{"_id":"@agenticprimitives/fedcm-rp","_rev":"4-544943ccb48b3c0245fb8bfb92b05cc0","name":"@agenticprimitives/fedcm-rp","dist-tags":{"alpha":"1.0.0-alpha.6","latest":"1.0.0-alpha.9"},"versions":{"1.0.0-alpha.6":{"name":"@agenticprimitives/fedcm-rp","version":"1.0.0-alpha.6","keywords":["fedcm","relying-party","federation","sign-in","agentic"],"license":"MIT","_id":"@agenticprimitives/fedcm-rp@1.0.0-alpha.6","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"homepage":"https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/fedcm-rp","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"c018f82c80b7631e3d6a2649a1244a510dad61f0","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-rp/-/fedcm-rp-1.0.0-alpha.6.tgz","fileCount":8,"integrity":"sha512-k7Kw7Bt2bWo7/djrjWL8T1Ciiu9xwFhfF6Oh5hls2Wigur/gme6Tz0Y2AMyizeDCB+WioJa3p7EW559ehDnXIQ==","signatures":[{"sig":"MEYCIQCk50BJ+irkfuFVtUwzwC3X9in543cSOQydtSctzGFsSgIhAPpzYW94NuvWp0hmm6TeBTKukAzYvypIET/4Se0Hn5LV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16268},"main":"./dist/index.js","type":"module","_from":"file:agenticprimitives-fedcm-rp-1.0.0-alpha.6.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"_npmUser":{"name":"richcanvas","email":"richardpedersen3@gmail.com"},"_resolved":"/tmp/claude-1000/1d7b2e72b916f2a72ac688ffdae41ab9/agenticprimitives-fedcm-rp-1.0.0-alpha.6.tgz","_integrity":"sha512-k7Kw7Bt2bWo7/djrjWL8T1Ciiu9xwFhfF6Oh5hls2Wigur/gme6Tz0Y2AMyizeDCB+WioJa3p7EW559ehDnXIQ==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-rp"},"_npmVersion":"11.16.0","description":"Relying-party FedCM wrapper: navigator.credentials.get({identity}) → IdP token. The FedCM strategy injected into browser-identity's chooseSignIn. FedCM-first, not FedCM-only (ADR-0031).","directories":{},"_nodeVersion":"24.12.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"tmp":"tmp/fedcm-rp_1.0.0-alpha.6_1781153993446_0.16423902840933002","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-alpha.7":{"name":"@agenticprimitives/fedcm-rp","version":"1.0.0-alpha.7","keywords":["fedcm","relying-party","federation","sign-in","agentic"],"license":"MIT","_id":"@agenticprimitives/fedcm-rp@1.0.0-alpha.7","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"homepage":"https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/fedcm-rp","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"4a68e7e68f8493b0b99048b88837307b6f2cb7be","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-rp/-/fedcm-rp-1.0.0-alpha.7.tgz","fileCount":8,"integrity":"sha512-39JxzVfdbIq3C6mYIYq0TFAhtu1cwDGR8PaBr8to/jEmDXdrSj41YgBR5kNGgodIr9B/jtsRWrE6cXWZzZJYGA==","signatures":[{"sig":"MEUCICTGBjNtOISGkAMsXMQwxr0SeSK2oXqY6SrG/vE9m6wnAiEA35SfAA6z7lGrn9XtfnIxyINu9/gd2eCT+UCyk0lfxVU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16268},"main":"./dist/index.js","type":"module","_from":"file:agenticprimitives-fedcm-rp-1.0.0-alpha.7.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab94ba9a-fb55-46da-a425-a26675c47ff5"}},"_resolved":"/tmp/c706700511af5044960cae1e126b6ef3/agenticprimitives-fedcm-rp-1.0.0-alpha.7.tgz","_integrity":"sha512-39JxzVfdbIq3C6mYIYq0TFAhtu1cwDGR8PaBr8to/jEmDXdrSj41YgBR5kNGgodIr9B/jtsRWrE6cXWZzZJYGA==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-rp"},"_npmVersion":"11.19.0","description":"Relying-party FedCM wrapper: navigator.credentials.get({identity}) → IdP token. The FedCM strategy injected into browser-identity's chooseSignIn. FedCM-first, not FedCM-only (ADR-0031).","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"tmp":"tmp/fedcm-rp_1.0.0-alpha.7_1789164114749_0.39000444551822855","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-alpha.8":{"name":"@agenticprimitives/fedcm-rp","version":"1.0.0-alpha.8","keywords":["fedcm","relying-party","federation","sign-in","agentic"],"license":"MIT","_id":"@agenticprimitives/fedcm-rp@1.0.0-alpha.8","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"homepage":"https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/fedcm-rp","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"48f98f0962e19734203dc4947aacb749000f5012","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-rp/-/fedcm-rp-1.0.0-alpha.8.tgz","fileCount":8,"integrity":"sha512-FeTcxaKhe2nGAy++FooGn/Fgw8o+EsXN6G6KsZAYzPOU/I/SW/XHuXUu1lKyWoyYBFq2mJjl0WOw2dhExFdO/g==","signatures":[{"sig":"MEUCIQD05en4XR8qn/eVO31GZc5q/eeWduRt92loWIqPXWmCSgIgYQ+62NfsuM3JKfVETnUGhlkZFuX2k8MNS/KUxVsoKG0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16268},"main":"./dist/index.js","type":"module","_from":"file:agenticprimitives-fedcm-rp-1.0.0-alpha.8.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab94ba9a-fb55-46da-a425-a26675c47ff5"}},"_resolved":"/tmp/d87399370cde5882df7615458e3a506e/agenticprimitives-fedcm-rp-1.0.0-alpha.8.tgz","_integrity":"sha512-FeTcxaKhe2nGAy++FooGn/Fgw8o+EsXN6G6KsZAYzPOU/I/SW/XHuXUu1lKyWoyYBFq2mJjl0WOw2dhExFdO/g==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-rp"},"_npmVersion":"11.19.0","description":"Relying-party FedCM wrapper: navigator.credentials.get({identity}) → IdP token. The FedCM strategy injected into browser-identity's chooseSignIn. FedCM-first, not FedCM-only (ADR-0031).","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"tmp":"tmp/fedcm-rp_1.0.0-alpha.8_1789230534451_0.5026813387618057","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-alpha.9":{"_id":"@agenticprimitives/fedcm-rp@1.0.0-alpha.9","bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"dist":{"shasum":"e2caeda791020080faf3f75a812f7ca5e7827882","tarball":"https://registry.npmjs.org/@agenticprimitives/fedcm-rp/-/fedcm-rp-1.0.0-alpha.9.tgz","fileCount":8,"integrity":"sha512-Sxo+PBXyRG5AFXbRCaqsCndaCqTjYloqCHCs8tFKmhaqHjBd/BmSGQI+ihPV1lVE/XK+fQs0x1ToI84raj9nzg==","signatures":[{"sig":"MEYCIQCe/U+84FvLr+BZPM+x/a5F6dVG58Kv12FQr6NFb24RZAIhAMWhCohItAwjyR72fzEcSA69ZI1vvekI6URzkfuNYovo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCr8HoqVWCs8zfuu+3okzOMCVwGmtuqKYBN6ixeH+DScQIhAOo/RFZQ84XHjcFEUn056FT7gnIhFkdSb+9BgR7gy0Z+"}],"unpackedSize":16766},"main":"./dist/index.js","name":"@agenticprimitives/fedcm-rp","type":"module","_from":"file:agenticprimitives-fedcm-rp-1.0.0-alpha.9.tgz","types":"./dist/index.d.ts","author":{"url":"https://agenticprimitives.dev","name":"Agentic Trust Labs"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"license":"MIT","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test:unit":"vitest run test/unit --passWithNoTests","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","test:integration":"vitest run test/integration --passWithNoTests"},"version":"1.0.0-alpha.9","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ab94ba9a-fb55-46da-a425-a26675c47ff5"}},"homepage":"https://agenticprimitives.dev","keywords":["fedcm","relying-party","federation","sign-in","agentic","agentic-primitives","agenticprimitives","ai-agents","agent-authority","agentic-trust"],"_resolved":"/tmp/a83c22039307a2822c8af6d3359e7316/agenticprimitives-fedcm-rp-1.0.0-alpha.9.tgz","_integrity":"sha512-Sxo+PBXyRG5AFXbRCaqsCndaCqTjYloqCHCs8tFKmhaqHjBd/BmSGQI+ihPV1lVE/XK+fQs0x1ToI84raj9nzg==","repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-rp"},"_npmVersion":"11.19.0","description":"Relying-party FedCM wrapper: navigator.credentials.get({identity}) → IdP token. The FedCM strategy injected into browser-identity's chooseSignIn. FedCM-first, not FedCM-only (ADR-0031).","directories":{},"maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","@types/node":"^22.7.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/fedcm-rp_1.0.0-alpha.9_1789814948013_0.941778987438026"}}},"time":{"created":"2026-06-11T04:59:53.249Z","modified":"2026-09-19T10:49:08.289Z","1.0.0-alpha.6":"2026-06-11T04:59:53.596Z","1.0.0-alpha.7":"2026-09-11T22:01:54.889Z","1.0.0-alpha.8":"2026-09-12T16:28:54.573Z","1.0.0-alpha.9":"2026-09-19T10:49:08.103Z"},"bugs":{"url":"https://github.com/agentictrustlabs/agenticprimitives/issues"},"license":"MIT","homepage":"https://agenticprimitives.dev","keywords":["fedcm","relying-party","federation","sign-in","agentic","agentic-primitives","agenticprimitives","ai-agents","agent-authority","agentic-trust"],"repository":{"url":"git+https://github.com/agentictrustlabs/agenticprimitives.git","type":"git","directory":"packages/fedcm-rp"},"description":"Relying-party FedCM wrapper: navigator.credentials.get({identity}) → IdP token. The FedCM strategy injected into browser-identity's chooseSignIn. FedCM-first, not FedCM-only (ADR-0031).","maintainers":[{"name":"richcanvas","email":"richardpedersen3@gmail.com"}],"readme":"# @agenticprimitives/fedcm-rp\n\n> Part of **[Agentic Primitives](https://agenticprimitives.dev)** — the open-source trust substrate for agentic applications: identity that can sign, authority checked at act time, evidence the owner carries. [Developer kit](https://github.com/agentictrustlabs/agentic-primitives) · [All packages](https://agenticprimitives.dev/developers)\n\n**Browser-native sign-in for the relying party — that hands back identity, never authority.**\n\nWhen the browser supports FedCM, a relying site can skip the redirect dance entirely: the browser shows a native account chooser and returns a signed assertion. `fedcm-rp` is the thin, dependency-free wrapper over `navigator.credentials.get({ identity })` that makes that call correctly — including the post-Chrome-145 field shapes that broke naive integrations — and returns the IdP token. It is the FedCM **strategy** you inject into [`@agenticprimitives/browser-identity`](https://github.com/agentictrustlabs/agenticprimitives/tree/master/packages/browser-identity)'s `chooseSignIn` — FedCM-first, not FedCM-only ([ADR-0031](https://github.com/agentictrustlabs/agenticprimitives/blob/master/docs/architecture/decisions/0031-fedcm-and-browser-credential-apis-are-adapters.md); [spec 264](https://github.com/agentictrustlabs/agenticprimitives/blob/master/specs/264-fedcm-idp-adapter.md)).\n\nThe returned `token` is a **thin identity bootstrap**: it says who signed in, nothing more. The deep capability/delegation object — scoped, revocable, on-chain-enforceable authority — is obtained from the substrate **after** this token (ADR-0031), never decoded from a FedCM scope. Sign-in and authorization stay separate layers, which is exactly where stitched stacks leak.\n\n> Part of [agenticprimitives](../../README.md) — the trust substrate for the agent economy: one canonical Smart Agent identity with custody, delegation, naming, credentials, and audit evidence designed as one system.\n\n## Install\n\n```bash\nnpm install @agenticprimitives/fedcm-rp\n```\n\n## Usage (as the injected FedCM strategy)\n\n```ts\nimport { chooseSignIn } from '@agenticprimitives/browser-identity';\nimport { fedcmSupported, fedcmGet } from '@agenticprimitives/fedcm-rp';\n\nconst result = await chooseSignIn({\n  // Run FedCM when the browser supports it; otherwise the guaranteed spec-259 fallback.\n  fedcm: fedcmSupported()\n    ? async () => {\n        const { token } = await fedcmGet({\n          providers: [{\n            configURL: 'https://www.example/fedcm/config.json',\n            clientId: 'demo-gs',\n            // post-145: nonce + custom params ride INSIDE params\n            params: { nonce, scope: 'profile.read', intent: 'signin' },\n          }],\n        });\n        return exchangeAssertionForSession(token); // → your app session + substrate delegation\n      }\n    : undefined,\n  fallback: () => startConnectPopup(),\n});\n```\n\n### `fedcmGet(options)`\n\n`providers[]` (1+; Chrome 136 multi-IdP), `context` (`signin`|`signup`|`use`|`continue`), `mode`\n(`passive`|`active` — `active` requires a single provider + a user gesture), `mediation`\n(`optional`|`required`|`silent`), `signal`. Returns `{ token, configURL?, isAutoSelected? }`. Throws if\nunsupported / dismissed / errored — treat a throw as \"use the fallback.\"\n\n## How it's different from calling FedCM directly\n\nYou could call `navigator.credentials.get({ identity })` yourself. Three reasons this wrapper earns its place:\n\n- **It tracks the moving contract.** FedCM's request shape changed across Chrome 143→145 (`nonce` and custom params moved inside `params`); this package encodes the current shape so your app code does not chase browser releases.\n- **It is failure-honest.** A throw means \"use the fallback\" — composing cleanly with `browser-identity`'s selector instead of leaving every caller to invent its own unsupported/dismissed/error handling.\n- **It refuses to be an authorization channel.** No token decoding, no scope interpretation, no substrate imports. The consumer exchanges the token with the substrate; permissions can never ride in on a browser credential.\n\nThe IdP half lives in [`fedcm-idp`](../fedcm-idp); the FedCM-vs-fallback selection in [`browser-identity`](../browser-identity).\n\n## Boundaries\n\nGeneric + transport-agnostic ([ADR-0021](https://github.com/agentictrustlabs/agenticprimitives/blob/master/docs/architecture/decisions/0021-generic-packages-vs-white-label-apps.md)):\nno app imports, no hostnames. The consumer supplies `configURL` / `clientId` / `params`, and exchanges the\ntoken with the substrate.\n\n## Status — draft, and labeled as such\n\n**This package is a draft (spec 264 Phase 1, `private: true`).** FedCM is Chromium-only today, and the field names changed across Chrome 143→145 (`params.nonce`, `.error`). Verify against a live Chrome before relying on this in production (spec 264 Phase 1b).\n\nBeyond that caveat: testnet/pilot-ready. Production launch is gated on the public checklist in the root README — including third-party contract audit and governance key rotation. Track every security finding live in [`docs/audits/findings.yaml`](../../docs/audits/findings.yaml).\n\n## Validate\n\n```bash\npnpm --filter @agenticprimitives/fedcm-rp build\npnpm --filter @agenticprimitives/fedcm-rp test\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","author":{"url":"https://agenticprimitives.dev","name":"Agentic Trust Labs"}}