agent   │──reg──▶ │  Aethyr  │         │ Your Service │\n│          │◀─cred── │ (issuer) │         │  (verifier)  │\n└──────────┘         └──────────┘         └──────────────┘\n      │                                          ▲\n      │          presents credential             │\n      └──────────────────────────────────────────┘\n                                                  │\n                                          ssi-verify checks:\n                                          ✓ authentic?\n                                          ✓ still valid?\n                                          ✓ authorized?\n```\n\n1. **Agent registers** with Aethyr and receives a signed credential\n2. **Agent presents** the credential when it interacts with your service\n3. **Your service verifies** using `ssi-verify` — no network call, fully offline\n4. **Your service decides** what the agent can do based on its capabilities\n\nEvery credential traces back to a responsible party. If the agent causes harm, you know who deployed it, what it was authorized to do, and who to contact. That's what makes autonomous agents legal, trustworthy, and insurable.\n\n## Why Post-Quantum\n\nEvery other agent identity solution uses classical cryptography (Ed25519, RSA, secp256k1). Aethyr uses **ML-DSA-65** (NIST FIPS 204) — a post-quantum signature algorithm. Agent credentials issued today may still be in circulation when quantum computers can break classical signatures. We're not waiting for that to become a problem.\n\n## Cryptography\n\n| Operation | Algorithm | Standard |\n|-----------|-----------|----------|\n| Digital signatures | ML-DSA-65 (Dilithium) | NIST FIPS 204 |\n\nImplemented via [`@noble/post-quantum`](https://github.com/paulmillr/noble-post-quantum) — zero-dependency, audited, pure TypeScript. Runs in any JavaScript runtime (Node.js, Deno, Bun, browsers).\n\n## API\n\n### `verifyCredential(credential, issuerPublicKey)`\n\nVerify a credential's ML-DSA-65 signature and expiry. Does not check revocation.\n\n### `verifyAction(signedAction, signingPublicKey)`\n\nVerify a signed action against a public key.\n\n### `verify(publicKey, data, signature)`\n\nRaw ML-DSA-65 signature verification.\n\n### `matchCapability(granted, requested)` / `matchCapabilities(granted[], requested)`\n\nCapability matching for authorization. Supports exact matches, trailing wildcards (`tool:hubspot_*`), and universal wildcards (`*`).\n\n### `parseDID(did)`\n\nParse a `did:aethyr:<namespace>:<identifier>` DID string.\n\n## Standards Alignment\n\n- **W3C Verifiable Credentials 2.0** — credential format\n- **W3C Decentralized Identifiers (DIDs)** — agent identity\n- **NIST FIPS 204 (ML-DSA)** — post-quantum signatures\n\n## Security\n\nSee [SECURITY.md](SECURITY.md) for vulnerability reporting.\n\n## License\n\n[MIT](LICENSE)\n\n## Related\n\n- [Aethyr Research](https://aethyrresearch.com) — Trust infrastructure for AI agents\n- [Agent Registry](https://registry.aethyr.cloud) — Register your agent and get a credential\n","readmeFilename":"README.md"}