{"_id":"@agglabs-one/gate","name":"@agglabs-one/gate","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@agglabs-one/gate","version":"0.1.0","description":"OpenID Connect client for AGG One Gate — sign-in, consent, tokens and ID-token verification.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"engines":{"node":">=18"},"dependencies":{"@agglabs-one/core":"^0.1.0"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run build"},"keywords":["agglabs","agg-one","gate","oidc","openid-connect","oauth2","sso","pkce","login"],"license":"UNLICENSED","publishConfig":{"access":"public"},"_id":"@agglabs-one/gate@0.1.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-I5wXscbJI8ZDnvDULXnMUGq3FtYe94YbV2NkL7eVwo/Ja0l5K77yezpScWV6+C+MSYHxa0Nv6UdjpQxHBbP9Mw==","shasum":"6185d547494cf760a22e29f7b87a0b23013efb0c","tarball":"https://registry.npmjs.org/@agglabs-one/gate/-/gate-0.1.0.tgz","fileCount":22,"unpackedSize":46365,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDek+AK6PbBL1M3ycIC5zG30vd9oqrJqY3xyXGC7cE3UwIhAKUE6OvwAQQtkILBAfAVlmMKpmTTB7+jyR3kED2b57mX"}]},"_npmUser":{"name":"agglabs","email":"maciejpukszta@agglabs.com"},"directories":{},"maintainers":[{"name":"agglabs","email":"maciejpukszta@agglabs.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gate_0.1.0_1786722578232_0.8587312968162106"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-14T15:49:38.038Z","0.1.0":"2026-08-14T15:49:38.380Z","modified":"2026-08-14T15:49:38.603Z"},"maintainers":[{"name":"agglabs","email":"maciejpukszta@agglabs.com"}],"description":"OpenID Connect client for AGG One Gate — sign-in, consent, tokens and ID-token verification.","keywords":["agglabs","agg-one","gate","oidc","openid-connect","oauth2","sso","pkce","login"],"license":"UNLICENSED","readme":"# @agglabs-one/gate\n\nOpenID Connect client for **AGG One Gate** (`gate.one.agglabs.com`) — the AGG\nOne identity provider. Add \"Sign in with AGG\" to your app: build the login\nredirect, exchange the code for tokens, and verify the ID token offline.\n\nThe Gate is the OpenID Provider (the token `iss`, discovery and JWKS host).\nThe login and consent screens are served by the One frontend — `/authorize`\nredirects the browser there, and after the user confirms you get a `code` back\nat your redirect URI.\n\n```bash\nnpm install @agglabs-one/gate\n```\n\n## Usage\n\n```ts\nimport { Gate } from '@agglabs-one/gate';\n\nconst gate = new Gate({\n  clientId: process.env.AGG_CLIENT_ID!,\n  clientSecret: process.env.AGG_CLIENT_SECRET, // omit for public/PKCE clients\n  redirectUri: 'https://loop-id.agglabs.com/callback',\n});\n\n// 1. Start login. Redirect the browser to `req.url`; the Gate shows the consent\n//    page. Persist state/nonce/codeVerifier (e.g. in a signed cookie/session).\nconst req = await gate.createAuthorizationUrl();\nres.cookie('oidc', { state: req.state, nonce: req.nonce, codeVerifier: req.codeVerifier });\nres.redirect(req.url);\n\n// 2. In your callback, after confirming `state` matches what you stored:\nconst tokens = await gate.exchangeCode({ code, codeVerifier });\nconst claims = await gate.verifyIdToken(tokens.id_token!, { nonce });\n// claims.sub, claims.email, claims.preferred_username …\n\n// 3. Later: refresh, look up the user, or log out.\nconst fresh = await gate.refresh(tokens.refresh_token!);\nconst user  = await gate.userInfo(tokens.access_token);\nconst out   = await gate.endSessionUrl({ idTokenHint: tokens.id_token, postLogoutRedirectUri: 'https://loop-id.agglabs.com' });\nawait gate.revoke(tokens.refresh_token!);\n```\n\n## API\n\n| Method | Purpose |\n| --- | --- |\n| `discover()` | Fetch/cache `.well-known/openid-configuration`. |\n| `createAuthorizationUrl(params?)` | Build the login redirect (PKCE + state + nonce). |\n| `exchangeCode({ code, codeVerifier, redirectUri? })` | Authorization-code → tokens. |\n| `refresh(refreshToken)` | Rotate a refresh token for a fresh token set. |\n| `verifyIdToken(idToken, { nonce?, audience?, clockToleranceSeconds? })` | Verify signature + claims offline against the JWKS. |\n| `userInfo(accessToken)` | Fetch claims from `/userinfo`. |\n| `revoke(refreshToken)` | Revoke a refresh token. |\n| `endSessionUrl({ idTokenHint?, postLogoutRedirectUri?, state? })` | Build the logout URL. |\n\nAll failures throw a typed `AggError` (re-exported here); `verifyIdToken` throws\n`TokenValidationError` on a bad signature or claim.\n","readmeFilename":"README.md","_rev":"1-c9c0edd99b417e061a10f6234ee73764"}