{"_id":"@agentlair/mastra","_rev":"2-916243cbdef5668b625fadd30f9136f7","name":"@agentlair/mastra","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@agentlair/mastra","version":"0.1.0","keywords":["agentlair","mastra","ai-agent","trust","identity","eddsa","jwt","jwks","agent-security","behavioral-trust"],"author":{"name":"AgentLair"},"license":"MIT","_id":"@agentlair/mastra@0.1.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"dist":{"shasum":"dbcc04f6052056fb1efaf0fb92508bccd83f2f72","tarball":"https://registry.npmjs.org/@agentlair/mastra/-/mastra-0.1.0.tgz","fileCount":15,"integrity":"sha512-C0yTCjTKKEk0ROuL5/uuGw3TfFeVJllvaYojVCH7dmAxZuUihpC3/qdSPKMsjAxgAfpmxluWK8WdO/zZ9DfbTQ==","signatures":[{"sig":"MEUCIQDIBGSszfLXA1cnWyzc0cKOTUNTk0/qzO0jgJ+eU7FuNgIgepgth7L3/9s2GM9MzlmA++v3S8+C5kW46CYM/WgLoSY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":221333},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./auth":{"types":"./dist/auth.d.ts","import":"./dist/auth.js"},"./tools":{"types":"./dist/tools.d.ts","import":"./dist/tools.js"},"./middleware":{"types":"./dist/middleware.d.ts","import":"./dist/middleware.js"}},"gitHead":"99af52d543942b7d9767b4fa34a98f828391623f","scripts":{"test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair integration for Mastra — agent identity verification, behavioral trust scoring, and trust-gated tool execution.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"zod":"^3.24.0","tsup":"^8.0.0","vitest":"^3.0.0","typescript":"^5.9.3","@types/node":"^22.0.0","@mastra/core":"^0.10.0"},"peerDependencies":{"zod":">=3.22.0","@mastra/core":">=0.10.0"},"peerDependenciesMeta":{"zod":{"optional":false},"@mastra/core":{"optional":false}},"_npmOperationalInternal":{"tmp":"tmp/mastra_0.1.0_1775978209128_0.4086078274127469","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentlair/mastra","version":"0.1.1","description":"AgentLair telemetry and trust integration for Mastra. Captures agent calls, tool use, and token usage — builds your agent's behavioral trust profile.","type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","test":"bun test","check":"tsc --noEmit","prepublishOnly":"bun run build"},"keywords":["agentlair","mastra","ai-agent","telemetry","behavioral-trust","agent-identity","observability","typescript"],"author":{"name":"AgentLair"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair-mastra.git"},"homepage":"https://agentlair.dev","engines":{"node":">=18.0.0"},"peerDependencies":{"@mastra/core":">=0.1.0"},"peerDependenciesMeta":{"@mastra/core":{"optional":true}},"devDependencies":{"typescript":"^5.9.3"},"_id":"@agentlair/mastra@0.1.1","bugs":{"url":"https://github.com/piiiico/agentlair-mastra/issues"},"_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-Nm1e6yv3szfBEHLcaX3Si0eeLvlbdYn2vo23ZocVwvLcXPecYGzV92EihAMwmEva67gCXgBhFG6QC69ZObvfEQ==","shasum":"70217bfcf8ed57fdc15febadb5f14122dc5c3dd5","tarball":"https://registry.npmjs.org/@agentlair/mastra/-/mastra-0.1.1.tgz","fileCount":14,"unpackedSize":44212,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCiOWQgdJCb9zh8dhm5SSoOudJ9Dm8wI1lk6f+c64sv3QIgM+ZEGXvZXXB2VEExpP2d3R8zC51z4u0mp8PHK0TbLgw="}]},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"directories":{},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mastra_0.1.1_1777770083571_0.8425979810718338"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-12T07:16:48.980Z","modified":"2026-05-03T01:01:23.863Z","0.1.0":"2026-04-12T07:16:49.281Z","0.1.1":"2026-05-03T01:01:23.720Z"},"bugs":{"url":"https://github.com/piiiico/agentlair-mastra/issues"},"author":{"name":"AgentLair"},"license":"Apache-2.0","homepage":"https://agentlair.dev","keywords":["agentlair","mastra","ai-agent","telemetry","behavioral-trust","agent-identity","observability","typescript"],"repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair-mastra.git"},"description":"AgentLair telemetry and trust integration for Mastra. Captures agent calls, tool use, and token usage — builds your agent's behavioral trust profile.","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"readme":"# @agentlair/mastra\n\nAgentLair integration for [Mastra](https://mastra.ai) — telemetry hooks, AAT verification, and Proof of Principal Authorization (PoPA) enrollment for AI agents.\n\nZero required runtime dependencies. No `@mastra/core` version pinning.\n\n## Install\n\n```bash\nnpm install @agentlair/mastra\n# or\nbun add @agentlair/mastra\n```\n\n## Quick start\n\n```typescript\nimport { createAgentLairPlugin } from '@agentlair/mastra';\nimport { Agent } from '@mastra/core/agent';\n\nconst agentlair = createAgentLairPlugin({\n  apiKey: process.env.AGENTLAIR_API_KEY!,  // al_live_...\n  agentId: 'my-mastra-agent',\n});\n\nconst agent = new Agent({ ... });\n\n// Wrap generate calls\nagentlair.onGenerateStart({ model: 'gpt-4o', toolCount: 3 });\nconst result = await agent.generate('Summarise last week's invoices');\nagentlair.onGenerateFinish({\n  text: result.text,\n  finishReason: 'stop',\n  usage: result.usage,\n});\n\nawait agentlair.shutdown(); // flush before process exit\n```\n\nGet your API key at [agentlair.dev](https://agentlair.dev).\n\n## What gets captured\n\n| Hook | AgentLair event | Category | Data |\n|---|---|---|---|\n| `onGenerateStart` | `generate_start` | session | model, tool count, message count |\n| `onGenerateFinish` | `generate_finish` | session | token usage, finish reason, error |\n| `onToolCallStart` | `{toolName}` | tool | tool name, call ID |\n| `onToolCallFinish` | `{toolName}_complete` | tool | duration, success/failure, error |\n\nEvents are batched and flushed every 5 seconds. Buffer auto-flushes at 50 events.\n\n## AAT verification\n\nVerify that incoming requests carry a valid AgentLair Agent Authentication Token:\n\n```typescript\nconst request = new Request('https://my-service.com/api/run', {\n  headers: { Authorization: 'Bearer <agent_aat>' },\n});\n\nconst token = request.headers.get('Authorization')?.replace('Bearer ', '') ?? '';\nconst agent = await agentlair.verifyAat(token, {\n  audience: 'https://my-service.com',\n});\n\nif (!agent) {\n  return new Response('Unauthorized', { status: 401 });\n}\n\nconsole.log(`Verified agent: ${agent.name} (${agent.agentId})`);\nconsole.log(`Scopes: ${agent.scopes.join(', ')}`);\n```\n\n`verifyAat` uses EdDSA/Ed25519 via the Web Crypto API — no external JWT library needed.\n\n## PoPA enrollment\n\nRecord that a human principal has explicitly delegated authority to an agent:\n\n```typescript\nconst enrollment = await agentlair.enrollPoPA({\n  principalId: 'user_hakon',\n  scopes: ['write:invoices', 'read:accounts'],\n  description: 'Authorized to process invoices on behalf of Håkon',\n  expiresAt: '2026-06-01T00:00:00Z',\n});\n\nconsole.log(`PoPA enrollment: ${enrollment.enrollmentId}`);\n```\n\n## Tool call tracking\n\nInstrument individual tool calls to capture timing and failure rates:\n\n```typescript\nconst tools = {\n  web_search: async (args) => {\n    const callId = crypto.randomUUID();\n    agentlair.onToolCallStart({ toolCallId: callId, toolName: 'web_search', args });\n\n    try {\n      const result = await doSearch(args.query);\n      agentlair.onToolCallFinish({ toolCallId: callId, toolName: 'web_search', result });\n      return result;\n    } catch (err) {\n      agentlair.onToolCallFinish({ toolCallId: callId, toolName: 'web_search', error: err });\n      throw err;\n    }\n  },\n};\n```\n\n## Configuration\n\n```typescript\nconst agentlair = createAgentLairPlugin({\n  // Required\n  apiKey: 'al_live_...',       // Your AgentLair API key\n  agentId: 'my-agent',         // Agent identifier for event attribution\n\n  // Optional\n  baseUrl: 'https://agentlair.dev',  // API base URL\n  flushInterval: 5000,               // Batch flush interval (ms)\n  maxBufferSize: 50,                 // Force-flush threshold (events)\n  sessionId: 'custom-session-id',    // Group events by session\n  timeout: 3000,                     // Request timeout (ms)\n  captureInputs: false,              // Log input metadata (message count)\n  captureOutputs: false,             // Log output metadata (response length)\n  onError: (err) => console.error(err),  // Error handler (swallowed by default)\n});\n```\n\n## Standalone vs. upstream PR\n\nThis package ships the integration independently of [Mastra PR #16032](https://github.com/mastra-ai/mastra/pull/16032) (`@mastra/auth-agentlair`). You can adopt AgentLair telemetry today without waiting for the PR to merge.\n\nWhen `@mastra/auth-agentlair` lands in the official Mastra release, it will provide deeper framework integration (Mastra Studio UI, native auth provider). This package remains the zero-dependency starting point.\n\n## Behavioral trust\n\nEvents submitted through this adapter feed AgentLair's trust engine. Your agent's trust profile reflects:\n\n- **Consistency** of tool usage patterns over time\n- **Transparency** of decision trails\n- **Reliability** under observed conditions\n\nTrust scores are available via the AgentLair API and can gate access to other agents and services.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}