{"_id":"@agentadmit/sdk","_rev":"17-c13d8434d35fe0d0cabcab3d4526912c","name":"@agentadmit/sdk","dist-tags":{"latest":"1.11.0"},"versions":{"1.0.0":{"name":"@agentadmit/sdk","version":"1.0.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.0.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"e9040e1f4158a8a0e7539af05c11a5b9c9d729be","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.0.0.tgz","fileCount":26,"integrity":"sha512-Jr206L4volMuu+JYce2RPshO/DFiARfm1JjNJYhA1vG3RQxryWG1gQvyHCrF/mhJxg64gYAGjPfI4DUsrHmk5A==","signatures":[{"sig":"MEUCIAEK+FOTJ+DEh81YiOdp8ZpYBHkRAJlnSIIux7t4lMmpAiEAiYKj35PCuO/Op2Qy0J7W9zXE1VVYgaSWIYjfqdxI8SI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":96658},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"96a9b20befc6fc464b51ebef712493bc00fd29b0","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc"},"_npmUser":{"name":"agentadmit","email":"christopher@agentadmit.com"},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"10.9.4","description":"AgentAdmit SDK — User-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.22.0","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","ts-jest":"29.0.0","typescript":"5.3.0","@types/jest":"29.0.0","@types/node":"20.0.0","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.0.0_1780512507637_0.40577877546218577","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@agentadmit/sdk","version":"1.1.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.1.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"b194808bc56a5ccf93a92e9956702d14dca2547a","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.1.0.tgz","fileCount":22,"integrity":"sha512-Iz5YntbeH1rKncNYAtX2fLvuqdMcTB01XBQaC5kgx8/B82UZrUSJRuN5DiM9+8Y5sib71Lz6htlRBVSCwarWYg==","signatures":[{"sig":"MEYCIQCh5fxJAPBFD+vbo/KABD3JfL4pilV6NOMX4jKGg8o6SQIhAI8vvGje2u73BG9OG/M0YIzmbbQL2CPiSKXhgsLtfaX0","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":80919},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"8114d5c2ba6162f37c5693f6dea6b8d383d45e70","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"11.17.0","description":"AgentAdmit SDK — User-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.22.3","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.1.0_1781209559644_0.0918870863111596","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@agentadmit/sdk","version":"1.1.1","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.1.1","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"aea02362d3cbceded3a9307257e2a5b2b0b6ccbf","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.1.1.tgz","fileCount":23,"integrity":"sha512-MP8a/kIrGc+DeWPTKGuZ3OGcTQhEb8eMnzWzf4t1W3cOqlG4QnK/DDKCvMN6dCPHKZInk61R7yZdJD8a3G4pzA==","signatures":[{"sig":"MEUCIQDzQghBgs2MgmasilWD2di0lL0jvFOG6euHEyXfSzW3VgIgdQ/L15IazHYvsBYgCwEoCunAjlIP6mqJI/qekQ/DKWU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":86164},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"662c1a80989695a7b820aba50c911bbd18b4b297","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"11.17.0","description":"AgentAdmit SDK — User-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.22.3","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.1.1_1781298531196_0.2908440582081755","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@agentadmit/sdk","version":"1.1.2","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.1.2","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"a4f6e0d147da81842feacfcd2c419429d636c7c1","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.1.2.tgz","fileCount":23,"integrity":"sha512-cBV7PT1fte1A/R9lpAkNYw0K68MMA3vLvLARMJ08AFxpEYPNzvnvLfh1KKQUPWSgkNchkbMx8Z3Stt2fbWT5eQ==","signatures":[{"sig":"MEUCIFYYjhbEIBjBv5DpBq5spTbPPd7IfMknO1xqAjG09RoyAiEAwLkkKlCVgOWavFTzxksntzFzDK43MBP7v8UyPnMM0hw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":87214},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"1709c3464102bd42b8499835d630a31d80a527f0","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"11.17.0","description":"AgentAdmit SDK — User-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.22.3","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.1.2_1781726337726_0.9499017593060732","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@agentadmit/sdk","version":"1.2.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.2.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"9182bf26af88556bf4e04d04eb93fda5112a553e","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.2.0.tgz","fileCount":27,"integrity":"sha512-IcRo/1ji8zhyRUmCbYB7zpT84UC1XqNoybfJLg5cK9MxV3OkxnmL2JfE7c+SdmrjMu1F6TIcq1hc3gguF3LDjQ==","signatures":[{"sig":"MEUCIGO9TmApDnLZVB/q5I/QZnEwJlnbjuTmJcm+NMIru8IBAiEA/4Mq5oXD1NMshIoWpUuhmquT8OOmuUdmF/s2eb1abPA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":114598},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"4842d6d8d83d7294304ef53bf5897ca4fc83a392","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"11.18.0","description":"AgentAdmit SDK — User-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.2.0_1783117912736_0.3089145393262256","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@agentadmit/sdk","version":"1.3.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.3.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"e2ea6b71373607e2fac5b1c1b6b3cea90300e655","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.3.0.tgz","fileCount":30,"integrity":"sha512-F2Mhc0LdywtSt3pj8dIcF7olBW12ehRbjNWxdEweJfTpGUeiy75ul+mLUIrARn4ngDmtVwxggQCTO5j4mT61Xg==","signatures":[{"sig":"MEUCIH8YkdEW/kofk/1msh3ZhAI3GGrfd3KdLQ+woQJdzsoQAiEAxDjSpPloTwKviit+iYQit+yPlmr+f4JY0xqv7xT4Mlc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":127375},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"07c982a2923221701785d804f7ecbbea767ebaa9","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"11.18.0","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.3.0_1783196054595_0.348884291002437","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@agentadmit/sdk","version":"1.4.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.4.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"fb9e258aeed1a2e122131ed56d51149ac9ad6bcd","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.4.0.tgz","fileCount":31,"integrity":"sha512-MRYIttQDQsT/OepKY3VjaNrehc6CJPOc+Rml+SY6W/Vbcu9VG2odnW3L0ajlXagBIae6UHs8oRzunboNsfiFDQ==","signatures":[{"sig":"MEYCIQCA2vml9qbLP+gndfK4S+Pg0RZhxcPIDgmI1I8n+SZ4jgIhAPkLue5+9GVx9rMCf8Y909zIsbLFs2u65PRE3LUyDbHa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":136207},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"e9241a86e56d27495db9b3dfb971f6600597b861","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"11.18.0","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.4.0_1783212254982_0.3623655378750479","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@agentadmit/sdk","version":"1.5.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.5.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"de74597a9643eda7fb7bff0550fc5823c3bbc256","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.5.0.tgz","fileCount":34,"integrity":"sha512-mEkVs+w2dEFiMEU2UrgT8TDn3UgNKaWYNtlQxBlA+G/A4mZbJDNnStBrBbNYow+gnmwfXgujOx6Zx2LjzFoWrg==","signatures":[{"sig":"MEUCIBP92smFrf6ch7xPHeSejNTjRSL9oDZg0k01pS3pXYAZAiEA5HYOx1DyDs7fpGwHwwBJvhmhMCjqgJ376NfGyVAZHSc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":157949},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"4e3500457d23b9fe7f96f2625af74b0d8b438164","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.1","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"uuid":"9.0.0","js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/uuid":"9.0.0","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.5.0_1783989644635_0.38533884462066625","host":"s3://npm-registry-packages-npm-production"}},"1.5.1":{"name":"@agentadmit/sdk","version":"1.5.1","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.5.1","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"efe7a933de9f4a59517c42621ff82ffad3f6dd18","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.5.1.tgz","fileCount":34,"integrity":"sha512-vxuUx7l8dAJ8ZTFBuoa5YBZ5enNZ+H6GFw2BZYJakS3jtSyYe2C5PzlVOKDu+gJKU68KYqhVQDqeDw0sGlBKFg==","signatures":[{"sig":"MEUCIQCIqv/3ubT7MnbaXONyFbgXId0PpSZ5nl/wIvC2BbbBXgIgUYNmK2L37qkmQcK/PpKKw28UE5cCNilcSYJQBWjhQmw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":163898},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"d6fe6f7191f97ef2e9edada3fac408ab844509cc","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.1","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"js-yaml":"4.1.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.5.1_1784321918392_0.13142484720552683","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@agentadmit/sdk","version":"1.6.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.6.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"59b781b955162d93ed26d9234b4a88998ca47765","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.6.0.tgz","fileCount":34,"integrity":"sha512-0FK1QF+fUmjS5H6nj4wtApI++yWOQ4pJnZVf+dG3a3uZRfwsj6VVFT9aiJj7YA/8mN39AzBbXzAYeWMd+/f7Fw==","signatures":[{"sig":"MEUCIHnOic8e1QJRfZL8CLfchqcP3wakkKSINtienNZHrYA5AiEAzvnWRzq4MvC/quIluE1qWvpsfcxxI4Ltbvfj1JT5wvU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":172266},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"4ecc1d64cd22dab77094d396cf2875d730dd61a2","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.1","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.6.0_1784520015984_0.7312645581396346","host":"s3://npm-registry-packages-npm-production"}},"1.7.0":{"name":"@agentadmit/sdk","version":"1.7.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.7.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"bbc3001b8437d3590ec6a52d2311edb887ad6707","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.7.0.tgz","fileCount":35,"integrity":"sha512-yzJn7V2/+Sh7t+kjVGkcSwuQiX6zf47nbX8UD5fmLZTNKWuD4Xu4c0s7Cw1h35keKGEx6bnXyWY3BCU8OqRwJg==","signatures":[{"sig":"MEUCIQCWjmsUuKQmW2Gmjq/RA7q6k6M/7EnjB3l7BdalEd8y1AIge5YbubvSYHKWGgdu6k/k0v85LP4rXCbCd4+i5VhLie0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":183487},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"7f83263631586141566d4c4d1b6464b12fc54934","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.2","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.7.0_1785959646263_0.319502605708297","host":"s3://npm-registry-packages-npm-production"}},"1.7.1":{"name":"@agentadmit/sdk","version":"1.7.1","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.7.1","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"aba3ecd1d8baf208c04704443c9c7c83b4dbd386","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.7.1.tgz","fileCount":35,"integrity":"sha512-dY6EbZwPgubUazEZAAbJbHXBU0VI0TnLmiMSXl5DFfDm/PUC2hrP5tAy5xluWm9nyVuzwraOjfe35C0snE3mEQ==","signatures":[{"sig":"MEUCIQDNRGf735oHqr6/C3OWWPFwfVH7nKNE3MGqmHHjQix+5wIgPlIig6Nou7yibf2EWD1brkj5Xm1CiPxUswUhCba/HyM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":188023},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"a3c5d984b1237c22302dd65fc7b709565a9b8e06","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.2","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.7.1_1785961678087_0.6452679837027195","host":"s3://npm-registry-packages-npm-production"}},"1.8.0":{"name":"@agentadmit/sdk","version":"1.8.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.8.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"df7018bb72285f4ece71fed5d698825e72141927","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.8.0.tgz","fileCount":36,"integrity":"sha512-wYTFLlJLAxl2coJi5NNUB3qGUTlJTApVXHCpOuHbW708uSPiWIymJdO5/likcPEWW7Jl6EGz29PhAC2iA7fS3A==","signatures":[{"sig":"MEUCIE7ONwXUDAcpGELV0ts8wevWzebqQAq0eZkcsB0sd4HTAiEAtmsX59g1JzWB2p5gwKt8bCa0UWIKgDjRkp7ciBDnRrk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":206479},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"900f399025db8ccd8c94cc4c031cfb3e597af21a","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.2","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.1","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.8.0_1786476251262_0.08776632468595524","host":"s3://npm-registry-packages-npm-production"}},"1.9.0":{"name":"@agentadmit/sdk","version":"1.9.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.9.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"bacee4f32c39049a7d76fcf18e726dfdd5db3678","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.9.0.tgz","fileCount":39,"integrity":"sha512-bJA6gbK0iwk38Nv0/znl6WVfh+RQXHaOu2qFNepLmW3JBkP/9xlwOHQS/AnnqlR0M2wtQhcETnrSZJ1X0haCGw==","signatures":[{"sig":"MEUCICidBh9tEikE8IKFxJ5Iy8+SEc81JXcYX8Fb0TKeoaqdAiEAujBgXkijh1Wf2yJx/a86CFGMhPrJtjs/RyzFLJeudGU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":224620},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"60f29ab8791424d584af6cc30c16eb84c55aa80e","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.2","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.2","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.9.0_1786642512521_0.28506487359355503","host":"s3://npm-registry-packages-npm-production"}},"1.10.0":{"name":"@agentadmit/sdk","version":"1.10.0","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.10.0","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"8c862bc49bed7c3f9199bbc3ebb0067e470e87e0","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.10.0.tgz","fileCount":40,"integrity":"sha512-fa4ya49HwOAkfsFzrK2tRyQxVMd8s16QeFMw4y7XSR+fQv/6RcDSV8Ge9d9bil0T13fyDHKJmZH+oOxAHxymDw==","signatures":[{"sig":"MEUCIQCdXP3ttTnmm2yM9E6rFN/eZu7vT9j5CxebONIyVIUxwAIgdqhLlGQ8yhHa7Tj5NugDAJ0uO5pMzcUqq88761jKDCs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":240060},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"529c0a815b33109fc7f8fa641c886ada9ad65334","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.2","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.2","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.10.0_1788288049555_0.9632730581937883","host":"s3://npm-registry-packages-npm-production"}},"1.10.1":{"name":"@agentadmit/sdk","version":"1.10.1","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","_id":"@agentadmit/sdk@1.10.1","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"dist":{"shasum":"65fe619808ad07883fc88f52327c97a478d80cc8","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.10.1.tgz","fileCount":40,"integrity":"sha512-cxCPNG/y03JOWwE725AFfXx1Ohcc1lXOxnNEpgAxGk2G5te+FVSrgROWuSct30SwrdvMaTgtzjACNHQv/J/uog==","signatures":[{"sig":"MEYCIQC8h34CsYtMg5iWNhN5gg8vlgSGTsSVdgRFivKBfiYOmAIhALWaXxcw6XaWltGSMd3GrgP8mly9Km7sS41c0IeqF8Ui","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.10.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":241098},"jest":{"roots":["<rootDir>/tests"],"preset":"ts-jest","testEnvironment":"node"},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"f049d2503ab4bf707933bf8d5a4352cafcdd9b59","scripts":{"dev":"tsc --watch","test":"jest","build":"tsc","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"repository":{"url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git","type":"git"},"_npmVersion":"12.0.2","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","directories":{},"_nodeVersion":"22.23.2","dependencies":{"js-yaml":"4.3.0","mongodb":"6.0.0","jsonwebtoken":"9.0.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"jest":"29.0.0","express":"^4.22.2","ts-jest":"29.0.0","typescript":"5.9.3","@types/jest":"29.0.0","@types/node":"22.19.20","@types/express":"4.17.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.10.1_1788290007075_0.35138520204273505","host":"s3://npm-registry-packages-npm-production"}},"1.11.0":{"name":"@agentadmit/sdk","version":"1.11.0","description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","main":"dist/index.js","types":"dist/index.d.ts","scripts":{"build":"tsc","dev":"tsc --watch","test":"jest","smoke":"node -e \"const sdk = require('./dist/index.js'); if (typeof sdk.createAgentAdmitRouter !== 'function' || typeof sdk.validateAgentToken !== 'function') throw new Error('built entry is missing exports');\"","prepack":"npm run build && npm run smoke"},"dependencies":{"js-yaml":"4.3.0","jsonwebtoken":"9.0.0","mongodb":"6.0.0"},"devDependencies":{"@types/express":"4.17.0","@types/jest":"29.0.0","@types/js-yaml":"4.0.0","@types/jsonwebtoken":"9.0.0","@types/node":"22.19.20","express":"^4.22.2","jest":"29.0.0","ts-jest":"29.0.0","typescript":"5.9.3"},"peerDependencies":{"express":">=4.0.0"},"peerDependenciesMeta":{"express":{"optional":true}},"jest":{"preset":"ts-jest","testEnvironment":"node","roots":["<rootDir>/tests"]},"license":"SEE LICENSE IN LICENSE","author":{"name":"Christopher Emerson"},"repository":{"type":"git","url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git"},"keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"gitHead":"2f028c2d48e705aa28fe8919728a845b7a06f01a","_id":"@agentadmit/sdk@1.11.0","bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","_nodeVersion":"22.23.2","_npmVersion":"12.0.2","dist":{"integrity":"sha512-pRRtUTQMrAnTcdXhn8axBWLI5atSg/khCz3HAx7kHRIHrnbHIrIVuyd08PgSMXumNyE3YTy5i++ZjgRJTB3teQ==","shasum":"ba3e007f08e94c7085e2919afe3948572d158935","tarball":"https://registry.npmjs.org/@agentadmit/sdk/-/sdk-1.11.0.tgz","fileCount":41,"unpackedSize":266795,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentadmit%2fsdk@1.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGgIAwUAD0Vj1AVKT5sMR/aZsNN6xa/FhU0bcHmJk+MgAiAyVjO+VxvvrQUGbfa+3RjLEscfTHnP5iBBX+O9pqXWVw=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9d480f8-f6d0-43fa-8e19-26b82c1ec56c"}},"directories":{},"maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_1.11.0_1789498739925_0.9508261490688215"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-03T18:48:27.450Z","modified":"2026-09-15T18:59:00.487Z","1.0.0":"2026-06-03T18:48:27.784Z","1.1.0":"2026-06-11T20:25:59.791Z","1.1.1":"2026-06-12T21:08:51.376Z","1.1.2":"2026-06-17T19:58:57.893Z","1.2.0":"2026-07-03T22:31:52.874Z","1.3.0":"2026-07-04T20:14:14.724Z","1.4.0":"2026-07-05T00:44:15.164Z","1.5.0":"2026-07-14T00:40:44.802Z","1.5.1":"2026-07-17T20:58:38.531Z","1.6.0":"2026-07-20T04:00:16.175Z","1.7.0":"2026-08-05T19:54:06.419Z","1.7.1":"2026-08-05T20:27:58.227Z","1.8.0":"2026-08-11T19:24:11.427Z","1.9.0":"2026-08-13T17:35:12.712Z","1.10.0":"2026-09-01T18:40:49.664Z","1.10.1":"2026-09-01T19:13:27.308Z","1.11.0":"2026-09-15T18:59:00.060Z"},"bugs":{"url":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node/issues"},"author":{"name":"Christopher Emerson"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/PhoenixCo-Founder/agentadmit-sdk-node#readme","keywords":["agentadmit","ai-agent","authorization","auth","sdk","middleware"],"repository":{"type":"git","url":"git+https://github.com/PhoenixCo-Founder/agentadmit-sdk-node.git"},"description":"AgentAdmit SDK: user-mediated AI agent authorization for Node.js apps","maintainers":[{"name":"agentadmit","email":"christopher@agentadmit.com"}],"readme":"# @agentadmit/sdk - Node.js\n\nUser-mediated AI agent authorization. Plug-and-play for Express and Next.js.\n\n> **Get started:** Sign up at [agentadmit.com](https://agentadmit.com) → Get your test keys → Install the SDK → Build.\n> Test keys are available immediately after signup. Live keys become available when you subscribe an app.\n\n> **Where the consent step runs (live keys).** The agent grant is approved on the AgentAdmit **hosted consent page**, opened on your app's behalf: your backend creates a consent session (`POST /api/v1/apps/{app_id}/consent-sessions`) with your live key and sends the signed-in user to the returned `session_url`. Scope selection, duration, intent, existing-grant review, the passkey ceremony, and the one-time token all happen there. **Direct token issuance (`POST /api/v1/apps/{app_id}/token`, and this SDK's issue-token helpers and any SDK-mounted `generate-token` route) is a sandbox facility for `aa_test_` keys only; a live key receives `403 hosted_consent_required`.** Verification (`/verify`) is unchanged and is the core of this SDK. Full walkthrough: [App Owner Guide, Step 4](https://agentadmit.com/docs/app-owner-guide).\n\n## Quick Start\n\n```bash\nnpm install @agentadmit/sdk\n```\n\nCreate an `agentadmit.yaml` file to define your scopes (see Configuration below), then add to your Express app:\n\n```javascript\nconst express = require('express');\nconst { loadConfig, createStorage, createAgentAdmitRouter, setStorage, requireScopeIfAgent } = require('@agentadmit/sdk');\n\nconst app = express();\napp.use(express.json());\n\n// Initialize AgentAdmit\nconst config = loadConfig('agentadmit.yaml');\nconst storage = createStorage(config);\nsetStorage(storage);\n\n// Create and mount AgentAdmit routes\nconst { wellknownRouter, agentadmitRouter } = createAgentAdmitRouter({\n  storage,\n  getCurrentUser: async (req) => { /* your auth logic */ },\n});\napp.use(wellknownRouter);\napp.use('/agentadmit', agentadmitRouter);\n\n// Protect your routes with scope enforcement\napp.get('/api/orders', requireScopeIfAgent('read:orders'), (req, res) => {\n  const user = req.agentAdmit?.user;\n  // Your existing logic - unchanged\n  res.json({ orders: getOrdersForUser(user.user_id) });\n});\n```\n\n## Next.js API Routes\n\n```typescript\n// pages/api/orders.ts (or app/api/orders/route.ts)\nimport { validateAgentToken, getConfig } from '@agentadmit/sdk';\n\nexport default async function handler(req, res) {\n  const token = req.headers.authorization?.replace('Bearer ', '');\n  const config = getConfig();\n\n  if (token?.startsWith(config.token_prefix_access)) {\n    const ctx = await validateAgentToken(token);\n    if (!ctx.scopes.includes('read:orders')) {\n      return res.status(403).json({ error: 'insufficient_scope' });\n    }\n    // Agent path\n    return res.json({ orders: await getOrders(ctx.user.user_id) });\n  }\n\n  // Regular user path\n  // ... your existing auth\n}\n```\n\n## MCP Server Integration\n\nBuilding an MCP server in TypeScript/Node? AgentAdmit is the auth layer. MCP servers are app owners. Same SDK, same pricing.\n\nFor **STDIO transport** (most MCP servers), the agent includes the token in tool arguments:\n\n```javascript\nconst { validateAgentToken } = require('@agentadmit/sdk');\n\nasync function handleToolCall(name, args) {\n  // 1. Extract token from tool arguments\n  const token = args.agentadmit_token;\n  delete args.agentadmit_token;\n  if (!token) throw new Error('agentadmit_token required');\n  \n  // 2. Validate via AgentAdmit hosted service\n  const ctx = await validateAgentToken(token);\n  \n  // 3. Check scope for this tool\n  const required = SCOPE_MAP[name];\n  if (required && !ctx.scopes.includes(required)) {\n    throw new Error(`Missing scope '${required}'`);\n  }\n  \n  // 4. Run the tool\n  return TOOL_HANDLERS[name](args, ctx);\n}\n```\n\nFor **HTTP transport** (Express-based MCP servers), use the full SDK middleware. The agent sends the token via `Authorization: Bearer` header, same as any HTTP API.\n\nFull MCP integration guide with complete before/after examples: `agentadmit.com/docs/mcp-guide`\n\n**MCP operators:** You also get the embeddable admin panel for monitoring connections and usage, full audit trail for billing, and user-initiated revocation. See the Embeddable Admin Panel section below.\n\n## How It Works\n\n1. User clicks \"AgentAdmit\" in your app\n2. Selects scopes and connection duration\n3. Gets a token to give to their AI agent\n4. Agent exchanges the token for scoped API access\n5. User revokes anytime\n\nThe token goes to the human, not the agent. No automated delivery = no prompt injection surface.\n\n## Important\n\n**Mandatory introspection.** All token validation goes through api.agentadmit.com. There is no self-hosted mode. No local JWT validation. No bypass. This is required for security, audit logging, and scope enforcement.\n\n**User revocation.** Users revoke connections via `DELETE /agentadmit/connections/{connection_id}`. The SDK route verifies the requesting user owns the connection before forwarding the revocation to the hosted service; local storage is updated only after the hosted revoke succeeds.\n\n**Embeddable admin panel.** Drop the `<AgentAdmitAdminPanel>` React component into your admin section to view all agent connections, usage metrics, billing status, and revoke any connection without leaving your app. See the React SDK for details.\n\n**In-app AI scopes.** If your app has built-in AI features (analysis, plan generation, photo recognition), do not expose those as agent scopes. The user's AI agent can read the raw data and do the analysis itself. Exposing in-app AI endpoints to agents creates double cost.\n\n## Per-Call Audit Telemetry\n\nSince 1.10.0, every verification call reports what the call actually did, so the\napp's tamper-evident audit log on the AgentAdmit hosted service records per-call\nusage instead of just token validity:\n\n- `scope_used` - the scope the route enforces, sent automatically by\n  `requireScope` and `requireScopeIfAgent`.\n- `endpoint` - the inbound request path (path only; the query string is never\n  sent).\n- `method` - the HTTP method.\n\nNo integration changes are needed: the middlewares you already use collect\nthese automatically. Calls verified without a scope-enforcing middleware\n(`resolveAuth`, `requirePresence`, or a bare `validateAgentToken`) still send\nendpoint and method, and the hosted audit log honestly records that no\nexercised scope was declared. Direct `validateAgentToken(token, telemetry)`\ncallers can pass a `VerifyTelemetry` object themselves.\n\n`callerConsent({ requiredScope })` reports the same three fields and sets the\nhosted `consent_first` guard automatically, so a denied caller class cannot\nlearn scope state before the middleware returns its consent 403.\n\nThe SDK also fails closed on per-call refusals: when the hosted service answers\nthat the token is valid but THIS call is refused (`insufficient_scope`,\n`bound_exceeded` when a user-set usage ceiling is reached, or any future\nrefusal class), the middleware returns 403 (`VerifyRefusedError` for direct\ncallers) and never invokes your route handler.\n\n## Confirm Each Time (Exercise-Time Human Confirmation)\n\nSome actions should never run on a standing grant alone: moving money, sending\nor publishing on the user's behalf, deleting data, touching production. Mark\nthose scopes `confirm_each_time: true` when you register them, and the hosted\nservice requires a fresh human confirmation for every call that exercises\nthem, even inside a valid connection.\n\nIn `agentadmit.yaml`:\n\n```yaml\nscopes:\n  - name: write:payments\n    description: Move money\n    category: Payments\n    role: user\n    confirm_each_time: true\n```\n\nThe flag is typed on `ScopeDefinition` and round-trips unchanged to the\n`/scopes` endpoint the hosted service reads, so the registration your app\npublishes is the policy the hosted service enforces.\n\nHow a call flows:\n\n1. The agent calls your route. The SDK verifies the token as usual, carrying\n   the exercised scope, a `sha256:` digest of the request body, and the\n   plain-language `actionSummary` you provide.\n2. The hosted service refuses the first call with `confirmation_required` and\n   stages a one-time ceremony for exactly that action. Your route returns 403\n   with a `confirmation` block; the agent gives `confirmation.action_session_url`\n   to the user.\n3. The user confirms on AgentAdmit's hosted page with their passkey. The\n   signature commits to the scope, method, endpoint, request digest, and the\n   summary they saw. Only a user-verified ceremony produces an attestation; the\n   agent cannot complete it.\n4. The agent retries the same request with the header\n   `X-AgentAdmit-Action-Attestation: <action_session_id>`. The SDK forwards it,\n   the hosted service consumes the attestation once (exact action only), and\n   the call proceeds. The audit row names the confirmation.\n\n```ts\nimport { requireScope, ConfirmationRequiredError } from '@agentadmit/sdk';\n\napp.post(\n  '/api/payments',\n  requireScope('write:payments', {\n    actionSummary: (req) => `Pay ${req.body.trainer} $${req.body.amount}`,\n  }),\n  handler,\n);\n```\n\nThe 403 body an agent receives on the first call:\n\n```json\n{\n  \"error\": \"confirmation_required\",\n  \"error_description\": \"Scope \\\"write:payments\\\" requires a fresh human confirmation for each call. ...\",\n  \"confirmation\": {\n    \"action_session_id\": \"asess_...\",\n    \"action_session_url\": \"https://agentadmit.com/confirm/action/asess_...\",\n    \"expires_at\": \"2026-09-02T18:30:00.000Z\",\n    \"scope\": \"write:payments\",\n    \"method\": \"POST\",\n    \"endpoint\": \"/api/payments\",\n    \"request_digest\": \"sha256:...\",\n    \"summary\": \"Pay Alex $50\"\n  }\n}\n```\n\nNotes:\n\n- The summary is yours. AgentAdmit shows it as the headline of the confirmation\n  page and commits to the text shown; it does not verify the description\n  against the request.\n- A confirmation covers exactly one call. A retry with a different body, route,\n  method, or summary is refused again with `attestation_status: \"action_mismatch\"`.\n- `validateAgentToken` throws `ConfirmationRequiredError` (a `VerifyRefusedError`)\n  with the typed `confirmation` block when you build your own middleware.\n- Confirmation only applies when the call declares the exercised scope, which\n  `requireScope` always does.\n\n## Rate Limiting\n\nThe AgentAdmit introspection endpoint enforces rate limits. The Node.js SDK handles HTTP 429 responses **automatically** with exponential backoff and jitter - no changes needed in your middleware code.\n\n### Retry behavior\n\n| Parameter | Default | Description |\n|-----------|---------|-------------|\n| Initial delay | 1 second | First retry wait |\n| Backoff multiplier | 2× | Doubles each retry |\n| Cap | 30 seconds | Maximum wait per retry |\n| Jitter | 0–500 ms | Random addition to each delay |\n| Max retries | **3** | Configurable |\n\nThe SDK also respects the `Retry-After` response header - if present, it overrides the computed backoff delay.\n\n### Configuring max retries\n\nIn `agentadmit.yaml`:\n\n```yaml\nmax_retries: 5  # default: 3. Set to 0 to disable retries.\n```\n\n### Handling exhausted retries\n\nWhen all retries are exhausted, `validateAgentToken` throws `RateLimitError`:\n\n```typescript\nimport { requireScope, RateLimitError } from '@agentadmit/sdk';\n\napp.use((err: any, req, res, next) => {\n  if (err instanceof RateLimitError) {\n    res.set('Retry-After', String(err.retryAfter ?? 60));\n    return res.status(429).json({\n      error: 'rate_limited',\n      retry_after: err.retryAfter,\n      limit: err.limit,\n      remaining: err.remaining,\n      reset: err.reset,\n    });\n  }\n  next(err);\n});\n```\n\n`RateLimitError` properties:\n- `retryAfter` - seconds from `Retry-After` header (or `null`)\n- `limit` - `X-RateLimit-Limit` header value (or `null`)\n- `remaining` - `X-RateLimit-Remaining` header value (or `null`)\n- `reset` - `X-RateLimit-Reset` Unix timestamp (or `null`)\n\n## Documentation\n\nFull integration guide: https://agentadmit.com/docs/app-owner-guide\n\n\n## Data Collection & Privacy\n\nThe AgentAdmit Node.js SDK runs server-side and does not interact with app stores or end-user devices directly.\n\n### What the SDK does\n- Validates AgentAdmit tokens by calling AgentAdmit's hosted introspection endpoint (`https://api.agentadmit.com/api/v1/verify`) on every agent request - this is mandatory introspection; there is no local or offline validation mode\n- Enforces scope-based access control on your API routes\n- Manages connection lifecycle (create, revoke, audit) using your configured storage backend\n\n### What the SDK does NOT do\n- Does not transmit raw end-user PII (such as name, email, or device identifiers) - each introspection request sends the opaque access token and your API key\n- Does not perform passive background telemetry or analytics - network calls occur only during active token validation\n- Does not maintain its own persistent storage - local state (connections, audit log) lives in the storage backend you configure\n\n### What the AgentAdmit hosted service records\nOn every token validation, AgentAdmit's `/api/v1/verify` endpoint receives the access token and API key, resolves the token to its `user_id`, `connection_id`, granted `scopes`, and `agent_label`, and records per-call metadata (including the endpoint and timestamp) for billing, audit logging, the security alerts engine, and usage metering. This is integral to how AgentAdmit works and applies to both test and live keys. See the \"Mandatory introspection\" notes above and the [compliance guide](https://agentadmit.com/docs/compliance) for the full data-handling description.\n\n### Privacy impact\nSince this SDK runs on your server, it has no direct App Store or Play Store compliance surface. Your client-side integration (e.g., the AgentAdmit React SDK) handles privacy manifest and data safety requirements.\n\nFor complete compliance guidance, see our [compliance guide](https://agentadmit.com/docs/compliance).\n\n## License\n\nAll rights reserved. Patent pending.\n\n## Consent Ledger (Caller-Identity Consent)\n\nAgentAdmit can host per-user consent switches for three independent caller classes: `human_session`, `in_app_ai`, and `external_agent`. No class's setting implies another's.\n\n**External agents:** the verify response already includes the verdict; it rides into your middleware context as `req.agentAdmit.consent`. The hosted service deliberately omits the verdict when its consent store is unreadable (degraded mode), so treat an absent verdict as *unresolved*, never as a grant — resolve it with `checkConsent`:\n\n```typescript\napp.get('/api/workouts', requireScope('read:workouts'), async (req, res) => {\n  let { consent, user } = (req as any).agentAdmit;\n  if (!consent || typeof consent.granted !== 'boolean') {\n    consent = await checkConsent({ appUserId: user.user_id, callerClass: 'external_agent' }); // fail closed on error\n  }\n  if (consent.granted !== true) {\n    return res.status(403).json({ error: 'consent_not_granted' });\n  }\n  // serve the data\n});\n```\n\nThe `callerConsent()` middleware does all of this for you: it evaluates the consent verdict **before** the scope check (a caller whose class the owner denied learns nothing about scope state or step-up) and resolves an absent verdict through the Consent Ledger, fail-closed.\n\n**Human sessions and in-app AI** never hold AgentAdmit tokens, so ask directly:\n\n```typescript\nimport { checkConsent } from '@agentadmit/sdk';\n\nconst verdict = await checkConsent({ appUserId: 'user_8842', callerClass: 'in_app_ai' });\nif (!verdict.granted) {\n  // do not run AI over this user's data\n}\n```\n\nConsent is orthogonal to revocation: a denied verdict means your app returns its own 403; the connection and token stay valid so the user can flip consent back on without re-connecting. Write the switches through `PUT /api/v1/consent/settings` from your backend, and export the full audit trail with `GET /api/v1/consent/export` (every plan).\n\n## Presence Verification (Human Presence)\n\nConnections authorized on the AgentAdmit hosted consent page can require a WebAuthn ceremony (Touch ID, Windows Hello, a security key) before the token is generated. The verify response reports the fact on every introspection as `presence`, and it rides into your middleware context as `req.agentAdmit.presence`:\n\n```typescript\nimport { requirePresence, presenceVerified } from '@agentadmit/sdk';\n\n// Gate a sensitive route on a presence-verified connection (403 otherwise):\napp.post('/api/transfers', requirePresence(), transferHandler);\n\n// Or branch on it yourself:\napp.get('/api/workouts', requireScope('read:workouts'), (req, res) => {\n  const ctx = (req as any).agentAdmit;\n  if (!presenceVerified(ctx)) {\n    // connection was minted without a human presence ceremony\n  }\n});\n```\n\nTo require presence at authorization time, create the consent session with `\"presence\": \"required\"`; token generation fails closed until a human completes the ceremony. `requirePresence()` is strict: connections from servers or sessions that never ran a ceremony report `verified: false` and are rejected.\n\n### Presence gate for embedded token minting\n\nIf you mount the SDK's user-authenticated `/agentadmit/connections/generate-token`\nroute inside your own app, gate that route with your app's own human-presence\nceremony. A browser-driving agent can ride a logged-in user session, so scoped\ntoken minting should require a fresh passkey, WebAuthn, or equivalent\nout-of-band confirmation before the hosted token call is made.\n\n```typescript\nconst { wellknownRouter, agentadmitRouter } = createAgentAdmitRouter({\n  storage,\n  getCurrentUser: async (req) => req.user ?? null,\n  requireTokenMintPresence: async (req, currentUser) => {\n    const ok = await verifyAndConsumePasskeyAttestation({\n      userId: currentUser.user_id,\n      attestationId: req.body?.presence_attestation_id,\n      purpose: 'token_mint',\n    });\n    if (!ok) {\n      const err: any = new Error('Confirm human presence before generating a connection token');\n      err.statusCode = 403;\n      err.detail = { error: 'presence_attestation_required' };\n      throw err;\n    }\n  },\n});\n```\n\nThe hook runs after user authentication and local request validation, and before\nAgentAdmit's hosted token mint or any local connection record is written. If no\nhook is configured, existing apps keep the previous behavior.\n\n**Throw to deny.** The hook must `throw` to deny (attach `statusCode`/`detail`\nfor a custom response), and must *verify and consume* the attestation\nsingle-use (checking alone lets it be replayed). Returning nothing allows the\nmint; returning an `AppAttestedPresence` allows the mint and forwards the\nceremony fact (below); returning any other value fails closed with a `500` so\na misconfigured hook that returns a denial object instead of throwing can\nnever let the mint proceed.\n\n### App-Attested Presence (forward the ceremony fact)\n\nYour ceremony is origin-bound, so AgentAdmit never witnesses it: by default\nthe hosted service reports `presence.verified: false` for connections your\nhook gated, even though a real passkey ceremony happened. To close that gap,\nreturn an `AppAttestedPresence` from the hook after verifying and consuming\nyour attestation:\n\n```typescript\nimport { AppAttestedPresence } from '@agentadmit/sdk';\n\nrequireTokenMintPresence: async (req, currentUser) => {\n  const attestation = await verifyAndConsumePasskeyAttestation({\n    userId: currentUser.user_id,\n    attestationId: req.body?.presence_attestation_id,\n    purpose: 'token_mint',\n  });\n  if (!attestation) {\n    const err: any = new Error('Confirm human presence before generating a connection token');\n    err.statusCode = 403;\n    err.detail = { error: 'presence_attestation_required' };\n    throw err;\n  }\n  return new AppAttestedPresence({\n    method: 'my_webauthn',              // lowercase alphanumeric/underscore\n    verifiedAt: attestation.createdAt,  // Date, or ISO string WITH offset\n  });\n},\n```\n\nThe SDK forwards it to the hosted mint as\n`presence: {verified: true, uv: true, method, verified_at}`. The hosted\nservice validates freshness (10-minute window, 60 s future clock-skew slack)\nand stores the method provenance-marked `app:<method>` so app-attested facts\nstay distinct from ceremonies AgentAdmit witnessed itself. Introspection, the\ngrant-event ledger, and the evidence API then carry `presence.verified: true`\nfor the connection, and the local record behind `GET /connections` carries\nthe same `presence` object.\n\nHonesty ceiling: this is *your app's attestation*, recorded and\nprovenance-marked. It is not witnessed by AgentAdmit and not independently\nverifiable. Only construct one for a ceremony that verified the user with UV\n(biometric or PIN user verification); `verified`/`uv` are literal `true`. A\nceremony without UV carries no presence fact, so return nothing instead.\nPass `verifiedAt` as a `Date` (serialized safely) or an ISO-8601 string with\nan explicit offset; offset-less strings are rejected at construction because\nthe hosted mint rejects them.\n\n## Declared Purpose\n\nDeclared purpose: the user-facing reason recorded on the grant at the consent moment. Review-time record only, never an enforcement input; authorization decisions ride scopes, connection status, and consent.\n\nPass an optional `purpose` (1–300 characters) when generating a connection token; the SDK forwards it to the hosted mint, which records it on the grant:\n\n```typescript\n// POST /agentadmit/connections/generate-token\n{ \"scopes\": [\"read:things\"], \"purpose\": \"Reconcile July invoices\" }\n```\n\nThe verify response reports it back on every introspection, and it rides into your middleware context as `req.agentAdmit.purpose` — `undefined` when no purpose was declared:\n\n```typescript\napp.get('/api/invoices', requireScope('read:invoices'), (req, res) => {\n  const ctx = (req as any).agentAdmit;\n  // Show it in your own audit views or connection lists:\n  console.log(`Access under declared purpose: ${ctx.purpose ?? '(none declared)'}`);\n});\n```\n\nDo not branch authorization on `purpose` — it is a record for humans reviewing a grant, not a gate. Scope checks, connection status, and consent verdicts remain the only decision inputs.\n\n## User-Declared Intent\n\nUser-declared intent: the user's own words for what they want the agent to do, typed at the consent moment. Where `purpose` records the app's words — the app's declared reason for the grant — `user_intent` records the user's own words. Review-time record only, never an enforcement input; authorization decisions ride scopes, connection status, and consent.\n\nPass an optional `user_intent` (1–300 characters) when generating a connection token; the SDK forwards it to the hosted mint, which records it on the grant:\n\n```typescript\n// POST /agentadmit/connections/generate-token\n{ \"scopes\": [\"read:things\"], \"user_intent\": \"Find me the cheapest flight to Lisbon in October\" }\n```\n\nIt flows identically to `purpose`: recorded on the grant, reported back on verify, carried on audit rows and ledger events. When the hosted presence ceremony runs, the intent is included in the verifiable-consent-evidence commitment, so the user's authenticator signs their own words alongside the rest of the consent evidence.\n\nThe verify response reports it back on every introspection, and it rides into your middleware context as `req.agentAdmit.user_intent` — `undefined` when no intent was declared:\n\n```typescript\napp.get('/api/flights', requireScope('read:flights'), (req, res) => {\n  const ctx = (req as any).agentAdmit;\n  // Show it in your own audit views or connection lists:\n  console.log(`Access under user-declared intent: ${ctx.user_intent ?? '(none declared)'}`);\n});\n```\n\nDo not branch authorization on `user_intent` — it is a record for humans reviewing a grant, not a gate. Scope checks, connection status, and consent verdicts remain the only decision inputs.\n\n## Security Alerts\n\nMonitor suspicious agent activity. Six alert types:\n- `volume_spike`, `failed_scope_attempts`, `burst_pattern`,\n- `stale_reactivation`, `new_scope_usage`, `revoked_connection_attempt`\n\n### Configure Alert Thresholds\n\n```typescript\nimport { configureAlerts } from '@agentadmit/sdk';\n\nawait configureAlerts({\n  app_id: 'app_abc123',\n  alert_type: 'volume_spike',\n  enabled: true,\n  threshold_value: 100,\n  threshold_window_minutes: 5,\n  kill_switch_enabled: true,\n});\n```\n\n### List Alert Events\n\n```typescript\nimport { listAlerts } from '@agentadmit/sdk';\nconst { events, total } = await listAlerts({ app_id: 'app_abc123', alert_type: 'volume_spike' });\n```\n\n### Get Current Config\n\n```typescript\nimport { getAlertConfig } from '@agentadmit/sdk';\nconst config = await getAlertConfig({ app_id: 'app_abc123' });\n```\n\n\n### Notifying Your Users\n\nAgentAdmit detects anomalies, fires alerts, and (with kill switch) auto-revokes connections. **How you notify your own users is up to you.** AgentAdmit provides the data - you deliver it through your own system (in-app notifications, email, push, etc.).\n\n- **Poll alerts** - Use the SDK methods above from your backend to check for new events, then notify users through your existing system.\n- **Webhook delivery** - Configure a webhook URL in your AgentAdmit dashboard. When an alert fires, AgentAdmit POSTs the payload to your server, signed with your `whsec_…` secret. The payload carries `alert_id`, `alert_type`, `severity`, the connection's `agent_label`, and the grant's declared `purpose`; the full shape is documented in the Webhook Delivery section of the MCP guide at https://agentadmit.com/docs/mcp-guide. Always verify the signature against the **raw** request body before trusting the payload:\n\n  ```ts\n  import express from 'express';\n  import { verifyWebhookSignature, WebhookSignatureError } from '@agentadmit/sdk';\n\n  app.post('/agentadmit/alerts', express.raw({ type: 'application/json' }), (req, res) => {\n    try {\n      verifyWebhookSignature(\n        req.body, // raw Buffer\n        req.header('X-AgentAdmit-Signature') ?? '',\n        process.env.AGENTADMIT_WEBHOOK_SECRET!, // whsec_…\n      );\n    } catch (err) {\n      if (err instanceof WebhookSignatureError) {\n        return res.status(400).json({ error: 'invalid_signature' });\n      }\n      throw err;\n    }\n    const event = JSON.parse(req.body.toString('utf-8'));\n    // ...\n    res.sendStatus(200);\n  });\n  ```\n\n  The header format is `t=<unix_ts>,v1=<hex>` - an HMAC-SHA256 of `${t}.${rawBody}` keyed with your signing secret. The helper compares in constant time and rejects timestamps more than 5 minutes off (replay protection).\n- **React SDK** - Embed the `<AlertsPanel>` component so users can view their own alert history and tighten thresholds.\n","readmeFilename":"README.md"}