{"_id":"@afterauth/core","_rev":"4-9d776f25f9256acd29e88dd9e05fb71b","name":"@afterauth/core","dist-tags":{"latest":"0.0.4"},"versions":{"0.0.1":{"name":"@afterauth/core","version":"0.0.1","license":"MIT","_id":"@afterauth/core@0.0.1","maintainers":[{"name":"afterauth","email":"afterauth@gmail.com"}],"dist":{"shasum":"54b214d081e8aff4696f2d5fbcb92d1af330f784","tarball":"https://registry.npmjs.org/@afterauth/core/-/core-0.0.1.tgz","fileCount":30,"integrity":"sha512-243/mMKIanLvWkLIY6fT8l7JUMFc7LuyR+ZAFp7tBQ2CYLoZkdffHENgLxMzCjHpk1KI7oASpnndJ7WWoufEMg==","signatures":[{"sig":"MEUCIQDK/8K1qWZwMyH9tWZWCNWEJpknAsgncBWto126DeGBGAIgfrLr5cBdcIiN9lE3QhxEC9zeD4qRMUcZOv/QzvLLT8U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35821},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"2f63c437231982111f5fae4fada19c8c1a17e976","scripts":{"lint":"tsc -p tsconfig.json --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","prepare":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"afterauth","email":"afterauth@gmail.com"},"_npmVersion":"11.10.0","description":"Deterministic trust decision engine for progressive trust after auth","directories":{},"_nodeVersion":"25.6.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/core_0.0.1_1777423737647_0.411811735861199","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@afterauth/core","version":"0.0.2","license":"MIT","_id":"@afterauth/core@0.0.2","maintainers":[{"name":"afterauth","email":"afterauth@gmail.com"}],"dist":{"shasum":"93d10f8eca2bb65708c54327b594f655b31269f0","tarball":"https://registry.npmjs.org/@afterauth/core/-/core-0.0.2.tgz","fileCount":31,"integrity":"sha512-O6h2xlOUOo7bVXKPmqVHo6b8Ihk2G/lWVq03vqY0Mcvs9J5x79Ml2985dtPtW7+DyZa008seId+8PlK7xb1ehg==","signatures":[{"sig":"MEUCIBDraExVB5pbQyAEVnOig/vcL0vN4nCIsrC3kh+Oy+u/AiEAjDAb9aGxoJmzr4I6UfYeOsMuzV62JphTQJtpRr5eLB4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":39858},"main":"./dist/index.js","type":"module","_from":"file:afterauth-core-0.0.2.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"tsc -p tsconfig.json --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"afterauth","email":"afterauth@gmail.com"},"_resolved":"/private/var/folders/b4/jxqd49m15fl4n9fqg0j43qzc0000gn/T/e6d261ea3e2009e6249635363477614e/afterauth-core-0.0.2.tgz","_integrity":"sha512-O6h2xlOUOo7bVXKPmqVHo6b8Ihk2G/lWVq03vqY0Mcvs9J5x79Ml2985dtPtW7+DyZa008seId+8PlK7xb1ehg==","_npmVersion":"11.10.0","description":"Deterministic trust decision engine for progressive trust after auth","directories":{},"_nodeVersion":"25.6.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/core_0.0.2_1777526385858_0.09806337576444957","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"name":"@afterauth/core","version":"0.0.3","license":"MIT","_id":"@afterauth/core@0.0.3","maintainers":[{"name":"afterauth","email":"afterauth@gmail.com"}],"dist":{"shasum":"eecc7d94010bea8af0b255e62b4dda76cd21099a","tarball":"https://registry.npmjs.org/@afterauth/core/-/core-0.0.3.tgz","fileCount":31,"integrity":"sha512-qRcR9mA0L9KmSF7rnq6BgX1YwmUXy4yJl7tzLfnnHd7jvgQJnUcaCmKTRX7S6iu/RopR0p/Z4PaMRwgWW2jdVw==","signatures":[{"sig":"MEYCIQD615NBHQktxJFvekm3TC5NC8o+NFzvo/19PaEkPpCPigIhAK1HjbnszgYAIrpSDnNQnw+YN2+63AA2i3aLc6ctdoOR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":42725},"main":"./dist/index.js","type":"module","_from":"file:afterauth-core-0.0.3.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"tsc -p tsconfig.json --noEmit","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"afterauth","email":"afterauth@gmail.com"},"_resolved":"/private/var/folders/b4/jxqd49m15fl4n9fqg0j43qzc0000gn/T/2f33d7493cb362c6783f18db69048e6f/afterauth-core-0.0.3.tgz","_integrity":"sha512-qRcR9mA0L9KmSF7rnq6BgX1YwmUXy4yJl7tzLfnnHd7jvgQJnUcaCmKTRX7S6iu/RopR0p/Z4PaMRwgWW2jdVw==","_npmVersion":"11.10.0","description":"Deterministic trust decision engine for progressive trust after auth","directories":{},"_nodeVersion":"25.6.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.8","typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/core_0.0.3_1777742987277_0.6545070050745359","host":"s3://npm-registry-packages-npm-production"}},"0.0.4":{"name":"@afterauth/core","version":"0.0.4","type":"module","description":"Deterministic trust decision engine for progressive trust after auth","license":"MIT","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.7.2","vitest":"^2.1.8"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run","lint":"tsc -p tsconfig.json --noEmit"},"_id":"@afterauth/core@0.0.4","_integrity":"sha512-J9Vdg0vnNbLD8Nt0Ei3SwAgk9i4PoYV4uaBgJDP8aHPNI8q7zuK8U7T2QHrQR8FiX3h7Jox4X4FGrGX5LhS2Rw==","_resolved":"/private/var/folders/b4/jxqd49m15fl4n9fqg0j43qzc0000gn/T/47cd748bb224959cfa86e7bce9de1507/afterauth-core-0.0.4.tgz","_from":"file:afterauth-core-0.0.4.tgz","_nodeVersion":"25.6.0","_npmVersion":"11.10.0","dist":{"integrity":"sha512-J9Vdg0vnNbLD8Nt0Ei3SwAgk9i4PoYV4uaBgJDP8aHPNI8q7zuK8U7T2QHrQR8FiX3h7Jox4X4FGrGX5LhS2Rw==","shasum":"22adf44abf4e5c825b1030f18e82e338173aad55","tarball":"https://registry.npmjs.org/@afterauth/core/-/core-0.0.4.tgz","fileCount":31,"unpackedSize":43033,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDk906udNVuxs6b7G68FxvuzYChPAH6qMZHXdDa/n3snQIhAMhf8pPnonCQl2HdJ5PwL8UwETiGH6b7TAPvfwKpfcbn"}]},"_npmUser":{"name":"afterauth","email":"afterauth@gmail.com"},"directories":{},"maintainers":[{"name":"afterauth","email":"afterauth@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/core_0.0.4_1778372183119_0.5080989992487357"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-29T00:48:57.549Z","modified":"2026-05-10T00:16:23.368Z","0.0.1":"2026-04-29T00:48:57.814Z","0.0.2":"2026-04-30T05:19:46.010Z","0.0.3":"2026-05-02T17:29:47.492Z","0.0.4":"2026-05-10T00:16:23.274Z"},"license":"MIT","description":"Deterministic trust decision engine for progressive trust after auth","maintainers":[{"name":"afterauth","email":"afterauth@gmail.com"}],"readme":"# @afterauth/core\n\nDeterministic trust decision engine for progressive trust after auth.\n\nAfterAuth evaluates user trust signals against a policy ruleset and returns a decision — `allow`, `allow_limited`, `delay`, `require_verification`, or `deny` — along with a tamper-proof evidence hash for auditability.\n\n## Installation\n\n```bash\nnpm install @afterauth/core\n```\n\n## Usage\n\n```ts\nimport { evaluate } from \"@afterauth/core\";\n\nconst decision = evaluate({\n  request: {\n    requestId: \"req_001\",\n    requestType: \"credit_unlock\",\n    userId: \"user_123\",\n    benefitType: \"trial_credits\",\n    requestedAmount: 500,\n    signals: {\n      email: \"founder@example.com\",\n      emailVerified: true,\n      hasPaymentMethod: false,\n      accountAgeDays: 3,\n    },\n    metadata: { source: \"onboarding\" },\n  },\n  priorEvents: [],\n  policyRuleSet: null, // uses DEFAULT_POLICY_RULE_SET\n  policyId: null,\n  policyName: null,\n});\n\nconsole.log(decision.outcome);       // \"allow_limited\"\nconsole.log(decision.approvedAmount); // number\nconsole.log(decision.reasonCodes);    // [\"work_email_limited_unlock\"]\nconsole.log(decision.evidenceHash);   // sha256 of frozen context\n```\n\n## Outcomes\n\n| Outcome | Meaning |\n|---|---|\n| `allow` | Full access granted |\n| `allow_limited` | Partial access granted up to `approvedAmount` |\n| `delay` | Hold request for later processing |\n| `require_verification` | Additional verification needed before proceeding |\n| `deny` | Access denied |\n\n## Policy Rules\n\nPolicies are evaluated first-match-wins against a set of typed conditions:\n\n```ts\nimport { evaluateRules } from \"@afterauth/core\";\nimport type { PolicyRuleSet } from \"@afterauth/core\";\n\nconst policy: PolicyRuleSet = {\n  version: 1,\n  defaultOutcome: \"allow_limited\",\n  defaultApprovedRatio: 0.2,\n  rules: [\n    {\n      id: \"verified_payment\",\n      conditions: { hasPaymentMethod: true },\n      outcome: \"allow\",\n      approvedRatio: 1,\n      reasonCode: \"payment_method_present\",\n    },\n    {\n      id: \"work_email\",\n      conditions: { emailDomainType: [\"work\"] },\n      outcome: \"allow_limited\",\n      approvedRatio: 1,\n      maxApprovedAmount: 500,\n      reasonCode: \"work_email_limited_unlock\",\n    },\n  ],\n};\n```\n\n## Supported Signals\n\n| Signal | Type | Description |\n|---|---|---|\n| `email` | `string` | User email address |\n| `emailVerified` | `boolean` | Email verification status |\n| `hasPaymentMethod` | `boolean` | Payment method on file |\n| `accountAgeDays` | `number` | Days since account creation |\n| `githubAccountAgeDays` | `number` | Days since GitHub account creation |\n| `activationCount` | `number` | Number of activation events |\n| `multiAccountDetected` | `boolean` | Abuse signal: multiple accounts |\n| `velocityExceeded` | `boolean` | Abuse signal: request velocity |\n| `disposableEmail` | `boolean` | Disposable email domain detected |\n\n## Auditability\n\nEvery decision includes a `frozenContext` snapshot and a deterministic `evidenceHash` (SHA-256) so decisions can be replayed and verified later:\n\n```ts\nconsole.log(decision.frozenContext); // full signal + policy snapshot at decision time\nconsole.log(decision.evidenceHash);  // sha256 hash of frozenContext\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}