{"_id":"@algovoi/audit-verifier","_rev":"4-441d434223883307e476ebcc4a512192","name":"@algovoi/audit-verifier","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@algovoi/audit-verifier","version":"0.1.0","keywords":["algovoi","audit","verifier","jcs","rfc8785","hash-chain","compliance","agentic-payments"],"author":{"name":"AlgoVoi","email":"chopmob@gmail.com"},"license":"MIT","_id":"@algovoi/audit-verifier@0.1.0","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"homepage":"https://verify.algovoi.co.uk","bugs":{"url":"https://github.com/chopmob-cloud/algovoi-audit-verifier/issues"},"dist":{"shasum":"ebdb5b09d6cb647bb2c122acc1b8eddbbf4b61b1","tarball":"https://registry.npmjs.org/@algovoi/audit-verifier/-/audit-verifier-0.1.0.tgz","fileCount":43,"integrity":"sha512-AiKawcMOIilPJ9pBOrwjPlUDLb6DCCm4NRU2n5zs45ciqgQpeiZkfngQsw4oMVng7aa6HryfqFY7uECm4li6yg==","signatures":[{"sig":"MEUCIQCxejzhstawZRjxGwdpSaqeR/ngq1HtQavcZDGwhJdZCgIgeYlwjAtaq/altU4og0WkD9Jga3eUTkO5jTo4TLCAL7c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108442},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ed58eb8d280a6256d2d8e775747de6f828eb758f","scripts":{"test":"vitest run","build":"tsc","clean":"rimraf dist","test:watch":"vitest","prepublishOnly":"npm run clean && npm run build && npm test"},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"repository":{"url":"git+https://github.com/chopmob-cloud/algovoi-audit-verifier.git","type":"git","directory":"typescript"},"_npmVersion":"11.6.2","description":"Standalone reference verifier for AlgoVoi selective-disclosure audit bundles. TypeScript port; byte-for-byte parity with the Python algovoi-audit-verifier.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"canonicalize":"^3.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^5.0.0","vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-verifier_0.1.0_1779560716010_0.33942729464441634","host":"s3://npm-registry-packages-npm-production"},"deprecated":"No longer maintained on npm. AlgoVoi keystone packages are now distributed via PyPI. See https://algovoi.co.uk"},"0.1.1":{"name":"@algovoi/audit-verifier","version":"0.1.1","keywords":["algovoi","audit","verifier","jcs","rfc8785","hash-chain","compliance","agentic-payments"],"author":{"name":"AlgoVoi","email":"chopmob@gmail.com"},"license":"MIT","_id":"@algovoi/audit-verifier@0.1.1","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"homepage":"https://verify.algovoi.co.uk","bugs":{"url":"https://github.com/chopmob-cloud/algovoi-audit-verifier/issues"},"dist":{"shasum":"04805977157219f4c58a2684709b0c2a054eed58","tarball":"https://registry.npmjs.org/@algovoi/audit-verifier/-/audit-verifier-0.1.1.tgz","fileCount":43,"integrity":"sha512-7J7jXJkkmzNiD6Dkfth0ZIZMLgpJ4SPqz5TLEko0O8Z+gJv4aztnHIlz1P0dld7hEzztWesmmPOQ+3pNllNeew==","signatures":[{"sig":"MEQCIA7Ci+NCLDse4YcYhZCLP+YksIlgAKyJsY9M4nmqfeyJAiBPnRY70+aV2y7ExEAqjpmcVDl/wjUQa2POOK4V3Dbc0A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":110953},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"6b88ddb80dccddce5731cce69cf9147c4daf95b5","scripts":{"test":"vitest run","build":"tsc","clean":"rimraf dist","test:watch":"vitest","prepublishOnly":"npm run clean && npm run build && npm test"},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"repository":{"url":"git+https://github.com/chopmob-cloud/algovoi-audit-verifier.git","type":"git","directory":"typescript"},"_npmVersion":"11.6.2","description":"Standalone reference verifier for AlgoVoi selective-disclosure audit bundles. TypeScript port; byte-for-byte parity with the Python algovoi-audit-verifier.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"canonicalize":"^3.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^5.0.0","vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-verifier_0.1.1_1779805542761_0.17276815808096302","host":"s3://npm-registry-packages-npm-production"},"deprecated":"No longer maintained on npm. AlgoVoi keystone packages are now distributed via PyPI. See https://algovoi.co.uk"},"0.1.2":{"name":"@algovoi/audit-verifier","version":"0.1.2","keywords":["algovoi","audit","verifier","jcs","rfc8785","hash-chain","compliance","agentic-payments"],"author":{"name":"AlgoVoi","email":"chopmob@gmail.com"},"license":"Apache-2.0","_id":"@algovoi/audit-verifier@0.1.2","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"homepage":"https://verify.algovoi.co.uk","bugs":{"url":"https://github.com/chopmob-cloud/algovoi-audit-verifier/issues"},"dist":{"shasum":"db4a7a9fb2dd9c9f8bc4e55f812e7df11d28b833","tarball":"https://registry.npmjs.org/@algovoi/audit-verifier/-/audit-verifier-0.1.2.tgz","fileCount":43,"integrity":"sha512-1ZZwOYeIk4HzgstksobuGI6pbn/RMRBx0h0D0uj+nY0Pl7sgHwRjo7X4CUqFNocNdJZUPEvJVVKFB+np3Eb2oQ==","signatures":[{"sig":"MEYCIQC0ylGnY43olyi5mLdBnNbXQpm3oB4rHy+5gfKOAY5iLAIhAMi55SMuKrg9IAhResKhhhMxO8z+KHOzF1ypPd5XSUsX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":121219},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c77e5aeae7cd8f32ba75eef48a4ebf88982bc6e6","scripts":{"test":"vitest run","build":"tsc","clean":"rimraf dist","test:watch":"vitest","prepublishOnly":"npm run clean && npm run build && npm test"},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"repository":{"url":"git+https://github.com/chopmob-cloud/algovoi-audit-verifier.git","type":"git","directory":"typescript"},"_npmVersion":"11.6.2","description":"Standalone reference verifier for AlgoVoi selective-disclosure audit bundles. TypeScript port; byte-for-byte parity with the Python algovoi-audit-verifier.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"canonicalize":"^3.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^5.0.0","vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/audit-verifier_0.1.2_1779941117661_0.058770350876476085","host":"s3://npm-registry-packages-npm-production"},"deprecated":"No longer maintained on npm. AlgoVoi keystone packages are now distributed via PyPI. See https://algovoi.co.uk"}},"time":{"created":"2026-05-23T18:25:15.830Z","modified":"2026-06-30T19:45:54.675Z","0.1.0":"2026-05-23T18:25:16.153Z","0.1.1":"2026-05-26T14:25:42.893Z","0.1.2":"2026-05-28T04:05:17.806Z"},"bugs":{"url":"https://github.com/chopmob-cloud/algovoi-audit-verifier/issues"},"author":{"name":"AlgoVoi","email":"chopmob@gmail.com"},"license":"Apache-2.0","homepage":"https://verify.algovoi.co.uk","keywords":["algovoi","audit","verifier","jcs","rfc8785","hash-chain","compliance","agentic-payments"],"repository":{"url":"git+https://github.com/chopmob-cloud/algovoi-audit-verifier.git","type":"git","directory":"typescript"},"description":"Standalone reference verifier for AlgoVoi selective-disclosure audit bundles. TypeScript port; byte-for-byte parity with the Python algovoi-audit-verifier.","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"readme":"# @algovoi/audit-verifier (TypeScript)\r\n\r\nTypeScript reference verifier for AlgoVoi selective-disclosure audit bundles.\r\nByte-for-byte parity with the Python sibling\r\n[`algovoi-audit-verifier`](https://pypi.org/project/algovoi-audit-verifier/)\r\non PyPI.\r\n\r\nStandalone — auditor-runnable on any Node.js 18+ machine with no AlgoVoi\r\ninfrastructure trust required.\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install @algovoi/substrate canonicalize        # peer deps\r\nnpm install @algovoi/audit-verifier\r\n```\r\n\r\nOr just install the package directly (canonicalize is a dependency, pulled\r\nautomatically):\r\n\r\n```bash\r\nnpm install @algovoi/audit-verifier\r\n```\r\n\r\n## Three ways to verify\r\n\r\n### 1. Hosted endpoint (zero install)\r\n\r\nPOST your bundle to `https://verify.algovoi.co.uk/verify` and get a\r\nstructured verification report. Same code path as this package.\r\n\r\n### 2. Programmatic use\r\n\r\n```ts\r\nimport { verifyBundle } from '@algovoi/audit-verifier';\r\n\r\nconst bundle = JSON.parse(fs.readFileSync('audit-bundle.json', 'utf-8'));\r\nconst report = await verifyBundle(bundle, {\r\n  signingKey: process.env.AUDIT_BUNDLE_KEY,  // optional\r\n});\r\n\r\nconsole.log(report.render());                 // human-readable PASS/FAIL\r\nconsole.log(report.toJSON());                 // machine-readable\r\nif (!report.allPassed) process.exit(1);\r\n```\r\n\r\n### 3. Demo + smoke test\r\n\r\n```ts\r\nimport { buildDemoBundle, verifyBundle } from '@algovoi/audit-verifier';\r\n\r\nconst bundle = buildDemoBundle({ chainName: 'audit_log', rowCount: 3 });\r\nconst report = await verifyBundle(bundle, {\r\n  signingKey: 'demo-key-not-for-production-use',\r\n});\r\nconsole.log(report.allPassed);   // true\r\n```\r\n\r\n## What this verifier checks\r\n\r\n| # | Check | What it proves |\r\n|---|---|---|\r\n| 1 | `per_row_content_hash` | Each row's stored `content_hash` matches `SHA-256(JCS(canonical-fields))` — per-row tamper-evidence |\r\n| 2 | `continuity` | `prev_hash` walks unbroken across `rows + bridging_rows` ordered by `chain_position` — no fabricated gap or reorder |\r\n| 3 | `bundle_signature` | HMAC-SHA256 over `JCS(bundle - signature)` matches `bundle_signature.hex` — proves AlgoVoi emission (when signing key supplied) |\r\n| 4 | `selection_criteria_match` | Selected rows actually match the filter declared in `selection_criteria` (when exact-match filters are set) |\r\n| 5 | `off_vm_anchor` | Off-VM Object-Lock manifest tail entry matches `chain_anchor.current_head` (when `manifestDir` supplied) |\r\n\r\nA bundle that passes all five checks (or has them skipped for legitimate\r\nreasons — no signing key supplied, no manifest available, etc.) has its\r\n`all_passed` set to `true`.\r\n\r\n## Cross-implementation parity\r\n\r\nThis TypeScript verifier is **byte-for-byte equivalent** to the Python\r\nsibling on PyPI:\r\n\r\n| Implementation | Package |\r\n|---|---|\r\n| Python | [`algovoi-audit-verifier`](https://pypi.org/project/algovoi-audit-verifier/) |\r\n| TypeScript | `@algovoi/audit-verifier` (this package) |\r\n\r\nBoth verifiers produce identical:\r\n- JCS canonical bytes for the same input object (RFC 8785)\r\n- SHA-256 hash for the same canonical preimage\r\n- HMAC-SHA256 signature for the same `(bundle - signature, key)` pair\r\n- Per-row `content_hash` for the same row content\r\n- Check report shape (`all_passed`, `fatal[]`, `checks[]`)\r\n\r\nThe parity is exercised by 9 cross-impl tests in this repo's\r\n`test/parity.test.ts`, which generate bundles in Python and verify them in\r\nTypeScript (and vice versa).\r\n\r\n## Substrate\r\n\r\nThis verifier composes against the AlgoVoi-authored canonicalisation substrate:\r\n\r\n- Spec: [docs.algovoi.co.uk/canonicalisation-substrate](https://docs.algovoi.co.uk/canonicalisation-substrate) (v1) and [docs.algovoi.co.uk/canonicalisation-substrate-v2](https://docs.algovoi.co.uk/canonicalisation-substrate-v2) (v2, PQC-aware)\r\n- IETF I-D: [`draft-hopley-x402-canonicalisation-jcs-v1`](https://datatracker.ietf.org/doc/draft-hopley-x402-canonicalisation-jcs-v1/) (Independent Submission, Informational, sole AlgoVoi authorship)\r\n- Upstream spec PR: [x402#2453](https://github.com/x402-foundation/x402/pull/2453) (replaces closed #2436)\r\n- Pin: `urn:x402:canonicalisation:jcs-rfc8785-v1`\r\n- Substrate SDK: [`@algovoi/substrate`](https://www.npmjs.com/package/@algovoi/substrate)\r\n- 53-vector conformance corpus: [`chopmob-cloud/algovoi-jcs-conformance-vectors`](https://github.com/chopmob-cloud/algovoi-jcs-conformance-vectors)\r\n\r\n## Hosted equivalent\r\n\r\nThe same code path runs at <https://verify.algovoi.co.uk> behind nginx + Cloudflare on a dedicated VM. POST any audit bundle to `/verify` and get back the same `CheckReportJSON` shape this package returns programmatically.\r\n\r\n## Conformance to the canonicalisation discipline\r\n\r\nThis verifier consumes receipts pinned to `canon_version: jcs-rfc8785-v1` (or `jcs-rfc8785-v2` under the strictly-additive PQC-aware discipline). The pin selects which canonicalisation rule the verifier applies at receipt-bytes verification time. A receipt without a recognised `canon_version` pin is treated as opaque; the verifier fails closed rather than guessing the rule.\r\n\r\n## Substrate adopters\r\n\r\nAlgoVoi is recorded in the [Substrate Adopters Registry](https://docs.algovoi.co.uk/adopters) as the substrate author. Parties anchoring their own services or specifications to `canon_version: jcs-rfc8785-v1` (or v2) are recorded in the registry via the [submission process](https://docs.algovoi.co.uk/adopters#how-to-submit-an-adoption-entry). AlgoVoi validates submissions against the artefact's canonical bytes and adds qualifying entries.\r\n\r\n## Licence\r\n\r\nApache 2.0. See `LICENSE`.\r\n\r\n## Author\r\n\r\nAlgoVoi (Christopher Hopley, GitHub [`chopmob-cloud`](https://github.com/chopmob-cloud)).\r\n","readmeFilename":"README.md"}