{"_id":"@akku-work/consent-sdk-auth","name":"@akku-work/consent-sdk-auth","dist-tags":{"beta":"0.1.0-beta.1","latest":"0.1.0-beta.1"},"versions":{"0.1.0-beta.1":{"name":"@akku-work/consent-sdk-auth","version":"0.1.0-beta.1","description":"Akku Consent - zero-dependency SDK for authenticated web applications. Identity travels only inside a host-signed subject token.","keywords":["consent","gdpr","dpdp","privacy","cmp","preference-management","authenticated","sdk"],"license":"UNLICENSED","author":{"name":"Akku"},"homepage":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent","repository":{"type":"git","url":"git+https://bitbucket.org/cnw-bitbucket-ws/akku-consent.git","directory":"packages/consent-sdk-auth"},"bugs":{"url":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent/issues"},"//private":"PKG-006 pattern repeated here: this is the SECOND workspace package (after @akku-work/consent-sdk) that is NOT private — every other app/package keeps `private: true`. Publishing is tag-triggered only (sdk-v*, bitbucket-pipelines.yml); do not run a bare `pnpm publish -r` from the repo root.","publishConfig":{"access":"public","tag":"beta"},"type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./ui":{"types":"./dist/ui.d.ts","import":"./dist/ui.js","require":"./dist/ui.cjs"}},"dependencies":{},"devDependencies":{"rimraf":"^6.0.1","tsup":"^8.3.5","typescript":"^5.6.3","vitest":"^3.2.6","@akku/contracts":"0.1.0"},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run","test:coverage":"vitest run --coverage","lint":"eslint .","typecheck":"tsc -p tsconfig.json --noEmit","clean":"rimraf dist"},"_id":"@akku-work/consent-sdk-auth@0.1.0-beta.1","_integrity":"sha512-xvqdfbxkO1xSLZCZm1qEMF+u/HYkZtyAdLXjSNmSQAJjYaSOgLLzPWIhnj9MwGfRXd+eZvq/Pgo+rkP7yDBY4A==","_resolved":"C:\\Users\\RAJAND~1\\AppData\\Local\\Temp\\494921ee563e815dfa964fbda924c57e\\akku-work-consent-sdk-auth-0.1.0-beta.1.tgz","_from":"file:akku-work-consent-sdk-auth-0.1.0-beta.1.tgz","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-xvqdfbxkO1xSLZCZm1qEMF+u/HYkZtyAdLXjSNmSQAJjYaSOgLLzPWIhnj9MwGfRXd+eZvq/Pgo+rkP7yDBY4A==","shasum":"350e8848d24b2f7e5aeda7f9cf0f28db418f49fe","tarball":"https://registry.npmjs.org/@akku-work/consent-sdk-auth/-/consent-sdk-auth-0.1.0-beta.1.tgz","fileCount":17,"unpackedSize":221140,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFsZFL9R6XvFkt4j/rnXWB2Elp4pClgby9cHan5WfaG2AiEAmGbcDGn8EKubIx0vm2sn/Pxvkzuu9OJe2PHZAxYzeHM="}]},"_npmUser":{"name":"rajandavidt","email":"rajandavid.t@cloudnowtech.com"},"directories":{},"maintainers":[{"name":"cloudnowtech","email":"developer@cloudnowtech.com"},{"name":"rajandavidt","email":"rajandavid.t@cloudnowtech.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/consent-sdk-auth_0.1.0-beta.1_1787298938574_0.6153044730000901"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-21T07:55:38.416Z","0.1.0-beta.1":"2026-08-21T07:55:38.705Z","modified":"2026-08-21T07:55:38.874Z"},"maintainers":[{"name":"cloudnowtech","email":"developer@cloudnowtech.com"},{"name":"rajandavidt","email":"rajandavid.t@cloudnowtech.com"}],"description":"Akku Consent - zero-dependency SDK for authenticated web applications. Identity travels only inside a host-signed subject token.","homepage":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent","keywords":["consent","gdpr","dpdp","privacy","cmp","preference-management","authenticated","sdk"],"repository":{"type":"git","url":"git+https://bitbucket.org/cnw-bitbucket-ws/akku-consent.git","directory":"packages/consent-sdk-auth"},"author":{"name":"Akku"},"bugs":{"url":"https://bitbucket.org/cnw-bitbucket-ws/akku-consent/issues"},"license":"UNLICENSED","readme":"# @akku-work/consent-sdk-auth\r\n\r\nConsent and preference management for an **authenticated** web application. Zero runtime\r\ndependencies.\r\n\r\nThis is the authenticated plane. Use it when the person whose consent you are recording is signed\r\nin to your app and you can prove who they are. If you need a cookie banner for anonymous visitors,\r\nuse [`@akku-work/consent-sdk`](https://www.npmjs.com/package/@akku-work/consent-sdk) instead — the\r\ntwo are separate packages with separate release cadences, and they are not interchangeable.\r\n\r\nThis package is **headless**: it decides, it does not draw. It resolves each published purpose to a\r\nlegal basis, a validity window and an outcome, and leaves rendering to you. For ready-made React\r\ncomponents, add\r\n[`@akku-work/consent-sdk-react`](https://www.npmjs.com/package/@akku-work/consent-sdk-react).\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install @akku-work/consent-sdk-auth\r\n```\r\n\r\n## Usage\r\n\r\n```ts\r\nimport { ConsentManager } from \"@akku-work/consent-sdk-auth\";\r\n\r\nconst consent = new ConsentManager({\r\n  apiHost: \"https://consent.nova.example\",\r\n  siteKey: \"sk_live_9f2c…\",\r\n  applicationId: \"nova-bank-web\",\r\n  getSubjectToken: () => session.fetchConsentToken(),\r\n});\r\n\r\nconst states = await consent.getPurposeStates();\r\nfor (const state of states) {\r\n  // \"disclose\" | \"ask\" | \"silent\" | \"re-ask\" | \"re-confirm\"\r\n  console.log(state.key, state.outcome, state.granted);\r\n}\r\n\r\n// Only the purposes that still need a surface, in the order they were published.\r\nconst toAsk = await consent.purposesToAsk();\r\n```\r\n\r\n## There is no `userId` parameter\r\n\r\nIdentity travels **only** inside the host-signed subject token returned by `getSubjectToken()`. The\r\nAPI has no option to pass a subject identifier directly, and this is not an oversight.\r\n\r\nA user id handed over from the browser is a *claim*, not a *credential* — anyone with devtools open\r\ncan pass a different one. The backend derives the authenticated subject itself by verifying the\r\ntoken's signature, `exp`, `aud` and `iss`; a body-supplied user id on this plane is rejected\r\noutright rather than silently preferred. If you find yourself wanting to pass one, the token wiring\r\nis what needs fixing.\r\n\r\n`getSubjectToken` may be sync or async and is called fresh before every request, so refresh and\r\nrotation stay entirely yours.\r\n\r\n## The five outcomes\r\n\r\n`getPurposeStates()` is the whole point of this package. Each purpose resolves to one outcome,\r\nand rendering from `outcome` rather than from `granted` is what keeps two opposite mistakes from\r\ncreeping in — needlessly re-prompting someone who already answered, and treating a stale consent as\r\ncurrent.\r\n\r\n| Outcome      | Meaning                                                        |\r\n| ------------ | -------------------------------------------------------------- |\r\n| `disclose`   | Disclosed, never prompted — a `necessary` or `legal_obligation` basis. |\r\n| `ask`        | Nothing on file. Ask.                                          |\r\n| `silent`     | Decided, still fresh, under the current policy. Say nothing.    |\r\n| `re-ask`     | Decided but past its validity window. Ask again as a NEW decision. |\r\n| `re-confirm` | Decided under a policy version since superseded. Ask again as a re-confirmation. |\r\n\r\n\"Granted but lapsed\" and \"granted under a replaced policy\" are both `granted: false` with an\r\noutcome that says why. Collapsing them loses the distinction that matters.\r\n\r\n## API\r\n\r\n| Member                            | Purpose                                              |\r\n| --------------------------------- | ---------------------------------------------------- |\r\n| `getPurposeStates(now?)`          | Every published purpose joined with its outcome.     |\r\n| `purposesToAsk(keys?)`            | Only the purposes that still need a surface.         |\r\n| `hasConsent(key)`                 | Is this purpose granted right now?                   |\r\n| `getPurposes()`                   | The published purpose list, unmodified.              |\r\n| `getConsentState()`               | The raw decision map.                                |\r\n| `getPreferences()`                | Preference-centre state.                             |\r\n| `grantConsent(id)`                | Grant one purpose.                                   |\r\n| `updateConsent(decisions)`        | Record a per-purpose decision map.                   |\r\n| `recordDecisions(decisions)`      | Record decisions taken from a surface.               |\r\n| `savePreferences(decisions)`      | Persist a preference-centre submission.              |\r\n| `withdrawConsent(id?)`            | Withdraw one purpose, or all of them.                |\r\n| `onChange(listener)`              | Subscribe; returns an unsubscribe function.          |\r\n| `request<T>(path, init?)`         | Authenticated call against the Akku API.             |\r\n\r\n`resolvePurposeStates`, `basisOf` and `purposesNeedingDecision` are also exported as pure functions,\r\nfor deciding against purposes and a stored record you already hold.\r\n\r\n## Optional UI helpers\r\n\r\n```ts\r\nimport { … } from \"@akku-work/consent-sdk-auth/ui\";\r\n```\r\n\r\nA separate entry point on purpose. An app that never imports it pays zero bundle cost — `index.ts`\r\nnever reaches into it.\r\n\r\n## Licence\r\n\r\nProprietary. See [LICENSE](./LICENSE) — publication on npm grants no licence to use this software.\r\n","readmeFilename":"README.md","_rev":"1-79f1fbced5b2a2460e185c923e9bd7ac"}