{"_id":"@agent-id/express","_rev":"4-6673211b583e53ac6e9dacfe580ee702","name":"@agent-id/express","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@agent-id/express","version":"0.1.0","keywords":["agent-id","agentpass","bankid","jwt","express","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","_id":"@agent-id/express@0.1.0","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"}],"homepage":"https://github.com/your-org/agentpass#readme","bugs":{"url":"https://github.com/your-org/agentpass/issues"},"dist":{"shasum":"ecf7c16d5cbad85f927df293c181fa03f536af70","tarball":"https://registry.npmjs.org/@agent-id/express/-/express-0.1.0.tgz","fileCount":9,"integrity":"sha512-jXJqovxvwsNDww38TIyilHCBA5lA2wYyAFg4ytoUPpmBDUETDXK74n2Wy1YiNfDliFEW+GMIOn97qDJgf+awNg==","signatures":[{"sig":"MEQCIBofQwqj57ijos2n8hRT+QnMrBGK9ABRmm2trgmBfN4iAiAJ5oJiz+tqz3rTA0EzFPHINWGBr7TbmdDE0Aurucs/CQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57964},"main":"./dist/index.cjs","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"d4610fb2fe51c01bd0eb62af1889f963c407eefd","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run build"},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"repository":{"url":"git+https://github.com/your-org/agentpass.git","type":"git"},"_npmVersion":"11.4.2","description":"Agent-ID verifier middleware for Express.js — blocks unauthorized AI agents from your API routes","directories":{},"_nodeVersion":"22.17.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^3.0.0","express":"^4.21.0","typescript":"^5.6.0","@types/node":"^22.0.0","@types/express":"^5.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":false}},"_npmOperationalInternal":{"tmp":"tmp/express_0.1.0_1771706311067_0.33831301098248856","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-id/express","version":"0.1.1","keywords":["agent-id","bankid","jwt","express","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","_id":"@agent-id/express@0.1.1","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},{"name":"oscarnaslundcuesta","email":"oscar.ncuesta@yahoo.se"}],"homepage":"https://github.com/your-org/agentpass#readme","bugs":{"url":"https://github.com/your-org/agentpass/issues"},"dist":{"shasum":"e40894f9d2c1eed2dc9bf5367fd490f9fadd40e0","tarball":"https://registry.npmjs.org/@agent-id/express/-/express-0.1.1.tgz","fileCount":9,"integrity":"sha512-RVOX0knxbd5CTnj+TwPGsIi2dkghEp88aQdU8aqzS0TzHuQpajJStc5gS7tAYLSUw2Ku2d6GKUsU5dGLPbeXqw==","signatures":[{"sig":"MEYCIQDbl9dnkTwEpqe3PObobubVz4cV/eWJG0UUCPkgTU+zYgIhAObL6sG9Sxu6r1rTAfnOTOF8cI9Ng7hIp/CJrYf6Uw8O","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57960},"main":"./dist/index.cjs","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"b294ccb489b9cc2866533fcbdd0a142db808575f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run build"},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"repository":{"url":"git+https://github.com/your-org/agentpass.git","type":"git"},"_npmVersion":"11.4.2","description":"Agent-ID verifier middleware for Express.js — blocks unauthorized AI agents from your API routes","directories":{},"_nodeVersion":"22.17.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","vitest":"^3.0.0","express":"^4.21.0","typescript":"^5.6.0","@types/node":"^22.0.0","@types/express":"^5.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":false}},"_npmOperationalInternal":{"tmp":"tmp/express_0.1.1_1771716187914_0.5833735288411264","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agent-id/express","version":"0.1.2","description":"AgentID verifier middleware for Express.js — blocks unauthorized AI agents from your API routes","keywords":["agent-id","bankid","jwt","express","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","prepublishOnly":"npm run typecheck && npm run build"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":false}},"dependencies":{"jose":"^6.0.0"},"devDependencies":{"@types/express":"^5.0.0","@types/node":"^22.0.0","express":"^4.21.0","tsup":"^8.0.0","typescript":"^5.6.0","vitest":"^3.0.0"},"engines":{"node":">=18.0.0"},"repository":{"type":"git","url":"git+https://github.com/sakerhetspolisen/agentid-express.git"},"_id":"@agent-id/express@0.1.2","gitHead":"bc22d6e6557ca287061a2ef7b14d1a436b85a620","bugs":{"url":"https://github.com/sakerhetspolisen/agentid-express/issues"},"homepage":"https://github.com/sakerhetspolisen/agentid-express#readme","_nodeVersion":"22.17.0","_npmVersion":"11.4.2","dist":{"integrity":"sha512-bpc03FPPCaDNFsROEMwOTffTps7hb21whbUOOjLfJsXlMUl0orqw2j5iihp8oZpVJhxRj3riuPvVXJ5F8Y6nAg==","shasum":"ff96cb1746ea90e5217fc76186cce4ab36b782f0","tarball":"https://registry.npmjs.org/@agent-id/express/-/express-0.1.2.tgz","fileCount":9,"unpackedSize":56497,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC2U7ZrQHe8ssRRJyGGDz5SZMZPbY1/cRnCpuKUf8QDRgIhAL2DVQYp8T21NbEKdUbRE0at1b42TC2vD3nrQYpa/7t5"}]},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"directories":{},"maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},{"name":"oscarnaslundcuesta","email":"oscar.ncuesta@yahoo.se"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/express_0.1.2_1771844499567_0.7860491199435886"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-21T20:38:30.997Z","modified":"2026-02-23T11:01:39.854Z","0.1.0":"2026-02-21T20:38:31.222Z","0.1.1":"2026-02-21T23:23:08.059Z","0.1.2":"2026-02-23T11:01:39.722Z"},"bugs":{"url":"https://github.com/sakerhetspolisen/agentid-express/issues"},"license":"MIT","homepage":"https://github.com/sakerhetspolisen/agentid-express#readme","keywords":["agent-id","bankid","jwt","express","middleware","ai-agent","mcp","bot-detection"],"repository":{"type":"git","url":"git+https://github.com/sakerhetspolisen/agentid-express.git"},"description":"AgentID verifier middleware for Express.js — blocks unauthorized AI agents from your API routes","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},{"name":"oscarnaslundcuesta","email":"oscar.ncuesta@yahoo.se"}],"readme":"# @agent-id/express\n\nExpress.js middleware that automatically detects AI-agent traffic and requires a valid [AgentID](https://agentidapp.vercel.app) JWT. Human browser traffic always passes through untouched.\n\n## Install\n\n```bash\nnpm install @agent-id/express\n```\n\nRequires `express >= 4` and `node >= 18`.\n\n## Setup — 2 steps\n\n### 1. Add the middleware\n\n```ts\nimport express from 'express';\nimport { agentID } from '@agent-id/express';\n\nconst app = express();\n\napp.use(agentID());\n\napp.listen(3000);\n```\n\nThat's it. The middleware now:\n- Lets all human browser traffic through unchanged\n- Requires a valid AgentID JWT from any AI agent / bot\n- Returns `403 AGENT_UNAUTHORIZED` when the JWT is missing or invalid\n\n### 2. Read the verified identity in your route handlers (optional)\n\n```ts\napp.get('/api/data', (req, res) => {\n  const agent = req.agentId;\n\n  if (agent?.verified) {\n    // Verified AI agent — claims are fully typed\n    console.log(agent.claims.sub);          // pseudonymous stable user ID\n    console.log(agent.claims.auth_method);  // \"bankid\"\n    return res.json({ ok: true, sub: agent.claims.sub });\n  }\n\n  // Human traffic: agent.reason === 'not_agent'\n  return res.json({ ok: true });\n});\n```\n\n`req.agentId` is typed automatically — no extra TypeScript configuration needed.\n\n## How agents authenticate\n\nAgents add one header to every request:\n\n```\nAuthorization: Bearer <agentid-jwt>\n```\n\nThe JWT is obtained by completing a BankID flow at [agentidapp.vercel.app](https://agentidapp.vercel.app). Tokens are valid for 1 hour.\n\n## Options\n\nAll options are optional — `agentID()` with no arguments works out of the box.\n\n```ts\napp.use(agentID({\n  // Return 403 when an agent has no valid token (default: true).\n  // Set to false to let unverified agents through (useful for logging / gradual rollout).\n  blockUnauthorizedAgents: true,\n\n  // Override the JWKS endpoint — only needed if you self-host AgentID.\n  jwksUrl: 'https://your-agentid.example.com/api/jwks',\n\n  // Clock skew tolerance in seconds (default: 30).\n  clockTolerance: 30,\n\n  // Fully custom response when an agent is rejected.\n  onUnauthorizedAgent: (req, res, next, reason) => {\n    res.status(403).json({ error: 'No AgentID token', reason });\n  },\n}));\n```\n\n## What gets verified\n\nVerification is **fully offline** after the first request. The public key is fetched once from the AgentID JWKS endpoint and cached for 1 hour — no per-request network call.\n\n| Check | Requirement |\n|---|---|\n| Signature | RS256 — `alg:none` and HS256 are explicitly rejected |\n| Issuer (`iss`) | Must equal `\"agentid\"` |\n| Expiry (`exp`) | Must be in the future |\n| `auth_method` | Must equal `\"bankid\"` |\n\n## JWT claims\n\n| Field | Description |\n|---|---|\n| `sub` | Pseudonymous stable user ID (HMAC-SHA256 of BankID personal number — non-reversible, same person always gets the same ID) |\n| `auth_method` | Always `\"bankid\"` |\n| `iss` | `\"agentid\"` |\n| `exp` | Unix timestamp — 1 hour from issue |\n| `iat` | Unix timestamp — when issued |\n| `jti` | Unique token ID |\n","readmeFilename":"README.md"}