{"_id":"@alexar76/awr-emit","name":"@alexar76/awr-emit","dist-tags":{"latest":"2.0.0"},"versions":{"2.0.0":{"name":"@alexar76/awr-emit","version":"2.0.0","description":"Emit a signed AWR/2 WorkReceipt from Node with zero runtime dependencies — W3C Verifiable Credential, eddsa-jcs-2022 over RFC 8785, did:key. Includes an MCP tool-call wrapper.","keywords":["awr","work-receipt","provenance","verifiable-credentials","w3c-vc","data-integrity","eddsa-jcs-2022","rfc8785","jcs","did-key","ed25519","mcp","ai-agent","audit","zero-dependency"],"type":"module","main":"awr-emit.mjs","exports":{".":"./awr-emit.mjs","./mcp":"./mcp-middleware.mjs"},"engines":{"node":">=22"},"scripts":{"test":"node --test test.mjs"},"author":{"name":"AICOM","url":"alexar76"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/alexar76/aicom.git","directory":"awr/emitters/typescript"},"homepage":"https://verify.modelmarket.dev","bugs":{"url":"https://github.com/alexar76/aicom/issues"},"publishConfig":{"access":"public"},"dependencies":{},"devDependencies":{},"_id":"@alexar76/awr-emit@2.0.0","gitHead":"c567f866b5528b8da2ac9197dca17e22c0e19d3a","_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-1ZVszoYUtDUHzeRSNHr/aFKHCIbZ5FZlDggG/+HP2BhNdLTdtIpdTpJRGMjEqIWfVotaSM4LB1fYWwjHK8Juow==","shasum":"6379520201cb52ef9c28b6aab6bb954b50f1bd8f","tarball":"https://registry.npmjs.org/@alexar76/awr-emit/-/awr-emit-2.0.0.tgz","fileCount":5,"unpackedSize":20676,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFoAna3Z8CbOaCPjmVOzYEyT0B1PmsrjVL4yhNvwcvf8AiA9zTTOkyOwS92lSNUyAKU+4I4MDuiTQ19nL9NUKvc3qw=="}]},"_npmUser":{"name":"alexar76","email":"alexar76@rambler.ru"},"directories":{},"maintainers":[{"name":"alexar76","email":"alexar76@rambler.ru"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/awr-emit_2.0.0_1785754729718_0.6838661727732818"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-03T10:58:49.586Z","2.0.0":"2026-08-03T10:58:49.835Z","modified":"2026-08-03T10:58:50.028Z"},"maintainers":[{"name":"alexar76","email":"alexar76@rambler.ru"}],"description":"Emit a signed AWR/2 WorkReceipt from Node with zero runtime dependencies — W3C Verifiable Credential, eddsa-jcs-2022 over RFC 8785, did:key. Includes an MCP tool-call wrapper.","homepage":"https://verify.modelmarket.dev","keywords":["awr","work-receipt","provenance","verifiable-credentials","w3c-vc","data-integrity","eddsa-jcs-2022","rfc8785","jcs","did-key","ed25519","mcp","ai-agent","audit","zero-dependency"],"repository":{"type":"git","url":"git+https://github.com/alexar76/aicom.git","directory":"awr/emitters/typescript"},"author":{"name":"AICOM","url":"alexar76"},"bugs":{"url":"https://github.com/alexar76/aicom/issues"},"license":"MIT","readme":"# @alexar76/awr-emit\n\nEmit a signed [AWR/2](https://github.com/alexar76/aicom/blob/main/awr/SPEC.md) `WorkReceipt`\nfrom Node. **Zero runtime dependencies** — the RFC 8785 canonicalizer, base58btc, `did:key`\nderivation and the Ed25519 signing all sit in one file over `node:crypto`.\n\nThere are two sides to AWR and they need different code. A **verifier** reads a receipt and\nchecks it. An **emitter** writes one: it takes what your system just did and signs a document\nsaying so. This is an emitter, and it verifies nothing — deliberately, because a component that\nboth issues and judges its own work is not evidence of anything.\n\n```bash\nnpm install @alexar76/awr-emit\n```\n\n```js\nimport { emitReceipt, generateKey, jcsPayload } from '@alexar76/awr-emit';\n\nconst key = generateKey();              // keep this; its .did is your issuer identity\n\nconst receipt = emitReceipt({\n  key,\n  modelId: 'claude-opus-5@anthropic',\n  inputPayload: jcsPayload({ prompt: 'summarise this', n: 3 }),\n  outputPayload: '...the model\\'s answer...',\n  latencyMs: 2340,\n});\n```\n\n`receipt` is a plain object, ready for `JSON.stringify`. Anyone can check it without this\npackage and without trusting you:\n\n```bash\npip install awr\npython -m awr verify receipt.json\n```\n\n## MCP tool calls\n\n`./mcp` wraps an MCP tool handler so every call it serves produces a receipt — including the\ncalls that fail, because an unverifiable failure is what a dispute usually turns on.\n\n```js\nimport { withAwrReceipts } from '@alexar76/awr-emit/mcp';\n\nconst handler = withAwrReceipts(myToolHandler, {\n  key,\n  modelId: 'my-server@v1',\n  onReceipt: (doc, err) => save(doc),   // required: a receipt nobody keeps is not evidence\n});\n```\n\n## Cross-implementation agreement\n\nThe [Python emitter](https://github.com/alexar76/aicom/tree/main/awr/emitters/python) and this\none produce **byte-identical documents** for the same inputs and key. That is not a claim, it is\na test:\n`test_the_typescript_emitter_agrees_byte_for_byte` runs Node from pytest and compares the bytes,\nand the timestamp-derivation rules are pinned on both sides after a real divergence was found by\ndiffing partial inputs.\n\nThe format itself has three independent verifiers — Python, Rust and browser JavaScript — that\nagree on 354 conformance cases, and an unmodified off-the-shelf W3C VC library verifies these\ndocuments given nothing but a `did:key` resolver.\n\n## Links\n\n- Specification: <https://github.com/alexar76/aicom/blob/main/awr/SPEC.md>\n- Paste a receipt into a browser verifier: <https://verify.modelmarket.dev>\n- Verifier package for Python: <https://pypi.org/project/awr/>\n\nMIT.\n","readmeFilename":"README.md","_rev":"1-1bc74f5d84e17f8cf2b93c6e3de60a1e"}