{"_id":"@agent-id/nextjs","_rev":"5-150672e02f0ec6d408b044259d41d094","name":"@agent-id/nextjs","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@agent-id/nextjs","version":"0.1.0","keywords":["agent-id","agentpass","bankid","jwt","nextjs","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","_id":"@agent-id/nextjs@0.1.0","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"}],"homepage":"https://github.com/your-org/agentpass#readme","bugs":{"url":"https://github.com/your-org/agentpass/issues"},"dist":{"shasum":"91ecc800a3b7696ae19d7af3fd0e90be1d1cf073","tarball":"https://registry.npmjs.org/@agent-id/nextjs/-/nextjs-0.1.0.tgz","fileCount":9,"integrity":"sha512-/x8Gt7ZoAZUeJIddBZu+axRk9saAlEmphidMjzGetlIgw34tG62FgBIvipwiHWr/r9BLuElcxgw9+yTmGpIZiA==","signatures":[{"sig":"MEUCICWCvRvRnMAOxyUAl3N2LXR6DY87RdPeb/0t2D6kXukIAiEA5YJnF69FEhXYtAq8UQiPU0ef0cnxF4pUPPNp3pb6oPY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66553},"main":"./dist/index.cjs","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"d4610fb2fe51c01bd0eb62af1889f963c407eefd","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run build"},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"repository":{"url":"git+https://github.com/your-org/agentpass.git","type":"git"},"_npmVersion":"11.4.2","description":"Agent-ID verifier middleware for Next.js — blocks unauthorized AI agents from your API routes","directories":{},"_nodeVersion":"22.17.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"^16.0.0","tsup":"^8.0.0","vitest":"^3.0.0","typescript":"^5.6.0","@types/node":"^22.0.0"},"peerDependencies":{"next":">=14.0.0"},"_npmOperationalInternal":{"tmp":"tmp/nextjs_0.1.0_1771703005006_0.5638755811304061","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-id/nextjs","version":"0.1.1","keywords":["agent-id","agentpass","bankid","jwt","nextjs","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","_id":"@agent-id/nextjs@0.1.1","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"}],"homepage":"https://github.com/your-org/agentpass#readme","bugs":{"url":"https://github.com/your-org/agentpass/issues"},"dist":{"shasum":"f184c4c3333e6177217a7a6bf921aa505423d480","tarball":"https://registry.npmjs.org/@agent-id/nextjs/-/nextjs-0.1.1.tgz","fileCount":9,"integrity":"sha512-rC1NIgdBtzx0ZhZVlTwyRT304NdeiPn6rcUJ9fDnkDuwmFR7ymLH2D8Gdy604Y7Uf4BiniGMDUP9bLL3HIRaow==","signatures":[{"sig":"MEYCIQCU6BFewxtcBOZ91VQm9e7GELueJ8RB00tU8eMnrHq16QIhAMNlnv7EXB+wUVhhqaH9jqQCfO2zPYX1/UaBl68csVuA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65969},"main":"./dist/index.cjs","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"d4610fb2fe51c01bd0eb62af1889f963c407eefd","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run build"},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"repository":{"url":"git+https://github.com/your-org/agentpass.git","type":"git"},"_npmVersion":"11.4.2","description":"Agent-ID verifier middleware for Next.js — blocks unauthorized AI agents from your API routes","directories":{},"_nodeVersion":"22.17.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"^16.0.0","tsup":"^8.0.0","vitest":"^3.0.0","typescript":"^5.6.0","@types/node":"^22.0.0"},"peerDependencies":{"next":">=14.0.0"},"_npmOperationalInternal":{"tmp":"tmp/nextjs_0.1.1_1771705732137_0.9707950749404548","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agent-id/nextjs","version":"0.1.2","keywords":["agent-id","bankid","jwt","nextjs","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","_id":"@agent-id/nextjs@0.1.2","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},{"name":"oscarnaslundcuesta","email":"oscar.ncuesta@yahoo.se"}],"homepage":"https://github.com/your-org/agentpass#readme","bugs":{"url":"https://github.com/your-org/agentpass/issues"},"dist":{"shasum":"cef107e302b0b4b761ee49252ff09aca4e5807d9","tarball":"https://registry.npmjs.org/@agent-id/nextjs/-/nextjs-0.1.2.tgz","fileCount":9,"integrity":"sha512-8sBxscrxosgoDYjQgs9sMVa4lJnQ2PDClsljBYWjX9v11lSgLR3P4/qCPBeV19VQqrqOjVZqOCSV06Esh+d2XQ==","signatures":[{"sig":"MEQCIAorXg/ygdRcuqJoMQ3nlHSlZ0SuIRmdPAgKVrV4rmx7AiA19g2rj5i1EXnw0fpE/RtC3JzJiy8Z4dnIw2jem1huQQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65965},"main":"./dist/index.cjs","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"b294ccb489b9cc2866533fcbdd0a142db808575f","scripts":{"dev":"tsup --watch","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run build"},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"repository":{"url":"git+https://github.com/your-org/agentpass.git","type":"git"},"_npmVersion":"11.4.2","description":"Agent-ID verifier middleware for Next.js — blocks unauthorized AI agents from your API routes","directories":{},"_nodeVersion":"22.17.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"^16.0.0","tsup":"^8.0.0","vitest":"^3.0.0","typescript":"^5.6.0","@types/node":"^22.0.0"},"peerDependencies":{"next":">=14.0.0"},"_npmOperationalInternal":{"tmp":"tmp/nextjs_0.1.2_1771716159637_0.8529877215905308","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agent-id/nextjs","version":"0.1.3","description":"AgentID verifier middleware for Next.js — blocks unauthorized AI agents from your API routes","keywords":["agent-id","bankid","jwt","nextjs","middleware","ai-agent","mcp","bot-detection"],"license":"MIT","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","prepublishOnly":"npm run typecheck && npm run build"},"peerDependencies":{"next":">=14.0.0"},"dependencies":{"jose":"^6.0.0"},"devDependencies":{"@types/node":"^22.0.0","next":"^16.0.0","tsup":"^8.0.0","typescript":"^5.6.0","vitest":"^3.0.0"},"engines":{"node":">=18.0.0"},"repository":{"type":"git","url":"git+https://github.com/sakerhetspolisen/agentid-nextjs.git"},"_id":"@agent-id/nextjs@0.1.3","gitHead":"4e796228a784824c77ddd9ba8387f6f25c107edb","bugs":{"url":"https://github.com/sakerhetspolisen/agentid-nextjs/issues"},"homepage":"https://github.com/sakerhetspolisen/agentid-nextjs#readme","_nodeVersion":"22.17.0","_npmVersion":"11.4.2","dist":{"integrity":"sha512-oo+XokGUMfnM9rKbDTFGILpBsx8yN5wc1DBRU2lw8N22z0YPpgc1/I3VEdT28ejx/ChjwfYIPwMPH6TWSH8PnA==","shasum":"21d119e0fdd226474b2713c2f2becab523020761","tarball":"https://registry.npmjs.org/@agent-id/nextjs/-/nextjs-0.1.3.tgz","fileCount":9,"unpackedSize":64056,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDb/ihlek7IX40HeHw+tnsQigtktp5jK/WW52vylJXkBgIgPOI9ug+c1wFw0b2nGROf53ozM9LU4BZF3RgJ7pnysTc="}]},"_npmUser":{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},"directories":{},"maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},{"name":"oscarnaslundcuesta","email":"oscar.ncuesta@yahoo.se"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nextjs_0.1.3_1771843669929_0.8499052492499382"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-21T19:43:24.909Z","modified":"2026-02-23T10:47:50.250Z","0.1.0":"2026-02-21T19:43:25.145Z","0.1.1":"2026-02-21T20:28:52.268Z","0.1.2":"2026-02-21T23:22:39.768Z","0.1.3":"2026-02-23T10:47:50.102Z"},"bugs":{"url":"https://github.com/sakerhetspolisen/agentid-nextjs/issues"},"license":"MIT","homepage":"https://github.com/sakerhetspolisen/agentid-nextjs#readme","keywords":["agent-id","bankid","jwt","nextjs","middleware","ai-agent","mcp","bot-detection"],"repository":{"type":"git","url":"git+https://github.com/sakerhetspolisen/agentid-nextjs.git"},"description":"AgentID verifier middleware for Next.js — blocks unauthorized AI agents from your API routes","maintainers":[{"name":"sakerhetspolisen","email":"legendenomzelda@gmail.com"},{"name":"oscarnaslundcuesta","email":"oscar.ncuesta@yahoo.se"}],"readme":"# @agent-id/nextjs\n\nNext.js proxy that automatically detects AI-agent traffic and requires a valid [AgentID](https://agentidapp.vercel.app) JWT. Human browser traffic always passes through untouched.\n\n## Install\n\n```bash\nnpm install @agent-id/nextjs\n```\n\nRequires `next >= 16`.\n\n## Setup — 2 steps\n\n### 1. Add the proxy\n\nCreate `proxy.ts` in your project root (same level as `app/`):\n\n```ts\nimport { createAgentIDMiddleware } from '@agent-id/nextjs';\nimport type { NextRequest } from 'next/server';\n\nconst agentID = createAgentIDMiddleware();\n\nexport function proxy(request: NextRequest) {\n  return agentID(request);\n}\n\n// Protect your API routes\nexport const config = {\n  matcher: '/:path*',\n};\n```\n\nThat's it. The proxy now:\n- Lets all human browser traffic through unchanged\n- Requires a valid AgentID JWT from any AI agent / bot\n- Returns `403 AGENT_UNAUTHORIZED` when the JWT is missing or invalid\n\n### 2. Read the verified identity in your route handlers (optional)\n\n```ts\n// app/api/anything/route.ts\nimport { getAgentIDResult } from '@agent-id/nextjs';\nimport type { NextRequest } from 'next/server';\n\nexport async function GET(request: NextRequest) {\n  const agent = getAgentIDResult(request);\n\n  if (agent.verified) {\n    // Verified AI agent — claims are fully typed\n    console.log(agent.claims.sub);          // pseudonymous stable user ID\n    console.log(agent.claims.auth_method);  // \"bankid\"\n  }\n\n  // Human traffic: agent.verified === false, agent.reason === 'not_agent'\n  return Response.json({ ok: true });\n}\n```\n\n## How agents authenticate\n\nAgents add one header to every request:\n\n```\nAuthorization: Bearer <agentid-jwt>\n```\n\nThe JWT is obtained by completing a BankID flow at [agentidapp.vercel.app](https://agentidapp.vercel.app). Tokens are valid for 1 hour.\n\n## Options\n\nAll options are optional — `createAgentIDMiddleware()` with no arguments works out of the box.\n\n```ts\ncreateAgentIDMiddleware({\n  // Return 403 when an agent has no valid token (default: true).\n  // Set to false to let unverified agents through (useful for logging / gradual rollout).\n  blockUnauthorizedAgents: true,\n\n  // Override the JWKS endpoint — only needed if you self-host AgentID.\n  jwksUrl: 'https://your-agentid.example.com/api/jwks',\n\n  // Clock skew tolerance in seconds (default: 30).\n  clockTolerance: 30,\n\n  // Fully custom response when an agent is rejected.\n  onUnauthorizedAgent: (request, reason) =>\n    NextResponse.json({ error: 'No AgentID token', reason }, { status: 403 }),\n})\n```\n\n## What gets verified\n\nVerification is **fully offline** after the first request. The public key is fetched once from the AgentID JWKS endpoint and cached for 1 hour — no per-request network call.\n\n| Check | Requirement |\n|---|---|\n| Signature | RS256 — `alg:none` and HS256 are explicitly rejected |\n| Issuer (`iss`) | Must equal `\"agentid\"` |\n| Expiry (`exp`) | Must be in the future |\n| `auth_method` | Must equal `\"bankid\"` |\n\n## JWT claims\n\n| Field | Description |\n|---|---|\n| `sub` | Pseudonymous stable user ID (HMAC-SHA256 of BankID personal number — non-reversible, same person always gets the same ID) |\n| `auth_method` | Always `\"bankid\"` |\n| `iss` | `\"agentid\"` |\n| `exp` | Unix timestamp — 1 hour from issue |\n| `iat` | Unix timestamp — when issued |\n| `jti` | Unique token ID |\n","readmeFilename":"README.md"}