{"_id":"@ai-manifests/aar-validate","name":"@ai-manifests/aar-validate","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@ai-manifests/aar-validate","version":"1.0.0","description":"Validate AAR record entries and checkpoints and audit ledger hash-chain integrity","type":"module","bin":{"aar-validate":"bin/cli.js"},"main":"./src/index.js","exports":{".":"./src/index.js"},"scripts":{"test":"node --test src/*.test.js"},"keywords":["aar","agent-acknowledgment-record","validate","ledger","hash-chain","reputation"],"author":{"name":"David H. Friedel Jr. — MarketAlly Pte Ltd"},"license":"Apache-2.0","homepage":"https://aar-manifest.dev","repository":{"type":"git","url":"git+https://github.com/ai-manifests/aar-validate.git"},"dependencies":{"ajv":"^8.17.0","ajv-formats":"^3.0.0"},"_id":"@ai-manifests/aar-validate@1.0.0","gitHead":"50959ab4faaf5286b7649af978a0aee70eb9e7c1","bugs":{"url":"https://github.com/ai-manifests/aar-validate/issues"},"_nodeVersion":"20.19.4","_npmVersion":"10.8.2","dist":{"integrity":"sha512-ebHFvCpVhGISaoywdq+wZHs4MI01vjTbo2zkucxSiWFHZkVE7V0H0MuOX6oa6QPs15DOTpvfoLIVt9YFh+TwJg==","shasum":"11b4e1afbd5a31130b5b1733601cfcfd189a6174","tarball":"https://registry.npmjs.org/@ai-manifests/aar-validate/-/aar-validate-1.0.0.tgz","fileCount":8,"unpackedSize":39181,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICINfnwQDkNjvmHXsqW4D8VrCPrWQQYN3R7myPE03q6IAiEA+4ccCyCdPEE1hIsNHFpL3LsIJj/DYmHe3HDUg0DMtLA="}]},"_npmUser":{"name":"logikonline","email":"dave@marketally.com"},"directories":{},"maintainers":[{"name":"logikonline","email":"dave@marketally.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/aar-validate_1.0.0_1780369363982_0.06917459898546063"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-02T03:02:43.859Z","1.0.0":"2026-06-02T03:02:44.116Z","modified":"2026-06-02T03:02:44.317Z"},"maintainers":[{"name":"logikonline","email":"dave@marketally.com"}],"description":"Validate AAR record entries and checkpoints and audit ledger hash-chain integrity","homepage":"https://aar-manifest.dev","keywords":["aar","agent-acknowledgment-record","validate","ledger","hash-chain","reputation"],"repository":{"type":"git","url":"git+https://github.com/ai-manifests/aar-validate.git"},"author":{"name":"David H. Friedel Jr. — MarketAlly Pte Ltd"},"bugs":{"url":"https://github.com/ai-manifests/aar-validate/issues"},"license":"Apache-2.0","readme":"# aar-validate\n\n[![npm](https://img.shields.io/npm/v/@ai-manifests/aar-validate.svg?label=npm)](https://www.npmjs.com/package/@ai-manifests/aar-validate)\n[![Downloads](https://img.shields.io/npm/dm/@ai-manifests/aar-validate.svg)](https://www.npmjs.com/package/@ai-manifests/aar-validate)\n[![Node](https://img.shields.io/badge/node-20%2B-blue.svg)](https://nodejs.org/)\n[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](LICENSE)\n[![Spec](https://img.shields.io/badge/spec-aar--manifest.dev-informational)](https://aar-manifest.dev)\n\nValidate [AAR](https://aar-manifest.dev) record entries and checkpoints, and\naudit an append-only ledger's hash-chain integrity, sequencing, and replay\nprotection.\n\n## Install\n\n```bash\nnpm install -g @ai-manifests/aar-validate\n```\n\n## Usage\n\n### Validate record entries and checkpoints\n\n```bash\naar-validate ./record-entry.json\naar-validate ./checkpoint.json\naar-validate ./entry-a.json ./entry-b.json\n```\n\nEach record entry is also re-hashed and compared against its stored `entry_hash`\n(hand-authored examples with placeholder hashes surface a warning, not an error).\n\n### Audit a ledger\n\nPass a directory of entries to validate them as one ordered ledger — genesis,\nstrict `seq` monotonicity, `prev_hash` chain linkage, `withdrawal_ref`\nresolution, and cross-entry replay (duplicate wrapped event id):\n\n```bash\naar-validate --ledger ./ledger/\n```\n\nAdd `--verify-hashes` to recompute every `entry_hash` from content (RFC 8785\ncanonicalization + SHA-256) and compare against the stored value:\n\n```bash\naar-validate --ledger ./ledger/ --verify-hashes\n```\n\n## Checks\n\n| Check | Mode | Type | Threat |\n|-------|------|------|--------|\n| Schema (record entry or checkpoint) | all | Error | — |\n| Genesis: sentinel `prev_hash` + null `event` | entry / ledger | Error | T1 |\n| `withdrawn` ⇒ `withdrawal_ref` present | entry / ledger | Error | T2 |\n| `withdrawal_ref` is a non-negative integer | entry / ledger | Error | T2 |\n| Checkpoint `interval_start_seq` ≤ `interval_end_seq` | entry | Error | — |\n| Checkpoint is signed | entry | Error | T1/T3 |\n| Checkpoint `prev_checkpoint_hash` null only first | entry | Warning | T3 |\n| Strictly increasing `seq` (no gaps, no dupes) | ledger | Error | T1 |\n| `prev_hash` equals previous `entry_hash` | ledger | Error | T2 |\n| `withdrawal_ref` resolves within the segment | ledger | Warning | — |\n| Duplicate wrapped event `id` (replay) | ledger | Error | T6 |\n| Recomputed `entry_hash` matches stored | `--verify-hashes` | Error | T2 |\n\n## Programmatic Use\n\n```javascript\nimport {\n  validateEntry,\n  validateRecordEntry,\n  validateCheckpoint,\n  validateLedger,\n  computeEntryHash,\n  computeCommitment,\n  canonicalize,\n  classify,\n} from '@ai-manifests/aar-validate';\n\nconst result = validateEntry(obj);                 // dispatches on shape\nconst ledger = validateLedger(entries, { recomputeHashes: true });\n\n// Build a correct chain\nconst entryHash = computeEntryHash(entry);          // sha256: over JCS(entry minus entry_hash)\nconst commitment = computeCommitment(aggregatorDid, seq, event);  // spec §3.4\n```\n\n## How It Composes\n\n`aar-validate` audits the ledger that stores AAP acknowledgment events. Validate\nthe events themselves at the source with\n[`aap-validate`](https://github.com/ai-manifests/aap-validate). AAR is to AAP\nwhat ADJ is to ADP — the append-only record layer — so `aar-validate`'s\nchain-integrity checks mirror `adj-validate`'s deliberation-record checks.\n\n```\naap-validate   validates the acknowledgment event\naar-validate   validates the ledger that stores, chains, and aggregates it\n```\n\nThe reputation aggregation interface (`ReputationSource`) AAR exposes to ADP\nmirrors ADJ's `CalibrationSource`; the normative `default` aggregation algorithm\nis specified in AAR §9.\n\n## Status\n\n**v1.0** — Validates against AAR spec v1.0 (stable). Schemas for both `v0` (draft\nbaseline) and `v1.0` ship in `schema/`.\n\n## License\n\nApache-2.0 — see [`LICENSE`](LICENSE) for the full license text and [`NOTICE`](NOTICE) for attribution.\n","readmeFilename":"README.md","_rev":"1-19a02b465752a64450ff307dc7d7e19a"}