{"_id":"@agent-custody/state","_rev":"23-e5d9e8f9436030be94ce4132d8e291f4","name":"@agent-custody/state","dist-tags":{"latest":"0.5.9"},"versions":{"0.1.0":{"name":"@agent-custody/state","version":"0.1.0","license":"Apache-2.0","_id":"@agent-custody/state@0.1.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"dist":{"shasum":"59c349f0c704357ba1b1f35e2bfe7343670fc45c","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.0.tgz","fileCount":7,"integrity":"sha512-+Ml2oK3p7cH3MZr+IOIIMVHPzjXK/zNcvvF49D9TAtTV+zRVv2qZd8CncKCy7ypLp8le34FeKd9g1HZif8Xiww==","signatures":[{"sig":"MEUCIQDxD2yajXnH9We7CXm5sl9UOezC0WfsTokDR7j8L5e7iQIgHzPoKDGakde3vARlCBQeQj49Z/gKkWPEF7bAkkSsS5s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24776},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.0.tgz","_integrity":"sha512-+Ml2oK3p7cH3MZr+IOIIMVHPzjXK/zNcvvF49D9TAtTV+zRVv2qZd8CncKCy7ypLp8le34FeKd9g1HZif8Xiww==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"@agent-custody/receipts":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.0_1788670889368_0.06579065368284831","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-custody/state","version":"0.1.1","license":"Apache-2.0","_id":"@agent-custody/state@0.1.1","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"dist":{"shasum":"4bc74536e50790bc9cd86d65f86e62415d6551c8","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.1.tgz","fileCount":7,"integrity":"sha512-y+XZ1GnlV/z9FZlfzUNMFeCOTfq07yVx2t5b38SnvnbZ2K29/eKTu/7U/u7b0a7fvj/wxu3GK2ZIJrBVS64PPg==","signatures":[{"sig":"MEUCIQCraJ2WGeWmtGcae7CKBjUYfCHrRq2paa1MajdNx28bIgIgA5fFUbycY9N5I9+dK3zp+m4pdSCJV6ub2xtI4SW1FA8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24891},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.1.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.1.tgz","_integrity":"sha512-y+XZ1GnlV/z9FZlfzUNMFeCOTfq07yVx2t5b38SnvnbZ2K29/eKTu/7U/u7b0a7fvj/wxu3GK2ZIJrBVS64PPg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"@agent-custody/receipts":"0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.1_1788678350701_0.9706366210460806","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agent-custody/state","version":"0.1.2","license":"Apache-2.0","_id":"@agent-custody/state@0.1.2","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"dist":{"shasum":"4b3cd7fd232c3ed1f87a84bf494410a18921f2dc","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.2.tgz","fileCount":7,"integrity":"sha512-FMwuXF9rGqGVTDRz3aZMvJtDhPURFqJ6UGOft8gNi7AmQXdwCQztX68zufMN0rIG25kpEASWH80N1BWdfCWrHA==","signatures":[{"sig":"MEUCIQCXy6aIV4v93RZO2qkGNkNRV4wuyD9MbcGxfnhDK2YSoAIgclDKMrsdtC6MIdlVBJALJxo7wP7PPvYb7RuHbjDEXVc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24891},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.2.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.2.tgz","_integrity":"sha512-FMwuXF9rGqGVTDRz3aZMvJtDhPURFqJ6UGOft8gNi7AmQXdwCQztX68zufMN0rIG25kpEASWH80N1BWdfCWrHA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"@agent-custody/receipts":"0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.2_1788757307674_0.9825078523055233","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agent-custody/state","version":"0.1.3","license":"Apache-2.0","_id":"@agent-custody/state@0.1.3","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"9c4aa206828d292c85206d8f01fac6e329440093","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.3.tgz","fileCount":11,"integrity":"sha512-0uD74CDVqjDsXpw7ibcsXS+WbtJ+JoEi+3/cSoiA272ppyKR2yZGMBGOjIaT8u4mKXYC9EHJOqCqrQJsXeRIpg==","signatures":[{"sig":"MEQCIGf37raQ2n6bUlk6GGVAuc4VxC/6Iv3Qx3vyYieFssHpAiAuSA+3erLYH8azIhTz6ZYYZHRfswbrIqTVFZ3A9fatww==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36382},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.3.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.3.tgz","_integrity":"sha512-0uD74CDVqjDsXpw7ibcsXS+WbtJ+JoEi+3/cSoiA272ppyKR2yZGMBGOjIaT8u4mKXYC9EHJOqCqrQJsXeRIpg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.3","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.3_1788766926698_0.9671807993417323","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@agent-custody/state","version":"0.1.4","license":"Apache-2.0","_id":"@agent-custody/state@0.1.4","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"83b2e2249b7c2ecbf2c7806db6acb7046b9e1a1f","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.4.tgz","fileCount":17,"integrity":"sha512-V9z/QmCv8NZbgESn/Ew7aZhXWrCJ06pR+hLEp7P0DpRHD/BQz00jqdnKurc6zMHYTSlQVLyuR6erPIptrqDmAA==","signatures":[{"sig":"MEQCIFKLhkBIIfMtMcUJWguKbTf3oUPHMbtXrgq6OF6jUd25AiAbeBT5URW+eq7rJyEjtLoO1iaezjNKMl3qUz/VeFsvbw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":62628},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.4.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.4.tgz","_integrity":"sha512-V9z/QmCv8NZbgESn/Ew7aZhXWrCJ06pR+hLEp7P0DpRHD/BQz00jqdnKurc6zMHYTSlQVLyuR6erPIptrqDmAA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.4","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.4_1788768741365_0.10816758296966333","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@agent-custody/state","version":"0.1.5","license":"Apache-2.0","_id":"@agent-custody/state@0.1.5","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"58501c3b0fe8b880a4dde821858d3d985e005093","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.5.tgz","fileCount":21,"integrity":"sha512-y8jerrA2YLZTqmaehX6ArHgQ4IICw8yIH2TxOb3qjQjLM6B5Ud1EPJhhUtmul5Ui69roxdLx/KUBlVNpEyDrGQ==","signatures":[{"sig":"MEUCICQ3BjXOaBsC1aY5km3XslSRP+duANpU+9OdKIEMAHDQAiEAzOwZlchv+oNSBElWKUx2mV1N9OrHnrElUBLy4rNkoQ4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":88158},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.5.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.5.tgz","_integrity":"sha512-y8jerrA2YLZTqmaehX6ArHgQ4IICw8yIH2TxOb3qjQjLM6B5Ud1EPJhhUtmul5Ui69roxdLx/KUBlVNpEyDrGQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.5","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.5_1788771565234_0.5380583526755862","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@agent-custody/state","version":"0.1.6","license":"Apache-2.0","_id":"@agent-custody/state@0.1.6","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"93e6b2bd6c46be9ad16fa66eef41f0d8b9e582db","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.6.tgz","fileCount":21,"integrity":"sha512-c72R19oKiRQZmLEcO6sRPWiy9UkahxxBFPlySIz77QwFuQRvwmjH5eALJ3bf3uP3XOdUMmgQ2Lz8LkqCX4zFPg==","signatures":[{"sig":"MEQCICpJ4dEu0jh9eVIfLek8/I8r3bR8U3TkaM5/r1CnzUaNAiBLpqmVq/f4n5ncgZwLQmpGNKTSrm8ibsCoLseoIrujIA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101235},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.6.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.6.tgz","_integrity":"sha512-c72R19oKiRQZmLEcO6sRPWiy9UkahxxBFPlySIz77QwFuQRvwmjH5eALJ3bf3uP3XOdUMmgQ2Lz8LkqCX4zFPg==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.6_1788778821008_0.2214033488297451","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@agent-custody/state","version":"0.1.7","license":"Apache-2.0","_id":"@agent-custody/state@0.1.7","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"399f0f8ccef4ae4da8703f30f05f70beceaeba56","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.7.tgz","fileCount":21,"integrity":"sha512-kWaDRzrw/iccyAtPPYXvuDRvsZl6Gz5Zq8gRlhRmyBpx1cZ87Tn8cw5QO+clYdWS21d7jb+cPgNYUOskVubOyA==","signatures":[{"sig":"MEUCIQCOCoumMlfBpV5Iq37l9C7ZuDHrXQMDUghhB/pU0bDm0wIgByMqx4PoBZEPxfC6ZOZ2fTM0CVpnmHljqcuDbLLk8hc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":110802},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.7.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.7.tgz","_integrity":"sha512-kWaDRzrw/iccyAtPPYXvuDRvsZl6Gz5Zq8gRlhRmyBpx1cZ87Tn8cw5QO+clYdWS21d7jb+cPgNYUOskVubOyA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.7","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.7_1788786831250_0.633280464273192","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@agent-custody/state","version":"0.1.8","license":"Apache-2.0","_id":"@agent-custody/state@0.1.8","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"6b37edcb4171a4bce8d76739fcba020881f3c21e","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.8.tgz","fileCount":25,"integrity":"sha512-BzAsXfCwmHtp4Ge4nXAPbSkftCHd6Fp/OBa612n2nkhZxxEMI19PDyfsDVBfPUVupZRMZn2pb3DW0GVSBGhnZA==","signatures":[{"sig":"MEUCIQDd6E7NRB1+txzvmek0Uwwdc2ulbiXNw1RkOrSzl0goTQIgf650mPzohbrPClF1Br/tZhVqoB4JP84WHusfgEts21I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":128178},"type":"module","_from":"file:packages/state/agent-custody-state-0.1.8.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.8.tgz","_integrity":"sha512-BzAsXfCwmHtp4Ge4nXAPbSkftCHd6Fp/OBa612n2nkhZxxEMI19PDyfsDVBfPUVupZRMZn2pb3DW0GVSBGhnZA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.8_1788790324704_0.8314569327385759","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@agent-custody/state","version":"0.1.9","license":"Apache-2.0","_id":"@agent-custody/state@0.1.9","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"1e12c553bcb6b342b92db27201ba585befcee39f","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.1.9.tgz","fileCount":27,"integrity":"sha512-ZJJ2id0ad1BbOeHoAnKI4Tq43NDmXV8cfKHnSYhisnbNXMz3U4SGQ6nxX/VdYn1djrtoWl6Ka1/wT43uA9D2zA==","signatures":[{"sig":"MEUCIQCbHaQ+ZeRKIvH6gEh0oUVKnVY+oxvk4fru4/XVQJjSjwIgDQL93mQXtJcjokkza3Ka/Fqc5TC0Bvqr/hgO8+JKjns=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":146980},"type":"module","_from":"file:agent-custody-state-0.1.9.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.1.9.tgz","_integrity":"sha512-ZJJ2id0ad1BbOeHoAnKI4Tq43NDmXV8cfKHnSYhisnbNXMz3U4SGQ6nxX/VdYn1djrtoWl6Ka1/wT43uA9D2zA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, and lineage, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.1.9","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0"},"_npmOperationalInternal":{"tmp":"tmp/state_0.1.9_1788801206750_0.4154358471596846","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agent-custody/state","version":"0.2.0","license":"Apache-2.0","_id":"@agent-custody/state@0.2.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"b330d69f07c53a2d5c61c5ebcff88a6a78b5b25d","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.2.0.tgz","fileCount":27,"integrity":"sha512-ZaSYWeSIF/jFZuLOkwFGvnYzC/TV4n1VMC0IGNjMDJkPMxOgZx1NJXedKBQpNwvM7Bno3emqzXKuSyN2TSmHaA==","signatures":[{"sig":"MEUCIQCWAyu+MraAF/j1ADD5jus5XYQM+96qGwWmVrmsGwAaMQIgEsCOcTs895OOer+6VnPSXEI/wFB9W4QlBCyMS6UbEXU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":168350},"type":"module","_from":"file:agent-custody-state-0.2.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.2.0.tgz","_integrity":"sha512-ZaSYWeSIF/jFZuLOkwFGvnYzC/TV4n1VMC0IGNjMDJkPMxOgZx1NJXedKBQpNwvM7Bno3emqzXKuSyN2TSmHaA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.2.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.2.0_1788803696431_0.4800157651768797","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agent-custody/state","version":"0.3.0","license":"Apache-2.0","_id":"@agent-custody/state@0.3.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"e0b296b067ebdff2297f1ae9d1e567de93fe3f73","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.3.0.tgz","fileCount":29,"integrity":"sha512-6AAMIep6kifibbHCNBCokjRhoKVb++71SdFnS4ILa/+FRHrNcsoGgdSSVU5BVxc5vKp4ykU3ox0iD4j48SaZNw==","signatures":[{"sig":"MEQCIFVDDPfG/xlX+ric7eM+G7cqpuBElOjccCk76CT1UxUjAiAVOnrMt0vWVRNXRqfeRehu8KFvw1z+uU1yJAbcfxbVZQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.3.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.3.0.tgz","_integrity":"sha512-6AAMIep6kifibbHCNBCokjRhoKVb++71SdFnS4ILa/+FRHrNcsoGgdSSVU5BVxc5vKp4ykU3ox0iD4j48SaZNw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.3.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.3.0_1788838521394_0.11476646693745662","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@agent-custody/state","version":"0.4.0","license":"Apache-2.0","_id":"@agent-custody/state@0.4.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"fbbe1b823ffa58659a399ccd1ca12c44214b7131","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.4.0.tgz","fileCount":29,"integrity":"sha512-gr/3aaS8mCh2mceZwb5kzJpWW0y51GDJV928zRXWSXoXdBcXwoYbO/Pxxp9oOag0mbS1zf3U3YFp2iHM+KDV2A==","signatures":[{"sig":"MEUCIQCGhPFnrVugiofqudGq6WASI707OWF7fQvdDtian9t9SwIgYSVVfP/wTRBbDsnjdq4+JbjaEud+TRBGtXg7bkN3EWA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.4.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.4.0.tgz","_integrity":"sha512-gr/3aaS8mCh2mceZwb5kzJpWW0y51GDJV928zRXWSXoXdBcXwoYbO/Pxxp9oOag0mbS1zf3U3YFp2iHM+KDV2A==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.4.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.4.0_1788849695353_0.7752095311037863","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agent-custody/state","version":"0.5.0","license":"Apache-2.0","_id":"@agent-custody/state@0.5.0","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"6946e7906b7159d9955ef3948c38b84f2738bff2","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.0.tgz","fileCount":29,"integrity":"sha512-TNecDPQPuxy+mBB+aAs15krhv8JcHFuCgmyicW1j1Bb6UwXvbrsV0YT8UG2j7uOiFSLCdjQhTz6XLltlgPT59w==","signatures":[{"sig":"MEUCIQD2ozFJvjl2uzNuxbULIZFt4PLRt0yuaf0HwjbSik+VxAIgXDp7U9zJ1zltg83eornEaxyRclq/myA8bjSM8uByGIk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.5.0.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.0.tgz","_integrity":"sha512-TNecDPQPuxy+mBB+aAs15krhv8JcHFuCgmyicW1j1Bb6UwXvbrsV0YT8UG2j7uOiFSLCdjQhTz6XLltlgPT59w==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.0","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.0_1788851325318_0.7406059532273013","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@agent-custody/state","version":"0.5.1","license":"Apache-2.0","_id":"@agent-custody/state@0.5.1","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"a851c77e71e14df28949eca53ce4b6151008e4eb","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.1.tgz","fileCount":29,"integrity":"sha512-VX2h/1/UmTj81vg0cSTGVu7Np+b506c+2jOOunjDs7z0V/4GR5AhDQMqZfTsS1VvKcv0qpDhD3qIFrblsZJ2jQ==","signatures":[{"sig":"MEYCIQDZnJRqf8Ewv7NmU3fBbIQOxS7Z31lL2xY1cKdSM8gNHAIhANBw4aHBKK6wx9O1lew8UyrPOHBY3emsPbRT/TUxgKl6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.5.1.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.1.tgz","_integrity":"sha512-VX2h/1/UmTj81vg0cSTGVu7Np+b506c+2jOOunjDs7z0V/4GR5AhDQMqZfTsS1VvKcv0qpDhD3qIFrblsZJ2jQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.1","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.1_1788859464804_0.5184288711006739","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@agent-custody/state","version":"0.5.2","license":"Apache-2.0","_id":"@agent-custody/state@0.5.2","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"f8b581ae169f2c3b3c0845a80ff22315fe78d8ec","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.2.tgz","fileCount":29,"integrity":"sha512-l6ssnf/tT42JZF2HUGvFem1felUenFfsUmAGSktJwkM0YxjMCIeifNFErsh4Ol6PzkUE86gqDyklO0R0kfNdVQ==","signatures":[{"sig":"MEUCIQDa+FOwSVAonmUifrM+B9o53oSbhWTQGRdCHcp+5eDOkQIgZLDsx51TwgI5qFDCrsZFiWbBnCrWst/eOf0If9xiV/o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.5.2.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.2.tgz","_integrity":"sha512-l6ssnf/tT42JZF2HUGvFem1felUenFfsUmAGSktJwkM0YxjMCIeifNFErsh4Ol6PzkUE86gqDyklO0R0kfNdVQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.2","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.2_1788877683786_0.10368492222284131","host":"s3://npm-registry-packages-npm-production"}},"0.5.3":{"name":"@agent-custody/state","version":"0.5.3","license":"Apache-2.0","_id":"@agent-custody/state@0.5.3","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"2438aa87d7953bbd831ea772fd5fe612c1bda182","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.3.tgz","fileCount":29,"integrity":"sha512-+cKUbzsxbLo+riLK3cJbsmupdZAh9W0wXaIsoJ+Q3YdJumPVfLHXEm+udNsPYPsqWsrrt6Smo8WudhYXn0APWA==","signatures":[{"sig":"MEYCIQDOl3Ig3csUnKByTazBjaIqeT/03p4mVtrQbgWcIDFuVgIhANqYtv93GTcHZ1Bl4HUX1iGsLKliD4CW7cOUNOJAmo6l","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.5.3.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.3.tgz","_integrity":"sha512-+cKUbzsxbLo+riLK3cJbsmupdZAh9W0wXaIsoJ+Q3YdJumPVfLHXEm+udNsPYPsqWsrrt6Smo8WudhYXn0APWA==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.3","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.3_1788878057132_0.008117583817663032","host":"s3://npm-registry-packages-npm-production"}},"0.5.4":{"name":"@agent-custody/state","version":"0.5.4","license":"Apache-2.0","_id":"@agent-custody/state@0.5.4","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"2e115a78f10d043511b3bef118cd72a08312bf1f","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.4.tgz","fileCount":29,"integrity":"sha512-NgLBb1Uj8SAM7mR19GawmAprlp0x/5LMcyNq9gd7ujaGvNaYbtWmLHdU8H/2MJRtOE8V1YQsu9LAAPI6TQn1tQ==","signatures":[{"sig":"MEUCIAtcg4NeRC1gGhbNXM95gDcAY/VV6wz2AgFhNKGwbcZbAiEAyattzuOv2ap2nR7pFkjb9lNVFqf2j2dGPWIIUYojupI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.5.4.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.4.tgz","_integrity":"sha512-NgLBb1Uj8SAM7mR19GawmAprlp0x/5LMcyNq9gd7ujaGvNaYbtWmLHdU8H/2MJRtOE8V1YQsu9LAAPI6TQn1tQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.4","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.4_1788885299684_0.1533085449250171","host":"s3://npm-registry-packages-npm-production"}},"0.5.5":{"name":"@agent-custody/state","version":"0.5.5","license":"Apache-2.0","_id":"@agent-custody/state@0.5.5","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"7ae401460c64e2a712bd10922ddc2b5f9a8f3c58","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.5.tgz","fileCount":29,"integrity":"sha512-Pb0Q9aNLCB7ieHfiirW3BSLH/HeaaekCI+zydKX+oshcfDZv/i3keQ+g2k/DcfUrfqrX+xiQj3B3Z9F8pAw4hw==","signatures":[{"sig":"MEYCIQDLVzclZiPG0sC2vOTDujM1ovamBwhJbMfAN1YY/52hBgIhAO6rAVc8t5QLTJuuHhngiWdwHuD0iHbZ9aOjAwdQLd2+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":190415},"type":"module","_from":"file:agent-custody-state-0.5.5.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.5.tgz","_integrity":"sha512-Pb0Q9aNLCB7ieHfiirW3BSLH/HeaaekCI+zydKX+oshcfDZv/i3keQ+g2k/DcfUrfqrX+xiQj3B3Z9F8pAw4hw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.5","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.5_1788885711235_0.5683113135582865","host":"s3://npm-registry-packages-npm-production"}},"0.5.6":{"name":"@agent-custody/state","version":"0.5.6","license":"Apache-2.0","_id":"@agent-custody/state@0.5.6","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"ad559bf00a349b1d05f14f1266ca69a918471a49","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.6.tgz","fileCount":31,"integrity":"sha512-nzjHEQv2IqC26BYu142pVVeLkGc3KiHS5NDcIFWlJ0Bf5BRV/knGc3y3d4LRbIbFCF/QAPV7Rn01S0aGl71q3w==","signatures":[{"sig":"MEUCIGw8qG90X7nHcFpD99YTAIWg2IYVWGBstfyhyehel6OBAiEA32uKnSpPF/wH/6GK5KK09Dk8OZAPlxIGz2/YiRGiyvI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":211487},"type":"module","_from":"file:agent-custody-state-0.5.6.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.6.tgz","_integrity":"sha512-nzjHEQv2IqC26BYu142pVVeLkGc3KiHS5NDcIFWlJ0Bf5BRV/knGc3y3d4LRbIbFCF/QAPV7Rn01S0aGl71q3w==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.6","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.6_1788892685680_0.019774202959158105","host":"s3://npm-registry-packages-npm-production"}},"0.5.7":{"name":"@agent-custody/state","version":"0.5.7","license":"Apache-2.0","_id":"@agent-custody/state@0.5.7","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"5049978402d333dc5e3b60244d799e66b788fde2","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.7.tgz","fileCount":31,"integrity":"sha512-gVXlq/zYiILx51RN865aw+cBUwwZI6vVBDNwS5X0SffaiX6TZ1LJS92G7e1cg7cMAZ63dJi0h044soKzITOjbw==","signatures":[{"sig":"MEUCIQCDAfNLfHvGjNnfiQRw2gAOaXUNjkBKdmP5Anya50+0SQIgbTRDwx8g/Gm24oC+YYKiw6nlhRKYpysRQQeXj/worlk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":211487},"type":"module","_from":"file:agent-custody-state-0.5.7.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.7.tgz","_integrity":"sha512-gVXlq/zYiILx51RN865aw+cBUwwZI6vVBDNwS5X0SffaiX6TZ1LJS92G7e1cg7cMAZ63dJi0h044soKzITOjbw==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.7","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.7_1788916162483_0.4708872831700055","host":"s3://npm-registry-packages-npm-production"}},"0.5.8":{"name":"@agent-custody/state","version":"0.5.8","license":"Apache-2.0","_id":"@agent-custody/state@0.5.8","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"bin":{"agent-custody-memory":"dist/cli.js"},"dist":{"shasum":"a099e3c2386a96efa617f60d44cf6efa66099c6b","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.8.tgz","fileCount":31,"integrity":"sha512-XlB42GrRKVK9R4rK8uIDjpMDzi8TVGDSCItj2gxnf41vEFC3vUuuqQtBdFRwqS36OXwolcY33CRWhzcmkH1EgQ==","signatures":[{"sig":"MEUCICUlhwJNT3pOohV1v7gqTKR3SYfw3brrHXadZ6TT8nUOAiEAnz8x/9Re5LWkswV9+yvzsabiDuzDFOQKAm16FPvcAlw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":211487},"type":"module","_from":"file:agent-custody-state-0.5.8.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"tsc -p ../receipts/tsconfig.build.json && vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit"},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.8.tgz","_integrity":"sha512-XlB42GrRKVK9R4rK8uIDjpMDzi8TVGDSCItj2gxnf41vEFC3vUuuqQtBdFRwqS36OXwolcY33CRWhzcmkH1EgQ==","repository":{"url":"git+https://github.com/ch4r10t33r/agent-custody.git","type":"git","directory":"packages/state"},"_npmVersion":"10.9.4","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^4.5.4","@agent-custody/receipts":"0.5.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"mem0ai":"^3.1.8","vitest":"^5.0.0","typescript":"^7.0.2","@types/node":"^26.4.1","@getzep/zep-cloud":"^3.28.0","@electric-sql/pglite":"0.5.8"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/state_0.5.8_1788917147894_0.8274507093464682","host":"s3://npm-registry-packages-npm-production"}},"0.5.9":{"name":"@agent-custody/state","version":"0.5.9","description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/ch4r10t33r/agent-custody.git","directory":"packages/state"},"publishConfig":{"access":"public"},"type":"module","bin":{"agent-custody-memory":"dist/cli.js"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.build.json","typecheck":"tsc -p ../receipts/tsconfig.build.json && tsc --noEmit","test":"tsc -p ../receipts/tsconfig.build.json && vitest run"},"engines":{"node":">=22"},"dependencies":{"@agent-custody/receipts":"0.5.9","@modelcontextprotocol/sdk":"^1.30.0","zod":"^4.5.4"},"devDependencies":{"@electric-sql/pglite":"0.5.8","@getzep/zep-cloud":"^3.28.0","@types/node":"^26.4.1","mem0ai":"^3.1.8","typescript":"^7.0.2","vitest":"^5.0.0"},"peerDependencies":{"pg":">=8"},"peerDependenciesMeta":{"pg":{"optional":true}},"_id":"@agent-custody/state@0.5.9","bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"homepage":"https://github.com/ch4r10t33r/agent-custody#readme","_integrity":"sha512-Uwlkf4z3dtarYA9u7lFuBwAY2+d4LzIiPUi6cHW5VSEbD48RBWGEi4DfsfV5armeknG9NnkJ7uD99PAjDcnyXQ==","_resolved":"/Users/partha/agentic-network/agent-custody/packages/state/agent-custody-state-0.5.9.tgz","_from":"file:agent-custody-state-0.5.9.tgz","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-Uwlkf4z3dtarYA9u7lFuBwAY2+d4LzIiPUi6cHW5VSEbD48RBWGEi4DfsfV5armeknG9NnkJ7uD99PAjDcnyXQ==","shasum":"22bf197fc3e0d42d9e330d541bcd41fbd6f8c21b","tarball":"https://registry.npmjs.org/@agent-custody/state/-/state-0.5.9.tgz","fileCount":31,"unpackedSize":211487,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDCbHFzGq25IKNXIaHU8kWrIuBBZyz/2iZNY3OKovgz3AIhAPT9EsYDQ4XDenHkIZNLd3pxZyOA+06fUQHI2Q+a2P8C"}]},"_npmUser":{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"},"directories":{},"maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/state_0.5.9_1789026674669_0.7757474390517038"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-06T05:01:29.211Z","modified":"2026-09-10T07:51:15.091Z","0.1.0":"2026-09-06T05:01:29.530Z","0.1.1":"2026-09-06T07:05:50.829Z","0.1.2":"2026-09-07T05:01:47.810Z","0.1.3":"2026-09-07T07:42:06.831Z","0.1.4":"2026-09-07T08:12:21.494Z","0.1.5":"2026-09-07T08:59:25.365Z","0.1.6":"2026-09-07T11:00:21.159Z","0.1.7":"2026-09-07T13:13:51.414Z","0.1.8":"2026-09-07T14:12:04.834Z","0.1.9":"2026-09-07T17:13:26.885Z","0.2.0":"2026-09-07T17:54:56.577Z","0.3.0":"2026-09-08T03:35:21.539Z","0.4.0":"2026-09-08T06:41:35.543Z","0.5.0":"2026-09-08T07:08:45.455Z","0.5.1":"2026-09-08T09:24:24.950Z","0.5.2":"2026-09-08T14:28:03.915Z","0.5.3":"2026-09-08T14:34:17.276Z","0.5.4":"2026-09-08T16:34:59.815Z","0.5.5":"2026-09-08T16:41:51.364Z","0.5.6":"2026-09-08T18:38:05.821Z","0.5.7":"2026-09-09T01:09:22.625Z","0.5.8":"2026-09-09T01:25:48.035Z","0.5.9":"2026-09-10T07:51:14.811Z"},"bugs":{"url":"https://github.com/ch4r10t33r/agent-custody/issues"},"license":"Apache-2.0","homepage":"https://github.com/ch4r10t33r/agent-custody#readme","repository":{"type":"git","url":"git+https://github.com/ch4r10t33r/agent-custody.git","directory":"packages/state"},"description":"Governed memory for AI agents: a fact ledger with provenance, valid time, rollback, lineage, certified forget, and a store that is a JSONL file, SQLite, or Postgres, built on @agent-custody/receipts","maintainers":[{"name":"ch4r01teer41","email":"partha@charioteerconsulting.com"}],"readme":"# @agent-custody/state\n\nGoverned memory for AI agents. Not a vector store: a ledger of facts where every write cites the receipt that caused it, carries valid time and transaction time, and can be superseded or retracted without losing what the agent believed at any earlier moment.\n\nRetrieval stays with whatever store you already use. This package owns provenance, time, and undo.\n\n## Getting started\n\n```bash\nnpm install @agent-custody/state           # or bun add, pnpm add\n```\n\nPublished on npm as [`@agent-custody/state`](https://www.npmjs.com/package/@agent-custody/state): compiled JavaScript with type declarations, Node 22 or later, Apache-2.0.\n\n```ts\nimport { Ledger } from \"@agent-custody/state\";\n\n// a JSONL file, a .sqlite path, or \"postgres://…\" with the pg package installed; the ledger is asynchronous\nconst ledger = new Ledger(\"./state/ledger.jsonl\");\nconst a = await ledger.assert({ subject: \"acct:42\", predicate: \"plan\", value: \"pro\", space: \"org\", actor: \"agent:support\", source: { receiptId } });\nawait ledger.assert({ subject: \"acct:42\", predicate: \"plan\", value: \"enterprise\", space: \"org\", actor: \"agent:sales\", supersedes: a.fact.factId });\nawait ledger.retract({ factId: a.fact.factId, actor: \"user:admin\", reason: \"poisoned by a tool result\" });\nawait ledger.asOf({ validAt: \"2026-09-01T00:00:00Z\", txAt: \"2026-09-01T00:00:00Z\" });\n```\n\nSix runnable examples, all executed by the test suite. [06-actions-on-beliefs.ts](examples/06-actions-on-beliefs.ts) puts memory and a payments API behind one gateway and finds the refund in a belief's blast radius. [05-blast-radius.ts](examples/05-blast-radius.ts) walks from a retracted belief to everything that relied on it. [04-evals.ts](examples/04-evals.ts) scores the ledger and a naive store on the same memory incidents. [03-memory-behind-the-gateway.ts](examples/03-memory-behind-the-gateway.ts) runs the memory server as the gateway's upstream. [01-ledger.ts](examples/01-ledger.ts) walks through a wrong write and its undo. [02-receipt-to-belief.ts](examples/02-receipt-to-belief.ts) runs the whole loop with the receipts package: a tool call gets a signed receipt, the receipt is verified, the belief taken from it is recorded citing the receipt, and later retracted. Run them with `node examples/<file>` from this directory, after `bun run build` at the repository root.\n\n## The memory server\n\nThe ledger as MCP tools, meant to run as the upstream of the receipts gateway. Behind the gateway, every write and read is checked by the Cedar policy and gets a signed receipt, and two things reach this server in the call's `_meta` that no caller can supply: the receipt id, which becomes the fact's `source`, and the agent from the signed delegation grant, which becomes the fact's `actor`. A caller's own claims about either are ignored.\n\n```bash\nagent-custody-memory serve --ledger ./ledger.jsonl        # over stdio; refuses calls that did not come through the gateway\n```\n\nIn the gateway's config, the memory server is the upstream, and the grant names the memory tools as scopes:\n\n```json\n{ \"upstream\": { \"command\": \"agent-custody-memory\", \"args\": [\"serve\", \"--ledger\", \"/abs/path/ledger.jsonl\"] }, ... }\n```\n\n| tool | does | policy sees |\n| --- | --- | --- |\n| `memory.write` | records a belief in a space, optionally superseding an earlier fact | `context.args.space`, `subject`, `predicate`, `value` |\n| `memory.read` | the facts believed at a moment, by space, subject, predicate, valid time, transaction time | the query |\n| `memory.confirm` | lifts a quarantined fact to attested; accepted only through the gateway | `factId` |\n| `memory.retract` | undoes a belief, keeping it visible to questions about the past | `factId`, `reason` |\n| `memory.forget` | erases the value from the ledger and every store, keeping the digest; the receipt is the certificate | `factId`, `reason` |\n| `pack` (CLI) | one fact's history, receipts, holds, blast radius, and forget certificate as one signed artefact, verifiable offline | |\n| `memory.hold`, `memory.release` | legal hold: while it stands the fact cannot be forgotten by request or sweep | `factId`, `reason` |\n| `memory.sweep` | retention: forget what was learned before an instant, in a space or all, skipping held facts, reaching every store | `before`, `space`, `reason` |\n| `memory.get` | one fact by id in any state, for the gateway's policy lookups | `factId` |\n| `memory.history` | every event that touched a fact | `factId` |\n\n**Quarantine.** Every fact carries a provenance: `claimed`, `attested`, or `verified`. A write that came through the gateway is `attested`: its actor is the agent named in a human-signed grant and its receipt exists. A write that arrived any other way is `claimed`, and claimed facts are quarantined: `memory.read` leaves them out unless the caller asks for `includeClaimed`, and the policy can refuse that. `memory.confirm`, accepted only through the gateway, lifts a claimed fact to attested with its own receipt and transaction time, so \"was this fact still in quarantine on Tuesday\" is answerable. A tool result an SDK-only agent wrote down cannot become something the rest of the fleet believes until an attested party says so. Over stdio the server has one client; shared over HTTP, below, gateways and direct writers feed one ledger and quarantine does its job.\n\n**Value-level quarantine.** An attested write still carries whatever value the agent chose to write. When the agent can say where a value came from, the gateway's own observation decides. A `memory.write` may name `evidence: { fact, path }`, a fact the gateway fetched itself for this call through its fact-lookup mechanism (a CRM record, say) and optionally a field in it. The memory server compares the value with the observation: equal, and the fact is written as `verified`, the third provenance level, where both the actor and the value are vouched for by something other than the agent; different, and the write is refused. A policy can require evidence for a space (`context.args has evidence`), and `memory.read` with `requireVerified` returns only verified facts. The test suite runs this with a CRM lookup behind the same gateway as the memory server.\n\n**Policy over the fact being changed.** The gateway can look up the fact a write supersedes or a retraction targets before deciding, through its fact-lookup mechanism and the `memory.get` tool, and the policy then sees that fact's space, actor, and provenance as observed facts. This is the second half of trust tiers: a self-reported note in the org space can be superseded by anyone the grant allows, while an attested org fact cannot be displaced or retracted except by whoever the policy names. In the gateway config:\n\n```json\n\"facts\": [\n  { \"name\": \"target\", \"tool\": \"memory.get\", \"args\": { \"factId\": \"$args.supersedes\" }, \"forTools\": [\"memory.write\"], \"optional\": true },\n  { \"name\": \"target\", \"tool\": \"memory.get\", \"args\": { \"factId\": \"$args.factId\" }, \"forTools\": [\"memory.retract\"] }\n]\n```\n\n```cedar\nforbid(principal, action in [Action::\"memory.write\", Action::\"memory.retract\"], resource)\nwhen { context.facts has target && context.facts.target.space == \"org\" && context.facts.target.provenance == \"attested\" };\n```\n\nThe lookup for writes is optional, so a write that supersedes nothing needs no lookup; the one for retractions is required. The denial receipt records the fact the policy saw, observed by the gateway. The test suite runs exactly this configuration.\n\n**Attested executions.** Started with `--key memory.key`, the server signs every result for the receipt the gateway is issuing. A verifier given `memory.pub` then reports the execution of each memory call as attested by the memory server, not only observed by the gateway; the test suite verifies a write this way.\n\n**Shared over HTTP.** `agent-custody-memory serve --ledger ./ledger.jsonl --http --port 8790 --token-env MEMORY_TOKEN` serves the same tools over Streamable HTTP, so several gateways, one per agent host, and, with `--allow-direct`, SDK-only agents share one ledger. That is the deployment quarantine was built for: writes arriving through a gateway are attested, writes arriving directly are claimed and hidden until a gateway confirms them, and the ledger tells them apart. A gateway reaches it with `\"upstream\": { \"url\": \"http://127.0.0.1:8790/mcp\", \"tokenEnv\": \"MEMORY_TOKEN\" }` in its config. Bind wider than loopback only behind the token. The test suite runs exactly this: one gateway writer, one direct writer, one ledger.\n\n[Writing policies](../receipts/docs/policies.md#policies-for-memory) in the receipts guide has six tested policies for the memory tools, from confining an agent to its team's space to a complete support-agent policy. Trust tiers are Cedar policies over the space and, through `includeClaimed`, over quarantine: `permit(principal, action == Action::\"memory.write\", resource) when { context.args.space == \"team:support\" };` lets this agent write team memory and nothing else. A read's receipt carries, as `observed`, the exact facts returned, so the ids the agent relied on are already on the record.\n\n`--allow-direct` lets the server take calls without a gateway; then `source.receiptId` is null and `actor` is whatever the caller said, recorded as such. [examples/03-memory-behind-the-gateway.ts](examples/03-memory-behind-the-gateway.ts) runs the whole loop, including a denied write and a retraction that cites its own receipt.\n\n## Certified forget\n\n\"Certified\" means the receipt certifies what was done, not that the value exists nowhere. What forget reaches is the ledger and the stores with adapters, and it reports what each of them answered. It does not reach caches, a model's context window, application logs, replicas, backups, warehouses fed by export, or any store without an adapter. On Postgres the erased row image stays in the table until the store's `VACUUM FULL` runs, which it does after each forget unless told not to ([the ledger](#the-ledger)). Say all of that plainly to whoever is relying on it, and read the per-store status in the result before calling anything gone.\n\nA deletion demand is different from a correction. Retract keeps the record; forget erases the value. `memory.forget` removes the fact's value from the ledger file itself, stops believing the fact, and removes it from every store behind the server. What it keeps in place of the value is a choice, recorded on the event as `digestKind`: a plain `sha256` of the value, which lets the ledger prove what it erased but is guessable for short values such as an email by anyone holding the file; an `hmac-sha256` under a forget key the server holds outside the file (`serve --forget-key-env NAME`), which proves the same to anyone shown the key and nothing to anyone else; or `none`, with `keepDigest: false`, for the case where counsel wants nothing derived from the value retained. Use the keyed form unless you have a reason not to. The result says exactly what happened: erased from the ledger, removed from which stores, still held by which, with the digest, the actor, and the reason.\n\n**Retention and legal hold.** `memory.sweep` forgets every fact the ledger learned of before an instant, in one space or all, and removes each from every store; it is retention as a receipted call, with the receipt as the record of what was erased. Retention windows live in the server: `serve --retention 'org=P365D,team:*=P90D,user:*=P30D'`, ISO 8601 durations by space pattern, and a sweep with no `before` uses them per space. To run it on a schedule without a daemon, `agent-custody-memory sweep --via retention-gateway.json --reason \"quarterly retention\"` spawns that gateway and calls `memory.sweep` through it, so the sweep runs as the principal named in the gateway's grant, a retention job with the single scope `memory.sweep`, and its receipt records when retention ran, by whom, what it erased, and what a hold kept. Any cron, systemd timer, or CI schedule drives that one command. `memory.hold` puts a legal hold on a fact: while it stands, neither a deletion request nor a sweep can forget it, and `memory.release` lifts it. Holds and releases are events with actor, reason, and receipt, so the history of a fact shows the hold as plainly as the write. `agent-custody-memory sweep --ledger ... --before ... --reason ...` runs retention on the ledger file alone, for ledgers with no stores behind them.\n\n**Removal is verified, not assumed.** A delete by id and a search index catching up are different moments. After every retraction, forget, or sweep, the server asks each store's own search whether the fact still surfaces, a few times with backoff, and records the outcome per store in the result and so in the receipt: `verified` (the store's search no longer finds it), `stillIndexed` (it still does, after the retries), `unverified` (the store cannot be asked, or the adapter has no search), or `failed` (the removal itself failed). Mem0 and Zep both verify through their search APIs; the tests drive the real clients against indexes that lag by a configurable number of searches. A certificate that says `stillIndexed` is an honest certificate; run forget again later, or read it as the store's problem to fix.\n\n**The pack.** `agent-custody-memory pack --ledger ... --receipts ... --fact <id> --out pack.json --sign keys/pack.key` gathers everything about one fact into one signed artefact: its history with the receipt that produced each event, its holds and releases, its blast radius with every downstream receipt, and, if it was forgotten, the forget certificate with what each store answered. `pack --verify pack.json --key keys/pack.pub --issuer-key keys/gateway.pub --principal-key keys/principal.pub` checks the pack's signature and digest, every receipt inside it against the gateway's keys, that every event's receipt is present, and that the forget receipt names this fact and records the erasure. Touch one receipt inside and the whole pack fails. It is the artefact counsel attaches to a ticket; the reviewer needs the two public keys and nothing from you.\n\nThe certificate is the receipt. Through the gateway, `memory.forget` is a receipted call whose result the gateway observed, so the signed, logged receipt records that the erasure happened, who asked for it, and what the stores answered. Hand that receipt to whoever demanded the deletion; anyone with the gateway's public key can verify it.\n\nReceipts are the other place a value lives: the receipt that recorded the write carries it in its request arguments, and the receipts of reads carry it in their results, signed and in a Merkle log. The receipts package's `prune` command is retention for the log: it replaces older leaves with their hashes, so every root and every proof still verifies while the content is gone, and removes the pruned receipts' bundle files. Run it on the same schedule as the sweep.\n\n## Blast radius\n\nWhen a belief turns out wrong, the next question is what relied on it. Two records answer it together. Every gateway receipt carries `consumed`: the fact ids the agent had been shown, through the gateway, before that call, which the memory server declares on each read. Every fact in the ledger carries the receipt that wrote it. Walking forward from a fact through those two links gives every later call and every belief written in those calls, transitively, and whether the root was retracted and which derived beliefs are still believed.\n\n```bash\nagent-custody-memory blast --ledger ./ledger.jsonl --receipts ./receipts --fact <factId>\n```\n\n```\nfact 3f2a…: acct:42 plan = \"enterprise\" (space team:support, by support-agent, attested)\nretracted at 2026-09-07T10:12:04.118Z by support-agent: CRM sync bug: account is on the free plan\n3 call(s) made after the agent was shown it:\n  2026-09-07T10:12:03.902Z  memory.write       executed  receipt 7c1e…\n  ...\n2 belief(s) written in those calls, 2 still believed:\n  acct:42 discount = \"20%\"  fact 9b04…  STILL BELIEVED\n  acct:42 support_tier = \"priority\"  fact e77d…  STILL BELIEVED\n```\n\nWith the gateway fronting several upstreams, memory and the tools the agent acts with, the radius reaches the actions too: a refund issued after the agent read a belief carries that belief's id and is listed. [examples/06-actions-on-beliefs.ts](examples/06-actions-on-beliefs.ts) shows it.\n\nIt is an upper bound by design: a call made after the agent had seen the fact is in the radius whether or not the agent used it, because no receipt can prove what a model attended to. What it never misses is the thing that matters, a downstream action or belief that did depend on the fact. [examples/05-blast-radius.ts](examples/05-blast-radius.ts) runs the whole loop.\n\n## Explain one action\n\nThe question a security owner asks first is not about a fact but about an action: *what is refund 183722, and can I trust the answer?* `agent-custody-memory explain --receipts receipts --receipt <id> --ledger ledger.sqlite --issuer-key keys/gateway.pub --principal-key keys/principal.pub` answers it in the order it is asked:\n\n```\nWHO                          support-agent (attested, named in a signed grant)\nWHO AUTHORIZED IT            user_456, grant signed by key bfa1c0d2e3f4, valid 2026-09-08T08:00:00.000Z to 2026-09-08T16:00:00.000Z\nWHAT WAS ALLOWED             tools customer.lookup, stripe.refund\n                             policy 9c1d2e3f4a5b decided allow\nWHAT THE AGENT SAW           customer = {\"verified\":true,\"plan\":\"pro\"} (fetched by the gateway via customer.lookup)\n                             1 belief(s) shown before this call:\n                               acct:42 plan = \"enterprise\" [0b83d822]\nWHAT IT DID                  stripe.refund {\"customer_id\":\"cust_123\",\"amount\":845000} -> executed\nWHY                          the policy permitted it\nWHAT EVIDENCE                receipt 7f2e…, leaf 41 of a log whose head is signed by 3a9b0c1d2e3f\n                             authorization committed as leaf 40, before the call was forwarded\nCAN I VERIFY IT              VERIFIED, 23 checks\nDID ANYTHING DEPEND ON THIS  1 belief(s) written in this call, 3 later call(s) made after seeing them, 2 belief(s) derived\nWHAT NEEDS REVERSAL          2 belief(s) still believed, and 3 later call(s) to review\n```\n\nThe first eight lines come from the receipt alone and work without a ledger; the last two are answered from the ledger, and without one they say `unknown without a ledger` rather than pretending nothing depended on the call. `--out action.json --sign keys/pack.key` writes the same answers as one signed action pack with the receipt and every downstream receipt inside it, and `explain --verify action.json --key keys/pack.pub --issuer-key ... --principal-key ...` checks the pack's signature and digest, the receipt, every downstream receipt, and that the written beliefs cite this receipt. Touch one receipt inside and the pack fails. The custody pack below is the same artefact seen from a fact instead of an action.\n\n**The review page.** `agent-custody-memory review --receipts receipts --ledger ledger.sqlite --issuer-key keys/gateway.pub --principal-key keys/principal.pub` serves the same answers as pages on loopback: an index of every receipt with when, tool, outcome, agent, principal, producer, and its verdict, and one page per receipt with the ten answers, the verification report, and the receipt itself to download. `--out <dir>` writes the same as static files for a case file or a shared drive. It runs where the receipts are, because nobody else holds them; it has no login of its own, so expose it only behind one you already have.\n\n## Write-through to the stores you already use\n\nThe ledger is not a retrieval store, and it does not try to be. `src/stores.ts` puts it under the ones teams already run: a fact written through the memory server also lands in every configured store, with its custody metadata (fact id, space, actor, provenance, receipt id), the store's own id is recorded on the fact, and a retraction reaches the store by that id. Certified forget will be built on this: a deletion is only real once it has reached the stores that serve recall. For teams whose recall is a pgvector table, `pgvectorStore` writes the fact's text, its embedding from the function you already use, and its custody metadata as one row keyed by the fact id, and verifies a removal with the same nearest-neighbour query a retrieval call runs.\n\n```ts\nimport { MemoryClient } from \"mem0ai\";\nimport { ZepClient } from \"@getzep/zep-cloud\";\nimport { Ledger, createMemoryServer, mem0Store, zepStore } from \"@agent-custody/state\";\n\nconst stores = [\n  mem0Store(new MemoryClient({ apiKey: process.env.MEM0_API_KEY! }), { userId: \"user_42\" }),   // infer is off: the memory is the fact, verbatim\n  zepStore(new ZepClient({ apiKey: process.env.ZEP_API_KEY! }), { userId: \"user_42\" }),         // or { graphId } for a shared graph\n  pgvectorStore(pool, { embed, dimensions: 1536, table: \"agent_memories\" }),                    // your Postgres, your embedding function\n];\ncreateMemoryServer(new Ledger(\"./ledger.jsonl\"), { stores });\n```\n\nOrder matters and is fixed: the ledger's checks run first, so a write it would refuse never reaches a store; the stores are written next, so their ids can be recorded; the ledger appends last. A store that refuses the write fails the write and nothing is recorded anywhere. On retraction the ledger goes first, since custody must not depend on a store being up, and a store that fails to remove is named in the error so the caller knows recall may still serve the value. The adapters are typed structurally and carry no runtime dependency on either vendor; the tests drive the real `mem0ai` and `@getzep/zep-cloud` clients against fake endpoints, offline.\n\n## Scoring memory mutations\n\n`src/evals.ts` is a harness that scores a memory system on what goes wrong after writes, not on recall. A scenario is a script of writes, reads, supersessions, and retractions with the value a correct system returns at each read. The score counts stale reads (a value served after a correction was known), contradictions (two values for one subject and predicate at once), blast radius (reads that served a write the scenario marks as bad), and correct reads. Any system behind the small `MemoryUnderTest` interface can be scored; this ledger and a naive overwrite store ship as the two reference points, and [examples/04-evals.ts](examples/04-evals.ts) prints both reports side by side.\n\n```ts\nimport { Ledger, ledgerUnderTest, runAll, SCENARIOS, formatReport } from \"@agent-custody/state\";\nconsole.log(formatReport(await runAll(ledgerUnderTest(new Ledger(\"./ledger.jsonl\")), SCENARIOS)));\n```\n\nFrom the shell, on a schedule:\n\n```bash\nagent-custody-memory eval --baseline                                     # built-in scenarios, ledger and a naive store side by side\nagent-custody-memory eval --scenarios incidents.json --sign keys/eval.key --out report.json   # your own incidents, signed report\nagent-custody-memory eval --verify report.json --key keys/eval.pub       # what a reviewer runs\n```\n\nA scenario file is `{ \"version\": \"0.1\", \"scenarios\": [{ \"name\", \"ops\": [...] }] }` with the same write, read, and retract ops as the built-ins; every read carries `expect`, null meaning nothing. The file is validated and a bad one names the offending op. The signed report is an in-toto statement over the scores, bound to a digest of the scenarios it ran, in the same envelope format as receipts; `eval --verify` checks the signature and the digest. `eval` exits non-zero when the ledger scores below perfect on the scenarios it was given, so a cron job that runs it fails loudly when a change regresses memory behaviour.\n\n## The ledger\n\n`src/ledger.ts` keeps an append-only log of events. It holds none of them itself: every question is a query to a store, so the store decides how large a ledger can be and who shares it. A store answers four questions, everything in order (export, audits), everything about the facts matching a filter (a bitemporal read), everything that touched one fact (its history and its checks), and which spaces exist (retention), and it does three things: append, replace one assert in place (forget), and compact after erasures. Three stores ship, and the whole ledger suite runs against each of them, so they answer identically.\n\n**JSONL** is the default: one event per line, readable by anyone, the file you copy for an audit. It answers from memory, which is fine to tens of thousands of events. **SQLite**, chosen by a path ending in `.sqlite` or `.db`, is for durability on one machine: transactional writes with write-ahead logging, an in-place forget that overwrites the erased value (secure delete, then a truncating checkpoint so nothing lingers in the write-ahead log), and every query answered by an index on fact, time, space, subject, predicate, and supersession. Node ships the SQLite module, so there is no native dependency; a ledger written by an earlier version gets the index columns filled from its JSON the first time it is opened. Measured on a million-event ledger: open in 0.2 s, a subject read in about 1 ms, a fact's history in well under a millisecond, the spaces for a sweep in 2 ms. **Postgres**, chosen by a `postgres://` URL, is for a shared ledger: several memory servers on one table, in the database your security team has already approved, the same queries pushed down as SQL. It needs the `pg` package installed beside this one; `?table=custody.events` names the table and `?vacuum=false` skips the vacuum described below. In code, pass a `PostgresStore` around your own `pg` Pool, with whatever TLS and credentials you already use. The adapter is tested against the real Postgres engine in-process through PGlite, including that a forgotten value is absent from the database files, and checked by hand against Postgres 16.\n\nForget on Postgres is an `UPDATE`, and MVCC keeps the old row image in the table until vacuum. So after a forget or a sweep the store runs `VACUUM FULL` on the table, which rewrites it without the old image. That takes an exclusive lock for the rewrite; a very large ledger may set `vacuum: false` and run its own schedule, and the forget certificate then rests on that schedule. The write-ahead log, replicas, and backups keep their own copies for as long as their retention says; that is true of every database, and the honest reading of a forget certificate is that the live ledger no longer holds the value.\n\nChoose JSONL for one server process and for anything an auditor should read with `cat`. Choose SQLite when one machine serves the ledger over HTTP, when a crash between two writes must not cost you an event, or when a deletion demand must leave no trace of the value in the file. Choose Postgres when more than one server must share the ledger, or when the ledger belongs in the database you already operate. Warehouses are not stores: Snowflake and Databricks keep deleted rows for days by default and are built for scans, not one small write per agent call. Feed them with `agent-custody-memory export --ledger postgres://… --out ledger.jsonl`, which writes the auditable JSONL from any store, and query the ledger where your compliance team already works.\n\nThe log holds these kinds of event.\n\n- **assert** creates a fact: subject, predicate, value, the space it lives in (a person, a team, an org), the actor that wrote it, the source receipt id if the write went through a receipts producer, and the valid-time interval. An assert may **supersede** an earlier fact, which ends that fact's validity where the new one begins.\n- **retract** says a fact should never have been believed. This is the undo. The record stays, so queries about earlier moments still see the fact, and anything the retracted fact had superseded is believed again.\n\nTwo clocks, kept apart on purpose:\n\n| | question it answers | set by |\n| --- | --- | --- |\n| valid time | was this true in the world at T | the writer, defaults to now |\n| transaction time | did the ledger know it at T | the ledger, never the writer |\n\n`asOf({ validAt, txAt, space, subject, predicate })` returns the facts believed at a moment. Setting both times to the same instant answers \"what did the agent believe on Tuesday\", including beliefs later retracted. `history(factId)` returns every event that touched a fact.\n\nThe ledger refuses to supersede a fact that is unknown, already superseded, or retracted, and refuses a replacement whose validity starts before the fact it replaces.\n\n## Layout\n\n```\nsrc/ledger.ts   the fact record, the event kinds, as-of queries, supersession, retraction, forget, holds, sweeps\nsrc/storage.ts  the store interface and its three stores: JSONL (default, auditable), SQLite (indexed, one machine), Postgres (shared); chosen by path or URL\nsrc/server.ts   the ledger as MCP tools; source and actor taken from the gateway's _meta\nsrc/http.ts     the memory server over Streamable HTTP with bearer auth, for a shared ledger\nsrc/explain.ts  one action explained: the ten answers from a receipt and the ledger, and the signed action pack\nsrc/review.ts   the review page: the explain output as pages, served on loopback or written as files\nsrc/pack.ts     the custody pack: build, sign, verify, format\nsrc/cli.ts      agent-custody-memory serve (stdio or --http, with --retention and --forget-key-env), sweep (ledger-only or --via a gateway), eval, explain, review, pack, export, blast\nsrc/blast.ts    blast radius: from receipts' consumed facts and the ledger's source receipts, forward\nsrc/stores.ts   write-through adapters: Mem0, Zep, and pgvector, and the Store interface for others\nsrc/evals.ts    the memory-mutation harness: scenarios, scoring, report\nsrc/evals-ledger.ts  the ledger and a naive overwrite store behind the harness interface\nsrc/evals-file.ts    scenario files, validated; signed eval reports and their verification\nsrc/index.ts    public surface\nexamples/       runnable walkthroughs, each ends with OK and is run by the test suite\ntest/           one test per question a platform owner asks after a memory incident\ntsconfig.build.json  emits dist/ for consumers; the repo itself runs the .ts directly\n```\n\n## Plan\n\n**Done**\n\n- Bitemporal fact ledger with supersession, retraction, as-of and history queries, persisted as JSONL, SQLite, or Postgres behind one store interface that answers every query from an index, with export back to JSONL.\n- The memory server: the ledger as MCP tools behind the receipts gateway, with the source receipt id and the attested actor supplied by the gateway, policy over spaces, and a denial receipt for every refused write.\n- Forget digests are keyed under a server-held secret, or absent on request, so an erased value cannot be guessed back from the file.\n- Retention windows per space in the server, sweeps that default to them, and a `sweep --via` trigger that runs retention through a gateway as a named principal, on any timer.\n- The review page: the explain output as pages for the reviewer who will not open a terminal, an index of every receipt with its verdict and one page per receipt, served on loopback or written as static files.\n- Explain one action: from a receipt id, who, who authorized it, what was allowed, what the agent saw, what it did, why, the evidence, whether it verifies, what depended on it, and what needs reversal; the same as a signed action pack that carries every downstream receipt.\n- The custody pack: a fact's history with receipts, holds, blast radius, and forget certificate as one signed artefact, verified as a whole.\n- Removal verification: after a retraction, forget, or sweep the server asks each store's search whether the value still surfaces and records verified, stillIndexed, unverified, or failed per store, in the receipt.\n- Retention and legal hold: a receipted sweep forgets what was learned before an instant and reaches the stores; a hold refuses forget and sweep until released, as events on the fact's history.\n- Value-level quarantine: a write may cite a fact the gateway fetched itself; the value must match it and the fact is then `verified`, the provenance level above attested, or the write is refused.\n- Attested executions: with a key, the memory server signs its results for the gateway's receipt, so a verifier holding its public key sees memory calls as attested.\n- The memory server over HTTP: one ledger shared by several gateways and direct writers, bearer-token auth, quarantine live.\n- Certified forget: `memory.forget` erases a value from the ledger file keeping its digest, stops believing it, removes it from every store, and reports exactly what happened; the gateway's receipt of that call is the certificate.\n- Policy over provenance: the gateway looks up the fact a write supersedes or a retraction targets, so policy decides on its space, actor, and provenance; a claimed fact can be displaced, an attested org fact cannot.\n- Consumed facts and blast radius: the memory server declares the facts it serves, the gateway records them on every later receipt, and `blast` walks from a fact to every downstream call and derived belief, transitively, with its retraction status.\n- Write-through to pgvector: the fact's text, embedding, and custody metadata as one row in the Postgres a team already runs, keyed by the fact id; removal verified by the same nearest-neighbour query recall runs; tested against Postgres with the extension in Docker.\n- Write-through adapters for Mem0 and Zep: every write lands in the store with custody metadata, the store id is recorded on the fact, retractions reach the store, and failures are ordered so nothing is half-recorded.\n- The eval CLI: built-in or custom scenario files, the naive baseline beside the ledger, a signed report a reviewer verifies, and a non-zero exit on regression, for cron.\n- The memory-mutation eval harness: stale reads, contradictions, blast radius, and correct reads over scripted incidents, scored the same way for the ledger and for anything behind the same interface.\n- Quarantine: facts carry `attested` or `claimed` provenance; claimed facts are hidden from reads by default and a gateway-only `memory.confirm` lifts them, as a recorded event.\n\n**Next, in the order it pays off**\n\n1. The hosted plane, behind early access: tenanted log, then memory, then reports and a control plane, with SSO, SCIM, residency, and SIEM export. [Issue #6](https://github.com/ch4r10t33r/agent-custody/issues/6).\n2. Write-through adapters for Letta, LangMem, and Cognee, one per user who asks. [Issue #4](https://github.com/ch4r10t33r/agent-custody/issues/4).\n\n","readmeFilename":"README.md"}