{"_id":"@agentauthoritychain/client","_rev":"3-b759bd701f7bc703afe6e31ac9dd3220","name":"@agentauthoritychain/client","dist-tags":{"latest":"0.5.2"},"versions":{"0.5.0":{"name":"@agentauthoritychain/client","version":"0.5.0","keywords":["ai-agents","authority","delegation","authorization","capabilities","fail-closed"],"license":"Apache-2.0","_id":"@agentauthoritychain/client@0.5.0","maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"homepage":"https://agentauthoritychain.com/quickstart/","bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"dist":{"shasum":"11aa4beee8528bf2588274343840ed7f9219f9c6","tarball":"https://registry.npmjs.org/@agentauthoritychain/client/-/client-0.5.0.tgz","fileCount":6,"integrity":"sha512-WLo9/q8StnKy1fmudrbBI9zgqK7X3tQSj0RskrqWCnOgYo7HzWcS/xuF4LAdAra2CsYjaFqn+pIwzOs3EIy82Q==","signatures":[{"sig":"MEQCIANgneY1/Nr06C6PgejlcqqivUUtcPLh2fMvQDvt3CdmAiBKBLqLcbN6fZ5jWlWqNY9+MjzNI85jYfWAfnJzrLxStw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":18187},"type":"module","engines":{"node":">=20"},"exports":{".":"./aac-client.mjs","./aacp":"./aacp-client.mjs","./public-test":"./aac-public-test.mjs"},"gitHead":"6bcc9cd4da33015277aa8344b63a4cb40c304fcd","_npmUser":{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"},"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/javascript"},"_npmVersion":"11.17.0","description":"Fail-closed AI-agent authority verification and delegated capability enforcement with signed decision receipts","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/client_0.5.0_1787693821094_0.9258232236963793","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@agentauthoritychain/client","version":"0.5.1","keywords":["ai-agents","agent-authorization","delegated-authority","delegation","capability-enforcement","revocation","decision-receipts","fail-closed"],"license":"Apache-2.0","_id":"@agentauthoritychain/client@0.5.1","maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"homepage":"https://agentauthoritychain.com/wiki/","bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"dist":{"shasum":"a918a2af88ca812330f319f3c8f00c7972299007","tarball":"https://registry.npmjs.org/@agentauthoritychain/client/-/client-0.5.1.tgz","fileCount":6,"integrity":"sha512-4wVOpG+TxjB3JNGttwnPVTkxuI1GuLJVAxrjgG3KL1LQI4B6EujBeD4NiXV5ycHTWTK6b43YPmcb9zhCTdkhhw==","signatures":[{"sig":"MEUCICEdtP9WsjrKyzTCQhlO7srMNIZG5PSsio5lzoFFbM1GAiEAjmbZJoTfkw9Q56wew37mZ6deo9rxd1h4/jlYy8Jrcmo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":20350},"type":"module","engines":{"node":">=20"},"exports":{".":"./aac-client.mjs","./aacp":"./aacp-client.mjs","./public-test":"./aac-public-test.mjs"},"gitHead":"877d3574053e2d57c499f221fe8c0464c32035e9","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","approver":{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"},"trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb18197b-a00d-41f8-a5da-5e8ceb46b281"}},"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/javascript"},"_npmVersion":"11.19.0","description":"Fail-closed AI-agent authority verification and delegated capability enforcement with signed decision receipts","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/client_0.5.1_1787710195016_0.590086797902692","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"_id":"@agentauthoritychain/client@0.5.2","bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"dist":{"shasum":"58a0df88874cc7e07dd69007276ae0e5f89f8b54","tarball":"https://registry.npmjs.org/@agentauthoritychain/client/-/client-0.5.2.tgz","integrity":"sha512-V/Fp2UE6gpYa7s7BDbC9mhcoaTj04VQkS+MugYAy6a1bSEQ60wNPvNMAh+A4rn94WwRi+OEFEnzmXMzRWT2yvw==","fileCount":8,"unpackedSize":26028,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFodIv+wSfw4W+ZY+nVji56gBCreJLuOPObAhnQ+iH3zAiEAhtbzE0ujDHSW3DFeIXDOidrI56r5aiZxU/Et4aDB6kI="}]},"name":"@agentauthoritychain/client","type":"module","engines":{"node":">=20"},"exports":{".":"./aac-client.mjs","./aacp":"./aacp-client.mjs","./adcs":"./aac-adcs.mjs","./public-test":"./aac-public-test.mjs","./framework-adapters":"./aac-framework-adapters.mjs"},"gitHead":"a157a73e61e4a5bc47b4b0500ad882cf4e9e74a1","license":"Apache-2.0","version":"0.5.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb18197b-a00d-41f8-a5da-5e8ceb46b281"},"approver":{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}},"homepage":"https://agentauthoritychain.com/wiki/","keywords":["ai-agents","agent-authorization","delegated-authority","delegation","capability-enforcement","revocation","decision-receipts","fail-closed"],"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/javascript"},"_npmVersion":"11.19.0","description":"Fail-closed AI-agent authority verification and delegated capability enforcement with signed decision receipts","directories":{},"maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/client_0.5.2_1787749641384_0.6028737669457822"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-25T21:37:00.816Z","modified":"2026-08-26T13:07:21.755Z","0.5.0":"2026-08-25T21:37:01.252Z","0.5.1":"2026-08-26T02:09:55.105Z","0.5.2":"2026-08-26T13:07:21.474Z"},"bugs":{"url":"https://github.com/AgentAuthorityChain/aac/issues"},"license":"Apache-2.0","homepage":"https://agentauthoritychain.com/wiki/","keywords":["ai-agents","agent-authorization","delegated-authority","delegation","capability-enforcement","revocation","decision-receipts","fail-closed"],"repository":{"url":"git+https://github.com/AgentAuthorityChain/aac.git","type":"git","directory":"integrations/javascript"},"description":"Fail-closed AI-agent authority verification and delegated capability enforcement with signed decision receipts","maintainers":[{"name":"agentauthoritychain-owner","email":"no-reply@agentauthoritychain.com"}],"readme":"# Agent Authority Chain JavaScript client\n\nFail-closed authorization for consequential AI-agent actions in Node.js. Use this package when a principal delegates constrained authority to agents and a tool, API, workflow or transaction must reject widened, expired, revoked, malformed or unverifiable authority.\n\nAAC verifies authority rather than identity alone. It checks Ed25519-signed delegation chains and returns a signed decision receipt. Denial, timeout, network failure, malformed output and receipt-verification failure never release the protected operation.\n\n```bash\nnpm install @agentauthoritychain/client@0.5.2\n```\n\n```javascript\nimport { AACClient, AACDenied } from \"@agentauthoritychain/client\";\n\nconst client = new AACClient({ credential: process.env.AAC_API_CREDENTIAL });\ntry {\n  const { result, receipt } = await client.enforce(signedScenario, executeProtectedOperation);\n} catch (error) {\n  if (error instanceof AACDenied) denyOperation();\n  else throw error;\n}\n```\n\n`enforce` calls the protected operation only after an exact permit and successful Ed25519 receipt verification. The client creates a fresh timestamp and high-entropy nonce for each request.\n\n## Protect one framework tool\n\n```javascript\nimport { AACClient } from \"@agentauthoritychain/client\";\nimport { guardOpenAIAgentsTool } from \"@agentauthoritychain/client/framework-adapters\";\n\nconst protectedTool = guardOpenAIAgentsTool(toolHandler, {\n  client: new AACClient({ credential: process.env.AAC_API_CREDENTIAL }),\n  buildSignedScenario: buildSignedAuthorityForCall,\n});\n```\n\nThe same module exports named bindings for Anthropic Agent SDK, LangGraph, CrewAI, Claude Code hooks, and Codex hooks. They all use the canonical client and remain closed on denial, timeout, malformed output, or unverifiable evidence.\n\n`@agentauthoritychain/client/adcs` provides a one-way ADCS v0.1.0 audit projection. Real runtime IDs, tools, scopes, timestamps, and remaining budget are required and are never inferred. An ADCS audit document cannot become AAC authority.\n\n## When this package fits\n\n- principal-to-agent and multi-hop delegation;\n- capability narrowing and bounded constraints;\n- revocation and expiry checks before execution;\n- signed, auditable permit-or-deny evidence;\n- framework-neutral Node.js services, APIs, workers and automation.\n\nFor MCP handlers use `@agentauthoritychain/mcp-guard`; Python projects use `agentauthoritychain`; other platforms use the same direct HTTP/OpenAPI contract.\n\n## Evaluate before configuration\n\n```bash\nnode --input-type=module -e \"import('@agentauthoritychain/client/public-test').then(async m => { const r = await m.runPublicConformance(); console.log(r); if (!r.every(x => x.passed)) process.exitCode = 1 })\"\n```\n\nThe public suite is credential-free and must pass every exact expected case. Keep the once-shown organization credential in a secret manager and private issuer keys in your own environment. On managed Windows TLS, run Node with `--use-system-ca`; never disable certificate verification.\n\n- Integration Wiki: https://agentauthoritychain.com/wiki/\n- OpenAPI contract: https://agentauthoritychain.com/openapi.json\n- Machine-readable discovery: https://agentauthoritychain.com/agents.json\n- Canonical source: https://github.com/AgentAuthorityChain/aac\n- Security reporting: https://agentauthoritychain.com/.well-known/security.txt\n\nRequires Node.js 20+. AAC supplies technical verification evidence; it is not legal authority, payment authorization, regulatory certification or independent proof of issuer legitimacy.\n","readmeFilename":"README.md"}