{"_id":"@aikdna/kdna-web-server","_rev":"10-123d2fbac3ad4c66c8012186b240144f","name":"@aikdna/kdna-web-server","dist-tags":{"latest":"0.3.1"},"versions":{"0.1.0":{"name":"@aikdna/kdna-web-server","version":"0.1.0","keywords":["kdna","kdna-web-server","nextjs","express","cloudflare-workers","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.1.0","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"8ceaba096ae73c87bb04f91b2ef8dd4afe68d88e","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.1.0.tgz","fileCount":16,"integrity":"sha512-y6uuukILwRIQVOjnmfwa8dlB4KQZvlqA1RvCe8Ffu73NWNxg2ALBOF/3Z4TxXRaw2yePU00VZE1YACg4B7cxAA==","signatures":[{"sig":"MEYCIQDxRIcbmMUtow59ItN52udMvJHAg3iqHgXHBWYly95QagIhAIgtkT8QSlLEP7+s8v6ZA8CwlMTyeexcjx1INuKO++yb","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":39491},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js","./cloudflare":"./src/adapters/cloudflare/index.js"},"gitHead":"e6385563e0f4410e4fc51d0bfc96ce784fe4a680","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"node --test tests/**/*.test.js"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Server-side adapter for the KDNA runtime — route handlers for Next.js, Express, and Cloudflare Workers. All KDNA decryption and license verification runs server-side.","directories":{},"_nodeVersion":"22.22.3","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"@aikdna/kdna-core":"^0.15.10"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.1.0_1783068081196_0.5007605375702857","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@aikdna/kdna-web-server","version":"0.1.1","keywords":["kdna","kdna-web-server","nextjs","express","cloudflare-workers","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.1.1","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"7da63f54a3083aa6ba1e45165ffb1c9857a8dd80","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.1.1.tgz","fileCount":16,"integrity":"sha512-9419YoYwY3gP6tDqAe/QVTAVzznpK7p82PEPzuXpqT/ZR8kaqDYceIDHdUYQuSqaejueTXOAu2ih9Q62QN8M9Q==","signatures":[{"sig":"MEYCIQC5N/7YiSw0fqVzWz3ZydAbcfKoJERpf9Gi/kPjH0btqAIhAPx8/oII38n78H4Sms0GTQIp7OnWEsCJMVHkVuoN0Sv0","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":39536},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js","./cloudflare":"./src/adapters/cloudflare/index.js"},"gitHead":"4b8f9d3022c873751bcda5b20be7b199884caa1b","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"node --test tests/server.test.js","prepublishOnly":"npm run ci"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Server-side adapter for the KDNA runtime — route handlers for Next.js, Express, and Cloudflare Workers. All KDNA decryption and license verification runs server-side.","directories":{},"_nodeVersion":"22.23.1","dependencies":{},"_hasShrinkwrap":false,"peerDependencies":{"@aikdna/kdna-core":"^0.15.10"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.1.1_1783089249193_0.25539981413830937","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@aikdna/kdna-web-server","version":"0.2.0","keywords":["kdna","kdna-web-server","nextjs","express","cloudflare-workers","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.2.0","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"fc1a45845e4ca3ebd49b36c98f7649f4615e3f4a","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.2.0.tgz","fileCount":16,"integrity":"sha512-odamXItPHq6nhf2G+GFXbVjzseQ8kxiJkYPXZ64Dglk8/1X0wPKKmUbhZ07sa0whQgelB6uoqZfFMhYFDWhy7w==","signatures":[{"sig":"MEUCIHL6iLD95/xKajP6A9g0sD6S8atzmodTzo6H3NotnzAoAiEAoE9CgBWA2pHQM1PDGxvFO9aiyVZ29WOJNcO89BuIl0o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":40105},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js","./cloudflare":"./src/adapters/cloudflare/index.js"},"gitHead":"159fa96f274d7716137124f22f4101a30dec89e3","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"node --test tests/server.test.js","prepublishOnly":"npm run ci"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Server-side adapter for the KDNA runtime — route handlers for Next.js, Express, and Cloudflare Workers. All KDNA decryption and license verification runs server-side.","directories":{},"_nodeVersion":"22.23.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"@aikdna/kdna-core":"0.15.12"},"peerDependencies":{"@aikdna/kdna-core":"0.15.12"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.2.0_1783904745710_0.21093877968585684","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@aikdna/kdna-web-server","version":"0.2.1","keywords":["kdna","kdna-web-server","nextjs","express","cloudflare-workers","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.2.1","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"4b3d548e0d35f67da27a947b972effac949a17ab","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.2.1.tgz","fileCount":16,"integrity":"sha512-+vrUee0BT7e3yy3JuLLU32uBC2vWYu8QS8+rb0h+rRYXmH5YJwGpOD8+5RbzIVPuwRRLWPvzrOLwgSPO1eIQ6g==","signatures":[{"sig":"MEUCIQCTG7QdueGp2sDS+U47eRcuLl+mup+y95rYKYqoBRQNKgIgDjIxH8+AkkH3HQJXp3aG4ZVGyrwpMTMneoq3/QsAEwQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":41562},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js","./cloudflare":"./src/adapters/cloudflare/index.js"},"gitHead":"85ddb3f4c04682f4ce8bb0dc9833bb6bbcdd4718","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"node --test tests/server.test.js","prepublishOnly":"npm run ci"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Server-side adapter for the KDNA runtime — route handlers for Next.js, Express, and Cloudflare Workers. All KDNA decryption and license verification runs server-side.","directories":{},"_nodeVersion":"22.23.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"@aikdna/kdna-core":"0.16.0"},"peerDependencies":{"@aikdna/kdna-core":"0.16.0"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.2.1_1783932044957_0.6455233128163878","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@aikdna/kdna-web-server","version":"0.2.2","keywords":["kdna","kdna-web-server","nextjs","express","cloudflare-workers","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.2.2","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"5d0af70e0aa82aa0daf285ebe6832856b74e278f","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.2.2.tgz","fileCount":16,"integrity":"sha512-q6TuvIedNsm/YBnJfyHBFEpeBKoOQyH7wX1v3fQJG/VOi/I/G9YrMxKKSlb3Jzy2Ew1Q4NkUnzfTFmgP1X4eXw==","signatures":[{"sig":"MEUCIFaXuuSPQcAhDFhPnpa2amkA3liZfpAIQ1rR/f2BAZuPAiEAp9qipmZAVTv6IMEFXjN6PuoK0TDinzSVnfh3b2OQ4+U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":41560},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js","./cloudflare":"./src/adapters/cloudflare/index.js"},"gitHead":"9fcda70e70edba9a51a0684e366c3ef25fee4b60","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"node --test tests/server.test.js","prepublishOnly":"npm run ci"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Server-side adapter for the KDNA runtime — route handlers for Next.js, Express, and Cloudflare Workers. All KDNA decryption and license verification runs server-side.","directories":{},"_nodeVersion":"22.23.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"@aikdna/kdna-core":"0.16.0"},"peerDependencies":{"@aikdna/kdna-core":"0.16.0"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.2.2_1783932757210_0.41454554601807114","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@aikdna/kdna-web-server","version":"0.2.3","keywords":["kdna","kdna-web-server","nextjs","express","cloudflare-workers","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.2.3","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"67f96a94138ad320ec812872997b03f460928f6e","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.2.3.tgz","fileCount":16,"integrity":"sha512-DaRuXrzQ8cJghzC9gAS8qq8e/+LhPz33Zk9Yeijg5KMOnydaDoArfkerxz3FlCTGr6YIa3P9QGwZqMnTRMSzxA==","signatures":[{"sig":"MEUCIQCqQ7JsnA7wehkwvT6x7CV85HhhTJYEOuQ7fba0oHbCpQIgdjO6PX17po3OZXHaNBiizSZine1a0+UARfhOeECIjk4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.2.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":41699},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js","./cloudflare":"./src/adapters/cloudflare/index.js"},"gitHead":"e99bf65ec95101a2bc9a7bed1e85f597db001486","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"node --test tests/server.test.js","prepublishOnly":"npm run ci","test:core-compat":"node --test tests/core-compat.test.js"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Server-side adapter for the KDNA runtime — route handlers for Next.js, Express, and Cloudflare Workers. All KDNA decryption and license verification runs server-side.","directories":{},"_nodeVersion":"22.23.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"@aikdna/kdna-core":"0.17.0"},"peerDependencies":{"@aikdna/kdna-core":"0.17.0"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.2.3_1784035694400_0.737975219019062","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aikdna/kdna-web-server","version":"0.3.0","keywords":["kdna","kdna-web-server","nextjs","express","server-adapter","judgment-asset"],"license":"Apache-2.0","_id":"@aikdna/kdna-web-server@0.3.0","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"homepage":"https://github.com/aikdna/kdna-web-server","bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"dist":{"shasum":"1922252b11c91e5fbefab713713ca3023b80cec5","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.3.0.tgz","fileCount":14,"integrity":"sha512-GMvp5nsG252NJaKj8EQ1dmDxOAJOHoE9K89XOQ/ms3tO8FLc8tmxdElH8sI+UyOs6X72VtLGQT8vQMNt5jrVCg==","signatures":[{"sig":"MEQCIBp0g8N7a6CLHN0embXH+ysgmHSXMskE5Q2ynnNto4DaAiB1CHgujR8Sv2+hLzKwHwPXsVm66KXF/Sp23yds2+kJNQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":53371},"type":"module","engines":{"node":">=18"},"exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js"},"gitHead":"6a7cfc493d454affda249a5fc8c12ec0ed473fb1","scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","lint":"node scripts/lint.js","test":"npm run check:public-surface && npm run check:protocol-names && node --test tests/server.test.js tests/release-context.test.cjs","prepublishOnly":"npm run ci","test:core-compat":"node --test tests/core-compat.test.js","check:protocol-names":"node scripts/check-protocol-names.js","check:public-surface":"node scripts/check-public-surface.js"},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"repository":{"url":"git+https://github.com/aikdna/kdna-web-server.git","type":"git"},"_npmVersion":"10.9.8","description":"Node.js server adapter for the KDNA runtime, with route handlers for Next.js and Express. Decryption and license verification remain server-side.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"devDependencies":{"@aikdna/kdna-core":"0.20.0","@aikdna/kdna-activation-server":"0.2.0"},"peerDependencies":{"@aikdna/kdna-core":"0.20.0"},"_npmOperationalInternal":{"tmp":"tmp/kdna-web-server_0.3.0_1784363510033_0.6088180224290074","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@aikdna/kdna-web-server","version":"0.3.1","description":"Node.js server adapter for the KDNA runtime, with route handlers for Next.js and Express. Decryption and license verification remain server-side.","type":"module","exports":{".":"./src/index.js","./nextjs":"./src/adapters/nextjs/index.js","./express":"./src/adapters/express/index.js"},"scripts":{"ci":"npm test && npm run lint && npm pack --dry-run --json","check:public-surface":"node scripts/check-public-surface.js","check:protocol-names":"node scripts/check-protocol-names.js","test":"npm run check:public-surface && npm run check:protocol-names && node --test tests/server.test.js tests/release-context.test.cjs","test:core-compat":"node --test tests/core-compat.test.js","lint":"node scripts/lint.js","prepublishOnly":"npm run ci"},"engines":{"node":">=18"},"peerDependencies":{"@aikdna/kdna-core":"0.21.0"},"devDependencies":{"@aikdna/kdna-activation-server":"0.2.0","@aikdna/kdna-core":"0.21.0"},"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/aikdna/kdna-web-server.git"},"bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"homepage":"https://github.com/aikdna/kdna-web-server","keywords":["kdna","kdna-web-server","nextjs","express","server-adapter","judgment-asset"],"_id":"@aikdna/kdna-web-server@0.3.1","gitHead":"a4dce0b636193d604e39b383cdcf8f5a897b3872","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-nJE6IrIPpy/ixOaaUZoGq1cFBRrdKgoOPKfJYFPETHp7DpeH/87425soHk5c6f3HzMcL0iLfEy2PZWFrIH38NQ==","shasum":"8a73617c8ec8b24ce52570065c47ae44a920fda2","tarball":"https://registry.npmjs.org/@aikdna/kdna-web-server/-/kdna-web-server-0.3.1.tgz","fileCount":14,"unpackedSize":64745,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aikdna%2fkdna-web-server@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDlfmY9HGTPtwnIjfgYBCqJ8Vl3DvLOfDRSf1c6rR/+pQIhAL3DJ/oggXgBbtQgfd9XdhweGiVAEL4wydos8EYJVqL6"}]},"_npmUser":{"name":"code2mp4","email":"hi@code2mp4.com"},"directories":{},"maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/kdna-web-server_0.3.1_1785820568609_0.12197926999011566"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-03T08:41:20.911Z","modified":"2026-08-04T05:16:09.220Z","0.1.0":"2026-07-03T08:41:21.329Z","0.1.1":"2026-07-03T14:34:09.330Z","0.2.0":"2026-07-13T01:05:45.859Z","0.2.1":"2026-07-13T08:40:45.070Z","0.2.2":"2026-07-13T08:52:37.359Z","0.2.3":"2026-07-14T13:28:14.524Z","0.3.0":"2026-07-18T08:31:50.172Z","0.3.1":"2026-08-04T05:16:08.820Z"},"bugs":{"url":"https://github.com/aikdna/kdna-web-server/issues"},"license":"Apache-2.0","homepage":"https://github.com/aikdna/kdna-web-server","keywords":["kdna","kdna-web-server","nextjs","express","server-adapter","judgment-asset"],"repository":{"type":"git","url":"git+https://github.com/aikdna/kdna-web-server.git"},"description":"Node.js server adapter for the KDNA runtime, with route handlers for Next.js and Express. Decryption and license verification remain server-side.","maintainers":[{"name":"code2mp4","email":"hi@code2mp4.com"}],"readme":"# @aikdna/kdna-web-server\n\n**Server-side adapter for the KDNA runtime.**\n\n> **Status:** Experimental published server integration. The published\n> `0.3.0` binds the exact `@aikdna/kdna-core@0.20.0` runtime; the `0.3.1`\n> source candidate re-anchors the peer contract to\n> `@aikdna/kdna-core@0.21.0` and is not yet on npm `latest`. It is not an\n> AIKDNA-hosted service and does not decide which\n> asset a user or Host should attach to a task.\n\nMount one function call and your Node.js-hosted Next.js or Express app gains\na KDNA API: validate, inspect, plan-load, load, and\nactivation proxying. Studio export is not included in this server MVP yet.\n\n> **Security invariant:** decryption, license verification, and\n> entitlement checks run exclusively server-side. Passwords and\n> license keys are never reflected to the client.\n\n> New to KDNA? → [KDNA Core](https://github.com/aikdna/kdna)\n>\n> Need browser-side file picking and upload? →\n> [@aikdna/kdna-web-client](https://github.com/aikdna/kdna-web-client)\n>\n> Need React components? →\n> [@aikdna/kdna-react](https://github.com/aikdna/kdna-react)\n\n[![npm](https://img.shields.io/npm/v/@aikdna/kdna-web-server)](https://www.npmjs.com/package/@aikdna/kdna-web-server)\n[![License](https://img.shields.io/badge/license-Apache%202.0-blue)](LICENSE)\n\n---\n\n## Install\n\n```bash\nnpm install @aikdna/kdna-web-server @aikdna/kdna-core\n```\n\nThe published `0.3.0` requires the exact `@aikdna/kdna-core@0.20.0` runtime\ncontract; the `0.3.1` source candidate requires `@aikdna/kdna-core@0.21.0`.\nOther Core versions are intentionally outside the tested peer\nrange. The package targets Node.js 18 or later; Edge and Worker runtimes are\nnot part of the verified surface.\n\nThe load endpoint defaults to Core's JSON Runtime Capsule. The server stores\nthe uploaded `.kdna` file but does not decode `payload.kdnab` itself; all\nvalidation, authorization, decryption, and profile selection stay inside Core.\n\nUpload storage, a file identifier, and a successful LoadPlan are not user\nconsent for unrelated future tasks. The consuming application owns attachment\nscope, visible active state, and disable/switch/rollback controls.\n\nStudio export is planned for a later server milestone. The MVP returns\na structured `501 KDNA_EXPORT_NOT_IMPLEMENTED` response for `/export`.\n\n---\n\n## Quick start\n\n### Next.js (App Router)\n\n```js\n// app/api/kdna/[...route]/route.js\nimport { createNextHandlers } from '@aikdna/kdna-web-server/nextjs'\n\nconst { GET, POST } = createNextHandlers({\n  storageDir: process.env.KDNA_STORAGE_DIR ?? './kdna-files',\n  activationServerUrl: process.env.KDNA_ACTIVATION_URL,    // optional\n})\n\nexport { GET, POST }\n```\n\nThat single route file registers:\n\n| Method | Path | Description |\n|--------|------|-------------|\n| `POST` | `/api/kdna/validate` | Validate a `.kdna` file |\n| `POST` | `/api/kdna/inspect` | Return manifest and load-plan metadata |\n| `POST` | `/api/kdna/plan-load` | Evaluate the LoadPlan and return requirements |\n| `POST` | `/api/kdna/load` | Authorize and return a JSON Runtime Capsule |\n| `POST` | `/api/kdna/activate` | Proxy an entitlement activation request |\n| `POST` | `/api/kdna/export` | Not implemented in the MVP; returns `501` |\n\n→ [Full Next.js guide](./docs/adapters/nextjs.md)\n\n### Express\n\n```js\nimport express from 'express'\nimport { createKDNARouter } from '@aikdna/kdna-web-server/express'\n\nconst app = express()\napp.use('/api/kdna', createKDNARouter({\n  storageDir: process.env.KDNA_STORAGE_DIR ?? './kdna-files',\n}))\napp.listen(3000)\n```\n\n→ [Full Express guide](./docs/adapters/express.md)\n\n## HTTP API reference\n\nAll endpoints accept `multipart/form-data` or `application/json` as\nnoted. All responses are `application/json`.\n\n### `POST /validate`\n\nValidate a `.kdna` file. Returns the validation result without loading\nany content.\n\n**Request** (`multipart/form-data`)\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `file` | File | The `.kdna` file to validate |\n\n**Response**\n\n```json\n{\n  \"valid\": true,\n  \"domain\": \"kdna:aikdna:laozi-wuwei\",\n  \"version\": \"0.1.1\",\n  \"warnings\": []\n}\n```\n\n---\n\n### `POST /inspect`\n\nReturn the manifest and LoadPlan metadata from a `.kdna` file.\nNo decryption is performed.\n\n**Request** (`multipart/form-data`)\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `file` | File | The `.kdna` file to inspect |\n\n**Response**\n\n```json\n{\n  \"fileId\": \"8d1b2ab0-...\",\n  \"domain\": \"kdna:aikdna:laozi-wuwei\",\n  \"version\": \"0.1.1\",\n  \"title\": \"Asset display name\",\n  \"description\": \"...\",\n  \"encrypted\": false,\n  \"defaultProfile\": \"compact\",\n  \"loadPlan\": {\n    \"state\": \"ready\",\n    \"required_action\": \"load\",\n    \"can_load_now\": true\n  }\n}\n```\n\nThe exact Core 0.20 inspect contract exposes the default profile, not an\nauthoritative list of every available projection. A custom runtime may add a\n`profiles` array when it can provide that list.\n\n---\n\n### `POST /plan-load`\n\nEvaluate the LoadPlan for a `.kdna` file and return what the client\nneeds to provide before `/load` will succeed.\n\n**Request** (`application/json`)\n\n```json\n{\n  \"fileId\": \"abc123\",\n  \"context\": {\n    \"hasPassword\": false,\n    \"entitlementToken\": null\n  }\n}\n```\n\n**Response**\n\n```json\n{\n  \"canProceed\": false,\n  \"missing\": [\"enter_password\"],\n  \"plan\": {\n    \"state\": \"needs_password\",\n    \"required_action\": \"enter_password\",\n    \"can_load_now\": false\n  }\n}\n```\n\n---\n\n### `POST /load`\n\nAuthorize and load a `.kdna` file. Returns the selected Runtime Capsule plus\n`content` as a convenience alias for the Capsule context.\n\n> **Security:** `password` and signed entitlement fields travel from\n> the client to this endpoint over HTTPS and are used for the single\n> in-flight authorization/load. They are not logged, stored, or returned.\n> Raw license keys belong on `/activate`, not `/load`.\n\n**Request** (`application/json`)\n\n```json\n{\n  \"fileId\": \"abc123\",\n  \"profile\": \"compact\",\n  \"password\": \"...\",\n  \"entitlementToken\": { \"status\": \"active\" }\n}\n```\n\nAll credential fields are optional — provide only what the LoadPlan\nrequires.\n\n**Response**\n\n```json\n{\n  \"domain\": \"kdna:aikdna:laozi-wuwei\",\n  \"version\": \"0.1.1\",\n  \"judgmentVersion\": \"0.1.0\",\n  \"profile\": \"compact\",\n  \"content\": {\n    \"highest_question\": \"What should guide this task?\",\n    \"axioms\": []\n  },\n  \"capsule\": {\n    \"type\": \"kdna.runtime-capsule\",\n    \"contract_version\": \"0.1.0\",\n    \"asset\": {\n      \"asset_id\": \"kdna:aikdna:laozi-wuwei\",\n      \"version\": \"0.1.1\",\n      \"judgment_version\": \"0.1.0\"\n    },\n    \"profile\": \"compact\",\n    \"context\": {\n      \"highest_question\": \"What should guide this task?\",\n      \"axioms\": []\n    }\n  }\n}\n```\n\nWrong decryption credentials return `401 KDNA_DECRYPT_FAILED` with a generic\nmessage. Cryptographic provider errors and internal paths are never returned.\n\n---\n\n### `POST /export`\n\nStudio export is not implemented in the server MVP yet.\n\n**Response** — `501 application/json`\n\n```json\n{\n  \"error\": {\n    \"code\": \"KDNA_EXPORT_NOT_IMPLEMENTED\",\n    \"message\": \"KDNA export is not included in the server MVP yet.\"\n  }\n}\n```\n\n---\n\n### `POST /activate`\n\nProxy an entitlement activation request to the configured activation\nserver. Returns the signed entitlement record.\n\n**Request** (`application/json`)\n\n```json\n{\n  \"domain\": \"kdna:author:asset-name\",\n  \"license_key\": \"<opaque-license-secret>\",\n  \"machine_fingerprint\": \"<64-lowercase-hex-sha256>\"\n}\n```\n\n**Response** — the signed public entitlement record from the exact Activation\n0.2 contract. Unknown upstream fields, private credential fields, malformed\nrecords, redirects, non-JSON bodies, oversized bodies, and stalled responses\nfail closed behind stable local error codes.\n\nFor compatibility with React form helpers, the proxy also accepts\n`licenseKey` and `machineFingerprint` and forwards them to the activation\nserver as `license_key` and `machine_fingerprint`.\n\n---\n\n## Configuration\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `storageDir` | `string` | OS temp dir | Directory where uploaded `.kdna` files are stored temporarily by the default Node storage adapter. |\n| `storage` | `object` | file storage | Custom storage adapter with `put`, `get`, `remove`, and `cleanup` methods. |\n| `ttlMs` | `number` | `3600000` | Upload TTL for the default file storage adapter. |\n| `maxFileSizeBytes` | `number` | `10485760` | Maximum accepted file size (10 MB). |\n| `maxMultipartBodyBytes` | `number` | file limit + 65536 | Maximum complete multipart request size, enforced while streaming before form parsing. |\n| `maxJsonBodyBytes` | `number` | `65536` | Maximum JSON request-body size, counted as bytes before parsing. |\n| `activationServerUrl` | `string` | `undefined` | HTTPS origin of an `@aikdna/kdna-activation-server` instance. Exact loopback HTTP origins are accepted for local tests. |\n| `activationPath` | `string` | `/entitlements/activate` | Canonical activation route. Alternate routes are rejected. |\n| `activationTimeoutMs` | `number` | `10000` | Total activation fetch and response-body timeout. |\n\n---\n\n## Security model\n\nSee [docs/security-model.md](./docs/security-model.md) for the\nauthoritative description of what runs server-side vs. what the\nbrowser is allowed to see.\n\n**Short version:**\n\n- The browser never receives encrypted payload bytes or decryption keys.\n- `/load` returns a Runtime Capsule only after the server-side runtime\n  authorizes and loads the asset.\n- Passwords and signed entitlements are single-use on `/load`; license keys\n  travel only to `/activate`. Credentials must use HTTPS and are not returned\n  in responses.\n- `/validate` and `/inspect` operate on public metadata only.\n- `/plan-load` tells the client what is required but reveals no secrets.\n\n---\n\n## Related packages\n\n| Package | Role |\n|---------|------|\n| [`@aikdna/kdna-core`](https://github.com/aikdna/kdna) | KDNA format, schemas, and runtime loading contract |\n| [`@aikdna/kdna-studio-core`](https://github.com/aikdna/kdna-studio-core) | Studio authoring kernel; server-side export integration is planned after the MVP |\n| [`@aikdna/kdna-activation-server`](https://github.com/aikdna/kdna-activation-server) | Self-hosted license activation server |\n| [`@aikdna/kdna-remote-server`](https://github.com/aikdna/kdna-remote-server) | Self-hosted remote projection server |\n| [`@aikdna/kdna-web-client`](https://github.com/aikdna/kdna-web-client) | Browser-side file picking, upload, and load-plan state |\n| [`@aikdna/kdna-react`](https://github.com/aikdna/kdna-react) | React components and hooks |\n| [`create-kdna-web-app`](https://github.com/aikdna/create-kdna-web-app) | Project scaffolding CLI |\n\n---\n\n## License\n\nApache 2.0 — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}