{"_id":"@alexar76/awr-verify","name":"@alexar76/awr-verify","dist-tags":{"latest":"2.0.0"},"versions":{"2.0.0":{"name":"@alexar76/awr-verify","version":"2.0.0","description":"Verify an AWR/2 work receipt in Node or the browser with zero dependencies — W3C Verifiable Credential, eddsa-jcs-2022 over RFC 8785, did:key. One of three implementations passing the AWR/2 conformance suite.","keywords":["awr","work-receipt","provenance","verifiable-credentials","w3c-vc","data-integrity","eddsa-jcs-2022","rfc8785","jcs","did-key","ed25519","verifier","audit","zero-dependency"],"main":"verifier.js","bin":{"awr-verify":"cli.js"},"exports":{".":"./verifier.js"},"engines":{"node":">=20"},"author":{"name":"AICOM","url":"alexar76"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/alexar76/aicom.git","directory":"docs/verifier/js"},"homepage":"https://verify.modelmarket.dev","bugs":{"url":"https://github.com/alexar76/aicom/issues"},"publishConfig":{"access":"public"},"dependencies":{},"devDependencies":{},"_id":"@alexar76/awr-verify@2.0.0","gitHead":"7aeaed57bfdfe0e852d40bdf80f0065bbb5ebcde","_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-iOyl4to5xlGFRoeFqnLjHydfyOFml6+1H4ALwWPjeagXwtfZ97tYnH6WN7ysH1YDcNF21AjEF59LVyjowd5V5Q==","shasum":"f849d86c91fcc0c11051f8833543043992ca508a","tarball":"https://registry.npmjs.org/@alexar76/awr-verify/-/awr-verify-2.0.0.tgz","fileCount":5,"unpackedSize":139456,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCY5DMUBDNIc4RCXbKyVoay+gGeq+Jk0/ytdckyjRnpJQIhAOkbuAKBnFa6/PciOOLfhMO9DheAPsQz0jrku4GWNyUg"}]},"_npmUser":{"name":"alexar76","email":"alexar76@rambler.ru"},"directories":{},"maintainers":[{"name":"alexar76","email":"alexar76@rambler.ru"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/awr-verify_2.0.0_1785786755853_0.39133991201196183"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-03T19:52:35.690Z","2.0.0":"2026-08-03T19:52:36.002Z","modified":"2026-08-03T19:52:36.225Z"},"maintainers":[{"name":"alexar76","email":"alexar76@rambler.ru"}],"description":"Verify an AWR/2 work receipt in Node or the browser with zero dependencies — W3C Verifiable Credential, eddsa-jcs-2022 over RFC 8785, did:key. One of three implementations passing the AWR/2 conformance suite.","homepage":"https://verify.modelmarket.dev","keywords":["awr","work-receipt","provenance","verifiable-credentials","w3c-vc","data-integrity","eddsa-jcs-2022","rfc8785","jcs","did-key","ed25519","verifier","audit","zero-dependency"],"repository":{"type":"git","url":"git+https://github.com/alexar76/aicom.git","directory":"docs/verifier/js"},"author":{"name":"AICOM","url":"alexar76"},"bugs":{"url":"https://github.com/alexar76/aicom/issues"},"license":"MIT","readme":"# @alexar76/awr-verify\n\nVerify an [AWR/2](https://github.com/alexar76/aicom/blob/main/awr/SPEC.md) work receipt. **Zero\ndependencies**, runs in Node and unchanged in a browser.\n\nThis is the same code that runs at <https://verify.modelmarket.dev>, and one of the three\nimplementations that pass the AWR/2 conformance suite — the others are the Python reference and a\nRust implementation written from the specification text alone. All three agree on 354 vectors.\n\n```bash\nnpm install @alexar76/awr-verify\n```\n\n```js\nconst awr = require('@alexar76/awr-verify');\n\n// async: the Ed25519 check goes through WebCrypto, which is promise-based\nconst result = await awr.verify(receipt);\nresult.valid       // true | false\nresult.reasons     // [{ code: 'AWR-PROOF-006', severity: 'error', detail: '…' }, …]\nresult.warnings    // same shape; does not invalidate the document\nresult.profile     // 'L0' | 'L1' | 'L2' | null\n```\n\nForgetting the `await` gives you a `Promise` whose `.valid` is `undefined` — which is falsy, so a\nnaive `if (result.valid)` fails closed rather than passing a bad receipt. It is still a bug, and\nthat is the one to check first if a receipt you believe in comes back invalid.\n\nOr from the command line, which implements the §17 CLI contract — exit 0 valid, 1 invalid,\n2 usage/IO, 3 unimplemented:\n\n```bash\nnpx awr-verify verify receipt.json\nnpx awr-verify canonicalize receipt.json    # the RFC 8785 canonical bytes\nnpx awr-verify digest receipt.json          # sha256-<base64> over those bytes\nnpx awr-verify hashdata receipt.json        # proofConfigHash, documentHash, hashData\n```\n\n## What a valid receipt means\n\nExactly this: **this issuer signed these claims, and the bytes are intact.** Attribution, and\nnothing more. It does not mean the model ran, that the digests correspond to real payloads, that\nthe price was paid, or that the output is correct. A verifier that told you otherwise would be\nlying to you, so this one does not.\n\nVerification is offline. It makes no network request — no registry, no blockchain, no call home,\nnot even to the AWR namespace URI in `@context`, which the specification forbids fetching (§13.5).\nNothing about the receipt you check is reported anywhere.\n\n## Reading the result\n\n`reasons` carries error codes; `warnings` carries things you should know but that do not invalidate\nthe document. Age is a warning on purpose: a receipt from two years ago is exactly as\ncryptographically sound as one from today, and audit is the main reason old receipts get read.\n\nReceipts issued under AWR/1, the pre-standard format, still verify — under explicit warnings\nsaying which fields that older signature did *not* cover, because they are not the same guarantee.\n\n## The other half\n\nTo *write* receipts rather than read them, see\n[`@alexar76/awr-emit`](https://www.npmjs.com/package/@alexar76/awr-emit) — also zero-dependency,\nand it ships an MCP tool-call wrapper. They are separate packages deliberately: a component that\nboth issues and judges its own work is not evidence of anything.\n\n## Links\n\n- Specification: <https://github.com/alexar76/aicom/blob/main/awr/SPEC.md>\n- Paste a receipt into the browser build: <https://verify.modelmarket.dev>\n- Python verifier: <https://pypi.org/project/awr/>\n\nMIT.\n","readmeFilename":"README.md","_rev":"1-db426632547630189ef60529af56c3be"}