{"_id":"@agentlair/audit-logger","_rev":"10-b6f8b69c235b24e65337045157213031","name":"@agentlair/audit-logger","dist-tags":{"latest":"0.7.0"},"versions":{"0.1.0":{"name":"@agentlair/audit-logger","version":"0.1.0","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.1.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"f5f80b6a3f435bd995438d17c8160760c8e5669d","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.1.0.tgz","fileCount":22,"integrity":"sha512-CSV0HnXWiTEF9I1h6a/f6Ebk+2Biasg4K8q7d3Q1nDLj2AorU15rGkXnKGE3OA8c+5UBKvLrh5UBOHcK/zXABg==","signatures":[{"sig":"MEUCIDtGRoI9JFbxO7vC9AuSby7x0WDmwS6b/3tZWQH7r+TdAiEAijnA7kOiPuNrZUiVc/fQn8eQOnHUpMb1LJ1EyU6TB/4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":40837},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"ebc79029eccac4de74ab0c2cf15fa6f8239e023b","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"11.12.1","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"24.3.0","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.1.0_1775035948302_0.45607036648622623","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentlair/audit-logger","version":"0.2.0","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.2.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"84890df3bc03534d72b3a00dea788e9e8f4bff4b","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.2.0.tgz","fileCount":22,"integrity":"sha512-/U45i2bpkBItLl9pG8ybhhydNZ/KhYMkT+r2swRLlH48c1mZAAqdfn6GBooz/jcS7ZfUv1+iO6KOQ5jKOvadkg==","signatures":[{"sig":"MEQCIDQ2x+XUoNBW1k49XnnX5XZqfQJIfMWOvc1sDKM5Tff3AiAwraw4zHO6Lhhr6oA/gq7/sVR1ACUrGAmH4Z/A1w1Ttg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60522},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"c12c0d34177519226554de3d5a86a9ab0bfb74e7","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.2.0_1780749098314_0.7456552678488428","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@agentlair/audit-logger","version":"0.3.0","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.3.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"8f7c5e55d887f076ba0574f37eff57306bf9054d","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.3.0.tgz","fileCount":22,"integrity":"sha512-2krIVdQwkP57YaTWeejVilrSeVcFHMsG7bhXuwRN7WqH9MS6rmLcfcmaJ2YftnzCXoscrNdJogtuJ4vt8ZP5+Q==","signatures":[{"sig":"MEUCIQCAupJeKc5PvoJKcvgWfjXeV5Fu4ZTVWfnvNfUhEvLsMAIgJ+aXwUAupptYUMOYtABPT3l2eu4LN1AN7/cskUl2yUk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65935},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"c12c0d34177519226554de3d5a86a9ab0bfb74e7","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.3.0_1780773683442_0.29318503542533225","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@agentlair/audit-logger","version":"0.4.0","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.4.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"c8879550487cea4317b551d81a9c16fc9722d0e2","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.4.0.tgz","fileCount":22,"integrity":"sha512-3Uaytlb52brtg2iIX6Ao6n6UQEfETLpFyaR2BoKQVFP4LOuHm+fA4/iya2Bm/oC+mHCTfKQTdtB0SENSbapK5Q==","signatures":[{"sig":"MEYCIQDuMDVnFUHewFiBkesUsDyt7CMnbM75mVZ6vHAoyODJOAIhALxl0JnwsFBz3+q4vYs3QXdfORkPATY1tOROBkrR7SNo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":72827},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"b7f8cab98cf2e15ec46a46b8109c43423dbfcf90","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.4.0_1780780549335_0.45771683935460605","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@agentlair/audit-logger","version":"0.4.1","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":"AgentLair","license":"MIT","_id":"@agentlair/audit-logger@0.4.1","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","dist":{"shasum":"1d8b1a1e7e410544c44cf0c4f5d84ff2dd917494","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.4.1.tgz","fileCount":22,"integrity":"sha512-3RR1vGxQUOQxSnKesk3PdTssbMXhpbhYL/zRoIhHCm96SzEQQw4GpTKBu8/Xbp28pETASSgzC1gBG1nAnCWUvg==","signatures":[{"sig":"MEUCIGHZUQwcm0N5NlCCRw183zsVwn5GG7czsmnIim+yWp0cAiEA1UAmIoIhZ7Bv2r9qEas6JkilFppZFLqnbkiL6kFOMVc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":80456},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","shasum":"1d8b1a1e7e410544c44cf0c4f5d84ff2dd917494","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"_integrity":"sha512-3RR1vGxQUOQxSnKesk3PdTssbMXhpbhYL/zRoIhHCm96SzEQQw4GpTKBu8/Xbp28pETASSgzC1gBG1nAnCWUvg==","repository":{"url":"https://github.com/piiiico/agentlair","type":"git"},"_npmVersion":"10.8.3","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"24.3.0","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.4.1_1780791433569_0.02768476906105488","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@agentlair/audit-logger","version":"0.4.2","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.4.2","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"198b8337af3887a1bb0a5e05d2aad56f3fa14a89","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.4.2.tgz","fileCount":22,"integrity":"sha512-kunXCVGJCgMB2FtLGvvHhQ6IZMwUS2XkPNk2fLvsU17Cz0VMLybAQLKT6if9f0PckUCujS/biwjJEk8b6xmyFg==","signatures":[{"sig":"MEQCIDUMUHC4rXzacwRC4WL8wUu35sUHdlm3l3WGDfQ4lOqjAiBCW4zr2no6iPZ/Jw6duoBA/dI2VyhCJwoVCLMmM45w3Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82335},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"8405e075b89b179d2a474ae3cf2319a56fd51f57","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.4.2_1780794672394_0.44653531881215414","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agentlair/audit-logger","version":"0.5.0","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.5.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"cfc6263050bfc0579b8c46b40762b75720b3197c","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.5.0.tgz","fileCount":22,"integrity":"sha512-TWvBgxDjZ2u5XTxfGSWjg77FA4EbMpgiBYeI8bWLtXy/wOacu8hfQjhYEVFqjUv29Qd4eBIQUlsicCbiecxmNQ==","signatures":[{"sig":"MEUCIQCw8iyFstAKsMf7KdiMEC7XORr4N8xmuzk9vhzaQ+7xKgIgQUU5aygpc6G6paciOqF9SBp+xxG95DyzlVEzxkldIIw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":111058},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"8d4302e07f44dd53e9aa8dc1439c286e91379e5f","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.5.0_1781225710194_0.1225659456804975","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@agentlair/audit-logger","version":"0.6.0","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.6.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"f928cb52f27404d5e8f49a7dc336a55fa84014e5","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.6.0.tgz","fileCount":22,"integrity":"sha512-k5Tdc+h8Gll/y4srf5hJI5kj16zSCIvpnOQQKKTtkSylJq/2Ff9j0ttRS7HnjhSXLq8TfUCssoQJ7BPl7jcVUg==","signatures":[{"sig":"MEUCIQDF6VvpTgK5HanOKSuM09JZzXO6bWZ5pMZ/VkszFHnW3gIgTkiW9yoLCCYJFLeT0J07+GMPe6sbptLVRcbR7w14yxY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":145805},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"b8e51b3394d21bc41d2b2d50c5152827a9f88839","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.6.0_1781233973497_0.674469157458516","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@agentlair/audit-logger","version":"0.6.1","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/audit-logger@0.6.1","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"f79a925c6cf437c6738cf0241140e0c3a5c3dac9","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.6.1.tgz","fileCount":22,"integrity":"sha512-BmZ0jpkQZH2kGf4SHzJ3rkki69sn83ZxgYpQQtkNmIJ7rcsOG6G0D/c2wqREsvaGiBjQ9quri4FUmER/03Fcrg==","signatures":[{"sig":"MEYCIQCB+DIrlq2wQC29RytoruGCYyh22rwMnIftQtvuQBD/RAIhAIXuVy2g8FubxsCCzK12CpYFwwUQJvmBVhTpDRPdS3wK","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":151957},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"d13a1d32b0293ec3d23827a8ba31db2dde87e2df","scripts":{"test":"bun test","build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"bun-types":"^1.3.11","typescript":"^6.0.2","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-logger_0.6.1_1781249798065_0.5681695674657958","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@agentlair/audit-logger","version":"0.7.0","description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"homepage":"https://agentlair.dev","repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair.git"},"license":"MIT","author":{"name":"AgentLair"},"type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"},"./langchain":{"import":"./dist/adapters/langchain.js","types":"./dist/adapters/langchain.d.ts"},"./anthropic":{"import":"./dist/adapters/anthropic.js","types":"./dist/adapters/anthropic.d.ts"}},"scripts":{"build":"tsc","test":"bun test","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"engines":{"node":">=18.0.0"},"devDependencies":{"@types/node":"^25.5.0","bun-types":"^1.3.11","typescript":"^6.0.2"},"_id":"@agentlair/audit-logger@0.7.0","gitHead":"fc98878846b009de6191505ae822069dbd250e46","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-BT5lobZLJW2v2PbvUqS1igPB+KrLxYSZv1v6e7oA6V8nPZLVfkp/jeFjJ7ZvM9e/jYwOVPNCh/ksuEQs41oeVg==","shasum":"5334fd6af63a7afb1f11afe4afb2dc6e9f998bfe","tarball":"https://registry.npmjs.org/@agentlair/audit-logger/-/audit-logger-0.7.0.tgz","fileCount":22,"unpackedSize":187721,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCYYbWrgve7TD5rvOhsWEN32EyM9R76D5pLtsvPXDJvyAIhAK2wMfG2bcTpXWDbHnNMAsvd64PMD5+FlJumGBxYIXwC"}]},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"directories":{},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/audit-logger_0.7.0_1781268900234_0.7237709849060288"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-01T09:32:28.226Z","modified":"2026-06-12T12:55:00.485Z","0.1.0":"2026-04-01T09:32:28.459Z","0.2.0":"2026-06-06T12:31:38.448Z","0.3.0":"2026-06-06T19:21:23.571Z","0.4.0":"2026-06-06T21:15:49.473Z","0.4.1":"2026-06-07T00:17:13.707Z","0.4.2":"2026-06-07T01:11:12.525Z","0.5.0":"2026-06-12T00:55:10.345Z","0.6.0":"2026-06-12T03:12:53.631Z","0.6.1":"2026-06-12T07:36:38.243Z","0.7.0":"2026-06-12T12:55:00.379Z"},"bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"author":{"name":"AgentLair"},"license":"MIT","homepage":"https://agentlair.dev","keywords":["ai-agent","audit","logging","langchain","crewai","claude","anthropic","agentlair","observability","agent-monitoring"],"repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair.git"},"description":"Framework-agnostic agent action logger. Logs locally by default. Connect to AgentLair for persistent, queryable audit trails.","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"readme":"# @agentlair/audit-logger\n\nA lightweight, framework-agnostic agent action logger. Log locally by default. Connect to [AgentLair](https://agentlair.dev) for persistent, queryable audit trails.\n\nZero runtime dependencies. Works in Node ≥ 18, Bun, Deno, and modern browsers.\n\n---\n\n## Install\n\n```bash\nnpm install @agentlair/audit-logger\n# or\nbun add @agentlair/audit-logger\n```\n\n---\n\n## Two-receipt AAR (recommended)\n\nThe standard `auditLog()` emits a single post-action record. For tamper-evidence and pre-authorization anchoring, use `beginAction` / `endAction` to emit **two chained receipts** per tool call — one before execution begins, one terminal receipt when the attempt closes.\n\n```typescript\nimport { AuditLogger } from '@agentlair/audit-logger';\n\nconst logger = new AuditLogger({\n  actorId: 'agent-researcher',\n  hmacSecret: process.env.AUDIT_HMAC_SECRET, // optional signing key\n});\n\n// 1. Emit the pre-action receipt BEFORE execution begins.\n//    expiresAt is authority data — covered by previousReceiptHash,\n//    so tampering with the deadline after signing breaks the chain.\nconst preAction = await logger.beginAction({\n  toolName: 'web_search',\n  toolCallId: 'call-abc123',\n  input: { query: 'latest AI agent frameworks' },\n  approvalDecision: 'approved',     // from preflight_trust_check\n  policyRef: 'trust-check:xyz-789', // link to the trust check result\n  expiresAt: new Date(Date.now() + 60_000).toISOString(),\n});\n\n// 2. Execute the tool\nconst startedAt = new Date();\nlet output: unknown;\nlet error: Error | undefined;\ntry {\n  output = await webSearch({ query: 'latest AI agent frameworks' });\n} catch (err) {\n  error = err as Error;\n} finally {\n  const endedAt = new Date();\n\n  // 3. Seal the attempt with a terminal receipt.\n  //    phase defaults to \"executed\"; pass \"failed\" / \"denied\" / \"expired\" / \"cancelled\"\n  //    when the attempt closes without successful execution.\n  await logger.endAction({\n    preAction,\n    phase: error ? 'failed' : 'executed',\n    startedAt,\n    endedAt,\n    output, // undefined on error\n    error,  // undefined on success\n  });\n}\n```\n\n### Why two receipts?\n\nA single post-action log proves nothing about intent — a compromised agent can construct a plausible receipt for an action it never authorized. The pre-action receipt is signed and chained **before** execution begins. To forge it, an adversary must predict the future or have already compromised the signing key.\n\n| Receipt              | Phase            | What it proves                                                |\n|----------------------|------------------|---------------------------------------------------------------|\n| `AARPreAction`       | Before execution | Input digest, authorization decision, deadline, chain position |\n| `AARTerminalReceipt` | Attempt closed   | Terminal phase, link back to pre-action, result/error digest  |\n\n**Every `beginAction` closes exactly once.** A denied or expired attempt is first-class evidence, not an absence — the chain detects omissions.\n\n### Terminal phase enum\n\n`endAction({ phase })` accepts one of:\n\n| Phase       | Meaning                                                                  |\n|-------------|--------------------------------------------------------------------------|\n| `executed`  | Tool ran to completion. `resultDigest` carries the output hash.          |\n| `failed`    | Tool ran but threw. `errorClass` / `errorDigest` carry the failure.      |\n| `denied`    | Policy refused before execution. No `executionStartedAt`.                |\n| `expired`   | Authority window elapsed before completion. `terminalAt >= expiresAt`.   |\n| `cancelled` | Caller withdrew the attempt before completion.                           |\n\n**Sign-time invariants enforced at `endAction()`:**\n\n- `phase: 'executed'` over `approvalDecision: 'denied'` throws. Executed-over-denied is structurally impossible to mint.\n- `phase: 'executed'` whose `executionEndedAt > preAction.expiresAt` throws (v0.4). The logger refuses to claim authorized execution past the deadline.\n- `phase: 'executed'` whose `effectiveEnvelopeHash !== preAction.approvedEnvelopeHash` throws (v0.5). When the pre-action bound a canonical envelope, the terminal must seal against the same envelope — drift on any consequential field (tool, target, arguments, scope, actor, policy/approval refs, execution-affecting defaults) closes the authority.\n\n### Envelope binding (v0.5)\n\nThe v0.4 chain proves *that* a tool ran; v0.5 proves the call that ran was the call that was approved. Pass `canonicalInput` — the consequential subset of the call — to `beginAction()` and `effectiveCanonicalInput` to `endAction()`:\n\n```typescript\nconst envelope = {\n  toolName: 'http_post',\n  target:   'https://api.example.com/v1/charges',\n  arguments: { amount: 500, currency: 'usd' },\n  scope:    'payments:write',\n  actorId:  'agent-001',\n};\n\nconst pre = await logger.beginAction({\n  toolName: 'http_post',\n  toolCallId: 'call-abc',\n  input: { ...envelope, _trace: traceId },   // raw bytes include transport noise\n  canonicalInput: envelope,                  // consequential subset, hashed for approval binding\n  approvalDecision: 'approved',\n  policyRef: 'policy:t1',\n});\n\n// ... execute ...\n\nawait logger.endAction({\n  preAction: pre,\n  phase: 'executed',\n  output: result,\n  effectiveCanonicalInput: envelope,         // must equal-by-hash; drift throws\n});\n```\n\n**What this buys you:**\n\n- **Non-consequential transport noise stops false-positiving the gate.** Retry IDs, trace headers, defaulted timeouts can change between approval and execution without breaking the chain — they're not in the envelope.\n- **Consequential drift fails closed.** Changing the target URL, the amount, the scope, or any defaulted argument that changes the call's effect rejects the `executed` terminal. The legal path is `phase: 'cancelled'` with `terminalReason: 'effective_call_changed'`, followed by a *new* `beginAction()` for the mutated envelope with a *different* `policyRef`.\n- **The verifier names which side drifted.** `verifyChain()` distinguishes (a) approved-envelope drift (canonical envelope on disk no longer hashes to the stored value — requires `replayedCanonicalInputs`), (b) effective-envelope drift (`effectiveEnvelopeHash !== approvedEnvelopeHash`), and (c) raw-input byte drift (`inputDigest` mismatch — requires `replayedRawInputs`). Each shows up with a distinct `expected` string on the break record.\n- **Canonicalization stays versioned.** `canonicalizationVersion` defaults to `'cv1'`. Cross-version replay fails closed unless `verifyChain(..., { migrationVerifiers: { cv1: ... } })` selects an explicit migration — old receipts stay replayable when the canonical-envelope spec evolves.\n\n`canonicalInput` is opt-in: omitting it preserves v0.4 semantics (only `inputDigest` is bound). When the call's authority depends on *what* it does rather than *what bytes* were shipped, supply it.\n\n### Canonicalizer accountability (v0.6)\n\nv0.5 commits the chain to *what* the call meant. v0.6 commits it to *who decided what counts as a meaning* — the canonicalizer itself becomes a trust boundary. The chain now proves three contracts independently: the canonicalizer profile (what fields it preserves), the policy surface (what fields the policy gates on), and the binding between them (compatibility, registered before authority is minted).\n\n```typescript\nimport {\n  AuditLogger,\n  InMemoryPolicyProfileBindingRegistry,\n  computeCanonicalizerProfileHash,\n  computePolicySurfaceHash,\n} from '@agentlair/audit-logger';\n\n// 1. Declare the canonicalizer profile — pure data, no environment lookup.\nconst httpProfileData = {\n  profileId: 'http',\n  version: '1.0',\n  toolFamily: 'http',\n  includedConsequentialFields: ['method', 'url', 'body', 'scope'],\n  excludedFields: ['traceId', 'retryId', 'userAgent'],\n  normalizationRules: { url: { percentEncoded: true, lowerCaseHost: true } },\n};\nconst httpProfile = {\n  ...httpProfileData,\n  profileHash: await computeCanonicalizerProfileHash(httpProfileData),\n};\n\n// 2. Declare the policy surface — what fields the policy gates on.\nconst paymentsSurfaceData = {\n  policyRef: 'policy:payments',\n  gatedFields: ['method', 'url', 'body', 'scope'],\n};\nconst paymentsSurface = {\n  ...paymentsSurfaceData,\n  surfaceHash: await computePolicySurfaceHash(paymentsSurfaceData),\n};\n\n// 3. Register the binding — verifies gatedFields ⊆ includedConsequentialFields.\n//    Refuses with policy_surface_unbound if the profile would hide a gated field.\nconst registry = new InMemoryPolicyProfileBindingRegistry();\nawait registry.register(paymentsSurface, httpProfile);\n\n// 4. beginAction looks up the binding (constant-time); no recompute, no silent compat.\nconst pre = await logger.beginAction({\n  toolName: 'http_post',\n  toolCallId: 'call-1',\n  input: rawInput,\n  canonicalInput: envelope,\n  canonicalizerProfile: httpProfile,\n  policySurface: paymentsSurface,\n  bindingRegistry: registry,\n  approvalDecision: 'approved',\n  policyRef: 'policy:payments',\n});\n\n// 5. endAction binds the terminal to the same profile hash.\nawait logger.endAction({\n  preAction: pre,\n  phase: 'executed',\n  effectiveCanonicalInput: envelope,\n  canonicalizerProfile: httpProfile, // mismatch throws profile_incompatible\n  output: result,\n});\n```\n\n**Pre-authority refusal — no AAR minted:**\n\n| `BeginActionRefusal.reason` | Trigger                                                                                              |\n|-----------------------------|------------------------------------------------------------------------------------------------------|\n| `unbound_policy_profile`    | No registered binding for (`policy.surfaceHash`, `profile.profileHash`).                             |\n| `policy_surface_unbound`    | At `registry.register()`: policy gates on a field absent from `profile.includedConsequentialFields`. |\n| `profile_data_incomplete`   | Profile declares a normalization rule for a field absent from the envelope.                          |\n\nPre-authority refusals throw a `BeginActionRefusal` rather than producing a terminal record — there is no authority to terminate. Terminal `profile_incompatible` is strictly reserved for drift *after* authority is minted (terminal profile hash ≠ pre-action profile hash).\n\n**What this buys you:**\n\n- **\"Trust the caller's hash function\" becomes checkable.** The profile names what the canonicalizer preserves and excludes. An independent verifier with `registeredCanonicalizerProfiles` rejects pre-actions whose `canonicalizerProfileHash` is absent from the registered set — BYO canonicalizers cannot launder unknown hashes through the chain.\n- **Policy and canonicalizer evolve independently.** `policySurfaceHash` declares what the policy depends on; `canonicalizerProfileHash` declares what the profile preserves; `policyProfileBindingHash` proves they fit. Either can drift without the other, and the verifier names which drifted.\n- **Migration that changes the policy surface requires a fresh approval.** `migrationVerifiers` entries now accept `{ migrate, preservesPolicySurface }`. When `preservesPolicySurface !== true`, cross-version replay is rejected with `migration_changes_policy_surface` — a migration whose output surface differs from input is a new decision, not silent replay.\n- **Pure data, no environment lookup.** The fs profile cannot ask the host \"are you case-sensitive\" at runtime — that answer is host-state, not envelope-state, and host migration silently invalidates replay. Normalization assumptions go into `normalizationRules` as declared data; changing them is a new profile id.\n\nAll v0.6 fields are opt-in: omitting `canonicalizerProfile` / `policySurface` / `bindingRegistry` preserves v0.5 semantics. The decomposition follows the [three-digest model](https://github.com/vercel/ai/issues/13215#issuecomment-4686858517) raised in the AAR thread.\n\n### Chain mechanics\n\nEach receipt includes a `previousReceiptHash` (SHA-256 of the canonical-JSON prior receipt payload). The chain grows linearly:\n\n```\nAARPreAction (tool 1)        → previousReceiptHash = undefined (chain start)\nAARTerminalReceipt (tool 1)  → previousReceiptHash = hash(AARPreAction tool 1)\nAARPreAction (tool 2)        → previousReceiptHash = hash(terminal of tool 1)\nAARTerminalReceipt (tool 2)  → previousReceiptHash = hash(AARPreAction tool 2)\n```\n\nDenied, expired, and cancelled terminals participate in the chain just like executed ones — omitting any of them breaks the successor's hash and is detectable by any verifier.\n\n---\n\n### Publication layer (v0.7) — verifier knows what the profile means\n\n`canonicalizerProfileHash` and `policyProfileBindingHash` make the chain commit to which profile and which binding were used. v0.7 closes the next gap: the verifier no longer has to trust whoever served the bytes for those hashes. Profiles and bindings are published at content-addressed URLs whose bytes the verifier hashes and whose JWS signatures resolve through the same JWKS as the AAR signing key itself.\n\n```ts\nimport { verifyChain, fetchPublishedProfile, fetchPublishedBinding } from '@agentlair/audit-logger';\n\nconst result = await verifyChain(receipts, {\n  resolveProfile: fetchPublishedProfile,   // GET https://agentlair.dev/.well-known/aar-profiles/<hash>\n  resolveBinding: fetchPublishedBinding,   // GET https://agentlair.dev/.well-known/aar-bindings/<hash>\n  issuerTrustSet: { 'agentlair-2026-q2': pubKeyBytes },\n});\n```\n\nEach terminal that pins a `canonicalizerProfileHash` is checked against the published bytes; each pre-action that pins a `policyProfileBindingHash` is checked against the published binding tuple. The verifier rejects when:\n\n| Layer | `expected` | Triggers when |\n|-------|------------|---------------|\n| Profile | `profile_published` | Resolver returns null (404). |\n| Profile | `profile_hash_matches_published_bytes` | Recomputed hash of resolver output ≠ URL hash. |\n| Profile | `terminal_profile_resolvable` | Resolver throws (network unreachable). |\n| Profile | `profile_issuer_trusted` | Published JWS `kid` ∉ `issuerTrustSet`. |\n| Profile | `profile_within_validity_window` | `beginAction.issuedAt` outside `[issued_at, expires_at/superseded_at)`. |\n| Binding | `binding_published` | Binding hash has no published record. |\n| Binding | `binding_canonicalizer_profile_hash_matches_pre_action` | Binding's profile hash ≠ pre-action's. |\n| Binding | `binding_policy_surface_hash_matches_pre_action` | Binding's surface hash ≠ pre-action's. |\n| Binding | `binding_issued_at_or_before_begin_action` | Binding issued AFTER beginAction. |\n| Binding | `binding_within_validity_window` | Binding expired, superseded, or non-active. |\n| Binding | `binding_issuer_trusted` | Binding JWS `kid` ∉ `issuerTrustSet`. |\n| Binding | `terminal_binding_hash_unchanged_when_profile_unchanged` | Terminal swapped only the binding hash while keeping the profile hash. |\n\nOffline / pinned mode: pass a custom resolver that reads from a local cache. Bypass the layer entirely by omitting both options — v0.7 preserves v0.6 behavior when the publication checks are not requested.\n\n---\n\n## Lightweight logging\n\nFor simple use cases, `auditLog()` emits a single post-action record with no configuration required:\n\n```typescript\nimport { auditLog } from '@agentlair/audit-logger';\n\n// Logs to console — no config needed\nawait auditLog({\n  agent: 'my-agent',\n  action: 'tool_call',\n  tool: 'web_search',\n  input: 'latest AI news',\n  output: results,\n});\n```\n\n`createAuditLogger` binds the agent name so you don't repeat it on every call:\n\n```typescript\nimport { createAuditLogger } from '@agentlair/audit-logger';\n\nconst log = createAuditLogger('inventory-agent');\n\nawait log({ action: 'check_stock', tool: 'db_query', input: { sku: 'ABC-123' } });\nawait log({ action: 'reorder', output: { orderId: 'PO-9999' } });\n```\n\n---\n\n## Connect to AgentLair\n\nSet `AGENTLAIR_API_KEY` to ship audit logs to AgentLair for persistent storage and querying.\n\n```bash\nexport AGENTLAIR_API_KEY=aal_...\n```\n\nThat's it. All `auditLog()` calls will now also POST to AgentLair asynchronously (non-blocking, fire-and-forget).\n\nGet a free API key at [agentlair.dev](https://agentlair.dev).\n\n---\n\n## API\n\n### `auditLog(entry, opts?)` — module-level convenience\n\n```typescript\nawait auditLog({\n  agent: string;        // Name/ID of the agent\n  action: string;       // Action category (e.g. \"tool_call\", \"llm_response\", \"decision\")\n  tool?: string;        // Tool name, if this is a tool call\n  input?: unknown;      // Input to the tool or LLM\n  output?: unknown;     // Output from the tool or LLM\n  timestamp?: string;   // ISO 8601 — defaults to now\n  metadata?: Record<string, unknown>;  // Any additional context\n});\n```\n\n### `AuditLogger` class\n\nFor AAR split (beginAction/endAction) and HMAC signing, instantiate directly:\n\n```typescript\nconst logger = new AuditLogger({\n  actorId: string;        // Agent identity (used as 'sub' in receipts)\n  hmacSecret?: string;    // Optional: HMAC-SHA256 key for receipt signing\n  apiKey?: string;        // Optional: AgentLair API key (or set AGENTLAIR_API_KEY)\n  silent?: boolean;       // Optional: suppress transport (testing)\n});\n```\n\n### `logger.beginAction(opts)` → `Promise<AARPreAction>`\n\nEmits a signed, chained pre-action receipt. Call **before** tool execution.\n\n| Field              | Type                                          | Required | Description                                                  |\n|--------------------|-----------------------------------------------|----------|--------------------------------------------------------------|\n| `toolName`         | `string`                                      | ✓        | Name of the tool being called                                |\n| `toolCallId`       | `string`                                      | ✓        | Framework-assigned call ID                                   |\n| `input`            | `unknown`                                     | ✓        | Input (SHA-256 digested, not stored raw)                     |\n| `approvalDecision` | `'approved' \\| 'denied' \\| 'conditional'`     | —        | From preflight_trust_check                                   |\n| `policyRef`        | `string`                                      | —        | Link to the trust check result ID                            |\n| `decidedBy`        | `string`                                      | —        | Identity who approved (for human-gated tools)                |\n| `sessionId`        | `string`                                      | —        | Session context                                              |\n| `expiresAt`        | `string \\| Date`                              | —        | ISO 8601 deadline (v0.4). Covered by `previousReceiptHash`. |\n| `canonicalInput`        | `unknown`                                | —        | v0.5: consequential subset of the call. Hashed into `approvedEnvelopeHash`. |\n| `canonicalizationVersion` | `string`                              | —        | v0.5: defaults to `'cv1'` when `canonicalInput` is set.     |\n| `canonicalizerProfile`  | `CanonicalizerProfile`                   | —        | v0.6: declared profile (preserved fields + normalization rules). Hashed into `canonicalizerProfileHash`. Requires `policySurface` + `bindingRegistry`. |\n| `policySurface`         | `PolicySurface`                          | —        | v0.6: declared policy surface (gated fields). Hashed into `policySurfaceHash`. |\n| `bindingRegistry`       | `PolicyProfileBindingRegistry`           | —        | v0.6: registry to look up the `(surfaceHash, profileHash)` binding. Unbound pair → `BeginActionRefusal('unbound_policy_profile')`. |\n\n**Throws `BeginActionRefusal`** (no AAR minted) when (v0.6) the policy-profile pair is not registered, the profile declares normalization for a field absent from the envelope, or `canonicalizerProfile` is supplied without `policySurface` + `bindingRegistry`.\n\n### `logger.endAction(opts)` → `Promise<AARTerminalReceipt>`\n\nSeals the attempt with a terminal receipt. Call exactly once per `beginAction`.\n\n| Field            | Type                                                                    | Required | Description                                                                          |\n|------------------|-------------------------------------------------------------------------|----------|--------------------------------------------------------------------------------------|\n| `preAction`      | `AARPreAction`                                                          | ✓        | The receipt returned by `beginAction`                                                |\n| `phase`          | `'executed' \\| 'failed' \\| 'denied' \\| 'expired' \\| 'cancelled'`       | —        | Defaults to `'executed'`. See Terminal phase enum above.                             |\n| `startedAt`      | `Date`                                                                  | —        | When execution began. Omit for `denied` / `expired` / `cancelled`.                   |\n| `endedAt`        | `Date`                                                                  | —        | When execution ended. Sign-time check: `executed` throws if `endedAt > expiresAt`.  |\n| `terminalAt`     | `Date`                                                                  | —        | Observation time of attempt close. Defaults to `now`.                               |\n| `terminalReason` | `string`                                                                | —        | Human-readable explanation (`'policy_deadline'`, `'user_cancel'`, ...).              |\n| `output`         | `unknown`                                                               | —        | Tool output (SHA-256 digested). Only for `executed`.                                 |\n| `error`          | `Error`                                                                 | —        | Error from failed execution. Only for `failed`.                                      |\n| `effectiveCanonicalInput` | `unknown`                                                      | v0.5\\*   | Required when `preAction.approvedEnvelopeHash` is set AND `phase === 'executed'`.   |\n| `canonicalizationVersion` | `string`                                                       | —        | Defaults to the pre-action's stored version; cross-version sealing throws.          |\n| `canonicalizerProfile`    | `CanonicalizerProfile`                                         | v0.6\\*   | Required when `preAction.canonicalizerProfileHash` is set AND `phase === 'executed'`. Mismatch throws `profile_incompatible`. |\n\n**Returns:** `AARTerminalReceipt` with `resultDigest` (executed), `errorClass` / `errorDigest` (failed), `previousReceiptHash` linking back to the pre-action, optional `effectiveEnvelopeHash` + `canonicalizationVersion` (v0.5, executed phase), optional `canonicalizerProfileHash` (v0.6, executed phase), and a signed `terminalAt` timestamp.\n\n### `configureLogger(options)` — configure module-level defaults\n\n```typescript\nimport { configureLogger } from '@agentlair/audit-logger';\n\nconfigureLogger({\n  apiKey: 'aal_...',    // or set AGENTLAIR_API_KEY\n  console: true,        // write to console (default: true)\n  silent: false,        // suppress all output (useful in tests)\n  sinks: [              // custom sinks\n    { write(entry) { myDb.insert(entry); } }\n  ],\n});\n```\n\n---\n\n## Framework adapters\n\n### LangChain.js\n\n```typescript\nimport { AgentAuditCallback } from '@agentlair/audit-logger/langchain';\nimport { LLMChain } from 'langchain/chains';\nimport { ChatOpenAI } from 'langchain/chat_models/openai';\n\nconst llm = new ChatOpenAI();\nconst chain = new LLMChain({\n  llm,\n  prompt,\n  callbacks: [new AgentAuditCallback('my-langchain-agent')],\n});\n\nawait chain.call({ question: 'What is 2+2?' });\n// Automatically logs: llm_start, llm_end, tool_start, tool_end, chain_start, chain_end\n```\n\n### Anthropic / Claude SDK\n\n```typescript\nimport Anthropic from '@anthropic-ai/sdk';\nimport { wrapAnthropicClient } from '@agentlair/audit-logger/anthropic';\n\nconst client = wrapAnthropicClient(new Anthropic(), 'researcher');\n\n// Use exactly like the normal client — all calls are logged\nconst msg = await client.messages.create({\n  model: 'claude-opus-4-5',\n  max_tokens: 1024,\n  messages: [{ role: 'user', content: 'Explain AgentLair in one sentence.' }],\n});\n```\n\n---\n\n## Custom sinks\n\nImplement the `AuditSink` interface to write to any backend:\n\n```typescript\nimport type { AuditSink, ResolvedAuditEntry } from '@agentlair/audit-logger';\n\nconst postgresSink: AuditSink = {\n  async write(entry: ResolvedAuditEntry) {\n    await db.insert('audit_log', entry);\n  },\n};\n\nconst logger = new AuditLogger({ sinks: [postgresSink], console: false });\n```\n\n---\n\n## Querying stored audit logs\n\nWhen `AGENTLAIR_API_KEY` is set, audit entries are stored as Observations under the `audit-log` topic in AgentLair:\n\n```typescript\nimport { AgentLair } from '@agentlair/sdk';\n\nconst lair = new AgentLair(process.env.AGENTLAIR_API_KEY!);\nconst { observations } = await lair.observations.read({\n  topic: 'audit-log',\n  limit: 50,\n});\n```\n\n---\n\n## Local-only vs hosted AgentLair\n\nThe library is fully usable without an API key — `auditLog`, `beginAction`, and `endAction` write to console and any custom sinks you wire up. That's the right setup for development, single-process agents, and anyone who already has their own log pipeline.\n\nYou'd want the hosted side once any of these become real:\n\n| Need                                                  | What the hosted side gives you                                                                                |\n|-------------------------------------------------------|---------------------------------------------------------------------------------------------------------------|\n| Retention beyond your own log lifetime                | Persistent storage. Starter: 1 year of audit log retention. Enterprise: up to 7 years.                        |\n| Querying across many runs / machines                  | Single endpoint to read filtered receipts (`topic: 'audit-log'`), not log-grep across boxes.                  |\n| EU AI Act Article 12 (automatic recording, queryable) | Tamper-evident Ed25519-signed hash chain stored independent of the agent's control boundary.                  |\n| Showing receipts to a third party                     | Public verification of chain + signature without exposing your infra.                                         |\n\nPricing — Free (1k verifications/month, 7-day history) · Starter $29/mo (50k verifications, 1-year audit log retention) · Pro $149/mo (500k verifications, 90-day history). Full table at [agentlair.dev/pricing](https://agentlair.dev/pricing).\n\nGet an API key at [agentlair.dev/register](https://agentlair.dev/register) — no credit card. Then:\n\n```bash\nexport AGENTLAIR_API_KEY=al_live_...\n```\n\nThe same `beginAction` / `endAction` calls now also ship to the hosted side. Nothing else changes.\n\n---\n\n## License\n\nMIT © [AgentLair](https://agentlair.dev)\n","readmeFilename":"README.md"}