{"_id":"@agent-grant-protocol/verifier","_rev":"7-1dd672bf55b394060f3f3205c060cf83","name":"@agent-grant-protocol/verifier","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.1":{"name":"@agent-grant-protocol/verifier","version":"0.1.1","license":"Apache-2.0","_id":"@agent-grant-protocol/verifier@0.1.1","maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/verifier-ts#readme","bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"dist":{"shasum":"50fff592b30159e4c8b59053eae06768300bf8fc","tarball":"https://registry.npmjs.org/@agent-grant-protocol/verifier/-/verifier-0.1.1.tgz","fileCount":48,"integrity":"sha512-gghi6cqArGCcNrux9hBvz2WqYSh0c9Gh7jfhqBzec/RkfNJ2ADy43cr2jw9AwOSFXGQKKppKM8Rbv5qWFCN5+g==","signatures":[{"sig":"MEUCIH5dEUX66VMSo7TukRrP3G5TZV0j6X7vOWGd/zROz55DAiEAkPCIBWVJk81aA4dNF0W4J6xiGSzpZ/nOfV+e0T4ckrY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":127361},"main":"dist/src/index.js","type":"module","types":"dist/src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js"},"./vectors/*":"./vectors/*","./keys/keyring.json":"./keys/keyring.json"},"gitHead":"307a6f868eb55404ea64d3731944829fea685503","scripts":{"test":"npm run build && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json","prepack":"npm run build","prepublishOnly":"npm test"},"_npmUser":{"name":"inasens","email":"ops@rawket.io"},"deprecated":"Please use the latest release","repository":{"url":"git+https://github.com/agent-grant-protocol/agp.git","type":"git","directory":"packages/verifier-ts"},"_npmVersion":"11.12.1","description":"TypeScript verifier for Agent Grant Protocol v0.1 grant+jwt tokens.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","dependencies":{"jose":"^5.10.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.3","@types/node":"^20.19.2"},"_npmOperationalInternal":{"tmp":"tmp/verifier_0.1.1_1783303397432_0.5622443770213601","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agent-grant-protocol/verifier","version":"0.1.2","license":"Apache-2.0","_id":"@agent-grant-protocol/verifier@0.1.2","maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/verifier-ts#readme","bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"dist":{"shasum":"9e9d983e61c12f3d5f7f1f3cd17c3d8c8da3fa88","tarball":"https://registry.npmjs.org/@agent-grant-protocol/verifier/-/verifier-0.1.2.tgz","fileCount":48,"integrity":"sha512-s8b3UoTmw+degtJNQIecnRiXSJ4rDyXjvSIiR+ZkIyV7Ti6JqBHUTNF4WkO6rdVgXKQis+XugPylzK+qm2UKRA==","signatures":[{"sig":"MEUCIQCzHnG5njPkWdDWOKpC8fUUliLkZKF5tfnWEX4jJciyjgIgARKZCisMi9bUe4r2X7Vd2XG17ZntLm78TkN7MPDcRkg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":129404},"main":"dist/src/index.js","type":"module","types":"dist/src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js"},"./vectors/*":"./vectors/*","./keys/keyring.json":"./keys/keyring.json"},"gitHead":"dd732c26ee9c65b65c94736dd4ad2c9e0fc0e456","scripts":{"test":"npm run build && node --test dist/test/*.test.js","build":"tsc -p tsconfig.json","prepack":"npm run build && npm run vectors:sync","vectors:sync":"node scripts/sync-vectors.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"inasens","email":"ops@rawket.io"},"repository":{"url":"git+https://github.com/agent-grant-protocol/agp.git","type":"git","directory":"packages/verifier-ts"},"_npmVersion":"11.12.1","description":"TypeScript verifier for Agent Grant Protocol v0.1 grant+jwt tokens.","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","dependencies":{"jose":"^5.10.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.8.3","@types/node":"^20.19.2"},"_npmOperationalInternal":{"tmp":"tmp/verifier_0.1.2_1783352774915_0.7489690087500427","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agent-grant-protocol/verifier","version":"0.1.3","type":"module","description":"TypeScript verifier for Agent Grant Protocol v0.1 grant+jwt tokens.","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/agent-grant-protocol/agp.git","directory":"packages/verifier-ts"},"homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/verifier-ts#readme","bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"main":"dist/src/index.js","types":"dist/src/index.d.ts","exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js"},"./vectors/*":"./vectors/*","./keys/keyring.json":"./keys/keyring.json"},"publishConfig":{"access":"public"},"sideEffects":false,"engines":{"node":">=18"},"scripts":{"build":"tsc -p tsconfig.json","vectors:sync":"node scripts/sync-vectors.mjs","prepack":"npm run build && npm run vectors:sync","prepublishOnly":"npm test","test":"npm run build && node --test dist/test/*.test.js"},"dependencies":{"jose":"^5.10.0"},"devDependencies":{"@types/node":"^20.19.2","typescript":"^5.8.3"},"gitHead":"c5e59c60d8915225a21ab8527fc795bfc4cd5911","_id":"@agent-grant-protocol/verifier@0.1.3","_nodeVersion":"24.15.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-2ykdxM7Q7/uUOMC+rYHOylepOwvCYYUPPSXCUyVInSri0tlKeDNcx1wI7yy1zw2x7cXGEKzbkskSRoU6/beYAw==","shasum":"04d94efd4c0da3d921b69b6303402e1199ad037b","tarball":"https://registry.npmjs.org/@agent-grant-protocol/verifier/-/verifier-0.1.3.tgz","fileCount":48,"unpackedSize":130236,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC/Z6kQEDKrAeHCti3oyJUHHaczmUmpGdA36uGrEYszDQIgXS8XowWvGuAIbqrb/y5606IeN6e8FbeXDn0vt6Iza0U="}]},"_npmUser":{"name":"inasens","email":"ops@rawket.io"},"directories":{},"maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/verifier_0.1.3_1783461852825_0.29864315205331304"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-06T02:03:17.264Z","modified":"2026-07-07T22:04:13.137Z","0.1.0":"2026-07-05T02:26:44.434Z","0.1.1":"2026-07-06T02:03:17.574Z","0.1.2":"2026-07-06T15:46:15.070Z","0.1.3":"2026-07-07T22:04:12.971Z"},"bugs":{"url":"https://github.com/agent-grant-protocol/agp/issues"},"license":"Apache-2.0","homepage":"https://github.com/agent-grant-protocol/agp/tree/main/packages/verifier-ts#readme","repository":{"type":"git","url":"git+https://github.com/agent-grant-protocol/agp.git","directory":"packages/verifier-ts"},"description":"TypeScript verifier for Agent Grant Protocol v0.1 grant+jwt tokens.","maintainers":[{"name":"inasens","email":"ops@rawket.io"}],"readme":"# Agent Grant Verifier\n\nTypeScript verifier for Agent Grant Protocol v0.1 `grant+jwt` tokens.\n\nThe package is intentionally small and dependency-light so a seller-side developer can verify an AGP grant from any compliant issuer with familiar JWT tooling.\nIt ships the published AGP v0.1 conformance vectors under `vectors/`; `npm test` runs all valid and invalid vectors against the verifier.\n\n## Verify\n\n```ts\nimport { verifyAgentGrant } from \"@agent-grant-protocol/verifier\";\n\nconst grant = await verifyAgentGrant(jwt, {\n  audience: \"https://seller.example\",\n  proof: agpProofJws,\n  operation: {\n    kind: \"do\",\n    action: \"mcp.tool\",\n    tool: \"calendar.create_event\",\n    method: \"POST\",\n    url: \"https://seller.example/tools/call\"\n  },\n  approvalSatisfied: true,\n  statusResolver: async (statusUrl) => {\n    const response = await fetch(statusUrl);\n    if (!response.ok) throw new Error(`status endpoint returned ${response.status}`);\n    return (await response.json()).status; // \"active\" | \"revoked\" | \"frozen\"\n  }\n});\n\ngrant.requireAction(\"mcp.tool\", \"calendar.create_event\");\n```\n\nOn rejection `verifyAgentGrant` throws `AgentGrantVerificationError`. Its `code` is a fine-grained diagnostic (`\"revoked\"`, `\"missing_scope\"`, ...); its `protocolCode` is the spec §7.3 normative closed set (`\"REVOKED\"`, `\"SCOPE_MISS\"`, ...) and is what belongs in HTTP responses and anything else that crosses an implementation boundary.\n\nOmitting `statusResolver` does not skip revocation checking: `do` and `spend` operations then fail closed with `status_unavailable`, since the status endpoint is effectively unreachable. Pass `statusPolicy: \"skip\"` if you really want verification without status checks.\n\n## v0.1 Checks\n\n- header `typ` must be `grant+jwt`\n- `alg` must be `ES256`\n- `iss` and `sub` must be P-256 `did:key` identifiers\n- the grant signature is verified against the public key encoded in `iss`\n- first-party and delegated grant chains are verified with attenuation-only subset checks\n- `exp`, `iat`, and optional audience are enforced\n- general grants must live 24 hours or less; spend grants must live 1 hour or less\n- `grant.v` must be `0.1`\n- `AGP-Proof` can be required and verified for `do` and `spend` operations\n- proof signatures are checked against the public key encoded in grant `sub`\n- proof `gid`, `htm`, `htu`, `iat`, optional body hash, and replay hooks are enforced\n- spend operations require replay-cache support for proof `jti` values\n- `do` operations with `approval: \"required\"` require an explicit approval signal from the caller\n- `http.request`, `message.send`, and `spend` operations are checked against their action-specific constraints\n- spend operation amounts are compared as exact decimal strings against `max_tx` and cumulative `max_period`\n- delegation chains are checked for root-first order, `iss`/`sub` linkage, scope attenuation, expiry, audience narrowing, and full-chain status\n- unknown scope fields, non-registry identifiers, and wildcards are rejected\n- revocation/status checks fail open by default for reads and fail closed by default for `do`/`spend` operations\n\n## Local Development\n\n```sh\nnpm install\nnpm test\n```\n","readmeFilename":"README.md"}