{"_id":"@agent-custody/receipts","_rev":"23-b15fd8b3bf7618467c892932d768ce9c","name":"@agent-custody/receipts","dist-tags":{"latest":"0.5.9"},"versions":{"0.1.0":{"name":"@agent-custody/receipts","version":"0.1.0","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"85145f794e68c4c645884c8848ddffcb2f202c00","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.0.tgz","fileCount":40,"integrity":"sha512-vBuiFwAxdhdHQBnwK9edMAVxRRmrwgTEJS8twu3oZoFMGD5g7jnx+lPwxKbBkcFzJ+SDbgyDaJGsvjxLfNCWCg==","signatures":[{"sig":"MEUCIQCSvtLkUkXkJcdn8SLoiS3/xe4Hx148rRTTUMh7vDqrRQIgbK2CFDcY6W0RdHd3WzzUXiYCfcL5ACr8PgPamwMbaX0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":130057},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.0.tgz","_integrity":"sha512-vBuiFwAxdhdHQBnwK9edMAVxRRmrwgTEJS8twu3oZoFMGD5g7jnx+lPwxKbBkcFzJ+SDbgyDaJGsvjxLfNCWCg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.0_1788670857026_0.6961647903989769","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-custody/receipts","version":"0.1.1","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.1","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"14ae92150a3465607a11e554c6e48f3662255720","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.1.tgz","fileCount":42,"integrity":"sha512-HgM2kgNwL91OzdgfX7TWQoyJXHe0Tx2ibaq4AKZpCg6cV7mHnH2+ajgdK4yV8xVYl30QPiUEwDaqvJPnxvLxeg==","signatures":[{"sig":"MEYCIQCw0UrvaMQNJ71XKTlPB+DNrnb/8drDvEOJRsXcsBJegQIhAN16HuqcI1Au3GuCSBAdJ+M336Oq+xW4na5n9vVcRuce","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":155514},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.1.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.1.tgz","_integrity":"sha512-HgM2kgNwL91OzdgfX7TWQoyJXHe0Tx2ibaq4AKZpCg6cV7mHnH2+ajgdK4yV8xVYl30QPiUEwDaqvJPnxvLxeg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.1_1788678328397_0.049249718345703686","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agent-custody/receipts","version":"0.1.2","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.2","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"7ecb3dc60c41cdec9fadce6a191e25ab1e1bc8bf","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.2.tgz","fileCount":44,"integrity":"sha512-X0/11O845vp0abz7AoxKk8min3soVTTHpEFm60qIXSg3M7U+mcFJlhtQ9wcHLNU+QgqNPJTSSa08RQYm4Qrpjg==","signatures":[{"sig":"MEUCIDjbrmkyeI5JD5sorZYrRI/zzTfba57G+tcLE3LNHD9JAiEAnUF/ReDKTvIXFaD+44pj0yV50K3tHj+WpRiM3pNGpck=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":166283},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.2.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.2.tgz","_integrity":"sha512-X0/11O845vp0abz7AoxKk8min3soVTTHpEFm60qIXSg3M7U+mcFJlhtQ9wcHLNU+QgqNPJTSSa08RQYm4Qrpjg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.2_1788757286807_0.5883162531297275","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agent-custody/receipts","version":"0.1.3","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.3","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"b4e40181107262fe550406460902529b0cd3973a","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.3.tgz","fileCount":48,"integrity":"sha512-KvHKk3xbQaAGKL/2DWdJ8J44AOrO3RA0ntvuaQucS2Z/FgNHYt2WQvJ24CgMBbPW2ipoAG9CbyssuRxKkAqGlw==","signatures":[{"sig":"MEUCIQCfoC72JF2BtXa9BjrL3aTnJIr3Vz/BlnPUMhnVJ4+6nQIgE8KIsmPkXfeBPV3Y7jbrGur6uIdz03D5tXW+dfkfWjc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":310796},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.3.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.3.tgz","_integrity":"sha512-KvHKk3xbQaAGKL/2DWdJ8J44AOrO3RA0ntvuaQucS2Z/FgNHYt2WQvJ24CgMBbPW2ipoAG9CbyssuRxKkAqGlw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.3_1788766908997_0.7455471183964217","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@agent-custody/receipts","version":"0.1.4","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.4","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"b99138e28e1a355c15e7c8951dd109d369ad3860","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.4.tgz","fileCount":48,"integrity":"sha512-BsgTuT3E/bkdmA4krj8WRgPa0bFL/OQI1nmvGRTzU3PdB0Pf0LvOyMtcJo1HF7S904BU9MYr3tvIlQSygai8wg==","signatures":[{"sig":"MEQCIDgmCUfp9FGhGtjQ97lc6u7GkWrN8yup2sGcNra0037sAiBqPwtn499pGchvS+JGXsPFeNP7Ph/spXjVps/ikCvKnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":310796},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.4.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.4.tgz","_integrity":"sha512-BsgTuT3E/bkdmA4krj8WRgPa0bFL/OQI1nmvGRTzU3PdB0Pf0LvOyMtcJo1HF7S904BU9MYr3tvIlQSygai8wg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.4_1788768721106_0.5381773519466568","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@agent-custody/receipts","version":"0.1.5","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.5","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"256d9c0c1855f725252ef407a079b58ac4dd12dc","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.5.tgz","fileCount":50,"integrity":"sha512-6oYa9PZdaqSJv9Km5uEC/KwycGbgEKDQdCUxhnTJ0x5w0hMHzGLXYFFGNIJg7jWEd94UpJcoFnYJp35I2Sfe8g==","signatures":[{"sig":"MEUCIHxT834ahv0ZNKNMmT7CnLOKU18ap8h2UvDIiT6YY3PTAiEA3nIpQTANzAXaAtNsMP9D3JP4LNHPBqb6Sqnw5H4ZawA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":375540},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.5.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.5.tgz","_integrity":"sha512-6oYa9PZdaqSJv9Km5uEC/KwycGbgEKDQdCUxhnTJ0x5w0hMHzGLXYFFGNIJg7jWEd94UpJcoFnYJp35I2Sfe8g==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.5_1788771550453_0.22122655509693923","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@agent-custody/receipts","version":"0.1.6","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.6","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"a12fd5ee737a964360d29442d3dc9e7b150cc4ab","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.6.tgz","fileCount":50,"integrity":"sha512-hSi7ydnEDn3+WaRih9MSW71VNz9j84GVHswgo9LGANC5C5tSuzjkaRgtYG3gXUEz1hm5hnlpBqsxeFK5C3cb9Q==","signatures":[{"sig":"MEYCIQDXb4le6O0Ki7Z+ci1n6K3km0zp51x1J5qNbYXNHmz/UgIhAPl+wAv49Ino6qsgtqBzDpHCI8+neXifZyVD+Hn6WGTa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":379730},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.6.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.6.tgz","_integrity":"sha512-hSi7ydnEDn3+WaRih9MSW71VNz9j84GVHswgo9LGANC5C5tSuzjkaRgtYG3gXUEz1hm5hnlpBqsxeFK5C3cb9Q==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.6_1788776221406_0.5822883634550939","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@agent-custody/receipts","version":"0.1.7","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.7","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"107bc7507887ee63c5841021bbc4fa7865e98c1f","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.7.tgz","fileCount":52,"integrity":"sha512-o0B2bHCjgB9PJbo7lclSo4LPzf3DIoFgeuWQUDOAGLHvZbjpMLdipo6qxAfUigLDEe/ss3pQw6f2CeCcwdBg8g==","signatures":[{"sig":"MEUCIFrhZLlrbjEztW3zXcZiLkTNxA6d3WbD8rvs+niB6PcyAiEAhm5KleRtt0BCZ2pD7V+GD43CTuVsb4VR9LMh9pa/gr0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":390717},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.7.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.7.tgz","_integrity":"sha512-o0B2bHCjgB9PJbo7lclSo4LPzf3DIoFgeuWQUDOAGLHvZbjpMLdipo6qxAfUigLDEe/ss3pQw6f2CeCcwdBg8g==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.7_1788786815706_0.22117027921122334","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@agent-custody/receipts","version":"0.1.8","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.8","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"438759055234398ac1dc4e1a3587564023257066","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.8.tgz","fileCount":52,"integrity":"sha512-vyGgEjUru8ztlXWJVWMkyFcO9mOZ+CL+y2S+bC3nFX3ZVeTi8gAk7DAy9qo5Ss1i0wd/Jg40NXXxseShrbuP9Q==","signatures":[{"sig":"MEQCIFsx31dGGAnLhyKD3XkJ9umGzh94bqO0JpdPskuUjX7jAiAyfe1Fe/TtEkeRqjI/g7OFUXDQR/fxizIrmr4c8gf/XA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":430710},"type":"module","_from":"file:packages/receipts/agent-custody-receipts-0.1.8.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.8.tgz","_integrity":"sha512-vyGgEjUru8ztlXWJVWMkyFcO9mOZ+CL+y2S+bC3nFX3ZVeTi8gAk7DAy9qo5Ss1i0wd/Jg40NXXxseShrbuP9Q==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.8_1788790307148_0.8006979061305022","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@agent-custody/receipts","version":"0.1.9","license":"Apache-2.0","_id":"@agent-custody/receipts@0.1.9","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"f8348ce4d91c99e4792ec266b7d04ce8f2377926","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.1.9.tgz","fileCount":52,"integrity":"sha512-UdIcJO/sRCsYrQT1D5YwRdsGlc0nTlnQPOfngRyXOscSdOBYeaxQoQOQpajQlHzHhPv/WMeNmAeHUbwiRHw2zA==","signatures":[{"sig":"MEYCIQD1YSTjRkN0XnZ9DxShfXhbBhIxGCfCfkmdgGluUC+aZgIhAJCWGp5jK3xN1OwPhshSTk+z0OPDNkFGePJd1U05p2GM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":430710},"type":"module","_from":"file:agent-custody-receipts-0.1.9.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.1.9.tgz","_integrity":"sha512-UdIcJO/sRCsYrQT1D5YwRdsGlc0nTlnQPOfngRyXOscSdOBYeaxQoQOQpajQlHzHhPv/WMeNmAeHUbwiRHw2zA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.1.9_1788801195806_0.9899124024400994","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agent-custody/receipts","version":"0.2.0","license":"Apache-2.0","_id":"@agent-custody/receipts@0.2.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"c5bbc27378e281f870ed873f4c87c31b1f531180","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.2.0.tgz","fileCount":52,"integrity":"sha512-MJAhA9Ta+G7BAuZ277sO3wwTXvY7XcZuzW4U9jw0jbMR8s4Q3Hfbc9WSKkRt9bYfTzZvWOJEZkOSmFCgPZ58zA==","signatures":[{"sig":"MEUCIC8NJXErOZyJrR9yfBs1xDQfH45QntFw8mbnMG0wZqw0AiEApF4uvqwF0ipyRpjhQ4xtyOXpSUnET4xfUAoRq6QriR0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":430710},"type":"module","_from":"file:agent-custody-receipts-0.2.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.2.0.tgz","_integrity":"sha512-MJAhA9Ta+G7BAuZ277sO3wwTXvY7XcZuzW4U9jw0jbMR8s4Q3Hfbc9WSKkRt9bYfTzZvWOJEZkOSmFCgPZ58zA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.2.0_1788803687079_0.4737211099341412","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agent-custody/receipts","version":"0.3.0","license":"Apache-2.0","_id":"@agent-custody/receipts@0.3.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"78412503e7be626783fad3f3dc5cebf9aa57786a","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.3.0.tgz","fileCount":56,"integrity":"sha512-wbO7v0Dem6Oe7eMUBDde5mtDMkivCsSkP5SHlPtmNQGGw8PFgg6Pylk8MEwkyjAb1Onnvj1/n17pTsMtD1HlVw==","signatures":[{"sig":"MEQCIFc2l6S24W9UTwointnJcLcH0kv4B2r3Mi91z6rr1F+aAiBJuGyZniHUcfaaSQtdsDi2rS5joAG3nmQqpeiqdn9ZxQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":572545},"type":"module","_from":"file:agent-custody-receipts-0.3.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.3.0.tgz","_integrity":"sha512-wbO7v0Dem6Oe7eMUBDde5mtDMkivCsSkP5SHlPtmNQGGw8PFgg6Pylk8MEwkyjAb1Onnvj1/n17pTsMtD1HlVw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.3.0_1788838510534_0.7848754062219778","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@agent-custody/receipts","version":"0.4.0","license":"Apache-2.0","_id":"@agent-custody/receipts@0.4.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"5daaa39c4fdd415dd836d711dae2b96d8bd98b45","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.4.0.tgz","fileCount":56,"integrity":"sha512-TY1AtVLo288R102st11xNgoe4OjfGyua3Y1YUFEONAiEqfGy35q5H6iww+NvZ+C9LYivNSari4a2uJ3AA6KUiQ==","signatures":[{"sig":"MEYCIQDK4LJcRnJlE+ASgV/Fk502xkgyZin8hMQkmTVZ1JIdGwIhAK7fsRZuoaIVDffeaerUBg5Aks7mFCMJp2M/et89BgQI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":580092},"type":"module","_from":"file:agent-custody-receipts-0.4.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.4.0.tgz","_integrity":"sha512-TY1AtVLo288R102st11xNgoe4OjfGyua3Y1YUFEONAiEqfGy35q5H6iww+NvZ+C9LYivNSari4a2uJ3AA6KUiQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9"},"peerDependencies":{"ai":">=5.0.0","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.4.0_1788849688795_0.5390300998785027","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agent-custody/receipts","version":"0.5.0","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"fc0eeeef2c2af6e66923fdb9029da82568433a57","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.0.tgz","fileCount":62,"integrity":"sha512-n4I0gNW2PsgXLs7FUwqEHIu61SGYCRINpjX7WQcejnVndYYCC+OhfJs/mLnx7644zM0gHP696/rUBz22x+IC0Q==","signatures":[{"sig":"MEQCIELO6+xu655hK2Kxhm7BLUolYDCwUpz7A32+Hzfy8DJUAiANhRD35r51O+uj+z1xwXgA1KTYyE/3UCPFtA15o8THKQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":639524},"type":"module","_from":"file:agent-custody-receipts-0.5.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.0.tgz","_integrity":"sha512-n4I0gNW2PsgXLs7FUwqEHIu61SGYCRINpjX7WQcejnVndYYCC+OhfJs/mLnx7644zM0gHP696/rUBz22x+IC0Q==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.0_1788851320016_0.2795270563073209","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@agent-custody/receipts","version":"0.5.1","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.1","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"ab692b975f1c04c215928ab49ad38cd88a3f580b","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.1.tgz","fileCount":64,"integrity":"sha512-PQ8QlT8L2Hc6P5OSBXBmjPHd/TR74MzaUivL9RyUPMH6e9tHC7o9gU5Il41nNIObzWVhJj1PsJrLhkFZTMoGfw==","signatures":[{"sig":"MEUCIGQGGky/IS5M3KYbdsN6qQLhaN6yp633w9ta5PyIkKArAiEAhMYUM1wZc8kXr+iemaPrTPoopx2Zolwyw5iJc3dDFn4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":660462},"type":"module","_from":"file:agent-custody-receipts-0.5.1.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.1.tgz","_integrity":"sha512-PQ8QlT8L2Hc6P5OSBXBmjPHd/TR74MzaUivL9RyUPMH6e9tHC7o9gU5Il41nNIObzWVhJj1PsJrLhkFZTMoGfw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.1_1788859458663_0.9175049684948258","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@agent-custody/receipts","version":"0.5.2","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.2","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"72eee19e59d09619de9e53d975ba28de70425ab6","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.2.tgz","fileCount":64,"integrity":"sha512-hUPuuzdXT3W8YiCrMFr4GnVwyWP55YIr2UUkd/ZMYbswTL4ELTNaFKjC21Dwk4IUAURRKYLjWCdNK4ryW08yOw==","signatures":[{"sig":"MEUCIDlSRMFYZ4nu0crOMxnH/6AbG0G8aA0/TdP0wUxtVCV3AiEA01TnuOr2RDqxZ+eRmFIosOKSeORuSwGPQsfM8up7G5E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":661411},"type":"module","_from":"file:agent-custody-receipts-0.5.2.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.2.tgz","_integrity":"sha512-hUPuuzdXT3W8YiCrMFr4GnVwyWP55YIr2UUkd/ZMYbswTL4ELTNaFKjC21Dwk4IUAURRKYLjWCdNK4ryW08yOw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.2_1788877678550_0.8047577635263994","host":"s3://npm-registry-packages-npm-production"}},"0.5.3":{"name":"@agent-custody/receipts","version":"0.5.3","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.3","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"405c185b6b3aeeb5bf14aecedde881031cb1c3ad","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.3.tgz","fileCount":64,"integrity":"sha512-O2UZAWEKnLWztbkzjGNZPcJeC2v1bhg8b3UMqROvLoCiCbZE6q5OWhgZyLfFdhU38b3zh14kcAHBtownMuJbQw==","signatures":[{"sig":"MEUCICo9lXV5X0DeqMWC2eBE0LW2UzHCgCPR26m+8dWMpMuGAiEAh226BUyCsZ1CAtRZOn6N3lP3P0XuN6O5Gl3YMTq3Ksw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":663075},"type":"module","_from":"file:agent-custody-receipts-0.5.3.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.3.tgz","_integrity":"sha512-O2UZAWEKnLWztbkzjGNZPcJeC2v1bhg8b3UMqROvLoCiCbZE6q5OWhgZyLfFdhU38b3zh14kcAHBtownMuJbQw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.3_1788878053868_0.08420161078462729","host":"s3://npm-registry-packages-npm-production"}},"0.5.4":{"name":"@agent-custody/receipts","version":"0.5.4","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.4","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"10b9a879e611ab7db4225d60c1e3685760303094","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.4.tgz","fileCount":66,"integrity":"sha512-vclVhRUaf8FKbmdZ9rvGGWekPI6ZR30lkI0IGPiWwEsUsfXwSCrJOnXgeb1QQvdgz0QyGSY1+qdWqIHLLZaD0Q==","signatures":[{"sig":"MEYCIQC08EPXvt1s2aOVpCTiGvQtaGFn+bq6SvBZ3JgW31SrawIhAJ279dvC/C3jUoWThYP4wTcTXTmvo3mfFoXrzuiIDqFC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":680216},"type":"module","_from":"file:agent-custody-receipts-0.5.4.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.4.tgz","_integrity":"sha512-vclVhRUaf8FKbmdZ9rvGGWekPI6ZR30lkI0IGPiWwEsUsfXwSCrJOnXgeb1QQvdgz0QyGSY1+qdWqIHLLZaD0Q==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.4_1788885187827_0.9031627656384331","host":"s3://npm-registry-packages-npm-production"}},"0.5.5":{"name":"@agent-custody/receipts","version":"0.5.5","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.5","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"4e46ad69f1b0a784964cbbdf564575456673dc01","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.5.tgz","fileCount":68,"integrity":"sha512-Hb+3suwpc32O87lp4H62FJ6ji+MtPUcIwbVXaBBF3iP8KduWRLKSYePiw5UtwfzT1OzHQF1ltBxsk4fKrFhKvQ==","signatures":[{"sig":"MEYCIQD5Xj2tu77lupuQ+lgZcS4OdB9wS3KqI0Dz8+DyetczAwIhAIW9j6MxURr7B7uSE1560P4PAhw3iiEgOVRqDnW5KB1F","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":695478},"type":"module","_from":"file:agent-custody-receipts-0.5.5.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.5.tgz","_integrity":"sha512-Hb+3suwpc32O87lp4H62FJ6ji+MtPUcIwbVXaBBF3iP8KduWRLKSYePiw5UtwfzT1OzHQF1ltBxsk4fKrFhKvQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.5_1788885705907_0.17037693220706873","host":"s3://npm-registry-packages-npm-production"}},"0.5.6":{"name":"@agent-custody/receipts","version":"0.5.6","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.6","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"1b480b1aed095d16e985846727254441dc731e19","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.6.tgz","fileCount":71,"integrity":"sha512-7bznZ99vl+xpMb9t/lLImymsiM7OFqNILuhxL4Qodp3+3lIGgB9OngHJ6ahz0JpXiA3Fi8wUZGSailJq30/yjg==","signatures":[{"sig":"MEUCIQCms6iVSjAfvHOgNw/ZUXq/T8VGk/20sl3bZMmdc1gIVwIgELuDASXLkxNke+HIb9KVqiN9Q9oqtxp7Bg2IEXKpAyU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":711509},"type":"module","_from":"file:agent-custody-receipts-0.5.6.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.6.tgz","_integrity":"sha512-7bznZ99vl+xpMb9t/lLImymsiM7OFqNILuhxL4Qodp3+3lIGgB9OngHJ6ahz0JpXiA3Fi8wUZGSailJq30/yjg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.6_1788892660523_0.2898902623871067","host":"s3://npm-registry-packages-npm-production"}},"0.5.7":{"name":"@agent-custody/receipts","version":"0.5.7","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.7","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"a33ebdc6e3c276b79c61552ad459e1a497ee97f6","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.7.tgz","fileCount":73,"integrity":"sha512-HgnLrSBi6o9+R/2DtnCDE0MK6K1V0IrMmHa/koFpka9SB8YTZOxvYopGliniXqisChAWOqNWeuQVoF5SW726tQ==","signatures":[{"sig":"MEUCIFNDt5Sdm/KmCboWr4a7ug9RwqKFxDnbSdjyioQFXeOXAiEAutUQk/XLytc2V+Vpf+1tL/qcfcN09viFA6FLGomZA+A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":725213},"type":"module","_from":"file:agent-custody-receipts-0.5.7.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.7.tgz","_integrity":"sha512-HgnLrSBi6o9+R/2DtnCDE0MK6K1V0IrMmHa/koFpka9SB8YTZOxvYopGliniXqisChAWOqNWeuQVoF5SW726tQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.7_1788916151007_0.04036250246617312","host":"s3://npm-registry-packages-npm-production"}},"0.5.8":{"name":"@agent-custody/receipts","version":"0.5.8","license":"Apache-2.0","_id":"@agent-custody/receipts@0.5.8","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody":"dist/cli.js"},"dist":{"shasum":"c0fd08ba9e79c907ebd216d0079b66800e453885","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.8.tgz","fileCount":74,"integrity":"sha512-mNcMGj+M3Iq2gyW3y+E+S2EY5eoeo0Uk0wUKXp5DkbIoMzB1+IirNT5op602DQns8WE9y2poDH1++HbUAThLxA==","signatures":[{"sig":"MEUCIQDCAvZBepe3maYfi9t1jix7qE2lkCrFGT/9lvbuBWKYNAIgb+pK2FBOhW3kvLhXYwvpfyll+h5oFS3QIPIrrlGopzU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":746577},"type":"module","_from":"file:agent-custody-receipts-0.5.8.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"}},"scripts":{"demo":"tsx scripts/demo.ts","test":"vitest run","build":"tsc -p tsconfig.build.json","vectors":"tsx scripts/vectors.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.8.tgz","_integrity":"sha512-mNcMGj+M3Iq2gyW3y+E+S2EY5eoeo0Uk0wUKXp5DkbIoMzB1+IirNT5op602DQns8WE9y2poDH1++HbUAThLxA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/receipts"},"_npmVersion":"10.9.4","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ai":"^7.0.92","tsx":"^4.23.13","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@openai/agents":"^0.17.0","@langchain/core":"^1.2.9","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"ai":">=5.0.0","pg":">=8","@openai/agents":">=0.1.0","@langchain/core":">=1.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"pg":{"optional":true},"@openai/agents":{"optional":true},"@langchain/core":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.5.8_1788917142343_0.6671486860764235","host":"s3://npm-registry-packages-npm-production"}},"0.5.9":{"name":"@agent-custody/receipts","version":"0.5.9","description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/ch4r10t33r/agent-custody.git","directory":"packages/receipts"},"publishConfig":{"access":"public"},"type":"module","bin":{"agent-custody":"dist/cli.js"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./sdk":{"types":"./dist/sdk/index.d.ts","default":"./dist/sdk/index.js"},"./sdk/claude":{"types":"./dist/sdk/claude.d.ts","default":"./dist/sdk/claude.js"},"./sdk/openai-agents":{"types":"./dist/sdk/openai-agents.d.ts","default":"./dist/sdk/openai-agents.js"},"./sdk/vercel-ai":{"types":"./dist/sdk/vercel-ai.d.ts","default":"./dist/sdk/vercel-ai.js"},"./sdk/langchain":{"types":"./dist/sdk/langchain.d.ts","default":"./dist/sdk/langchain.js"},"./cli":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"}},"scripts":{"build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","test":"vitest run","demo":"tsx scripts/demo.ts","vectors":"tsx scripts/vectors.ts"},"engines":{"node":">=22"},"dependencies":{"@cedar-policy/cedar-wasm":"^4.12.0","@modelcontextprotocol/sdk":"^1.30.0","zod":"^4.5.4"},"devDependencies":{"@langchain/core":"^1.2.9","@openai/agents":"^0.17.0","@types/node":"^26.4.1","ai":"^7.0.92","tsx":"^4.23.13","typescript":"^7.0.2","vitest":"^5.0.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"@langchain/core":">=1.0.0","@openai/agents":">=0.1.0","ai":">=5.0.0","pg":">=8"},"peerDependenciesMeta":{"@langchain/core":{"optional":true},"@openai/agents":{"optional":true},"ai":{"optional":true},"pg":{"optional":true}},"_id":"@agent-custody/receipts@0.5.9","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","_integrity":"sha512-bOOtanc+g3YM0/KATpmB76Qtvr3coZ8EucWveH5AJNSumY/gCtn6zL2X8psJTZ4y96hyP6TOmtBLT4R7h1Ujxw==","_resolved":"/Users/partha/agentic-network/agent-custody/packages/receipts/agent-custody-receipts-0.5.9.tgz","_from":"file:agent-custody-receipts-0.5.9.tgz","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-bOOtanc+g3YM0/KATpmB76Qtvr3coZ8EucWveH5AJNSumY/gCtn6zL2X8psJTZ4y96hyP6TOmtBLT4R7h1Ujxw==","shasum":"a97e43eefbab54e971aa07425f544e362b6ca3be","tarball":"https://registry.npmjs.org/@agent-custody/receipts/-/receipts-0.5.9.tgz","fileCount":74,"unpackedSize":748306,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAlxWaP2V24cHAiiQw2Q1k7CEty3n7B9E6tx0btxWFadAiEA+DvfaiBNbnG7XPYFEIqZNXlua4FEUYo5Obco3FNtFTM="}]},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"directories":{},"maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/receipts_0.5.9_1789026665858_0.8053566841514228"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-06T05:00:56.813Z","modified":"2026-09-10T07:51:06.262Z","0.1.0":"2026-09-06T05:00:57.151Z","0.1.1":"2026-09-06T07:05:28.532Z","0.1.2":"2026-09-07T05:01:26.937Z","0.1.3":"2026-09-07T07:41:49.142Z","0.1.4":"2026-09-07T08:12:01.249Z","0.1.5":"2026-09-07T08:59:10.591Z","0.1.6":"2026-09-07T10:17:01.559Z","0.1.7":"2026-09-07T13:13:35.858Z","0.1.8":"2026-09-07T14:11:47.357Z","0.1.9":"2026-09-07T17:13:15.947Z","0.2.0":"2026-09-07T17:54:47.236Z","0.3.0":"2026-09-08T03:35:10.736Z","0.4.0":"2026-09-08T06:41:28.937Z","0.5.0":"2026-09-08T07:08:40.181Z","0.5.1":"2026-09-08T09:24:18.797Z","0.5.2":"2026-09-08T14:27:58.721Z","0.5.3":"2026-09-08T14:34:14.025Z","0.5.4":"2026-09-08T16:33:08.009Z","0.5.5":"2026-09-08T16:41:46.068Z","0.5.6":"2026-09-08T18:37:40.768Z","0.5.7":"2026-09-09T01:09:11.197Z","0.5.8":"2026-09-09T01:25:42.495Z","0.5.9":"2026-09-10T07:51:06.073Z"},"bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"license":"Apache-2.0","homepage":"https://github.com/ch4r10t33r/agent-custody#readme","repository":{"type":"git","url":"git+https://github.com/ch4r10t33r/agent-custody.git","directory":"packages/receipts"},"description":"Chain of custody for AI agents: signed, independently verifiable receipts for tool calls. MCP gateway + Cedar policy + Merkle transparency log","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"readme":"# agent-custody\n\nChain of custody for AI agents: a signed receipt for every tool call, checkable with public keys alone. What each check proves, and against whom, is [a table below](#what-a-receipt-proves-and-what-it-does-not).\n\nTwo producers, one receipt format, one verifier.\n\n- **The gateway** is an MCP proxy between an agent and the systems it can affect. For every tool call, allowed or denied, it checks a delegation grant signed by the human principal, gathers the facts the policy needs by calling upstream itself, evaluates a Cedar policy that fails closed, forwards the call only on allow, and emits a signed receipt appended to a Merkle transparency log.\n- **The SDK** is an interceptor inside the agent's own process, hooked into the framework's tool-call callbacks: Claude Code, the Claude Agent SDK, the OpenAI Agents SDK, the Vercel AI SDK, LangChain, or any function you wrap. It reaches everything the gateway cannot see and issues the same receipts, labelled as self-reported.\n\nAnyone holding the public keys can verify a receipt offline. The agent is not trusted. The layer around it is, and the receipt says exactly how far that trust extends, starting with who issued it.\n\n- [Tutorials](docs/tutorials.md): eighteen runnable examples, one per aspect of the code, all executed by the test suite\n- [Usage guide](docs/usage.md): gateway setup, wiring into Claude Desktop, Claude Code, or your own agent loop\n- [The interceptor SDK](docs/sdk.md): Claude Code hooks, the Claude Agent SDK, adapters for the OpenAI Agents SDK, Vercel AI SDK and LangChain, and wrapping tool functions in anything else\n- [Writing policies](docs/policies.md): how a tool call becomes a Cedar request, with tested examples\n- [Verifying a receipt](docs/verification.md): what each check means and what a verified receipt does and does not prove\n- [What the evidence satisfies](docs/compliance.md): the receipts, packs, and certificates mapped to SOC 2, ISO 27001, the EU AI Act, and UK GDPR, with what none of them claims\n- [Threat model](docs/threat-model.md): every party who could make a receipt false, the move, what stops it, and whether that is a property of the evidence or of the deployment; and what is not defended\n\n## Getting started\n\n```bash\nnpm install @agent-custody/receipts        # or bun add, pnpm add\n```\n\nPublished on npm as [`@agent-custody/receipts`](https://www.npmjs.com/package/@agent-custody/receipts): compiled JavaScript with type declarations, Node 22 or later, Apache-2.0.\n\nRecord receipts from inside your own agent, no gateway needed. Generate a signing key, point a config at it, wrap the functions the agent calls:\n\n```bash\nnpx agent-custody keygen --dir keys --name app\n```\n\n```json\n{ \"agentId\": \"billing-bot\", \"identity\": { \"keyFile\": \"keys/app.key\" }, \"receiptsDir\": \"receipts\", \"logFile\": \"log.jsonl\" }\n```\n\n```ts\nimport { createSdkIssuer, loadSdkConfig, loadPublicKey, verifyBundle } from \"@agent-custody/receipts\";\n\nconst issuer = createSdkIssuer(loadSdkConfig(\"./sdk.json\"));\nconst refund = issuer.wrap(\"stripe.refund\", async (args: { amount: number }) => stripe.refund(args));\nawait refund({ amount: 5000 });                 // one signed receipt in receipts/, one leaf in log.jsonl\n\nconst bundle = JSON.parse(readFileSync(\"receipts/<id>.json\", \"utf8\"));\nverifyBundle(bundle, { issuerKeys: [loadPublicKey(\"keys/app.pub\")], logFile: \"log.jsonl\" }).ok;   // true\n```\n\nFramework hooks and adapters, including Claude Code, the OpenAI Agents SDK, the Vercel AI SDK and LangChain, are in [docs/sdk.md](docs/sdk.md). To enforce rather than record, put the gateway between the agent and its tools: `npx agent-custody gateway --config gateway.json`, set up in [docs/usage.md](docs/usage.md).\n\n## How it fits together\n\n```mermaid\nflowchart LR\n    P[\"Principal<br/>(human or org, holds a signing key)\"]\n    A[\"Agent host<br/>Claude Desktop, Claude Code,<br/>LangGraph, custom loop\"]\n    S[\"SDK interceptor<br/>inside the agent process:<br/>hooks or wrapped tools\"]\n    G[\"agent-custody gateway<br/>scope check → fact lookups → Cedar policy\"]\n    U[\"Upstream MCP server<br/>Stripe, database, GitHub, ...\"]\n    R[(\"receipt bundles<br/>receipts/*.json\")]\n    L[(\"Merkle log<br/>local file, or a remote log<br/>run by someone else\")]\n    V[\"Verifier<br/>auditor, counterparty, CI job\"]\n    O[\"Observability<br/>OTel, Splunk, LangSmith, Arize\"]\n\n    P -- \"signed delegation grant\" --> G\n    A -- \"MCP tools/call\" --> G\n    G -- \"only on allow\" --> U\n    U -- \"result\" --> G\n    G -- \"result + receipt id, or denial + receipt id\" --> A\n    G -- \"signed receipt (issuer: gateway)\" --> R\n    G -- \"leaf hash\" --> L\n    A -. \"in-process tool calls\" .-> S\n    S -- \"signed receipt (issuer: sdk)\" --> R\n    S -- \"leaf hash\" --> L\n    R --> V\n    L -. \"copy of the log (optional)\" .-> V\n    P -. \"public key\" .-> V\n    G -. \"public key\" .-> V\n    A -. \"traces (unchanged)\" .-> O\n    G -. \"one span per receipt, OTLP\" .-> O\n    S -. \"one span per receipt, OTLP\" .-> O\n```\n\nThree parties hold keys. The **principal** signs a grant saying which agent may use which tools until when. The **issuer**, gateway or SDK, signs every receipt and every tree head. The **verifier** holds only public keys and needs no access to the issuer, the agent, or the upstream system.\n\n## Two producers, one receipt\n\n| | gateway | SDK |\n| --- | --- | --- |\n| where it runs | separate process between agent and tools | inside the agent's process |\n| what it sees | MCP tool calls | whatever the framework's hooks expose |\n| enforcement | yes, denied calls never reach upstream | only where a hook can block |\n| provenance of its fields | `attested` and `observed` | `claimed`, all of them |\n| what a verifier learns | the agent could not skip or forge this | the agent's process reported this and it has not changed since |\n| install | one line in the host's MCP config | a hook entry or a wrapped function |\n\nEvery receipt names its issuer, and the verifier prints what that issuer kind is worth before anything else. A dashboard full of `sdk` rows is the reason to route the consequential calls through the gateway.\n\n### Supported hosts and frameworks\n\n| host or framework | producer | enforce + record | record only | tested against |\n| --- | --- | --- | --- | --- |\n| any MCP host: Claude Desktop, Claude Code, Cursor, custom | gateway | yes | | a real MCP client and upstream over stdio |\n| Claude Code | SDK | `hook` command, PreToolUse deny | PostToolUse | the documented hook contract, via stdin |\n| Claude Agent SDK | SDK | `claudeAgentHooks` | same | the same handler |\n| OpenAI Agents SDK (JS) | SDK | `wrapTools` | `observeRunner` | a real `Runner` with a scripted model |\n| Vercel AI SDK | SDK | `wrapTools` | | a real `generateText` loop over the SDK's mock model |\n| LangChain / LangGraph (JS) | SDK | `tool(issuer.wrap(fn))` | `ReceiptCallbackHandler` | real `StructuredTool` invocations |\n| anything else | SDK | `issuer.wrap(name, fn)` | `issuer.record` | plain functions |\n| Python: LangChain, OpenAI Agents SDK, CrewAI, Claude Agent SDK | sidecar + [Python package](../python/README.md) | `wrap_tools` (OpenAI Agents, CrewAI), `claude_hook` PreToolUse deny, `client.wrap` | `ReceiptCallbackHandler` | the real Python packages, receipts checked by this verifier |\n| Go, Java, Rust, any language with HTTP | sidecar | decide then record | record | [examples/languages](examples/languages), each run against a live sidecar |\n| any MCP host in any language: Claude Agent SDK Python, OpenAI Agents Python | gateway | yes | | the gateway is an MCP server; [usage.md](docs/usage.md#python-hosts) |\n| any REST API, as tools the agent reaches through the gateway | gateway, `rest` upstream | yes | | a stand-in HTTP API; [usage.md](docs/usage.md#setup-step-by-step) |\n\nThe framework packages are optional peer dependencies. Each adapter imports only from its own package.\n\n## One tool call, end to end\n\n```mermaid\nsequenceDiagram\n    participant Agent\n    participant Gateway\n    participant Upstream as Upstream MCP server\n    participant Log as Merkle log\n\n    Agent->>Gateway: tools/call stripe.refund {customer_id, amount}\n    Gateway->>Gateway: tool in signed grant's scopes?\n    Gateway->>Upstream: tools/call customer.lookup {customer_id}\n    Upstream-->>Gateway: {verified: true}\n    Note over Gateway: facts.customer = that result, labelled \"observed\"\n    Gateway->>Gateway: Cedar: permit if amount ≤ limit and facts.customer.verified\n    alt allow\n        Gateway->>Upstream: tools/call stripe.refund {customer_id, amount}\n        Upstream-->>Gateway: {refund_id, status}\n    else deny\n        Note over Gateway: no upstream call is made\n    end\n    Gateway->>Gateway: build in-toto statement, sign (DSSE, Ed25519)\n    Gateway->>Log: append canonical envelope\n    Log-->>Gateway: leaf index, inclusion proof, root\n    Gateway->>Gateway: sign tree head, write bundle to receipts/\n    Gateway-->>Agent: result or denial, _meta[\"agent-custody/receipt\"] = id\n```\n\nDenied calls get receipts too. \"The agent tried to pay out funds and was refused\" is evidence worth keeping.\n\n## Anatomy of a receipt bundle\n\n```mermaid\nflowchart TB\n    B[\"receipt bundle (one JSON file)\"]\n    B --> E[\"envelope: DSSE, signed by gateway key\"]\n    B --> T[\"treeHead: DSSE, signed by gateway key<br/>{treeSize, rootHash, timestamp}\"]\n    B --> I[\"inclusion: {leafIndex, treeSize, hashes[]}\"]\n    E --> S[\"in-toto Statement v1\"]\n    S --> SU[\"subject: tool-call:&lt;tool&gt;:&lt;id&gt;<br/>digest = sha256(args)\"]\n    S --> PR[\"predicate\"]\n    PR --> P0[\"issuer: gateway or sdk, keyid, framework\"]\n    PR --> P1[\"principal, agent, delegation<br/><b>attested</b>: signed by principal key (gateway)\"]\n    PR --> P2[\"tool, facts, policy decision, execution<br/><b>observed</b>: gateway obtained it (gateway)\"]\n    PR --> P3[\"args, model id, session<br/><b>claimed</b>: agent-supplied, unchecked (both)<br/>every field, when issued by the sdk\"]\n```\n\nEvery field carries a provenance label. This is the design decision that matters most, and it is what a verifier reads back.\n\n| provenance | meaning | today's examples |\n| --- | --- | --- |\n| `attested` | signed by a key other than the issuer's | principal id, agent id, the delegation grant (gateway receipts) |\n| `observed` | the issuer obtained it deterministically, outside the agent's control | upstream tool results, fact lookups, the policy decision, execution status (gateway receipts) |\n| `claimed` | originated from the agent, the model, or the agent's own process, no independent check | tool arguments, the model id, session ids, and every field of an SDK receipt |\n\n## Quick start\n\n```bash\nbun install                              # from the repository root, once for the workspace\ncd packages/receipts\nnode scripts/demo.ts                     # gateway: keys, grant, policy, four tool calls, verification, a tampering attempt; then the SDK wrapping the same tool\nnode examples/01-keys-and-signing.ts     # first of eighteen step-by-step examples, see docs/tutorials.md\nbun run test                             # this package; `bun run test` at the root runs every package\n```\n\nEverything runs on plain Node 22 or later. No build step, no `npx`, no `tsx` needed on the command line.\n\nThe demo leaves everything in `demo-out/`, including receipts from both producers. Verify a receipt by hand:\n\n```bash\nnode src/cli.ts verify demo-out/receipts/<id>.json \\\n  --issuer-key demo-out/keys/gateway.pub \\\n  --principal-key demo-out/keys/principal.pub \\\n  --log demo-out/log.jsonl\n```\n\nExit code 0 means every check passed. See [docs/verification.md](docs/verification.md) for what the report means.\n\nTo issue receipts from your own agent code, without a gateway:\n\n```ts\nimport { loadSdkConfig } from \"./src/config.ts\";\nimport { createSdkIssuer } from \"./src/sdk/index.ts\";\n\nconst issuer = createSdkIssuer(loadSdkConfig(\"./sdk.json\"));\nconst refund = issuer.wrap(\"stripe.refund\", async (args: { amount: number }) => stripe.refund(args));\n```\n\n[docs/sdk.md](docs/sdk.md) has the config file and the per-framework adapters.\n\n## What a receipt proves, and what it does not\n\n| claim | verifier | adversary | mechanism | status |\n| --- | --- | --- | --- | --- |\n| receipt was not altered after issue | anyone | later editor | DSSE signature over canonical JSON | done |\n| receipt was issued in sequence, none removed | auditor with a log copy | operator rewriting history | Merkle inclusion proof + recomputed root | done |\n| the principal really delegated this scope to this agent | anyone with the principal's key | operator, agent | grant signed by principal key, checked for scope and validity window | done |\n| the policy decision was made against this exact policy | anyone | operator swapping policies | sha256 of policy text in the receipt | done |\n| facts the policy relied on were not asserted by the agent | anyone reading the receipt | agent | facts fetched by the gateway, recorded with their own digests, labelled `observed` | done |\n| the side effect was committed to the log before it happened | anyone with a log copy | operator, log outage | for tools in `precommit`, a signed authorization logged first, embedded in the receipt with its leaf position, checked to precede the receipt | done |\n| the upstream system actually executed the action | anyone with the upstream's key or the provider's secret | operator | the upstream signs its result for the receipt, or the provider's own delivery signature (Stripe, GitHub) is embedded and checked | done, for upstreams that sign |\n| the operator itself cannot mint a false receipt | regulator, counterparty | operator | needs a TEE-hosted signer or a federated log | **not done** |\n| which model produced the call | anyone | operator | no hosted provider signs model identity | **not possible today**, labelled `claimed` |\n| an SDK receipt reflects what the tool really did | anyone | agent's own process | none; the SDK shares a process with the agent | **by design not claimed**; issuer kind `sdk` says so |\n\nIf a vendor tells you their receipts prove more than the first five rows, ask them which key signed it.\n\n## Layout\n\n```\nsrc/config.ts      gateway and SDK config schemas, path resolution\nsrc/crypto.ts      canonical JSON, sha256, Ed25519 keys, DSSE sign/verify\nsrc/log.ts         Merkle log: append, root, inclusion and consistency proofs, verify, JSONL persistence\nsrc/log-check.ts   the outside monitor: verifies the head, checkpoints, and witness of a running log\nsrc/log-export.ts  a tenant's export of their own log, self-checked, as a log file the verifier reads\nsrc/witness.ts     the witness: countersigns the log's checkpoints from another operator's machine, or refuses with an alarm\nsrc/signer.ts      the signer: the log's key in its own process, the key document verifiers fetch\nsrc/checkpoints.ts signed heads published on a schedule, to files and to Postgres\nsrc/log-store.ts   the log server's backends: the file, and Postgres with tenants, hashed tokens, one writer per tenant, rate limits\nsrc/log-sink.ts    where leaves go: the local file, or a remote log over HTTP; plus the reference log server\nsrc/policy.ts      Cedar evaluation wrapper, fail-closed\nsrc/delegation.ts  signed delegation grants\nsrc/receipt.ts     receipt and authorization statement types and provenance labels\nsrc/issue.ts       sign, log, and write a receipt, or commit an authorization first; shared by both producers\nsrc/gateway.ts     the MCP proxy: scope check, facts, policy, forward, receipt\nsrc/sdk/index.ts   the interceptor: policy decision, record, wrap(tool fn)\nsrc/sdk/claude.ts  Claude Code command hook and Claude Agent SDK in-process hooks\nsrc/sdk/openai-agents.ts, vercel-ai.ts, langchain.ts   framework adapters, tested against the real packages\nsrc/sidecar.ts     the SDK issuer behind a local HTTP API, for agents in other languages\nsrc/otel.ts        OpenTelemetry export: one OTLP/HTTP span per receipt, after the receipt, no SDK dependency\nsrc/splunk.ts      Splunk export: one HTTP Event Collector event per receipt, token from the environment, beside or instead of otel\nsrc/rest.ts        the REST connector: an HTTP API described as tools, standing where an MCP upstream stands\nsrc/upstream.ts    attested execution: an upstream signs its result for the receipt; the verifier checks it with the upstream key\nvectors/           conformance vectors: receipts, keys, logs, proofs, and expected verdicts; `bun run vectors` regenerates them\nsrc/verify.ts      offline verification, the human-readable report, and the audit that a later log extends an earlier one\nsrc/cli.ts         keygen, grant, gateway, hook, serve, log, prune, verify, audit\nsrc/retention.ts   pruning the log: leaves become their hashes, bundles are removed, proofs survive\nsrc/index.ts       the package's public surface; adapters are exported on ./sdk/<framework> subpaths\ntsconfig.build.json  emits dist/ (JavaScript plus declarations) for consumers; the repo itself runs the .ts directly\nscripts/           fake Stripe upstream (signs its results with --key), a second fake upstream, fixture builders for gateway and SDK, demo\nexamples/          eighteen runnable tutorials, plus examples/languages/: Python, Go, Java, and Rust clients of the sidecar, run by the test suite, one per aspect; each is run by the test suite\ntest/              unit tests per module, end-to-end gateway test, SDK and hook tests,\n                   adapter tests against the real packages, and a test that runs every policy in docs/policies.md\ndocs/              tutorials, usage (gateway), sdk, policies, verification\n```\n\n## Plan\n\nThe design is two producers feeding one verifier. The SDK is the top of the funnel: cheap to install, wide reach, honest about being self-reported. The gateway is what a security or compliance owner mandates for consequential actions. Both exist; the work is widening each.\n\n**Done**\n\n- Gateway: MCP proxy, signed delegation, gateway-fetched facts, Cedar policy, denial receipts, Merkle log, offline verifier.\n- Receipt schema carries the issuer kind, so a verifier reads gateway versus SDK before anything else.\n- SDK core: policy decision, record, and a generic `wrap(tool, fn)` for any framework whose tools are functions.\n- Claude Code command hook for PreToolUse, PostToolUse, and PostToolUseFailure, with blocking on deny.\n- Claude Agent SDK in-process hooks over the same handler.\n- Provider-native deliveries: an upstream wrapping Stripe or GitHub attaches the signed webhook or delivery for the call; a verifier with the shared secret checks the HMAC, the timestamp, and the binding to the result, and reports the execution as attested by shared secret.\n- Logarithmic appends: the Merkle log caches complete subtrees, so issuing a receipt costs the same at the millionth leaf as at the first; measured at 0.15 ms per receipt and about half a millisecond per gateway call including policy, a fact lookup, and the upstream signature. A remote log adds one network round trip plus about five milliseconds of server work per call, two for a pre-committed call; the [deployment guide](https://agent-custody.dev/guide/deployment) has the measurements against the live log.\n- Retention on the log: `prune` replaces leaves older than a cutoff with their hashes and removes their bundles, so proofs still verify and the content is gone.\n- Several upstreams under one gateway and one grant, each tool owned by exactly one, with the receipt naming which served the call; consumed facts flow across them.\n- Attested execution: an upstream that holds a key signs its result for the receipt, the gateway embeds it, and a verifier given the upstream key reports the execution as attested rather than observed. The memory server and the demo upstream sign.\n- HTTP upstreams: the gateway reaches an already-running MCP server over Streamable HTTP with a bearer token from the environment, as well as spawning one over stdio.\n- Optional fact lookups: a lookup that references a call argument the call does not carry is skipped rather than denying, so policy can see the fact a write is about to supersede without refusing writes that supersede nothing.\n- Consumed facts: an upstream declares the facts it served in its result `_meta`, and every later gateway receipt in the session carries those ids as `consumed`, observed, so what the agent had been shown before each call is on the record.\n- The forwarded call carries the receipt id and the attested agent and principal in `_meta`, so a stateful upstream can cite the receipt; the memory server in `@agent-custody/state` runs this way.\n- Conformance vectors, generated by the test suite and published with the spec, and a browser verifier on agent-custody.dev that passes all of them.\n- Sidecar: the SDK issuer behind a local HTTP API (`serve`), with a Python package on PyPI-ready footing and Go, Java, and Rust clients, so agents in any language get the same receipts from one signing implementation.\n- Consistency proofs between tree heads (RFC 9162), served by the log and checked by the `audit` command, so an auditor holding an old tree head can prove nothing before it was rewritten.\n- Remote log: the issuer can append to a log run by someone else over HTTP, whose key then signs the tree heads, so a verifier learns the receipt was in a log the operator could not rewrite. Includes the reference log server, bearer-token auth, and a root endpoint for auditors.\n- Framework adapters, each tested against the real package with a scripted model and no network: OpenAI Agents SDK (`wrapTools` enforces, `observeRunner` records from lifecycle events), Vercel AI SDK (`wrapTools` over a real `generateText` loop), LangChain (`ReceiptCallbackHandler` records, `issuer.wrap` enforces).\n\n- An audit trail of administrative actions: every tenant created or disabled and every token minted or revoked is recorded with who did it, from the admin page or the command line, shown on the page and carried in the tenant's export.\n- A tenant's export: `log-export` takes, with the tenant's own token, every leaf hash, the signed head, the published keys, the checkpoints, and their usage, checks that they add up, and writes a log copy the verifier reads offline; the evidence never depends on the operator staying in business.\n- Monitoring and metering: `log-check`, the outside probe that verifies the head, the checkpoints, and the witness and exits 1 on trouble, run every ten minutes by the `monitor` workflow; `GET /health`; and usage per tenant per month on the admin page and as CSV.\n- The witness: a second signer on a machine the log's operator does not control countersigns each checkpoint after proving it extends the last one it signed, refuses a rewritten or forked history with an alarm, and publishes its key; `audit --witness-url` requires it. Phase 6 of [issue #6](https://github.com/ch4r10t33r/agent-custody/issues/6).\n- The signer, keys, and checkpoints: the key in its own process (`signer`, `--signer-url`), the key document at `/.well-known/agent-custody-log.json` fetched and pinned by `verify --log-url` and `audit --log-url`, and signed checkpoints per log published to a directory and a table for a verifier who was not watching. Phase 3 of [issue #6](https://github.com/ch4r10t33r/agent-custody/issues/6).\n- The log over Postgres: `log --db-env`, leaves as hashes in one table keyed by tenant, one writer per tenant by advisory lock, tenants and hashed tokens in tables managed by `log-admin`, rate limits and a body cap, retries in the sink, and `import` for an existing file log. Phase 2 of [issue #6](https://github.com/ch4r10t33r/agent-custody/issues/6).\n- A log for someone else: `hashOnly` sends leaf hashes so the log never holds a receipt; the reference server runs several tenant logs at `/t/<tenant>/` with their own tokens and ids; tree heads name their log and the verifier checks it with `--log-id`. Phase 1 of the hosted log, [issue #6](https://github.com/ch4r10t33r/agent-custody/issues/6).\n- OpenTelemetry export: with `otel` in either config, every receipt is also one span at the collector the team already runs, trace id equal to the receipt id, attributes for tool, agent, principal, status, decision, and log position; after the receipt, best effort, never on the evidence path.\n- Splunk export: with `splunk` in either config, every receipt is also one event at the HTTP Event Collector, with the receipt id, tool, agent, principal, status, decision, and log position as searchable fields and the token from the environment; the same best-effort rule.\n- The REST connector: a plain HTTP API described as tools in the gateway config, credentials from the environment, so an agent's direct API calls become receipted, policy-checked tool calls through the gateway.\n- Pre-commit authorization for consequential tools: named in `precommit`, a call is signed and logged before it is forwarded, withheld if the log will not take it, and its receipt carries the committed authorization with proof that it precedes the execution.\n\n**Next, in the order it pays off**\n\n1. Run the witness for log.agent-custody.dev on a machine and under an account that is not ours, and require it in the welcome sheet. The code is done; what it needs is a second operator. [Issue #6](https://github.com/ch4r10t33r/agent-custody/issues/6).\n2. Post-quantum signatures: ML-DSA beside Ed25519 in the same DSSE envelope, hybrid by default when a PQ key is present, in every signed artefact and in the browser verifier. [Issue #11](https://github.com/ch4r10t33r/agent-custody/issues/11).\n3. An HTTP transport for the gateway, with the grant presented per connection, for a shared deployment rather than one process per agent session.\n4. Delegation chains for sub-agents.\n5. Receiver-attested receipts for agent-to-agent calls.\n6. A TEE-hosted signer, then SD-JWT redaction, then ZK proofs of policy compliance. Not before.\n\nA Python SDK follows the same shape once the TypeScript adapters have settled.\n","readmeFilename":"README.md"}