{"_id":"@agent-manifest/client","_rev":"3-e13e00571566bf26374131c930e63cab","name":"@agent-manifest/client","dist-tags":{"bootstrap":"0.0.0","latest":"0.1.1"},"versions":{"0.0.0":{"name":"@agent-manifest/client","version":"0.0.0","keywords":["agent-manifest","agent-manifest-spec","agent-declaration","structural-validation","json-schema","canonicalization","rfc8785"],"author":{"url":"https://orcid.org/0009-0008-7216-3032","name":"Hernán Alfredo Capucci"},"license":"Apache-2.0","_id":"@agent-manifest/client@0.0.0","maintainers":[{"name":"hernan-capucci","email":"hernancapucci@gmail.com"}],"homepage":"https://agent-manifest-spec.org","bugs":{"url":"https://github.com/agent-manifest/agent-manifest-client/issues"},"dist":{"shasum":"d69d80d794daf1a10263b6850c97ed7ba726e96c","tarball":"https://registry.npmjs.org/@agent-manifest/client/-/client-0.0.0.tgz","fileCount":18,"integrity":"sha512-IjEI3l4u0N50fEPzm+deWTB+MDubfBhNmMh91Y4W4lmAI01DinMNVerHxVA0VA6Uwq2RAfPyGw29DuACQNuu8Q==","signatures":[{"sig":"MEUCIEqRJ8Q+vFTZW8eouUTYZ6j63dmsj+DoSsZSEtAWqUgBAiEA+MZFOlu+dFGLA1RjVzzHTGinBA3EiiW520lp8TTlih0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60092},"type":"module","engines":{"node":">=22.12.0"},"exports":{".":"./src/index.js","./net":"./src/net/index.js","./validate":"./src/validate.js","./package.json":"./package.json"},"gitHead":"4871c4b9512b9317841346aff0681952c7a33345","scripts":{"test":"node --test"},"_npmUser":{"name":"hernan-capucci","email":"hernancapucci@gmail.com"},"not_goals":["It does not score, rank, grade or order manifests.","It does not emit verdicts about trust, safety or compliance.","It does not evaluate policy. The policy seat belongs to the consumer and is left deliberately empty.","It does not verify behaviour, and never uses the word verify for a structural result.","It does not certify, accredit or issue badges.","It does not sign anything or check signatures.","It does not write to any registry or remote surface.","It sends no telemetry, not even anonymous.","It does not fill in defaults or repair manifests.","It ships no thresholds, profiles or recommended lists.","It performs no network access outside the explicitly named access layer."],"repository":{"url":"git+https://github.com/agent-manifest/agent-manifest-client.git","type":"git","directory":"packages/client"},"_npmVersion":"11.11.0","description":"Reading client for Agent Manifest v1.0 declarations. Parses, canonicalises, fingerprints, compares and structurally validates manifests. It reports where a document came from and what cannot be concluded from it; it does not score, rank, certify or enforc","directories":{},"_nodeVersion":"25.8.1","dependencies":{"ajv":"^8.17.1","ajv-formats":"^3.0.1","@agent-manifest/schema":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/client_0.0.0_1785633650203_0.1491305618405565","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@agent-manifest/client","version":"0.1.0","keywords":["agent-manifest","agent-manifest-spec","agent-declaration","structural-validation","json-schema","canonicalization","rfc8785"],"author":{"url":"https://orcid.org/0009-0008-7216-3032","name":"Hernán Alfredo Capucci"},"license":"Apache-2.0","_id":"@agent-manifest/client@0.1.0","maintainers":[{"name":"hernan-capucci","email":"hernancapucci@gmail.com"}],"homepage":"https://agent-manifest-spec.org","bugs":{"url":"https://github.com/agent-manifest/agent-manifest-client/issues"},"dist":{"shasum":"95f00378944458191ea25611789e7c619866813b","tarball":"https://registry.npmjs.org/@agent-manifest/client/-/client-0.1.0.tgz","fileCount":18,"integrity":"sha512-o1C0gNH+cEnAENzSc6pBwbBX78jCb/KSu1QRRev/2xSzH8euuGZkKvPI+K1RADrF2gOYrAq4BymBqbNXYmJY3A==","signatures":[{"sig":"MEYCIQDR2qOI69UMRiVNzSiZTe/57DcAIogcmeaKcIwhbqi05AIhAMBWtpJYpVmJC/NQb2JK09s+54/AuNxZCqyPrwDVw3qj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-manifest%2fclient@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":60092},"type":"module","_from":"file:agent-manifest-client-0.1.0.tgz","engines":{"node":">=22.12.0"},"exports":{".":"./src/index.js","./net":"./src/net/index.js","./validate":"./src/validate.js","./package.json":"./package.json"},"scripts":{"test":"node --test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b08dc2a6-1075-43ee-8549-d75e7e172c1e"}},"_resolved":"/home/runner/work/agent-manifest-client/agent-manifest-client/agent-manifest-client-0.1.0.tgz","not_goals":["It does not score, rank, grade or order manifests.","It does not emit verdicts about trust, safety or compliance.","It does not evaluate policy. The policy seat belongs to the consumer and is left deliberately empty.","It does not verify behaviour, and never uses the word verify for a structural result.","It does not certify, accredit or issue badges.","It does not sign anything or check signatures.","It does not write to any registry or remote surface.","It sends no telemetry, not even anonymous.","It does not fill in defaults or repair manifests.","It ships no thresholds, profiles or recommended lists.","It performs no network access outside the explicitly named access layer."],"_integrity":"sha512-o1C0gNH+cEnAENzSc6pBwbBX78jCb/KSu1QRRev/2xSzH8euuGZkKvPI+K1RADrF2gOYrAq4BymBqbNXYmJY3A==","repository":{"url":"git+https://github.com/agent-manifest/agent-manifest-client.git","type":"git","directory":"packages/client"},"_npmVersion":"12.0.2","description":"Reading client for Agent Manifest v1.0 declarations. Parses, canonicalises, fingerprints, compares and structurally validates manifests. It reports where a document came from and what cannot be concluded from it; it does not score, rank, certify or enforc","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"^8.17.1","ajv-formats":"^3.0.1","@agent-manifest/schema":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/client_0.1.0_1785674811563_0.5952535133806394","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agent-manifest/client","version":"0.1.1","description":"Reading client for Agent Manifest v1.0 declarations. Parses, canonicalises, fingerprints, compares and structurally validates manifests. It reports where a document came from and what cannot be concluded from it; it does not score, rank, certify or enforc","keywords":["agent-manifest","agent-manifest-spec","agent-declaration","structural-validation","json-schema","canonicalization","rfc8785"],"homepage":"https://agent-manifest-spec.org","repository":{"type":"git","url":"git+https://github.com/agent-manifest/agent-manifest-client.git","directory":"packages/client"},"bugs":{"url":"https://github.com/agent-manifest/agent-manifest-client/issues"},"author":{"name":"Hernán Alfredo Capucci","url":"https://orcid.org/0009-0008-7216-3032"},"license":"Apache-2.0","type":"module","engines":{"node":">=22.12.0"},"exports":{".":"./src/index.js","./validate":"./src/validate.js","./net":"./src/net/index.js","./package.json":"./package.json"},"publishConfig":{"access":"public"},"scripts":{"test":"node --test"},"dependencies":{"@agent-manifest/schema":"0.1.0","ajv":"^8.17.1","ajv-formats":"^3.0.1"},"not_goals":["It does not score, rank, grade or order manifests.","It does not emit verdicts about trust, safety or compliance.","It does not evaluate policy. The policy seat belongs to the consumer and is left deliberately empty.","It does not verify behaviour, and never uses the word verify for a structural result.","It does not certify, accredit or issue badges.","It does not sign anything or check signatures.","It does not write to any registry or remote surface.","It sends no telemetry, not even anonymous.","It does not fill in defaults or repair manifests.","It ships no thresholds, profiles or recommended lists.","It performs no network access outside the explicitly named access layer."],"_id":"@agent-manifest/client@0.1.1","_integrity":"sha512-gSjRmWwHLN6xEkB32Xnx5JRP1KljNfXu/f5i46vCI8s0z73+8vOyz03i+EBWPcOa4PVTzTxouoM690Y3LQIKBA==","_resolved":"/home/runner/work/agent-manifest-client/agent-manifest-client/agent-manifest-client-0.1.1.tgz","_from":"file:agent-manifest-client-0.1.1.tgz","_nodeVersion":"24.18.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-gSjRmWwHLN6xEkB32Xnx5JRP1KljNfXu/f5i46vCI8s0z73+8vOyz03i+EBWPcOa4PVTzTxouoM690Y3LQIKBA==","shasum":"fbb19ae3718c7b8e49ad7d479173dc9b3d3e2f7a","tarball":"https://registry.npmjs.org/@agent-manifest/client/-/client-0.1.1.tgz","fileCount":18,"unpackedSize":62887,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agent-manifest%2fclient@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFmgKRw1L3dNzAX+aSFckiyXFl6OhcjQmixPOhfD0BshAiEAkjXPgyDW2zYbpiWajhZ1MRSjKheZ3bR/VL67TnYAqT0="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b08dc2a6-1075-43ee-8549-d75e7e172c1e"}},"directories":{},"maintainers":[{"name":"hernan-capucci","email":"hernancapucci@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/client_0.1.1_1785796865870_0.04553121975794183"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-02T01:20:50.077Z","modified":"2026-08-03T22:41:06.367Z","0.0.0":"2026-08-02T01:20:50.363Z","0.1.0":"2026-08-02T12:46:51.708Z","0.1.1":"2026-08-03T22:41:06.023Z"},"bugs":{"url":"https://github.com/agent-manifest/agent-manifest-client/issues"},"author":{"name":"Hernán Alfredo Capucci","url":"https://orcid.org/0009-0008-7216-3032"},"license":"Apache-2.0","homepage":"https://agent-manifest-spec.org","keywords":["agent-manifest","agent-manifest-spec","agent-declaration","structural-validation","json-schema","canonicalization","rfc8785"],"repository":{"type":"git","url":"git+https://github.com/agent-manifest/agent-manifest-client.git","directory":"packages/client"},"description":"Reading client for Agent Manifest v1.0 declarations. Parses, canonicalises, fingerprints, compares and structurally validates manifests. It reports where a document came from and what cannot be concluded from it; it does not score, rank, certify or enforc","maintainers":[{"name":"hernan-capucci","email":"hernancapucci@gmail.com"}],"readme":"# @agent-manifest/client\n\nReading client for [Agent Manifest](https://agent-manifest-spec.org) v1.0 declarations.\n\nIt answers three questions a reader actually has — *what does this document\nsay*, *has it changed*, and *is it shaped the way v1.0 says* — and refuses to\nanswer a fourth one it has no standing to answer: whether the agent behind it is\nany good.\n\n```bash\nnpm install @agent-manifest/client\n```\n\nRequires Node 22.12 or newer. The reading layer also runs unchanged in a\nbrowser.\n\n## Read a manifest\n\n```js\nimport { parse, detectVersion, fingerprint } from '@agent-manifest/client';\n\nconst { document } = parse(await (await fetch(url)).text());\n\ndetectVersion(document);        // '1.0', or null if none was declared\nawait fingerprint(document);    // 'sha256:…' — same document, same string\n```\n\n## Check its structure\n\nStructural validation lives behind its own entry point, so importing the reader\nabove does not load a JSON Schema validator.\n\n```js\nimport { validate } from '@agent-manifest/client/validate';\n\nconst { schemaValid, errors } = validate(document);\n// errors: [{ path: '/data_handling/retention', message: 'must match pattern …' }]\n```\n\n`validate()` takes the document. `parse()` returns `{ document, form }`, so the\ntwo go together like this:\n\n```js\nconst { document } = parse(readFileSync('manifest.json', 'utf8'));\nconst { schemaValid, errors } = validate(document);\n```\n\nPassing the whole `parse()` result instead is refused with a single error\ncarrying `source: 'usage'`, which is the only error that ever carries it —\nerrors about the document keep the `{ path, message }` shape above. The refusal\nexists because the alternative was worse than useless: the wrapper has none of\nthe required fields, so a perfectly good manifest came back described as broken\nin thirteen places, and the reader went looking for a defect that was in their\ncall all along. Nothing is unwrapped or repaired on your behalf.\n\nThe boolean is called `schemaValid` and not `valid`, and that is not fussiness.\n`valid` gets read as *the agent is fine*. What the schema constrains is the\nshape of a declaration; whether the declaration is true, complete, or worth\nrelying on is not something any validator can tell you.\n\n## See what changed\n\n```js\nimport { diff, canonicalize } from '@agent-manifest/client';\n\ndiff(lastWeek, today);\n// [{ path: '/autonomy/level', change: 'replaced', before: 1, after: 2 }]\n```\n\n`diff` reports the change. It does not tell you the change was an improvement or\na regression — that reading belongs to you and depends on what you are using the\nagent for.\n\n`canonicalize` is [RFC 8785](https://www.rfc-editor.org/rfc/rfc8785) (JCS). It is\nlossless: same document, one agreed way of writing it. Naming the scheme is what\nmakes a fingerprint computed here comparable to one computed by an\nimplementation in another language.\n\n## Find one on the network\n\nThe access layer is a separate entry point, so a network request is visible in\nan import line rather than buried in a call stack.\n\n```js\nimport { discover, discoverRegistry, resolve } from '@agent-manifest/client/net';\n\n// A host, at the location the specification prescribes. One request.\nawait discover('example.com');\n\n// By agent_id, against a registry index you named. Two requests.\nconst { registryUrl, registryVersion } = await discoverRegistry('agent-manifest-spec.org');\nconst { resolutions, absence } = await resolve('the-diplomat', { registryUrl });\n```\n\nEach resolution says where it came from and what that is worth:\n\n```js\n{\n  document,                     // exactly as served\n  schemaValid, errors,\n  source:  'https://…/the-diplomat.json',\n  route:   'registry-index',    // how it was found\n  binding: 'registry-indexed',  // what it is attached to\n  retrievedAt,\n  caveats                       // what you still cannot conclude\n}\n```\n\n`binding` never takes the value `verified`, `trusted` or `authentic`. No such\nstate exists in this ecosystem, and offering the word would invite its use.\n\nThree behaviours are deliberate and will not change:\n\n**Resolving an id returns zero, one or several resolutions.** Nothing here\ndeclares `agent_id` unique — no namespace, no issuing authority — so a function\nthat returned *the* entry would promise a uniqueness the data cannot support.\n\n**No registry is chosen for you.** `resolve` by id needs a `registryUrl` you\nnamed. Picking one on your behalf is picking whose word you take.\n\n**Nothing is retried and nothing falls back.** A read that fails returns an\n`absence` with a reason you can branch on — `no-document-at-well-known`,\n`host-did-not-respond`, `not-in-registry-index`, `unknown-registry-version`,\n`unparseable-json` and so on. With five manifests in the world, absence is the\ncommon case, and a generic failure is what makes an integrator stop after ten\nminutes.\n\nThat last reason is worth spelling out. The registry discovery document\ndeclares its own `registry_version`, and its field names are stable only while\nthat number is unchanged. So a version this package does not know is treated as\na document it cannot parse — the fields are not read hopefully by name, because\nthe contract that gave those names meaning is exactly what changed.\n\n## What you cannot conclude\n\n```js\nimport { CAVEATS } from '@agent-manifest/client';\n```\n\nFive statements about the limits of anything read from a manifest — that it is\nself-declared, that no behaviour was observed, that structure is not substance,\nthat identity is not bound, and that it is a point-in-time reading.\n\nThere is no option that switches them off. If you want to disregard them, do it\nexplicitly in your own code, in a line somebody can point at later.\n\n## Write your policy in your own code\n\nThis package has no `allow()`, no `check()`, no `isCompliant()` and no\nthresholds, and it is not going to grow them. The policy seat is yours, and it\nis left empty on purpose — what counts as acceptable depends on what you are\nabout to do with the agent, which is knowledge this package does not have and\nshould not pretend to.\n\nHere is the whole pattern. It is deliberately unglamorous:\n\n```js\nimport { parse } from '@agent-manifest/client';\nimport { validate } from '@agent-manifest/client/validate';\n\n/** Your rules. Yours to name, yours to change, yours to defend. */\nfunction acceptableForBillingWorkflow(manifest) {\n  const reasons = [];\n\n  if (manifest.autonomy?.level > 1) {\n    reasons.push('autonomy above 1 is more than this workflow delegates');\n  }\n  if (manifest.data_handling?.stores_personal_data &&\n      manifest.data_handling.retention !== 'none') {\n    reasons.push('personal data is retained beyond the session');\n  }\n  if (!manifest.stopping_authority?.stoppable_by?.includes('operator')) {\n    reasons.push('our operators are not listed as able to stop it');\n  }\n\n  return { accepted: reasons.length === 0, reasons };\n}\n\nconst { document } = parse(text);\nconst { schemaValid, errors } = validate(document);\nif (!schemaValid) throw new Error(`not a well-formed v1.0 manifest: ${errors[0].message}`);\n\nconst decision = acceptableForBillingWorkflow(document);\n```\n\nNote what the last three lines are doing: your decision is yours, it is recorded\nin your repository, and it is reviewable by your colleagues. That is a better\nplace for it than inside a dependency, whatever the dependency.\n\nAnd note what the manifest is doing: it tells you what the operator declared\n*before* you interact. It does not stop the agent, does not police it, and does\nnot promise that any of it is true.\n\n## This is one implementation, not the definition\n\nThe definition of Agent Manifest lives in the\n[specification](https://agent-manifest-spec.org/spec/v1.0/) and in the schema.\n`@agent-manifest/schema` distributes that schema together with a conformance\ncorpus — manifests with the expected structural result for each — so that\nanyone, in any language, can check that their reader agrees with this one\nwithout asking permission and without telling anybody the outcome.\n\nA second, independent implementation that passes the corpus is a good outcome\nfor the format. If one arrives and this package becomes unnecessary, that is the\nbest thing that could happen to it, not a loss.\n\n## What it does not do\n\nNo scoring, ranking or grading. No trust, safety or compliance verdicts. No\npolicy evaluation. No behaviour verification. No certification or badges. No\nsigning or signature checking. No writing to any registry. No telemetry, not\neven anonymous. No filling in defaults. No thresholds or recommended profiles.\nNo network access outside the access layer.\n\nThese are not aspirations. Every one of them is a test that fails the build,\nincluding a CI check that rejects any exported identifier matching the\nvocabulary above. See `test/doctrine.test.js` and `test/vocabulary.test.js`.\n\n## Licence\n\nApache-2.0. The schema file distributed by `@agent-manifest/schema` is dedicated\nto the public domain under CC0 1.0 so that it can be embedded without\nattribution obligations; the prose specification remains CC BY 4.0.\n","readmeFilename":"README.md"}