{"_id":"@agentcreds/sdk","_rev":"3-8b8321ee26de2442ddb85ff604dd8b9e","name":"@agentcreds/sdk","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@agentcreds/sdk","version":"0.1.0","license":"Apache-2.0","_id":"@agentcreds/sdk@0.1.0","maintainers":[{"name":"morganlr","email":"morganLR@proton.me"}],"homepage":"https://github.com/agentcreds/agentcreds#readme","bugs":{"url":"https://github.com/agentcreds/agentcreds/issues"},"dist":{"shasum":"a52d7980eba26efdf3bb40ff4d0d4205ccef09ec","tarball":"https://registry.npmjs.org/@agentcreds/sdk/-/sdk-0.1.0.tgz","fileCount":5,"integrity":"sha512-TW95+9JATRM9JL3vTSbbFjejW/83dZSWqSDFvbLKUxwp//RG6w8VXKSV8DtfJcnQo5uTzQfeWq378UiXGMl3sQ==","signatures":[{"sig":"MEYCIQCjRWXTgEAqmuX2gH3VXu9HY4RJu/YNLujyFMQtFrAQPQIhAJ4W2UduUIJN3Oo0jTkn7mhGyzP2/arVmZJ6pls51YTr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcreds%2fsdk@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":73843},"main":"index.js","napi":{"name":"agentcreds","triples":{"defaults":true,"additional":["aarch64-apple-darwin"]}},"types":"index.d.ts","engines":{"node":">= 16"},"gitHead":"e4c47958fad0fecfe9d5e762736022cf1a6c49d4","scripts":{"docs":"typedoc","test":"node examples/quickstart.js && node --test test/conformance.test.js test/accountability.test.js","build":"napi build --platform --release","version":"napi version","artifacts":"napi artifacts","build:debug":"napi build --platform","prepublishOnly":"napi prepublish -t npm","test:conformance":"node --test test/conformance.test.js"},"_npmUser":{"name":"morganlr","email":"morganLR@proton.me"},"repository":{"url":"git+https://github.com/agentcreds/agentcreds.git","type":"git"},"_npmVersion":"10.8.2","description":"Verifiable, attenuable delegation for AI agents - org-rooted and verified offline","directories":{},"_nodeVersion":"20.20.2","_hasShrinkwrap":false,"devDependencies":{"typedoc":"^0.25.0","@napi-rs/cli":"^2.18.0"},"optionalDependencies":{"@agentcreds/sdk-darwin-x64":"0.1.0","@agentcreds/sdk-darwin-arm64":"0.1.0","@agentcreds/sdk-linux-x64-gnu":"0.1.0","@agentcreds/sdk-win32-x64-msvc":"0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.0_1788838879720_0.9313747604572984","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Broken: published without platform binaries. Use >=0.1.1."},"0.1.1":{"name":"@agentcreds/sdk","version":"0.1.1","license":"Apache-2.0","_id":"@agentcreds/sdk@0.1.1","maintainers":[{"name":"morganlr","email":"morganLR@proton.me"}],"homepage":"https://github.com/agentcreds/agentcreds#readme","bugs":{"url":"https://github.com/agentcreds/agentcreds/issues"},"dist":{"shasum":"dd6556fbb40f3445c85b684266103b855e9bb4f2","tarball":"https://registry.npmjs.org/@agentcreds/sdk/-/sdk-0.1.1.tgz","fileCount":5,"integrity":"sha512-LT+Vi679Z1pmficZWJBxNlHoWDS8PJgISu8FTrKD7JIh1nXjEPYPk/c6xMbub9tcBTrQMBRNdOvuafmPoZpjuA==","signatures":[{"sig":"MEUCIQDUZuhmWDR5GeQK8IqZ34TM161vBCUCYoa/EWM/g9tdXQIgfjqP8Ld+7MeZg1P+7KTwtlrJMP6Zc9HE3MSaB7ahvuY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentcreds%2fsdk@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":73843},"main":"index.js","napi":{"name":"agentcreds","triples":{"defaults":true,"additional":["aarch64-apple-darwin"]}},"types":"index.d.ts","engines":{"node":">= 16"},"gitHead":"2af26679e501cf4ea038a1444ddad06ace4191f6","scripts":{"docs":"typedoc","test":"node examples/quickstart.js && node --test test/conformance.test.js test/accountability.test.js","build":"napi build --platform --release","version":"napi version","artifacts":"napi artifacts","build:debug":"napi build --platform","prepublishOnly":"napi prepublish -t npm","test:conformance":"node --test test/conformance.test.js"},"_npmUser":{"name":"morganlr","email":"morganLR@proton.me"},"repository":{"url":"git+https://github.com/agentcreds/agentcreds.git","type":"git"},"_npmVersion":"10.8.2","description":"Verifiable, attenuable delegation for AI agents - org-rooted and verified offline","directories":{},"_nodeVersion":"20.20.2","_hasShrinkwrap":false,"devDependencies":{"typedoc":"^0.25.0","@napi-rs/cli":"^2.18.0"},"optionalDependencies":{"@agentcreds/sdk-darwin-x64":"0.1.1","@agentcreds/sdk-darwin-arm64":"0.1.1","@agentcreds/sdk-linux-x64-gnu":"0.1.1","@agentcreds/sdk-win32-x64-msvc":"0.1.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.1_1788841098715_0.3088487191549216","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-09-08T03:41:19.525Z","modified":"2026-09-08T04:22:41.125Z","0.1.0":"2026-09-08T03:41:19.869Z","0.1.1":"2026-09-08T04:18:18.854Z"},"bugs":{"url":"https://github.com/agentcreds/agentcreds/issues"},"license":"Apache-2.0","homepage":"https://github.com/agentcreds/agentcreds#readme","repository":{"url":"git+https://github.com/agentcreds/agentcreds.git","type":"git"},"description":"Verifiable, attenuable delegation for AI agents - org-rooted and verified offline","maintainers":[{"name":"morganlr","email":"morganLR@proton.me"}],"readme":"# @agentcreds/sdk (Node.js / TypeScript)\n\nNode.js bindings for **AgentCreds** - verifiable, attenuable delegation for autonomous AI agents, verified offline.\n\n> **Scope.** This SDK is at parity with the Python core binding - identities,\n> credentials, tokens, presentations, revocation, key history, ADRs including\n> accountability and R10 verdicts. The **runtime enforcement** layer is different:\n> `@agentcreds/runtime` is **A2A-only by design** and is\n> not an MCP policy enforcement point. R10 execution-time gates, step-up approval and\n> the MCP enforcer are Python-only. A Node *agent* can talk to a Python PEP over the\n> wire; a Node service cannot host one.\n\nThese bindings wrap the `agentcreds-core` Rust engine via [napi-rs](https://napi.rs).\n\n## A note on async\n\nEvery operation in this SDK is **synchronous** - there is no `Promise`/\n`async`/`await` anywhere in this API. The underlying Rust operations (DID\ngeneration, credential issuance/verification, token minting/attenuation/\nverification, revocation checks) all complete in well under a millisecond,\nso wrapping them in promises would add overhead without benefit. This is a\ndeliberate deviation from async-styled quickstarts you may see elsewhere in\nthe AgentCreds docs.\n\n## Installation\n\n```bash\nnpm install @agentcreds/sdk\n```\n\n(or, building from source: `npm run build`, which invokes `napi build\n--platform --release`)\n\n## Quick start\n\n```typescript\nimport * as ac from \"@agentcreds/sdk\";\n\n// 1. Org trust anchor (in production: keys live in an HSM)\nconst anchor = ac.TrustAnchor.generate();\n\n// 2. Agent enrolled at deploy time\nconst agent = ac.AgentIdentity.createDidKey();\n\n// 3. Issue a capability credential\nconst claims = new ac.CapabilityClaims({\n  tools: [\"tool:search\", \"tool:email\"],\n  maxDelegationDepth: 3,\n  validForSecs: 3600, // valid for 1 hour\n});\nconst vc = ac.CapabilityCredential.issue(anchor, agent.did, claims);\n\n// 4. Mint a short-lived runtime token (valid 5 minutes)\nconst scope = new ac.Scope({ tools: [\"tool:search\"], budgetUsd: 100, maxDepth: 2 });\nconst token = ac.DelegationToken.mint(vc, scope, 300, agent);\n\n// 5. Verify at every tool call boundary (<1ms)\nconst action = new ac.Action(\"tool:search\", \"q=agentcreds\");\ntoken.verify(action);\n\n// 6. Delegate to a sub-agent (scope can only narrow)\nconst subAgent = ac.AgentIdentity.createDidKey();\nconst narrow = new ac.Scope({ tools: [\"tool:search\"], budgetUsd: 10, maxDepth: 1 });\nconst childToken = token.attenuate(narrow, 60, subAgent);\n```\n\n## Cross-org verification\n\n```typescript\nimport * as ac from \"@agentcreds/sdk\";\n\n// Org B registers Org A's trust anchor (resolved from a TRAIL registry in production)\nconst registry = new ac.TrustRegistry();\nregistry.register(new ac.TrustEntry(\n  orgAAnchor.did,\n  \"Organization A\",\n  orgAAnchor.publicKey,\n  \"verified\",\n));\n\n// Verify Org A's credential WITHOUT calling back to Org A\nconst entry = registry.verifyCredential(vcFromOrgA);\nconsole.log(`Verified by ${entry.orgName} (${entry.trustLevel})`);\n```\n\n## Revocation\n\n```typescript\nimport * as ac from \"@agentcreds/sdk\";\n\n// Create an OAuth Token Status List (131,072 entries by default)\nconst revocationList = new ac.RevocationList(\"https://registry.example.com/status/1\", anchor);\n\n// Revoke credential at index 42 (propagates in <30s in production)\nrevocationList.revoke(42, anchor);\n\n// Check revocation status (<0.1ms, no network call)\nconsole.assert(revocationList.isRevoked(42));\n```\n\n## Error handling\n\nEvery error thrown by this SDK is a JS `Error` whose `message` is prefixed\nwith an error kind, mirroring the exception hierarchy of the Python\nbindings (`agentcreds.AgentCredsError` and its subclasses). Branch on the\nprefix with `error.message.startsWith(...)`:\n\n```typescript\nimport * as ac from \"@agentcreds/sdk\";\n\ntry {\n  token.verify(new ac.Action(\"tool:delete-everything\", \"\"));\n} catch (e) {\n  const message = e instanceof Error ? e.message : String(e);\n  if (message.startsWith(\"ActionDeniedError\")) {\n    console.log(`denied: ${message}`);\n  } else if (message.startsWith(\"TokenExpiredError\")) {\n    console.log(`expired: ${message}`);\n  } else {\n    console.log(`other agentcreds error: ${message}`);\n  }\n}\n```\n\n| Message prefix | Raised when |\n|---|---|\n| `DidError` | DID resolution, signature, or key-material problems |\n| `CredentialError` | Malformed claims, issuer mismatch, invalid proof |\n| `CredentialExpiredError` | A credential's `expirationDate` has passed |\n| `CredentialRevokedError` | A credential's index is set in a revocation list |\n| `DelegationError` | Token chain integrity / depth-limit problems |\n| `ScopeWideningError` | An attenuation attempt would widen scope |\n| `TokenExpiredError` | A delegation token (or one of its blocks) has expired |\n| `ActionDeniedError` | The requested tool is not in the leaf block's scope |\n| `RevocationError` | Revocation list index out of bounds / bad signature |\n| `SerializationError` | JSON / CBOR / base64 (de)serialization failure |\n| `ValidationError` | A field value is missing, out of bounds, or of the wrong sign (e.g. a negative index) |\n\nArguments rejected directly by the binding layer (e.g. a negative\n`validForSecs`) throw with `error.code === \"InvalidArg\"`; errors propagated\nfrom `agentcreds-core` throw with `error.code === \"GenericFailure\"`. In\nboth cases the `message` prefix table above applies.\n\n## Type declarations\n\nA hand-written `index.d.ts` ships with this package for editor/IDE\nautocomplete and TypeScript type checking. Running `napi build` regenerates\nthis file directly from the Rust `#[napi]` annotations in `src/`.\n\n## Building\n\n```bash\nnpm run build              # napi build --platform --release\ncargo test --manifest-path ../agentcreds-core/Cargo.toml\n```\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}