{"_id":"@agentlair/mcp-trust-attestation","name":"@agentlair/mcp-trust-attestation","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@agentlair/mcp-trust-attestation","version":"0.1.0","description":"Drop-in Hono middleware that mounts AgentLair's BHC-S behavioral trust descriptor and per-subject attestation endpoint on any HTTP-transport MCP server in 3 lines. Implements the SEP-2133 unofficial extension dev.agentlair/trust-attestation (BHC-S spec ur","type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","test":"bun test","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"keywords":["agentlair","mcp","model-context-protocol","trust","attestation","bhc-s","sep-2133","hono","middleware","ai-agent"],"author":{"name":"AgentLair","email":"hello@agentlair.dev"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair.git","directory":"packages/mcp-trust-attestation"},"homepage":"https://agentlair.dev/docs/bhc-s","engines":{"node":">=20.0.0"},"dependencies":{"jose":"^5.0.0"},"peerDependencies":{"hono":"^4"},"devDependencies":{"hono":"^4.12.8","typescript":"^5.9.3"},"_id":"@agentlair/mcp-trust-attestation@0.1.0","gitHead":"44f7de50adcf448e8474478dd476d0ea8cdc0fb7","bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-HQHzLLom/eQUKlER38BH24w+/aZ88Tptq4Fxa/xkahRKWyDygSEmyvVsLvwjWmJ60f0dE6t1XgNV+svqwnr6hA==","shasum":"cee6828858e75cbfa766e8051807c0e9dafae0e8","tarball":"https://registry.npmjs.org/@agentlair/mcp-trust-attestation/-/mcp-trust-attestation-0.1.0.tgz","fileCount":14,"unpackedSize":42866,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICht0GIbI6rmc+cgrJiodJcGbs98xd7P9GpKD9Amd951AiALNP/XnB/43fJwKkq2AauxHWno6XM4XHItjpfAsEGlFg=="}]},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"directories":{},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-trust-attestation_0.1.0_1779081560618_0.44849529607362215"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-18T05:19:20.517Z","0.1.0":"2026-05-18T05:19:20.752Z","modified":"2026-05-18T05:19:20.984Z"},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"description":"Drop-in Hono middleware that mounts AgentLair's BHC-S behavioral trust descriptor and per-subject attestation endpoint on any HTTP-transport MCP server in 3 lines. Implements the SEP-2133 unofficial extension dev.agentlair/trust-attestation (BHC-S spec ur","homepage":"https://agentlair.dev/docs/bhc-s","keywords":["agentlair","mcp","model-context-protocol","trust","attestation","bhc-s","sep-2133","hono","middleware","ai-agent"],"repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair.git","directory":"packages/mcp-trust-attestation"},"author":{"name":"AgentLair","email":"hello@agentlair.dev"},"bugs":{"url":"https://github.com/piiiico/agentlair/issues"},"license":"Apache-2.0","readme":"# @agentlair/mcp-trust-attestation\n\nBehavioral trust attestation middleware for MCP servers. Implements the\nSEP-2133 unofficial extension `dev.agentlair/trust-attestation` for the\nBHC-S spec `urn:agentlair:bhc-s:v1`.\n\nMount it on any HTTP-transport MCP server in three lines. No AgentLair\nAPI key required at policy time. Verifiers fetch the descriptor and\nattestation tokens directly from your server.\n\n## Install\n\n```sh\nnpm install @agentlair/mcp-trust-attestation hono\n```\n\nRequires Node >= 20. `hono` is a peer dependency (works with any 4.x).\n\n## Quickstart\n\n```ts\nimport { Hono } from 'hono';\nimport { createAttestationMiddleware } from '@agentlair/mcp-trust-attestation';\n\nconst app = new Hono();\napp.use('/.well-known/agentlair-trust', createAttestationMiddleware({ serverId: 'url_sha256:abc...' }));\napp.use('/agentlair/trust-attestation/:subject', createAttestationMiddleware({ serverId: 'url_sha256:abc...' }));\n```\n\nThat's it. Your MCP server now exposes:\n\n- `GET /.well-known/agentlair-trust` — the BHC-S issuer descriptor.\n- `GET /agentlair/trust-attestation/:subject`: per-subject attestation\n  JWT, proxied from AgentLair and cached locally.\n\n## MCP server-card extension\n\nTo surface the attestation in your `initialize` response per SEP-2133:\n\n```ts\nimport { buildServerCardExtension } from '@agentlair/mcp-trust-attestation';\n\nconst initializeResponse = {\n  protocolVersion: '2025-03-26',\n  capabilities: { tools: {} },\n  serverInfo: { name: 'my-server', version: '1.0.0' },\n  extensions: { ...buildServerCardExtension({ serverId: 'url_sha256:abc...' }) },\n};\n```\n\n## Verify an attestation (client side)\n\n```ts\nimport { verifyAttestation } from '@agentlair/mcp-trust-attestation';\n\nconst result = await verifyAttestation(jwt, { issuer: 'https://agentlair.dev' });\nif (result.ok) {\n  // result.payload — verified BHC-S claims\n}\n```\n\n## node:http (no Hono)\n\n```ts\nimport http from 'node:http';\nimport { createNodeHttpHandler } from '@agentlair/mcp-trust-attestation';\n\nconst handler = createNodeHttpHandler({ serverId: 'url_sha256:abc...' });\nhttp.createServer(handler).listen(3000);\n```\n\n## Reference\n\n- BHC-S spec: <https://agentlair.dev/docs/bhc-s>\n- SEP-2133 (Extensions): the unofficial extension framework this package implements\n- Reference server: [`@agentlair/mcp-demo-attested`](../mcp-demo-attested)\n\nLicensed under Apache-2.0.\n","readmeFilename":"README.md","_rev":"1-cf729192f1b311ccda235dd804f729a6"}