{"_id":"@agenticprimitives/fedcm-idp","_rev":"4-0b718e6c42b8037f63204d3b41fa7488","name":"@agenticprimitives/fedcm-idp","dist-tags":{"alpha":"1.0.0-alpha.6","latest":"1.0.0-alpha.9"},"versions":{"1.0.0-alpha.6":{"name":"@agenticprimitives/fedcm-idp","version":"1.0.0-alpha.6","keywords":["fedcm","idp","federation","identity-provider","agentic"],"license":"MIT","_id":"@agenticprimitives/fedcm-idp@1.0.0-alpha.6","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"homepage":"https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/fedcm-idp","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"b27a605912aa734623efb8c37977f4be3b12c66f","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-idp/-/fedcm-idp-1.0.0-alpha.6.tgz","fileCount":8,"integrity":"sha512-UsoVV+HJCWbFVjpFmO4Q3BdE2uIVM77vUdyivLadRF4LXRxZhRpIJOhg0CAXDLw4kI5M7I9zKurd65GJrh9n7Q==","signatures":[{"sig":"MEUCICCWlPBOT7++gdcmA1F4VQc4NQOIaIrsFbVyW/uHwpFKAiEAjhIFwwPYUYYifEqD6zTNhzaZ70/DfUta4P+Z35or1Bk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29190},"main":"./dist/index.js","type":"module","_from":"file:agenticprimitives-fedcm-idp-1.0.0-alpha.6.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"_npmUser":{"name":"richcanvas","email":"richardpedersen3@gmail.com"},"_resolved":"/tmp/claude-1000/859ec0fcfe421cf9dab7dfd595e68b19/agenticprimitives-fedcm-idp-1.0.0-alpha.6.tgz","_integrity":"sha512-UsoVV+HJCWbFVjpFmO4Q3BdE2uIVM77vUdyivLadRF4LXRxZhRpIJOhg0CAXDLw4kI5M7I9zKurd65GJrh9n7Q==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-idp"},"_npmVersion":"11.16.0","description":"FedCM IdP contract as pure builders + validators: web-identity manifest, provider config, accounts list, thin id-assertion claims, request validators. Generic; the app hosts + signs (ADR-0031).","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"tmp":"tmp/fedcm-idp_1.0.0-alpha.6_1781153991368_0.007946993071316744","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-alpha.7":{"name":"@agenticprimitives/fedcm-idp","version":"1.0.0-alpha.7","keywords":["fedcm","idp","federation","identity-provider","agentic"],"license":"MIT","_id":"@agenticprimitives/fedcm-idp@1.0.0-alpha.7","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"homepage":"https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/fedcm-idp","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"4a41a47c474ddc4dcedb4faeff7e28277de00e43","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-idp/-/fedcm-idp-1.0.0-alpha.7.tgz","fileCount":8,"integrity":"sha512-+AUlGtRpvvZAkMnzgJ7yotaRyuHDyTFfV+4VELiZqPZ7Dkb5KoHrcFqFq082pekKVe66W4X/HvS4nBNLzY2XXg==","signatures":[{"sig":"MEUCIBfyaIU0shY6XXaGrqGnD51uBUOnosYnA2fEq6Jcm2MXAiEAg2tvcGpSaJUo/n7SOC6bvfdRoyDyuxHBzfH3rx9ybEs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29190},"main":"./dist/index.js","type":"module","_from":"file:agenticprimitives-fedcm-idp-1.0.0-alpha.7.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2ff07390-1131-4d22-b57e-120dbaf59997"}},"_resolved":"/tmp/7286c8256d6aafb68f838defbd606021/agenticprimitives-fedcm-idp-1.0.0-alpha.7.tgz","_integrity":"sha512-+AUlGtRpvvZAkMnzgJ7yotaRyuHDyTFfV+4VELiZqPZ7Dkb5KoHrcFqFq082pekKVe66W4X/HvS4nBNLzY2XXg==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-idp"},"_npmVersion":"11.19.0","description":"FedCM IdP contract as pure builders + validators: web-identity manifest, provider config, accounts list, thin id-assertion claims, request validators. Generic; the app hosts + signs (ADR-0031).","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"tmp":"tmp/fedcm-idp_1.0.0-alpha.7_1789164113796_0.3771255532195743","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-alpha.8":{"name":"@agenticprimitives/fedcm-idp","version":"1.0.0-alpha.8","keywords":["fedcm","idp","federation","identity-provider","agentic"],"license":"MIT","_id":"@agenticprimitives/fedcm-idp@1.0.0-alpha.8","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"homepage":"https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/fedcm-idp","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"d83af49dd9d8fe052901e34b30b3a64a7c711994","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-idp/-/fedcm-idp-1.0.0-alpha.8.tgz","fileCount":8,"integrity":"sha512-FiVx5w9xAK2RlSQiH6bt46jn0GnW98myjbzpM24FH/e9LcbjqWk1d+lF/uRdVw1OEXM8ESfTgD/9t9sOqvO2Lw==","signatures":[{"sig":"MEQCICvt56OMCOAXB0KStGQDTLbTD1JiOJ8ZSd4KBp0dDGdEAiAbA7OR1J5XIIsNi2mVWG6rgP+5ZnA/Bkd8IvbI2rCPTA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29190},"main":"./dist/index.js","type":"module","_from":"file:agenticprimitives-fedcm-idp-1.0.0-alpha.8.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2ff07390-1131-4d22-b57e-120dbaf59997"}},"_resolved":"/tmp/e5469092f2cde63b0440c9a0b3ab2d2c/agenticprimitives-fedcm-idp-1.0.0-alpha.8.tgz","_integrity":"sha512-FiVx5w9xAK2RlSQiH6bt46jn0GnW98myjbzpM24FH/e9LcbjqWk1d+lF/uRdVw1OEXM8ESfTgD/9t9sOqvO2Lw==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-idp"},"_npmVersion":"11.19.0","description":"FedCM IdP contract as pure builders + validators: web-identity manifest, provider config, accounts list, thin id-assertion claims, request validators. Generic; the app hosts + signs (ADR-0031).","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"tmp":"tmp/fedcm-idp_1.0.0-alpha.8_1789230533440_0.7179067077973791","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-alpha.9":{"_id":"@agenticprimitives/fedcm-idp@1.0.0-alpha.9","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"451203619015f36ad11a22651a4921ea650c3496","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-idp/-/fedcm-idp-1.0.0-alpha.9.tgz","fileCount":8,"integrity":"sha512-KeBcr6qC0pj4CwrRsQFNF4vlbUJxmq+F3GNaaqYL4GAezg2d8LdIvTwcOuG//UDELB+kGZxPHeVtnKXgKQlfUQ==","signatures":[{"sig":"MEYCIQDgKC8EmN3hyoCHFJR957IVVcMEBZf8lSxe0n0JQFfkiwIhAJOc+KOVCBkqERyRRgTmbsI2Bmmk9bLjjs03fzih3QtI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC1HC62UsUY+t856zRwf3pFedReQDzp6Xo5Hb6PxjbFFQIhAI5GmaazhtXTRoQsYzwwznwP5oJdvPS5p6HX4FOODxj1"}],"unpackedSize":29687},"main":"./dist/index.js","name":"@agenticprimitives/fedcm-idp","type":"module","_from":"file:agenticprimitives-fedcm-idp-1.0.0-alpha.9.tgz","types":"./dist/index.d.ts","author":{"url":"https://agenticprimitives.dev","name":"Agentic Trust Labs"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"license":"MIT","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"version":"1.0.0-alpha.9","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2ff07390-1131-4d22-b57e-120dbaf59997"}},"homepage":"https://agenticprimitives.dev","keywords":["fedcm","idp","federation","identity-provider","agentic","agentic-primitives","agenticprimitives","ai-agents","agent-authority","agentic-trust"],"_resolved":"/tmp/17b777f487fe8455a2f6a579e36c76b5/agenticprimitives-fedcm-idp-1.0.0-alpha.9.tgz","_integrity":"sha512-KeBcr6qC0pj4CwrRsQFNF4vlbUJxmq+F3GNaaqYL4GAezg2d8LdIvTwcOuG//UDELB+kGZxPHeVtnKXgKQlfUQ==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-idp"},"_npmVersion":"11.19.0","description":"FedCM IdP contract as pure builders + validators: web-identity manifest, provider config, accounts list, thin id-assertion claims, request validators. Generic; the app hosts + signs (ADR-0031).","directories":{},"maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/fedcm-idp_1.0.0-alpha.9_1789814968150_0.21741867534833093"}}},"time":{"created":"2026-06-11T04:59:51.171Z","modified":"2026-09-19T10:49:28.411Z","1.0.0-alpha.6":"2026-06-11T04:59:51.525Z","1.0.0-alpha.7":"2026-09-11T22:01:53.912Z","1.0.0-alpha.8":"2026-09-12T16:28:53.576Z","1.0.0-alpha.9":"2026-09-19T10:49:28.235Z"},"bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"license":"MIT","homepage":"https://agenticprimitives.dev","keywords":["fedcm","idp","federation","identity-provider","agentic","agentic-primitives","agenticprimitives","ai-agents","agent-authority","agentic-trust"],"repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-idp"},"description":"FedCM IdP contract as pure builders + validators: web-identity manifest, provider config, accounts list, thin id-assertion claims, request validators. Generic; the app hosts + signs (ADR-0031).","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"readme":"# @agenticprimitives/fedcm-idp\n\n> Part of **[Agentic Primitives](https://agenticprimitives.dev)** — the open-source trust substrate for agentic applications: identity that can sign, authority checked at act time, evidence the owner carries. [Developer kit](https://github.com/agentictrustlabs/agentic-primitives) · [All packages](https://agenticprimitives.dev/developers)\n\n**Become a FedCM identity provider for agents — where the account ID is an on-chain address, not a database row.**\n\nFedCM lets a browser broker federated sign-in natively, but hosting the IdP side means getting a fussy wire contract exactly right: the `/.well-known/web-identity` manifest, the provider config, the accounts list, the id-assertion exchange. `fedcm-idp` encodes that contract as pure, dependency-free builders and validators, so an app can host the FedCM IdP endpoints without hand-rolling the shapes — and with one substrate-grade twist: the account `id` the browser's chooser keys on is the Smart Agent address ([ADR-0010](https://github.com/agentictrustlabs/agenticprimitives/blob/master/docs/architecture/decisions/0010-smart-agent-canonical-identifier.md)), a stable on-chain identifier, never a name or a vendor user ID.\n\nThis is the IdP half of the FedCM **adapter** over the agenticprimitives authority substrate — FedCM-first, not FedCM-only ([ADR-0031](https://github.com/agentictrustlabs/agenticprimitives/blob/master/docs/architecture/decisions/0031-fedcm-and-browser-credential-apis-are-adapters.md); [spec 264](https://github.com/agentictrustlabs/agenticprimitives/blob/master/specs/264-fedcm-idp-adapter.md)). The package performs **no I/O, holds no key, signs nothing** — the app owns the session and account list and signs the assertion claims with its existing OIDC key. The assertion is a **thin** identity+intent bootstrap only; the deep capability/delegation object is issued by the substrate **after** the assertion, never as a FedCM scope.\n\n> Part of [agenticprimitives](../../README.md) — the trust substrate for the agent economy: one canonical Smart Agent identity with custody, delegation, naming, credentials, and audit evidence designed as one system.\n\n## Install\n\n```bash\nnpm install @agenticprimitives/fedcm-idp\n```\n\n## Usage (in the IdP app's route handlers)\n\n```ts\nimport {\n  buildWebIdentity, buildProviderConfig, buildAccountsResponse,\n  buildAssertionClaims, isWebIdentityRequest, parseAssertionRequest,\n} from '@agenticprimitives/fedcm-idp';\n\n// GET /.well-known/web-identity\nreturn Response.json(buildWebIdentity(['https://www.example/fedcm/config.json']));\n\n// GET /fedcm/config.json\nreturn Response.json(buildProviderConfig({\n  accountsEndpoint: '/fedcm/accounts',\n  idAssertionEndpoint: '/fedcm/assertion',\n  loginUrl: '/fedcm/login',\n  branding: { name: 'Example IdP' },\n}));\n\n// GET /fedcm/accounts  — app resolves the signed-in agents → rows; id = SA address (stable key)\nif (!isWebIdentityRequest(req.headers.get('sec-fetch-dest'))) return new Response(null, { status: 400 });\nreturn Response.json(buildAccountsResponse(agents.map(a => ({ id: a.address, name: a.label }))));\n\n// POST /fedcm/assertion  — parse, then the APP signs the claims with its OIDC key\nconst parsed = parseAssertionRequest(Object.fromEntries(await req.formData()));\nif (!parsed) return new Response(null, { status: 400 });\nconst claims = buildAssertionClaims({ iss, aud: parsed.clientId, sub: accountAddress, origin, nonce: parsed.nonce, iat });\nconst token = await signWithOidcKey(claims);          // app's key — NOT this package\nreturn Response.json({ token });\n```\n\nThe validators fail closed: `isWebIdentityRequest` rejects anything but a genuine browser FedCM fetch, and `parseAssertionRequest` returns nothing rather than a partially-valid request.\n\n## How it's different from rolling the FedCM contract yourself\n\nMost FedCM IdP implementations are bespoke route handlers written against the W3C/Chrome docs, with the wire shapes inlined and the key handling entangled. This package splits the concerns the way an auditor would want:\n\n- **Pure contract, zero authority.** Builders and validators only — no fetch, no storage, no signing key. The blast radius of this package is a malformed JSON body, not a forged token.\n- **Stable subjects by design.** The accounts-list `id` is the canonical Smart Agent address, so the browser's per-account state and the relying party's subject survive credential rotation and renames.\n- **Authority stays out of the assertion.** Scoped, revocable permissions come from the substrate's delegation layer after sign-in — a compromised or drifting FedCM contract cannot widen what an agent may do.\n\nThe relying-party half lives in [`fedcm-rp`](../fedcm-rp); the FedCM-vs-fallback selection lives in [`browser-identity`](../browser-identity).\n\n## Boundaries\n\nGeneric + transport-agnostic ([ADR-0021](https://github.com/agentictrustlabs/agenticprimitives/blob/master/docs/architecture/decisions/0021-generic-packages-vs-white-label-apps.md)):\nno hostnames, no signing, no app imports. The endpoint **hosting**, the account list, the OIDC signer,\nand the substrate delegation all live in the app.\n\n## Status — draft, and labeled as such\n\n**This package is a draft (spec 264 Phase 1, `private: true`).** FedCM IdP field names follow the W3C/Chrome contract, which had breaking changes across Chrome 143→145. Verify against the current FedCM spec and a live Chrome before relying on this in production (spec 264 Phase 1b).\n\nBeyond that caveat: testnet/pilot-ready. Production launch is gated on the public checklist in the root README — including third-party contract audit and governance key rotation. Track every security finding live in [`docs/audits/findings.yaml`](../../docs/audits/findings.yaml).\n\n## Validate\n\n```bash\npnpm --filter @agenticprimitives/fedcm-idp build\npnpm --filter @agenticprimitives/fedcm-idp test\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","author":{"url":"https://agenticprimitives.dev","name":"Agentic Trust Labs"}}