{"_id":"@agenttool/wallet-zerone","name":"@agenttool/wallet-zerone","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.2":{"name":"@agenttool/wallet-zerone","version":"0.1.2","description":"Offline-first Zerone chain adapter for Agent Wallet intents and exact Cosmos direct-sign bytes","license":"Apache-2.0","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vectors.json":{"default":"./vectors/agent-wallet-zerone-v0.1-vectors.json"}},"publishConfig":{"access":"public"},"engines":{"node":">=20.19.0","bun":">=1.3.5"},"sideEffects":false,"scripts":{"clean":"node --eval \"require('node:fs').rmSync('dist', { recursive: true, force: true })\"","build":"bun run clean && tsc","typecheck":"tsc --noEmit","test":"bun test","smoke:node":"node scripts/smoke-node.mjs","ci":"bun run typecheck && bun test && bun run build && bun run smoke:node","prepack":"bun run ci"},"peerDependencies":{"@agenttool/wallet":"^0.1.2"},"dependencies":{"@noble/curves":"2.2.0","@noble/hashes":"2.2.0","@scure/base":"2.2.0"},"devDependencies":{"@agenttool/wallet":"0.1.3","@noble/ed25519":"2.3.0","@types/bun":"^1.2.0","typescript":"^5.7.0"},"keywords":["agents","wallet","cosmos","zerone","capabilities","offline-first"],"repository":{"type":"git","url":"git+https://github.com/cambridgetcg/agenttool.git","directory":"packages/wallet-zerone"},"homepage":"https://github.com/cambridgetcg/agenttool/blob/main/docs/specs/AGENT-WALLET-ZERONE-0.1.md","_id":"@agenttool/wallet-zerone@0.1.2","bugs":{"url":"https://github.com/cambridgetcg/agenttool/issues"},"_integrity":"sha512-wiMX10N/NX4eyhY+ZR0gvxPvgBujFpsAAOjx69SnsaL0RRDN1p6eQUv0ZKr7vV5O85QugqrOxkAw2sNuJllZ5Q==","_resolved":"/home/runner/work/_temp/agenttool-npm-release/agenttool-wallet-zerone-0.1.2.tgz","_from":"file:/home/runner/work/_temp/agenttool-npm-release/agenttool-wallet-zerone-0.1.2.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-wiMX10N/NX4eyhY+ZR0gvxPvgBujFpsAAOjx69SnsaL0RRDN1p6eQUv0ZKr7vV5O85QugqrOxkAw2sNuJllZ5Q==","shasum":"1f7e67a0caefc9eee769bcc3f57e91662a20ea7c","tarball":"https://registry.npmjs.org/@agenttool/wallet-zerone/-/wallet-zerone-0.1.2.tgz","fileCount":52,"unpackedSize":260792,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agenttool%2fwallet-zerone@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDS79WvJXFD8WRlayFKltMwPVDd3O7Yfsy0hLM7Z2H6uwIhAM+xKzqqBe9owIz7HoEUAJvxKrPgcQyLSYyQh9XVEWpk"}]},"_npmUser":{"name":"agenttool","email":"contact@cambridgetcg.com"},"directories":{},"maintainers":[{"name":"agenttool","email":"contact@cambridgetcg.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wallet-zerone_0.1.2_1785362641839_0.2020438055806424"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-29T22:04:01.640Z","0.1.2":"2026-07-29T22:04:02.015Z","modified":"2026-07-29T22:04:02.362Z"},"maintainers":[{"name":"agenttool","email":"contact@cambridgetcg.com"}],"description":"Offline-first Zerone chain adapter for Agent Wallet intents and exact Cosmos direct-sign bytes","homepage":"https://github.com/cambridgetcg/agenttool/blob/main/docs/specs/AGENT-WALLET-ZERONE-0.1.md","keywords":["agents","wallet","cosmos","zerone","capabilities","offline-first"],"repository":{"type":"git","url":"git+https://github.com/cambridgetcg/agenttool.git","directory":"packages/wallet-zerone"},"bugs":{"url":"https://github.com/cambridgetcg/agenttool/issues"},"license":"Apache-2.0","readme":"# @agenttool/wallet-zerone\n\n> Offline-first Zerone transaction encoding and verification for\n> capability-bounded Agent Wallet intents.\n\n`@agenttool/wallet-zerone` is the narrow chain adapter between\n`@agenttool/wallet` and Zerone. It turns an already verified Wallet intent\ninto exact Cosmos `SIGN_MODE_DIRECT` bytes, verifies the returned secp256k1\nsignature and `TxRaw`, and supplies injected query, simulation, broadcast, and\nlookup boundaries.\n\nVersion `0.1.2` is the current exact `love-package/v1` release. Its locked\ndevelopment dependency is the exact public `@agenttool/wallet@0.1.3`, while\nthe consumer peer remains the compatible `^0.1.2` range. It remains a local\noffline runtime and has not become a hosted bridge, signer, custody provider,\nor RPC service. npm and GitHub are optional mirrors whose exact availability\nmust be checked independently.\n\nThe immutable `0.1.1` LOVE artifact remains public. Its first npm bootstrap\nrun stopped in credential-free preparation because the clean checkout's local\nfile dependency did not expose Wallet's built declarations; the protected\npublish job was skipped, so neither a GitHub Release nor npm package was\ncreated. Version 0.1.2 replaces only that development dependency and preserves\nthe wire protocol. The immutable `0.1.0` LOVE artifact also remains public,\nbut its embedded docs call it a release candidate; this paragraph is the\npublic erratum and neither historical artifact is rewritten. The wire contract\nis pinned to zerone-core commit\n`35284a22192df8fc6273135f14e8549c804778b6` and Cosmos SDK `v0.50.15`.\n\nIt does not derive, accept, store, or export private keys or mnemonics. It does\nnot choose a custody provider, bundle an RPC URL or bearer credential, retry a\nbroadcast, persist sequence/budget state, or expose a combined sign-and-send\noperation.\n\n## Supported contract\n\nThe 0.1 allowlist is deliberately small:\n\n- Zerone mainnet `cosmos:zerone-1` and testnet\n  `cosmos:zerone-testnet-1`;\n- canonical lowercase `zrn` Bech32 20-byte accounts;\n- compressed secp256k1 keys and one direct signer;\n- `/cosmos.bank.v1beta1.MsgSend` with exactly one positive `uzrn` coin; and\n- `/zerone.substrate_bridge.v1.MsgSubmitExternalAttestation` for\n  `agenttool-invocation-v1` / `agenttool.invocation`, using the witness-only\n  link subset.\n\nThe Wallet method has no leading slash:\n`zerone.substrate_bridge.v1.MsgSubmitExternalAttestation`. The protobuf\n`Any.type_url` does have a leading slash. Mixing them is rejected.\n\nThe native asset IDs use the adapter-local forms\n`cosmos:zerone-1/denom:uzrn` and\n`cosmos:zerone-testnet-1/denom:uzrn`. `denom` here is a local profile\nnamespace, not a claim that it is registered by CAIP. BIP-44 coin type `118`\nis derivation metadata only; it does not identify ZRN as a SLIP-44 asset.\n\n## Safe invocation witness\n\nUse `createAgentToolInvocationWitnessLink()` for marketplace invocations. It\naccepts only the exact ten-field public projection used by the pinned Go\nrelay, requires `status === \"released\"`, a non-empty `completion_sig`, and a\nnon-empty `settled_at`, and binds `source_id` to the projection's invocation\nID.\n\n```typescript\nimport {\n  createAgentToolInvocationWitnessLink,\n} from \"@agenttool/wallet-zerone\";\n\nconst link = createAgentToolInvocationWitnessLink({\n  invocation: releasedPublicInvocationProjection,\n  source_id: releasedPublicInvocationProjection.id,\n  source_url:\n    `https://api.agenttool.dev/v1/invocations/${releasedPublicInvocationProjection.id}`,\n  fetched_at_block: observedHeight,\n});\n```\n\nThe content hash matches Go `encoding/json` field order and escaping. The link\nhash matches the pinned `keeper.ComputeLinkHash` recipe. That keeper recipe\ndoes not bind `source_url` or `source.adapter_id`; this adapter therefore\nrequires `source.adapter_id` to stay empty and constrains the URL to canonical\nHTTPS with no credentials, query, or fragment. The URL remains inside the\nsigned protobuf message even though changing its host does not change the\nkeeper link hash.\n\nLow-level hash and link helpers are exported for parity testing. They do not\nperform the released-invocation check; production callers should use the\nhigh-level helper.\n\nThe high-level helper validates and hashes caller-supplied public data. It\ndoes not fetch the invocation, authenticate the AgentTool API response, or\ncryptographically verify the meaning or issuer of `completion_sig`. The host\nmust obtain the projection through an authenticated, freshness-bounded source\nand apply its own completion-evidence policy before creating the link.\n\n## Sign-time flow\n\nA host should keep policy, chain observation, simulation, signing, and\nbroadcast as distinct steps:\n\n1. Verify the Wallet descriptor, capability, intent, and simulation receipt\n   with `@agenttool/wallet`.\n2. Query the exact source `BaseAccount` and, for attestations, the exact active\n   adapter registration through injected transports.\n3. Call `createZeroneDirectSignPlan()`. It binds chain, source, signer,\n   account number, sequence, fee, gas, ordered messages, declared spend,\n   adapter snapshot, protobuf body, `AuthInfo`, `SignDoc`, and simulation\n   `TxRaw`.\n4. Simulate `plan.simulation_tx_bytes_b64u`, then seal the resulting Wallet\n   simulation receipt.\n5. Call `createZeroneSimulationBinding()` with that exact verified receipt and\n   transport result.\n6. Inside one durable sign-time transaction, re-read capability usage and\n   the exact account and adapter observations, repeat Wallet authorization,\n   reserve spend/fee/nonce, and persist at least\n   `{ plan_id, simulation_record_id, simulation_tx_bytes_hash }`. If account\n   number, sequence, registered key, adapter state, bond floor, qualification\n   rule, work-class list, or relevant height changed, discard the plan and\n   rebuild and re-simulate it; do not patch or reuse its bytes.\n7. Call `createZeroneSigningRequest()` with the exact plan, verified\n   simulation, binding, and authorization. Pass that request to a\n   non-exportable signer provider.\n8. Call `createZeroneSignedPayload()` or `verifyZeroneSignedPayload()`. The\n   adapter verifies the compact lower-S Cosmos secp256k1 signature and exact\n   planned `TxRaw` before returning the uppercase precomputed transaction hash.\n9. Persist the signed bytes, hash, and operation state before invoking\n   `broadcastOnce()` exactly once.\n\nRuntime brands and object-identity bindings prevent substitution inside one\nprocess. They are not durable proof. JSON serialization, cloning, or process\nrestart removes that protection, so the host must persist and re-verify the\nexplicit identifiers and hashes at its transaction boundary.\n\nAn unset `BaseAccount.pub_key` is accepted because the first transaction may\nset it. A registered key is accepted only when it is exactly the same Cosmos\nsecp256k1 key. Rotated Ed25519, unknown key types, and key mismatches are\nunsupported because the pinned chain's auth path would not verify these\ndirect-sign bytes safely.\n\n## Gas and fee floor\n\nThe pinned Zerone `ZRNGasDecorator` is skipped during simulation but enforced\nduring CheckTx and DeliverTx. The adapter therefore computes a separate\n`required_gas_limit`:\n\n```text\nmax(22,222, sum(21,000 for each MsgSend\n                + 22,222 for each MsgSubmitExternalAttestation))\n```\n\nThe attestation message is unmapped in the pinned table and therefore uses\nthe decorator's 22,222 fallback per message. `gas_limit` must meet that exact\nordered-message floor and stay at or below `11,111,111`. The fee must be\npositive `uzrn`, meet the pinned consensus floor of one `uzrn` per gas unit,\nand remain within the intent's `max_fee`.\n\nA successful simulation alone is not authoritative for this ante rule. At the\npinned commit, simulation also skips the emergency-halt, DID, frozen-account,\nand Zerone capability decorators. The adapter emits no memo, so the DID path\nis normally inert, but the other state can still change before delivery.\nSimulation is bounded evidence about exact bytes and observed state, not a\npromise that CheckTx or DeliverTx will accept them.\n\n## Network boundary and recovery\n\n`createZeroneAdapterClient()` accepts caller-supplied transports. It supplies\nfixed network context, deadlines, a 2 MiB `max_response_bytes` instruction,\nand an `AbortSignal`; it supplies no URLs, credentials, retry loop, or hidden\nnetwork fallback. Those limits are cooperative at the I/O boundary: the\ninjected transport must enforce the byte cap while streaming and before\nallocation, and must use the signal to cancel provider work where possible.\nThe adapter also validates serialized response size after return, but that\ncannot undo an allocation already made by the transport.\n\nIf the broadcast transport was never invoked, an invalid deadline or an\nalready-aborted signal throws and is safe to correct locally. Once the\ntransport closure is invoked, timeout, abort, provider exception, malformed\nresponse, wrong hash, or oversized response returns `ambiguous` with the\nprecomputed transaction hash. The host must not broadcast the bytes again.\nAn external abort returns the adapter call promptly even if the injected\ntransport ignores the signal, but no JavaScript signal universally cancels an\nunderlying socket, remote provider, or already transmitted request; ambiguity\nis the only safe result.\n\nTransaction lookup absence or provider unavailability does not authorize a\nretry, refund, new sequence reservation, or a second signer call. Positive\nlookup evidence can resolve the known hash. The adapter marks a code-zero\ntransaction confirmed after one additional committed block; that means only\nthat the transaction was included successfully at the configured depth.\n\nIt does not mean that an external attestation is `READY`, `SETTLED`, that its\nbond was returned, or that a witness reward was paid. The pinned message\nresponse and `external_attestation_submitted` event expose\n`attestation_id`. A host that needs application settlement must recover that\nID from the exact typed response/event, then query the module's typed\n`Attestation` service through gRPC, ABCI, or the Zerone CLI and track its\nstatus separately. Witness-only settlement returns the bond separately from\nany witness reward. A configured reward remains escrowed through its challenge\nwindow: adapter suspension defers release, tombstoning cancels it, and the\nchain supply cap may clip the amount actually minted.\n\nAlthough the module proto carries HTTP annotations, the pinned\n`AppModuleBasic.RegisterGRPCGatewayRoutes` implementation is empty. This\npackage therefore does not claim that the custom\n`/zerone/substrate_bridge/v1/...` REST paths are reachable. A deployment may\nadd independent routing, but the host must configure and authenticate that\ntransport explicitly.\n\n## Attestation competition limits\n\nThe chain reserves an `(adapter_id, source_id)` on first successful\nsubmission. The content hash and link hash make later verification\nre-derivable, but they do not prove that a pending transaction will win that\nreservation. A copied link can be submitted by another account before\ninclusion, particularly for an open adapter. This package does not provide a\nprivate mempool, anti-front-running relay, qualification proof, or atomic\nsource reservation. Treat those as deployment-level risks; never infer\nsettlement or reward entitlement from a locally signed transaction.\n\n## Development and parity\n\n```bash\n# From the repository root. The lock resolves the exact public Wallet 0.1.3\n# development dependency; consumer compatibility remains the ^0.1.2 peer.\n(cd packages/wallet-zerone \\\n  && bun install --frozen-lockfile \\\n  && bun run ci \\\n  && npm pack --ignore-scripts --dry-run)\n```\n\nThe checked-in vector was generated independently with zerone-core's own\nprotobuf types, `keeper.ComputeLinkHash`, Cosmos SDK `v0.50.15`\nunmarshal/re-marshal, and `secp256k1.PubKey.VerifySignature`. It also asserts\nthat simulation `TxRaw` has exactly one empty signature.\n\n```bash\n# Networked pinned checkout:\n./scripts/regenerate-go-cosmos-vector.sh --check\n\n# Or reuse a local pinned checkout and cached Go modules:\nZERONE_CORE_CHECKOUT=/path/to/zerone-core \\\nGOPROXY=off GOSUMDB=off \\\n./scripts/regenerate-go-cosmos-vector.sh --check\n```\n\nUse `--write` only when intentionally regenerating the committed vector after\nreviewing the pinned chain change.\n\nThe normative adapter draft is\n[`docs/specs/AGENT-WALLET-ZERONE-0.1.md`](../../docs/specs/AGENT-WALLET-ZERONE-0.1.md).\n\n## License\n\nApache-2.0. The protocol draft is offered under CC0 unless a section states\notherwise.\n","readmeFilename":"README.md","_rev":"1-79c1ab04626c34cb34d990835a901994"}