{"_id":"@agentcontextdistributionprotocol/acdp-wasm","_rev":"7-755d188b6775d2d62a185a1d6730a211","name":"@agentcontextdistributionprotocol/acdp-wasm","dist-tags":{"latest":"0.8.5"},"versions":{"0.7.0":{"name":"@agentcontextdistributionprotocol/acdp-wasm","version":"0.7.0","license":"MIT OR Apache-2.0","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.7.0","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"dist":{"shasum":"64071bc3ff90f82c00e9ca26a9b7b7aa378a8111","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.7.0.tgz","fileCount":5,"integrity":"sha512-DUqSERo1It57HTrreyd3P8MUI6OT819U/wg+Q1xl+O2hMfSKfAFNUdl4WJL9IAlFk4tnjMW2ZWz2Wtceizswaw==","signatures":[{"sig":"MEUCIQDWz8isnJgmIWh0+81XDRwt/jSL4T9dra9pa3U+B0EwSwIgHlluIoOSJ6SSkqHOzLSAM1HLdDplSwt19y4wrhldwNw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":800750},"main":"acdp_wasm.js","type":"module","types":"acdp_wasm.d.ts","gitHead":"475cf0fb77dc1a698573b8d921a9306f0001d3d6","_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"repository":{"url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","type":"git","directory":"bindings/acdp-wasm"},"_npmVersion":"10.8.2","description":"Agent Context Distribution Protocol — WebAssembly verification core","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/acdp-wasm_0.7.0_1783390596506_0.38422211635594006","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@agentcontextdistributionprotocol/acdp-wasm","version":"0.8.0","license":"MIT OR Apache-2.0","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.8.0","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"dist":{"shasum":"7d7d570f30c0b557889174b4b71f5e800ac82ace","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.8.0.tgz","fileCount":5,"integrity":"sha512-h/n3gLMK28fJlf0V7Zde57RQa71vFbFp6j9hH/MVqfsgY58hO+7R4RuRAcpxYPkcOCVZLql3YLToEKZcTORKwA==","signatures":[{"sig":"MEYCIQDJNb+/cwz5M8xzm6yL0i0j0WpWQuF46RcbsVBp12fJxgIhANrREFjCp/T2QKHMtLcMGuUT+NKK1pzD34g6eOq4Vnqm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":790269},"main":"acdp_wasm.js","type":"module","types":"acdp_wasm.d.ts","gitHead":"be72ca24fe7d0246b1fe132ef10c0eaed7ecfc0b","_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"repository":{"url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","type":"git","directory":"bindings/acdp-wasm"},"_npmVersion":"10.8.2","description":"Agent Context Distribution Protocol — WebAssembly verification core","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/acdp-wasm_0.8.0_1783714440256_0.0505765608582327","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@agentcontextdistributionprotocol/acdp-wasm","version":"0.8.1","license":"MIT OR Apache-2.0","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.8.1","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"dist":{"shasum":"892d095eaa9d76820d7db917ef850f8a9badeed4","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.8.1.tgz","fileCount":5,"integrity":"sha512-cecd5D3YrMm/nyyQbTCo8l0rhtfvCbzXiHm5v5ZUBU3D4QGQ0SffcZcWHXJAxQc/gKOgUGyeSy8Xv7ELUMY7dg==","signatures":[{"sig":"MEYCIQCwDQlN9ALpqh/2/+a2t6WKWN9sZMtXlcNPQrkpOshAZwIhANoqnvWx/E7vnrCGK0mk5BLtXiOENK2343Dde1Ea7b2j","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.8.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":780820},"main":"acdp_wasm.js","type":"module","types":"acdp_wasm.d.ts","gitHead":"b8da7b47d1d5dd20d00b2a59838f9aab19289464","_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"repository":{"url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","type":"git","directory":"bindings/acdp-wasm"},"_npmVersion":"10.8.2","description":"Agent Context Distribution Protocol — WebAssembly verification core","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/acdp-wasm_0.8.1_1788025168211_0.45216946415956505","host":"s3://npm-registry-packages-npm-production"}},"0.8.2":{"name":"@agentcontextdistributionprotocol/acdp-wasm","version":"0.8.2","license":"MIT OR Apache-2.0","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.8.2","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"dist":{"shasum":"4f5d0cd7e60f56c6db6d06d6c19881d0c0a07321","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.8.2.tgz","fileCount":5,"integrity":"sha512-wyvun06Mgp/i5VUBojfqR5fDzN9zN3mu54xPcrJWPeX1We9VWGcMFLmw+ECZ3aeHf49b9/PgTdg7yZAHFpOXKw==","signatures":[{"sig":"MEYCIQC+85SEhhk9rLaqMbJZQuPCqVuIFleU/TiBYI5ydwDbUQIhAMrQeCbBRHV3z7GHBXOarhH3CEKxa89+X6Ny0whA/1tQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.8.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":819845},"main":"acdp_wasm.js","type":"module","types":"acdp_wasm.d.ts","gitHead":"44da344adfac273cd9e82223c241f5347178b74c","_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"repository":{"url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","type":"git","directory":"bindings/acdp-wasm"},"_npmVersion":"10.8.2","description":"Agent Context Distribution Protocol — WebAssembly verification core","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/acdp-wasm_0.8.2_1788050395348_0.5564055110303745","host":"s3://npm-registry-packages-npm-production"}},"0.8.3":{"name":"@agentcontextdistributionprotocol/acdp-wasm","version":"0.8.3","license":"MIT OR Apache-2.0","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.8.3","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"dist":{"shasum":"5d3552489e44a77d91fda5512c64bcc3e9ac863e","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.8.3.tgz","fileCount":5,"integrity":"sha512-Rb/ng29QPOCsbO+n381A+OIjnxMuG6oWVbcBYYQQfrnRBpJenhk9CU8S6+rQjjZ4m5SQgk5hADmCIBhE2IJM2Q==","signatures":[{"sig":"MEUCIDpvwDr2hBwbxQ/T4rsf5esc4d1qCxPLv94ONCG0PPJSAiEA1fCuHZEVvgrVbp4eF/rl6PDmSyiXMzya2nXF6G0ZfxI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.8.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":819361},"main":"acdp_wasm.js","type":"module","types":"acdp_wasm.d.ts","gitHead":"08fc32d091be06bf0996f7ce14647a2cb8d72a79","_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"repository":{"url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","type":"git","directory":"bindings/acdp-wasm"},"_npmVersion":"10.8.2","description":"Agent Context Distribution Protocol — WebAssembly verification core","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/acdp-wasm_0.8.3_1788108726113_0.09321452031854283","host":"s3://npm-registry-packages-npm-production"}},"0.8.4":{"name":"@agentcontextdistributionprotocol/acdp-wasm","version":"0.8.4","license":"MIT OR Apache-2.0","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.8.4","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"dist":{"shasum":"e1a11ad9111ab614024802a8e5fa7f4a707a92fb","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.8.4.tgz","fileCount":5,"integrity":"sha512-1em1kS5D1L9YYU8Yna1Nv5mvFb6tvd8DtLZhdJba2XgQmh4mbS4BP8A62lQN/fYsRZOzXRl08aFck1rGISXRTw==","signatures":[{"sig":"MEUCIQC9VfAcHs0J6yT4wzN3Dt0/ojmGsW9/SVi/UMTfmQmqKwIgPR8E0w/SgVz/f5jyB79ALqQ/FIvZBVfYs01a0xSnmXg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.8.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":819361},"main":"acdp_wasm.js","type":"module","types":"acdp_wasm.d.ts","gitHead":"27f9f651f6f55dc28fa405f6c79dd4b28758b1f4","_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"repository":{"url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","type":"git","directory":"bindings/acdp-wasm"},"_npmVersion":"10.8.2","description":"Agent Context Distribution Protocol — WebAssembly verification core","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.20.2","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/acdp-wasm_0.8.4_1788113682523_0.9702815297757348","host":"s3://npm-registry-packages-npm-production"}},"0.8.5":{"name":"@agentcontextdistributionprotocol/acdp-wasm","type":"module","description":"Agent Context Distribution Protocol — WebAssembly verification core","version":"0.8.5","license":"MIT OR Apache-2.0","main":"acdp_wasm.js","types":"acdp_wasm.d.ts","sideEffects":["./snippets/*"],"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"repository":{"type":"git","url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","directory":"bindings/acdp-wasm"},"homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","_id":"@agentcontextdistributionprotocol/acdp-wasm@0.8.5","gitHead":"92d64ed36502e67a4632221b690c52c806ccd364","bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-BjOk+21sZpzqI1Sne7ycLsTA0hyZCeb5s/FePsHLVweUOkFHzi9hWYYYh5QcfohOxW7kilBqZs3CEnFw6i1Zlg==","shasum":"d924f12e1e3e73dda634c1bbdedd746fcbdddba2","tarball":"https://registry.npmjs.org/@agentcontextdistributionprotocol/acdp-wasm/-/acdp-wasm-0.8.5.tgz","fileCount":5,"unpackedSize":819845,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcontextdistributionprotocol%2facdp-wasm@0.8.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCN4IzH8bONZoN/FfzCQ8sLzrxDfhdB+sRydHIvCQBlkwIgdhgIOygxoygRNtJT+w4q4W58EJ9cm26ffgx9xHI8FvA="}]},"_npmUser":{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"},"directories":{},"maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/acdp-wasm_0.8.5_1788148523675_0.31515230458035126"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-07T02:16:36.260Z","modified":"2026-08-31T03:55:24.250Z","0.7.0":"2026-07-07T02:16:36.710Z","0.8.0":"2026-07-10T20:14:00.443Z","0.8.1":"2026-08-29T17:39:28.355Z","0.8.2":"2026-08-30T00:39:55.491Z","0.8.3":"2026-08-30T16:52:06.266Z","0.8.4":"2026-08-30T18:14:42.747Z","0.8.5":"2026-08-31T03:55:23.836Z"},"bugs":{"url":"https://github.com/agentcontextdistributionprotocol/acdp-rs/issues"},"license":"MIT OR Apache-2.0","homepage":"https://github.com/agentcontextdistributionprotocol/acdp-rs/tree/main/bindings/acdp-wasm","repository":{"type":"git","url":"git+https://github.com/agentcontextdistributionprotocol/acdp-rs.git","directory":"bindings/acdp-wasm"},"description":"Agent Context Distribution Protocol — WebAssembly verification core","maintainers":[{"name":"ajitkoti","email":"ajitkoti@zer07labs.com"}],"readme":"# acdp-wasm — ACDP WebAssembly verification core\n\nThe **browser / edge / WASI** member of the ACDP binding family\n(`bindings/acdp-py`, `bindings/acdp-node`). A pure, **offline**\ncryptographic verifier: it lets a consumer render an ACDP context and\nindependently reach a real verification **verdict** — the producer\nsignature, the `content_hash`, a registry receipt (RFC-ACDP-0010), a\nlineage-head receipt (RFC-ACDP-0011), a transparency-log checkpoint /\ninclusion / consistency proof (RFC-ACDP-0012), a lifecycle event\n(RFC-ACDP-0013), a key revocation (RFC-ACDP-0014), and witness\ncosignatures + quorum (RFC-ACDP-0015) — **without trusting any server to\nhave done it**. This is the client-side verification core the console's\nverdicts consume.\n\nIt is a standalone Cargo package (its own `[workspace]`) that depends on\nthe umbrella `acdp` crate with `default-features = false`, so\n`reqwest` / `tokio` / `rustls` never enter the `.wasm` binary. See\n`docs/research/wasm-target.md` for the design rationale.\n\n## Design (same rules as the Python / Node bindings)\n\n- **JSON across the boundary.** Every export takes JSON strings and\n  returns a JSON string — a **verdict object** (`{\"valid\": true, ...}` /\n  `{\"valid\": false, \"code\"?, \"error\"}`) for verification outcomes, or a\n  result string for constructors/resolvers. Malformed *host* input\n  throws a `JsError`; a failed *verification* is `{\"valid\": false}`,\n  never a throw.\n- **Crypto in Rust, HTTP in the host.** No network calls. `did:web`\n  resolution and all transport stay in JS (`fetch` the DID document /\n  receipt / body, pass the JSON in). `did:key` verification is fully\n  offline and needs no host help — the highest-value browser path.\n- **No crypto reimplemented.** Every check delegates to the same `acdp`\n  core the native library, Python, and Node bindings use. The 0.3/0.4\n  verdict logic (`src/v030.rs`, `src/v040.rs`) is lifted **verbatim,\n  byte-identical** from the other bindings.\n\n## Exported surface\n\nwasm-bindgen exports (camelCase in JS/TypeScript):\n\n| Export | RFC | Purpose |\n|---|---|---|\n| `verifyContentHash` | 0001 §5.7 | recompute `sha256(JCS(producer_content))` |\n| `verifySignatureEd25519` / `verifySignatureP256` | 0001 §5.8 | signature over the ASCII `\"sha256:<hex>\"` string |\n| `verifyBodyOffline` / `verifyPublishRequestOffline` | 0002 | full `did:key` context verify (no resolution) |\n| `fingerprintEd25519` / `verifyReceipt` | 0010 | registry-receipt verification |\n| `verifyLineageHeadReceipt` | 0011 | lineage-head receipt |\n| `verifyLogCheckpoint` / `verifyLogInclusion` / `verifyLogConsistency` / `buildLogLeaf` / `merkleLeafHash` / `merkleNodeHash` / `merkleRootHash` | 0012 | transparency log |\n| `verifyLifecycleEvent` | 0013 | lifecycle event |\n| `parseKeyRevocation` / `classifyUnderRevocation` | 0014 | key revocation |\n| `buildWitnessCosignature` / `verifyWitnessCosignature` / `evaluateWitnessQuorum` | 0015 | witness cosignatures + quorum |\n| `resolveDidKey` | — | offline `did:key` → public key |\n| `canonicalPreimage` / `explainHashMismatch` | — | hash-divergence diagnostics |\n\n## Install\n\nPublished to npm as **`@agentcontextdistributionprotocol/acdp-wasm`** (a\npublic scoped package, provenance-signed on GitHub Actions), so the console\nand other consumers depend on it without a sibling checkout:\n\n```bash\nnpm install @agentcontextdistributionprotocol/acdp-wasm\n```\n\n```js\nimport init, { verifyContentHash, verifySignatureEd25519 }\n  from \"@agentcontextdistributionprotocol/acdp-wasm\";\nawait init();\nconst verdict = JSON.parse(verifyContentHash(bodyJson, body.content_hash));\nif (verdict.valid) { /* the hash the consumer recomputed itself checks out */ }\n```\n\nThe package is built with `wasm-pack --target web`: an ESM module you\ninitialize once with `await init()`. This is the target the crate is\ndesigned and CI-tested around, and it loads cleanly in browsers and in\nNext.js client components (webpack 5 resolves the `new URL(..., import.meta.url)`\nwasm asset the `web` target emits — no `experiments.asyncWebAssembly`\nwebpack override, which the `bundler` target would require).\n\n## Build\n\n```bash\nrustup target add wasm32-unknown-unknown\n\n# Raw wasm (regression build-check):\ncargo build --target wasm32-unknown-unknown            # verify-only default\n\n# Browser package (.js / .wasm / .d.ts) with wasm-pack. `--scope` makes\n# wasm-pack emit the package name `@agentcontextdistributionprotocol/acdp-wasm`\n# (the same rename the release workflow performs):\nwasm-pack build --target web --out-dir pkg --scope agentcontextdistributionprotocol\n```\n\nImport from a browser (local, unpublished build):\n\n```js\nimport init, { verifyContentHash, verifySignatureEd25519 } from \"./pkg/acdp_wasm.js\";\nawait init();\nconst verdict = JSON.parse(verifyContentHash(bodyJson, body.content_hash));\nif (verdict.valid) { /* the hash the consumer recomputed itself checks out */ }\n```\n\n## Golden-vector parity\n\n`tests/golden.rs` is a **native** `cargo test` that runs the canonical\n`sig-001` (content hash + Ed25519 signature) and `wit-001` (witness\ncosignature mint + verify) spec fixtures through the same pure `core`\nfunctions the wasm exports wrap, asserting byte-for-byte reproduction of\nthe pinned golden values — the same constants the `acdp-py` / `acdp-node`\nsuites pin. It locates fixtures via `ACDP_SPEC_DIR` and skips gracefully\nwhen absent:\n\n```bash\nACDP_SPEC_DIR=../../../agentcontextdistributionprotocol cargo test\n```\n\n`tests/wasm.rs` is a `wasm-bindgen-test` real-engine smoke test of the\nexported wrappers (inline sig-001 constants, no fixtures needed):\n\n```bash\nwasm-pack test --node\n```\n\n## Randomness — a correction to the research memo\n\n`docs/research/wasm-target.md` §4 predicted a **verify-only** build would\nneed **no `getrandom` backend** on any wasm target. That holds at\n*runtime* — no exported verification (nor the deterministic Ed25519\nwitness mint) draws randomness. It does **not** hold at *compile time*\nfor `wasm32-unknown-unknown`: the core crates pull two randomness sources\n**unconditionally**, and each emits a hard `compile_error!` on that\ntarget unless a backend is wired:\n\n1. **`getrandom 0.2`** via `rand_core 0.6` / `OsRng` (a non-optional\n   dependency of `acdp-crypto`) → enabled with the getrandom **`js`\n   feature**.\n2. **`getrandom 0.4`** via **`uuid` v4** (a non-optional dependency of\n   `acdp-primitives`) → enabled with the getrandom **`wasm_js` feature**\n   *plus* `--cfg getrandom_backend=\"wasm_js\"` (set in\n   `.cargo/config.toml`). `uuid` additionally needs its own **`js`\n   feature** for its v4 RNG shim.\n\nAll three are wired here, **target-gated to `wasm32` only** (see\n`Cargo.toml` and `.cargo/config.toml`), so a native `cargo test` is\nuntouched. `crypto.getRandomValues` (the `js` backend) is the CSPRNG\nRFC-ACDP-0001 §5.10 names for the browser, so the choice is spec-blessed\n— but it is never invoked on the verify path; it is present only to link.\n\nA future `producer` feature (reserved, not yet wired) would expose fresh\nkey generation (`SigningKey::generate`, the only `OsRng` caller) and is\nwhere a runtime randomness draw would actually occur.\n\n## Security notes\n\n- This artifact is a **verifier, not a fetcher**. `RegistryClient`,\n  `CrossRegistryResolver`, and `did:web` resolution do NOT move to wasm;\n  the host owns HTTP and the RFC-ACDP-0006 §7 / RFC-ACDP-0008 SSRF\n  defenses. Pass fetched documents in as JSON.\n- A browser tab is not an HSM. Verification holds no secrets, but a\n  future `producer`/keygen surface would place the signing seed in wasm\n  linear memory during a call (RFC-ACDP-0001 §5.10).\n","readmeFilename":"README.md"}