{"_id":"@agntor/sdk","_rev":"2-20e69eee5015f724e5d716ffdba8e42e","name":"@agntor/sdk","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@agntor/sdk","version":"0.1.0","keywords":["agntor","agent","trust","escrow","settlement","reputation","verification","identity","ai-agents","x402","jwt","guard","redact","blockchain","ssrf"],"author":{"name":"Agntor Team"},"license":"MIT","_id":"@agntor/sdk@0.1.0","maintainers":[{"name":"agntor","email":"ayobrodamnwtf@gmail.com"}],"homepage":"https://agntor.com","bugs":{"url":"https://github.com/Garinmckayl/agntor/issues"},"dist":{"shasum":"5843a788065b0fda715a77140f5f416ed0643a34","tarball":"https://registry.npmjs.org/@agntor/sdk/-/sdk-0.1.0.tgz","fileCount":108,"integrity":"sha512-UCM2O0ys0cS9i/ZmfVJ5d6J/bLnpGefe0jf+YRRhPJZnnT+5zSTznY4wcpE2W3PBt3qi/CiJCC6oWg0t1C5LCg==","signatures":[{"sig":"MEYCIQCrSHeO57EbWFxlOTJK2d7+YvnI2rJFgoyXMdYGq0J3mgIhANjoyZutFRZ4M/u4+3umF7xrey0ysIzX/EkvcZwi68Hv","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":229753},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"80ce546cb9186d6b940ccd913fedefb36f77fde7","scripts":{"dev":"tsc --watch","test":"node --test","build":"tsc","clean":"rm -rf dist","prepublishOnly":"npm run build"},"_npmUser":{"name":"agntor","email":"ayobrodamnwtf@gmail.com"},"repository":{"url":"git+https://github.com/Garinmckayl/agntor.git","type":"git","directory":"packages/sdk"},"_npmVersion":"10.9.4","description":"Trust and payment rail for AI agents — identity, verification, escrow, settlement, and reputation.","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.24.1","ipaddr.js":"^2.2.0","jsonwebtoken":"^9.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.10.0","@types/jsonwebtoken":"^9.0.7"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.0_1770760829050_0.4083651900326313","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agntor/sdk","version":"0.2.0","description":"Trust and payment rail for AI agents — identity, verification, escrow, settlement, and reputation.","type":"module","sideEffects":false,"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"publishConfig":{"access":"public"},"keywords":["agntor","agent","trust","escrow","settlement","reputation","verification","identity","ai-agents","x402","jwt","guard","redact","blockchain","ssrf"],"author":{"name":"Agntor Team"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/Garinmckayl/agntor.git","directory":"packages/sdk"},"bugs":{"url":"https://github.com/Garinmckayl/agntor/issues"},"homepage":"https://github.com/Garinmckayl/agntor/tree/main/packages/sdk#readme","engines":{"node":">=18.0.0"},"scripts":{"build":"tsc","dev":"tsc --watch","test":"tsc && node --test tests/*.test.js","clean":"rm -rf dist","prepublishOnly":"npm run build"},"dependencies":{"ipaddr.js":"^2.2.0","jsonwebtoken":"^9.0.2","zod":"^3.24.1"},"devDependencies":{"@types/jsonwebtoken":"^9.0.7","@types/node":"^22.10.0","typescript":"^5.7.0"},"_id":"@agntor/sdk@0.2.0","gitHead":"2c8958f9f1a0fb9fc06021f0b6495b52f39cc247","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-4IJHgWZMCjAu7QB82fxq1zklv5KU82w4RU9HZD4gGXNxXqJVZ+aQRMv+4Fop7DBeUmR9isd2cK6Ahm3um6t+rw==","shasum":"7d2c9d98af917998a91cb799d737daa9550a2846","tarball":"https://registry.npmjs.org/@agntor/sdk/-/sdk-0.2.0.tgz","fileCount":108,"unpackedSize":236080,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFTf9hCxZBYINObSBLZ/WL5AHUD1UISGLiJDdr2hKp10AiEAuWQ1z6lsxZg5hLxgZySebXBnvSJMiBtc4n7WHSXND7s="}]},"_npmUser":{"name":"agntor","email":"ngetenew@gmail.com"},"directories":{},"maintainers":[{"name":"agntor","email":"ngetenew@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.2.0_1771167766734_0.4319309779308911"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-10T22:00:28.975Z","modified":"2026-02-15T15:02:46.990Z","0.1.0":"2026-02-10T22:00:29.215Z","0.2.0":"2026-02-15T15:02:46.887Z"},"bugs":{"url":"https://github.com/Garinmckayl/agntor/issues"},"author":{"name":"Agntor Team"},"license":"MIT","homepage":"https://github.com/Garinmckayl/agntor/tree/main/packages/sdk#readme","keywords":["agntor","agent","trust","escrow","settlement","reputation","verification","identity","ai-agents","x402","jwt","guard","redact","blockchain","ssrf"],"repository":{"type":"git","url":"git+https://github.com/Garinmckayl/agntor.git","directory":"packages/sdk"},"description":"Trust and payment rail for AI agents — identity, verification, escrow, settlement, and reputation.","maintainers":[{"name":"agntor","email":"ngetenew@gmail.com"}],"readme":"# @agntor/sdk\n\nTrust and payment rail for AI agents — identity, verification, escrow, settlement, and reputation.\n\n> **ESM-only.** This package ships as native ES modules and requires Node.js >= 18.\n\n## Installation\n\n```bash\nnpm install @agntor/sdk\n```\n\n## Quick Start\n\n```typescript\nimport { Agntor } from \"@agntor/sdk\";\n\nconst agntor = new Agntor({\n  apiKey: \"agntor_live_xxx\",\n  agentId: \"agent://my-agent\",\n  chain: \"base\",\n});\n\n// Check another agent's reputation\nconst rep = await agntor.reputation.get(\"agent://counterparty\");\nconsole.log(rep.successRate, rep.escrowVolume);\n\n// Create an escrow\nconst escrow = await agntor.escrow.create({\n  counterparty: \"agent://worker\",\n  amount: 50,\n  condition: \"task_complete\",\n  timeout: 3600,\n});\n```\n\n## Modules\n\n```\nAgntor\n ├─ identity   — register, resolve, me\n ├─ verify     — status, attest, badge\n ├─ escrow     — create, fund, status, cancel\n ├─ settle     — release, slash, resolve\n └─ reputation — get, history\n```\n\n### Identity\n\n```typescript\nawait agntor.identity.register();\nawait agntor.identity.resolve(\"agent://other\");\nawait agntor.identity.me();\n```\n\n### Verification\n\n```typescript\nawait agntor.verify.status(\"agent://other\");\nawait agntor.verify.attest({ capability: \"can_execute_http_calls\", proof: \"signed_msg\" });\nawait agntor.verify.badge();\n```\n\n### Escrow\n\n```typescript\nconst escrow = await agntor.escrow.create({\n  counterparty: \"agent://worker\",\n  amount: 100,\n  condition: \"api_returns_200\",\n  timeout: 3600,\n});\nawait agntor.escrow.fund(escrow.escrowId);\nawait agntor.escrow.status(escrow.escrowId);\nawait agntor.escrow.cancel(escrow.escrowId);\n```\n\n### Settlement\n\n```typescript\nawait agntor.settle.release(escrowId);\nawait agntor.settle.slash(escrowId);\nawait agntor.settle.resolve(escrowId, proofPayload);\n```\n\n### Reputation\n\n```typescript\nconst score = await agntor.reputation.get(\"agent://other\");\n// { successRate, escrowVolume, slashes, counterpartiesCount }\n\nconst history = await agntor.reputation.history(\"agent://other\");\n```\n\n## Events\n\n```typescript\nagntor.on(\"escrow_created\", (data) => console.log(\"New escrow:\", data));\nagntor.on(\"escrow_settled\", (data) => console.log(\"Settled:\", data));\nagntor.on(\"verification_changed\", (data) => console.log(\"Verification:\", data));\n```\n\n## Configuration\n\n| Option       | Default                   | Description                          |\n|--------------|---------------------------|--------------------------------------|\n| `apiKey`     | *required*                | Your Agntor API key                  |\n| `agentId`    | *required*                | Your canonical agent URI             |\n| `chain`      | *required*                | Target chain (e.g. `\"base\"`)         |\n| `baseUrl`    | `https://api.agntor.com`  | API base URL (override for staging)  |\n| `timeout`    | `30000`                   | Request timeout in ms                |\n| `maxRetries` | `3`                       | Max retries on transient errors      |\n\n## Protection Utilities\n\n### Prompt-Injection Guard\n\nDetects prompt injection attacks with a three-layer approach: fast regex patterns, heuristic analysis, and optional LLM-based deep scan.\n\n```typescript\nimport { guard } from \"@agntor/sdk\";\n\n// Fast regex + heuristic scan (no API key needed)\nconst result = await guard(\"user input\", {\n  injectionPatterns: [/ignore previous instructions/i],\n});\n\nif (result.classification === \"block\") {\n  console.log(\"Blocked:\", result.violation_types);\n}\n```\n\n#### Deep Scan with Guard Providers\n\nFor semantic analysis, use a battery-included guard provider — just pass an API key:\n\n```typescript\nimport { guard, createOpenAIGuardProvider } from \"@agntor/sdk\";\n\nconst provider = createOpenAIGuardProvider({ apiKey: \"sk-...\" });\n// or: createAnthropicGuardProvider({ apiKey: \"sk-ant-...\" })\n\nconst result = await guard(userInput, policy, {\n  deepScan: true,\n  provider,\n});\n```\n\nAvailable providers:\n\n| Factory                          | Env Variable         | Default Model              |\n|----------------------------------|----------------------|----------------------------|\n| `createOpenAIGuardProvider()`    | `OPENAI_API_KEY`     | `gpt-4o-mini`              |\n| `createAnthropicGuardProvider()` | `ANTHROPIC_API_KEY`  | `claude-3-5-haiku-latest`  |\n\n### PII & Secret Redaction\n\nStrips sensitive data from text before it leaves your system. Includes blockchain-specific patterns out of the box.\n\n```typescript\nimport { redact } from \"@agntor/sdk\";\n\nconst { redacted, findings } = redact(\n  \"My key is 0xac0974bec39a17e36ba4a6b4d238ff944bacb478cbed5efcae784d7bf4f2ff80\",\n  {},\n);\n// redacted: \"My key is [PRIVATE_KEY]\"\n```\n\n**Default patterns include:**\n\n| Category             | Examples                                          |\n|----------------------|---------------------------------------------------|\n| PII                  | Email, phone, SSN, credit card, street address    |\n| Cloud secrets        | AWS access keys, Bearer tokens, API key/secrets   |\n| Blockchain keys      | EVM private keys, Solana keys, BTC WIF keys       |\n| Wallet recovery      | BIP-39 mnemonic seeds (12- and 24-word)           |\n| Key storage          | Keystore JSON ciphertext, HD derivation paths     |\n\n### Tool Guard\n\nPolicy-based allow/blocklist for tool invocations:\n\n```typescript\nimport { guardTool } from \"@agntor/sdk\";\n\nconst check = guardTool(\"shell.exec\", undefined, {\n  toolBlocklist: [\"shell.exec\"],\n});\n// check.allowed === false\n```\n\n### wrapAgentTool\n\nHigh-level wrapper that automatically applies **redact + guard + SSRF check** to any tool function:\n\n```typescript\nimport { wrapAgentTool } from \"@agntor/sdk\";\n\nconst safeFetch = wrapAgentTool(myFetchTool, {\n  policy: { toolBlocklist: [\"dangerous_tool\"] },\n});\n\n// Inputs are redacted, guard-checked, and SSRF-validated before execution\nconst result = await safeFetch(\"https://api.example.com/data\");\n```\n\n## Settlement Guard (x402)\n\nEvaluates whether a payment request is legitimate or likely a scam. Combines fast heuristic checks with an optional LLM deep scan.\n\n```typescript\nimport { settlementGuard, createOpenAIGuardProvider } from \"@agntor/sdk\";\n\nconst result = await settlementGuard(\n  {\n    amount: \"50\",\n    currency: \"USDC\",\n    recipientAddress: \"0xabc...\",\n    serviceDescription: \"Data Analysis\",\n    reputationScore: 0.4,\n  },\n  {\n    deepScan: true,\n    provider: createOpenAIGuardProvider({ apiKey: \"sk-...\" }),\n  },\n);\n\nif (result.classification === \"block\") {\n  console.warn(`High-risk (${result.riskScore}):`, result.reasoning);\n  console.warn(\"Risk factors:\", result.riskFactors);\n}\n```\n\n**Heuristic checks (always run):**\n- Known-bad / sanctioned addresses\n- Low counterparty reputation score\n- High-value transaction threshold\n- Vague or missing service descriptions\n- Zero-address detection\n\n## Transaction Simulator\n\nDry-run an on-chain transaction via `eth_call` before signing:\n\n```typescript\nimport { TransactionSimulator } from \"@agntor/sdk\";\n\nconst sim = new TransactionSimulator({\n  rpcUrl: \"https://mainnet.base.org\",\n  maxGas: 500_000,\n});\n\nconst result = await sim.simulate({\n  from: \"0xSender...\",\n  to: \"0xContract...\",\n  data: \"0xCalldata...\",\n  value: \"0x0\",\n});\n\nif (!result.safe) {\n  console.warn(\"Simulation failed:\", result.error ?? result.warnings);\n}\n```\n\n## SSRF Protection\n\nValidates URLs against private/internal IP ranges with DNS resolution:\n\n```typescript\nimport { validateUrl } from \"@agntor/sdk\";\n\ntry {\n  await validateUrl(\"https://api.example.com/resource\");\n  // Safe to fetch\n} catch (err) {\n  // URL targets localhost, private IP, or uses blocked protocol\n}\n```\n\n## AP2 Protocol Helpers\n\nGenerate and parse [AP2 (Agentic Commerce)](https://github.com/google-agentic-commerce/ap2/tree/v0.1) headers:\n\n```typescript\nimport { getAP2Headers, parseAP2Headers } from \"@agntor/sdk\";\n\nconst headers = getAP2Headers(\"agent://my-agent\");\n```\n\n## Structured Output Schemas\n\nZod schemas for validating LLM responses:\n\n```typescript\nimport { parseStructuredOutput, GuardResponseSchema } from \"@agntor/sdk\";\n\nconst parsed = parseStructuredOutput(llmRawOutput, GuardResponseSchema);\n// { classification: \"pass\" | \"block\", reasoning: string }\n```\n\n## Ticket System\n\nFor low-level audit ticket operations:\n\n```typescript\nimport { TicketIssuer } from \"@agntor/sdk\";\n\nconst issuer = new TicketIssuer({\n  signingKey: process.env.AGNTOR_SECRET_KEY!,\n  issuer: \"agntor.com\",\n  algorithm: \"HS256\",\n  defaultValidity: 300,\n});\n\nconst ticket = issuer.generateTicket({\n  agentId: \"agent-123\",\n  auditLevel: \"Gold\",\n  constraints: {\n    max_op_value: 50,\n    allowed_mcp_servers: [\"finance-node\"],\n    kill_switch_active: false,\n  },\n});\n\nconst result = await issuer.validateTicket(ticket);\n```\n\n## License\n\nMIT — see [LICENSE](./LICENSE)\n","readmeFilename":"README.md"}