{"_id":"@agentlair/openai-agents","_rev":"6-5e29fbc54069a69650188c77b10d0e64","name":"@agentlair/openai-agents","dist-tags":{"latest":"0.2.0"},"versions":{"0.0.1":{"name":"@agentlair/openai-agents","version":"0.0.1","keywords":["agentlair","agent-trust","openai-agents","openai","behavioral-attestation","telemetry","aat"],"author":{"url":"piiiico","name":"AgentLair"},"license":"Apache-2.0","_id":"@agentlair/openai-agents@0.0.1","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"dist":{"shasum":"3e27c4b8bab566fe246b09bf834a6a329a70d3a0","tarball":"https://registry.npmjs.org/@agentlair/openai-agents/-/openai-agents-0.0.1.tgz","fileCount":6,"integrity":"sha512-hL2+HRFL8SyDI60TXLX2SYs0idwrmtnx8lTcXkSeJ/RaGPi2/np08rDNBKhPphTkWKQcmeW1Z7NJ9c30gMrp0w==","signatures":[{"sig":"MEYCIQD3XqfoaCSFcdDxMW2uNbk4RbEbueQDmefL+JplxRuv6wIhAPcWj3ArwqUxCIrpnhVibZDgYJqQHC8Np5reHMbHa69Q","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4241},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ae4d1be89419592d10eed7279aee801655dd16fa","scripts":{"build":"tsc","check":"tsc --noEmit","prepublishOnly":"tsc"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair-primitives.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair behavioral telemetry adapter for OpenAI Agents SDK — reserved namespace stub. See https://agentlair.dev","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/openai-agents_0.0.1_1777979041999_0.5841425797785118","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@agentlair/openai-agents","version":"0.1.0","keywords":["agentlair","agent-trust","openai-agents","openai","agent-identity","aat","audit","did-web","behavioral-attestation","agent-authentication-token"],"author":{"url":"piiiico","name":"AgentLair"},"license":"Apache-2.0","_id":"@agentlair/openai-agents@0.1.0","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"dist":{"shasum":"9ba54a5bdc1587933377555d7081f3e981df0a92","tarball":"https://registry.npmjs.org/@agentlair/openai-agents/-/openai-agents-0.1.0.tgz","fileCount":6,"integrity":"sha512-brytVhWdlNXpORHEaaNK6B8N8N4wQEErOY5MMrzVivFZbVV4wdHuWaYAugGUk5DjJk/N6hOICWMwIXBizX8WEg==","signatures":[{"sig":"MEQCIFnaEuykxHXT4Tn+R1V5r2S50sEsbhl3Br5D9Npo6JcDAiAOz6EjJuB2+T8KJq8/MvA0rFmhu8yed3+sV++KUc5sYw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31140},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ae4d1be89419592d10eed7279aee801655dd16fa","scripts":{"test":"bun test","build":"tsc","check":"tsc --noEmit","prepublishOnly":"tsc"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair-primitives.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair adapter for the OpenAI Agents SDK — issue per-agent AATs, attach Bearer tokens to tool calls, emit audit envelopes per invocation.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"peerDependencies":{"@openai/agents":">=0.7.0"},"peerDependenciesMeta":{"@openai/agents":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openai-agents_0.1.0_1778078338440_0.44480885868242304","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentlair/openai-agents","version":"0.1.1","keywords":["agentlair","agent-trust","openai-agents","openai","agent-identity","aat","audit","did-web","behavioral-attestation","agent-authentication-token"],"author":{"url":"piiiico","name":"AgentLair"},"license":"Apache-2.0","_id":"@agentlair/openai-agents@0.1.1","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"dist":{"shasum":"935b81057d25454a0ab66e48aefdba3ddde266b5","tarball":"https://registry.npmjs.org/@agentlair/openai-agents/-/openai-agents-0.1.1.tgz","fileCount":6,"integrity":"sha512-auRk7x7ENBGNaZ736KHUeXJ3tEqn1nMxT+8PKpnyZFgAdH2+Lb6joGFNSejg6enp/H7vnxEsyz3qbmBNNvRhVg==","signatures":[{"sig":"MEUCIQD59HCf88zFFAJz6TgPyXvu/EARZpAU7nKqjzxf6zie4AIgWfBHrtqAPV+wgiFgyvmjZ501BmlKhCqOyRJIBeqoaP8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34629},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ae4d1be89419592d10eed7279aee801655dd16fa","scripts":{"test":"bun test","build":"tsc","check":"tsc --noEmit","prepublishOnly":"tsc"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair-primitives.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair adapter for the OpenAI Agents SDK — issue per-agent AATs, attach Bearer tokens to tool calls, emit audit envelopes per invocation.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"peerDependencies":{"@openai/agents":">=0.7.0"},"peerDependenciesMeta":{"@openai/agents":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openai-agents_0.1.1_1778078493174_0.5635879935538457","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agentlair/openai-agents","version":"0.1.2","keywords":["agentlair","agent-trust","openai-agents","openai","agent-identity","aat","audit","did-web","behavioral-attestation","agent-authentication-token"],"author":{"url":"piiiico","name":"AgentLair"},"license":"Apache-2.0","_id":"@agentlair/openai-agents@0.1.2","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"dist":{"shasum":"defc11b346dcb1cff8126089ebbd81e5686f217f","tarball":"https://registry.npmjs.org/@agentlair/openai-agents/-/openai-agents-0.1.2.tgz","fileCount":6,"integrity":"sha512-XM/C42TRVzAq/D1n0ZduSwxA3eWpE77Rb3kOgFSf2TwjKhnRpn7dACuRYvmTWV8k1BXThL+A790oCe2o/KLBAA==","signatures":[{"sig":"MEQCIH+sf+EmZUsMSlb3zznkNaabi6J3nGSa3remE2SBmww3AiBx+KSu550Cn2kk3sDlNmX76FXnGITNIAc3JyOs4d4nkQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36153},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ae4d1be89419592d10eed7279aee801655dd16fa","scripts":{"test":"bun test","build":"tsc","check":"tsc --noEmit","prepublishOnly":"tsc"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair-primitives.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair adapter for the OpenAI Agents SDK — issue per-agent AATs, attach Bearer tokens to tool calls, emit audit envelopes per invocation.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"peerDependencies":{"@openai/agents":">=0.7.0"},"peerDependenciesMeta":{"@openai/agents":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openai-agents_0.1.2_1778092379817_0.8925273826237692","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agentlair/openai-agents","version":"0.1.3","keywords":["agentlair","agent-trust","openai-agents","openai","agent-identity","aat","audit","did-web","behavioral-attestation","agent-authentication-token"],"author":{"url":"piiiico","name":"AgentLair"},"license":"Apache-2.0","_id":"@agentlair/openai-agents@0.1.3","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"dist":{"shasum":"d94230a3151e7fc72cdc91166387b5137c923fc0","tarball":"https://registry.npmjs.org/@agentlair/openai-agents/-/openai-agents-0.1.3.tgz","fileCount":6,"integrity":"sha512-0pG0vTlFX9mVw5btyl+NdIJJzJnarobtV5dK3DRG/SMzkmzWrvpZxebuWIsyEbfscaUBS0g87mdbVAPs6jZgtw==","signatures":[{"sig":"MEYCIQC64L+JeNbTscMsiokx3gnibGyTdXnQr5Wcq2iLJ6C98gIhAPSH0JOj6YIi33nWF+DbEjQRfDaiYBkCMZjxzQ88VVL7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49077},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"55f0a0d06d8a28e237df48d70488d90dc7798642","scripts":{"test":"bun test","build":"tsc","check":"tsc --noEmit","prepublishOnly":"tsc"},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"repository":{"url":"git+https://github.com/piiiico/agentlair-primitives.git","type":"git"},"_npmVersion":"10.9.7","description":"AgentLair adapter for the OpenAI Agents SDK — issue per-agent AATs, attach Bearer tokens to tool calls, emit audit envelopes per invocation.","directories":{},"_nodeVersion":"22.22.2","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"peerDependencies":{"@openai/agents":">=0.7.0"},"peerDependenciesMeta":{"@openai/agents":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/openai-agents_0.1.3_1778201841809_0.24970824406946135","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentlair/openai-agents","version":"0.2.0","description":"AgentLair adapter for the OpenAI Agents SDK — issue per-agent AATs, attach Bearer tokens to tool calls, emit audit envelopes, and sign outbound HTTP requests with RFC 9421 / Web Bot Auth.","type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","check":"tsc --noEmit","test":"bun test","prepublishOnly":"tsc"},"keywords":["agentlair","agent-trust","openai-agents","openai","agent-identity","aat","audit","did-web","behavioral-attestation","agent-authentication-token","rfc9421","http-message-signatures","web-bot-auth"],"author":{"name":"AgentLair","url":"piiiico"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair-primitives.git"},"homepage":"https://agentlair.dev","bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"engines":{"node":">=18.0.0"},"peerDependencies":{"@openai/agents":">=0.7.0"},"peerDependenciesMeta":{"@openai/agents":{"optional":true}},"devDependencies":{"typescript":"^5.9.3"},"_id":"@agentlair/openai-agents@0.2.0","gitHead":"c6ce5d707cf4dbc1cc15529fba2b0ffbc6b7f768","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-1hVrDlS3dKH6tOW5F9o+lJtd5n4vZAb89BJ0RB+dCFzEzS3PSM3eFw4cbtN3tTPGNjH7dY4i7WSrv/aVRXzLDQ==","shasum":"0b2c7b3fad4ba216904f2fd520669898de309820","tarball":"https://registry.npmjs.org/@agentlair/openai-agents/-/openai-agents-0.2.0.tgz","fileCount":6,"unpackedSize":65211,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC3jLZTICLvrBMWtNGxelGRGbphVKp7bRR3ZboMgCdaKgIhAOAH++8NKUqXeFKhDlnoI4C8rzBa8jbMx8odxPhJAezm"}]},"_npmUser":{"name":"piiiico","email":"pico@amdal.dev"},"directories":{},"maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openai-agents_0.2.0_1778229927677_0.044887134546933716"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-05T11:04:01.900Z","modified":"2026-05-08T08:45:27.958Z","0.0.1":"2026-05-05T11:04:02.141Z","0.1.0":"2026-05-06T14:38:58.584Z","0.1.1":"2026-05-06T14:41:33.324Z","0.1.2":"2026-05-06T18:33:00.026Z","0.1.3":"2026-05-08T00:57:21.974Z","0.2.0":"2026-05-08T08:45:27.853Z"},"bugs":{"url":"https://github.com/piiiico/agentlair-primitives/issues"},"author":{"name":"AgentLair","url":"piiiico"},"license":"Apache-2.0","homepage":"https://agentlair.dev","keywords":["agentlair","agent-trust","openai-agents","openai","agent-identity","aat","audit","did-web","behavioral-attestation","agent-authentication-token","rfc9421","http-message-signatures","web-bot-auth"],"repository":{"type":"git","url":"git+https://github.com/piiiico/agentlair-primitives.git"},"description":"AgentLair adapter for the OpenAI Agents SDK — issue per-agent AATs, attach Bearer tokens to tool calls, emit audit envelopes, and sign outbound HTTP requests with RFC 9421 / Web Bot Auth.","maintainers":[{"name":"piiiico","email":"pico@amdal.dev"}],"readme":"# @agentlair/openai-agents\n\nAgentLair adapter for the [OpenAI Agents SDK](https://github.com/openai/openai-agents-js). Issue an Agent Authentication Token (AAT) per agent run, attach it to outbound tool calls, and emit a signed audit envelope per invocation — without changing how you write agents.\n\n## Install\n\n```bash\nnpm install @agentlair/openai-agents @openai/agents\n# or\nbun add @agentlair/openai-agents @openai/agents\n```\n\n`@openai/agents` is a (optional) peer dependency. Zero runtime dependencies otherwise. Works in Node 18+, Bun, and edge runtimes (Cloudflare Workers, Deno Deploy).\n\nGet a free AgentLair API key at [agentlair.dev](https://agentlair.dev) — no card required.\n\n## Usage\n\n```ts\nimport { Agent, run, tool } from '@openai/agents';\nimport { withAgentLair } from '@agentlair/openai-agents';\nimport { z } from 'zod';\n\nconst echo = tool({\n  name: 'echo',\n  description: 'Echo a string back to the caller',\n  parameters: z.object({ msg: z.string() }),\n  execute: async ({ msg }) => `you said: ${msg}`,\n});\n\nconst myAgent = new Agent({\n  name: 'demo',\n  instructions: 'Echo what the user says.',\n  tools: [echo],\n});\n\n// Wrap once at startup. The original agent is unchanged.\nconst governed = withAgentLair(myAgent, {\n  apiKey: process.env.AGENTLAIR_API_KEY!,\n  audience: 'https://my-mcp.example.com',\n  scopes: ['mcp:tools:read'],\n  agentName: 'demo',\n});\n\nconst result = await run(governed, 'echo \"hello\"');\n// On every tool call, AgentLair issued (or reused) an AAT and recorded\n// an audit envelope. Inspect at https://agentlair.dev/v1/audit/<jti>.\n```\n\nThat's it. No changes to your tools or `Agent` shape — `withAgentLair` returns a shallow clone with each tool's `execute` wrapped to issue an AAT and emit an audit envelope.\n\n## What it does\n\n1. **Issues an AAT** before each tool invocation (cached and reused until expiry by default — one issue per run, not one per tool call).\n2. **Records an audit envelope** for every tool call — args, result, duration, jti, agent name, audience. Best-effort; failures never block the tool.\n3. **Returns a verifiable did:web** — each AAT embeds `did:web:agentlair.dev:agents:<account_id>`, resolvable against AgentLair's JWKS.\n4. **Signs outbound HTTP requests with RFC 9421 / Web Bot Auth** (v0.2.0+) — `signRequest()` produces `Signature` / `Signature-Input` / `Signature-Agent` headers that Google Cloud Fraud Defense and any Web Bot Auth–aware origin can verify.\n\n## Web Bot Auth (RFC 9421 HTTP Message Signatures)\n\nSign outbound requests inside a tool so the receiving origin can prove the request came from your AgentLair-anchored agent — no shared secrets, no Bearer rotation:\n\n```ts\nimport { signRequest } from '@agentlair/openai-agents';\n\n// 32-byte Ed25519 keypair — generate once, register the public half at\n// POST https://agentlair.dev/v1/agents/signing-keys, then keep the private\n// half (and its 32-byte raw seed) wherever your agent stores secrets.\nconst req = new Request('https://api.example.com/resource');\nconst signed = await signRequest(req, { privateKey, publicKey });\nconst res = await fetch(signed);\n```\n\n`signRequest` adds three headers:\n\n- `Signature-Input` — covered components, `created`, `expires`, `keyid` (the RFC 8037 JWK thumbprint), and `tag=\"web-bot-auth\"`.\n- `Signature` — Ed25519 over the canonical signature base.\n- `Signature-Agent` — `https://agentlair.dev/agents/<thumbprint>` — verifiers fetch the JWK there.\n\nThe same Ed25519 keypair you register at `/v1/agents/signing-keys` is the one used here. AgentLair's directory endpoint at `GET /agents/<thumbprint>` resolves the public JWK with no auth required, so any verifier (Google Fraud Defense, a custom origin) can complete the loop.\n\nSee [`docs/web-bot-auth`](https://agentlair.dev/docs/web-bot-auth) for the full architecture.\n\n## Explicit Agent Self-Attestation\n\nAgents can post L3 self-attestations directly — no tool wrapping required. Use this when your agent wants to declare intent, record a decision, or attest to a constraint before acting:\n\n```ts\nimport { logAuditEvent } from '@agentlair/openai-agents';\n\n// Agent declares it will not exceed budget before starting work\nconst entry = await logAuditEvent(\n  {\n    category: 'budget',\n    action: 'budget.no_exceed',\n    details: { limit_usd: 10, projected_usd: 2.5, model: 'gpt-4o-mini' },\n  },\n  { apiKey: process.env.AGENTLAIR_API_KEY! },\n);\nconsole.log(entry.id);         // e.g. \"WSZqkmVNIzXrxwqnIwbF\"\nconsole.log(entry.signature);  // Ed25519 sig — independently verifiable\nconsole.log(entry.prev_hash);  // SHA-256 of previous chain entry\n```\n\nThe entry is hash-chained and Ed25519-signed server-side. Verify the chain at `GET /v1/audit/log`.\n\nValid categories: `task`, `tool_call`, `observation`, `reasoning`, `output`, `budget`, `memory`, `session`, and more — see `ALLOWED_AUDIT_CATEGORIES`.\nAction format: lowercase dot-separated, e.g. `\"task.complete\"`, `\"budget.no_exceed\"`. Validates against `AUDIT_ACTION_REGEX` client-side before the network call.\nThrows `AuditLogError` with typed `code` on validation failures or non-2xx responses.\n\n## Lower-level API\n\nIf you want fine-grained control:\n\n```ts\nimport { issueAATForAgent, recordAuditEvent, wrapTool } from '@agentlair/openai-agents';\n\n// Issue a token by hand\nconst aat = await issueAATForAgent({\n  apiKey: process.env.AGENTLAIR_API_KEY!,\n  audience: 'https://my-mcp.example.com',\n  scopes: ['mcp:tools:read', 'mcp:tools:execute'],\n  ttl: 3600,\n});\nconsole.log(aat.jti);      // aat_xxxxxxxxxxxxxxxx\nconsole.log(aat.did);      // did:web:agentlair.dev:agents:acc_...\nconsole.log(aat.token);    // eyJhbGciOiJFZERTQSIsImtpZCI6...\n\n// Wrap a single tool with a custom audit sink\nconst wrapped = wrapTool(myTool, {\n  apiKey: process.env.AGENTLAIR_API_KEY!,\n  audience: 'https://my-mcp.example.com',\n  preIssuedAAT: aat,\n  onAuditEvent: (e) => myObservabilityPipeline.send(e),\n});\n```\n\n## Options\n\n| Option | Type | Default | Notes |\n| --- | --- | --- | --- |\n| `apiKey` | string | — | **Required.** `al_live_*` or `al_pod_*` from agentlair.dev. |\n| `audience` | string | — | **Required.** Target service URL the AAT will be presented to. |\n| `scopes` | string[] | `['mcp:tools:read']` | Each must match `^[a-z][a-z0-9._:-]*$`. |\n| `ttl` | number | 3600 | Lifetime in seconds. Max 86400. |\n| `agentName` | string | — | `al_name` claim in the AAT. |\n| `agentEmail` | string | — | `al_email` claim in the AAT. |\n| `agentLairBaseUrl` | string | `https://agentlair.dev` | Override for staging/self-host. |\n| `cacheAAT` | boolean | true | Reuse the AAT across tool calls until expiry. |\n| `preIssuedAAT` | AAT | — | Skip the issue call entirely. Useful in tests. |\n| `onAuditEvent` | function | best-effort POST | Custom audit sink. Failures never block the tool. |\n| `fetchImpl` | typeof fetch | global `fetch` | For testing or edge runtimes. |\n\n## Verification\n\nAudit envelopes are signed with AgentLair's Ed25519 audit key. To verify a token or audit entry independently:\n\n```bash\n# Token — verify against JWKS\ncurl https://agentlair.dev/.well-known/jwks.json\n\n# Per-token metadata\ncurl https://agentlair.dev/v1/audit/<jti>\n```\n\n## Errors\n\n`issueAATForAgent` throws `AgentLairError` with a typed `code`:\n\n| Code | Meaning |\n| --- | --- |\n| `invalid_options` | apiKey or audience missing/malformed |\n| `network_error` | fetch threw (DNS, timeout, etc.) |\n| `http_error` | non-2xx response from `/v1/tokens/issue` (check `.status`) |\n| `invalid_response` | unparseable JSON or unexpected shape |\n\nTool wrapping (`wrapTool`, `withAgentLair`) never throws on AgentLair-side failures — the original tool error (if any) is rethrown unchanged.\n\n`logAuditEvent` throws `AuditLogError` with a typed `code`:\n\n| Code | Meaning |\n| --- | --- |\n| `invalid_category` | category not in `ALLOWED_AUDIT_CATEGORIES` |\n| `invalid_action` | action violates `AUDIT_ACTION_REGEX` or length limit (1–128 chars) |\n| `details_too_large` | details JSON-serialised size exceeds 4 KB |\n| `network_error` | fetch threw (DNS, timeout, etc.) |\n| `http_error` | non-2xx response from `/v1/audit/log` (check `.status`) |\n| `invalid_response` | unparseable JSON or unexpected response shape |\n\n## Reference\n\n- AgentLair: <https://agentlair.dev>\n- OpenAI Agents SDK (TypeScript): <https://github.com/openai/openai-agents-js>\n- Source: <https://github.com/piiiico/agentlair-primitives>\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}