{"_id":"@algovoi/substrate-pqc","_rev":"3-3189d150d4981ebc26760620f723a6b7","name":"@algovoi/substrate-pqc","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@algovoi/substrate-pqc","version":"0.1.0","keywords":["pqc","post-quantum","falcon","ml-dsa","dilithium","jcs","rfc8785","ap2","x402","agentic-payments","substrate","canonicalisation"],"author":{"url":"chopmob-cloud","name":"AlgoVoi","email":"chopmob@gmail.com"},"license":"Apache-2.0","_id":"@algovoi/substrate-pqc@0.1.0","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"homepage":"https://github.com/chopmob-cloud/algovoi-substrate-pqc","bugs":{"url":"https://github.com/chopmob-cloud/algovoi-substrate-pqc/issues"},"dist":{"shasum":"3ce0b7361f174534ebfb70fab38c156cb23735a5","tarball":"https://registry.npmjs.org/@algovoi/substrate-pqc/-/substrate-pqc-0.1.0.tgz","fileCount":33,"integrity":"sha512-kyLnhiCnfTD/zdV6J0Sn+L0zq0fTnQ58cGvMMXb1p38JYVNdvxWQsBlDARJLEdwCr8bxySh7+AdlcYfuHqON1w==","signatures":[{"sig":"MEQCIFZx4fSisKMR8Cq9OEQqZM9102zQeBIOVPq80n53zVf8AiAIs+BTwsGttk4poTAbFzn89V6V9dEHeXkEs+SALEk6sw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":337743},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./sign":{"types":"./dist/sign.d.ts","import":"./dist/sign.js","require":"./dist/sign.cjs"},"./proof":{"types":"./dist/proof.d.ts","import":"./dist/proof.js","require":"./dist/proof.cjs"},"./verify":{"types":"./dist/verify.d.ts","import":"./dist/verify.js","require":"./dist/verify.cjs"},"./registry":{"types":"./dist/registry.d.ts","import":"./dist/registry.js","require":"./dist/registry.cjs"},"./canonical":{"types":"./dist/canonical.d.ts","import":"./dist/canonical.js","require":"./dist/canonical.cjs"}},"gitHead":"973f8f97b583a349a3c6a98820b81512b9a1d64b","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rimraf dist","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"repository":{"url":"git+https://github.com/chopmob-cloud/algovoi-substrate-pqc.git","type":"git"},"_npmVersion":"11.6.2","description":"AlgoVoi substrate-author layer for JCS+PQC integration: signature_algorithm open-enum + cross-implementor byte-anchor convergence proof. TypeScript companion to algovoi-substrate-pqc on PyPI.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"canonicalize":"^3.0.0","@noble/curves":"^2.0.0","@noble/hashes":"^2.0.0","@noble/post-quantum":"^0.6.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","rimraf":"^6.0.1","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/substrate-pqc_0.1.0_1779784838744_0.8244320532929064","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@algovoi/substrate-pqc","version":"0.1.1","keywords":["pqc","post-quantum","falcon","ml-dsa","dilithium","jcs","rfc8785","ap2","x402","agentic-payments","substrate","canonicalisation"],"author":{"url":"chopmob-cloud","name":"AlgoVoi","email":"chopmob@gmail.com"},"license":"Apache-2.0","_id":"@algovoi/substrate-pqc@0.1.1","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"homepage":"https://github.com/chopmob-cloud/algovoi-substrate-pqc","bugs":{"url":"https://github.com/chopmob-cloud/algovoi-substrate-pqc/issues"},"dist":{"shasum":"2b5acdbc46216c51e2d44414c0f406f3e00706e3","tarball":"https://registry.npmjs.org/@algovoi/substrate-pqc/-/substrate-pqc-0.1.1.tgz","fileCount":33,"integrity":"sha512-rYgcVEe3I1TxpeCVbIZQm94KoVVX7t+vlgM+fIXMAjB/dDWHgSlM7yEODl9/YNArQo5FsAS3shq9gBqW24lsXg==","signatures":[{"sig":"MEUCICuQnFwbW0o74wRNfmaNThduzbm1cljB1w3cOAGUIgwcAiEAvOHHD5CTAFbd7k333WS5LAqbIhzOegE+f4KNcpa1Crw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":339557},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./sign":{"types":"./dist/sign.d.ts","import":"./dist/sign.js","require":"./dist/sign.cjs"},"./proof":{"types":"./dist/proof.d.ts","import":"./dist/proof.js","require":"./dist/proof.cjs"},"./verify":{"types":"./dist/verify.d.ts","import":"./dist/verify.js","require":"./dist/verify.cjs"},"./registry":{"types":"./dist/registry.d.ts","import":"./dist/registry.js","require":"./dist/registry.cjs"},"./canonical":{"types":"./dist/canonical.d.ts","import":"./dist/canonical.js","require":"./dist/canonical.cjs"}},"gitHead":"4bc2c54be4ac646782386ae4ea00c7841930deb1","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rimraf dist","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"repository":{"url":"git+https://github.com/chopmob-cloud/algovoi-substrate-pqc.git","type":"git"},"_npmVersion":"11.6.2","description":"AlgoVoi substrate-author layer for JCS+PQC integration: signature_algorithm open-enum + cross-implementor byte-anchor convergence proof. TypeScript companion to algovoi-substrate-pqc on PyPI.","directories":{},"_nodeVersion":"24.12.0","dependencies":{"canonicalize":"^3.0.0","@noble/curves":"^2.0.0","@noble/hashes":"^2.0.0","@noble/post-quantum":"^0.6.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","rimraf":"^6.0.1","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/substrate-pqc_0.1.1_1779805174228_0.5026122936097186","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@algovoi/substrate-pqc","version":"0.1.2","description":"AlgoVoi substrate-author layer for JCS+PQC integration: signature_algorithm open-enum + cross-implementor byte-anchor convergence proof. TypeScript companion to algovoi-substrate-pqc on PyPI.","type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./registry":{"types":"./dist/registry.d.ts","import":"./dist/registry.js","require":"./dist/registry.cjs"},"./canonical":{"types":"./dist/canonical.d.ts","import":"./dist/canonical.js","require":"./dist/canonical.cjs"},"./sign":{"types":"./dist/sign.d.ts","import":"./dist/sign.js","require":"./dist/sign.cjs"},"./verify":{"types":"./dist/verify.d.ts","import":"./dist/verify.js","require":"./dist/verify.cjs"},"./proof":{"types":"./dist/proof.d.ts","import":"./dist/proof.js","require":"./dist/proof.cjs"}},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","clean":"rimraf dist"},"dependencies":{"@noble/curves":"^2.0.0","@noble/hashes":"^2.0.0","@noble/post-quantum":"^0.6.1","canonicalize":"^3.0.0"},"devDependencies":{"@types/node":"^22.10.0","rimraf":"^6.0.1","tsx":"^4.19.2","typescript":"^5.7.2","vitest":"^2.1.8"},"engines":{"node":">=18.0.0"},"keywords":["pqc","post-quantum","falcon","ml-dsa","dilithium","jcs","rfc8785","ap2","x402","agentic-payments","substrate","canonicalisation"],"license":"Apache-2.0","author":{"name":"AlgoVoi","email":"chopmob@gmail.com","url":"chopmob-cloud"},"repository":{"type":"git","url":"git+https://github.com/chopmob-cloud/algovoi-substrate-pqc.git"},"bugs":{"url":"https://github.com/chopmob-cloud/algovoi-substrate-pqc/issues"},"homepage":"https://github.com/chopmob-cloud/algovoi-substrate-pqc","gitHead":"ad811152f0bab0157891c999fc09a2b2b24bcb63","_id":"@algovoi/substrate-pqc@0.1.2","_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-aRWOm34qpPLVcxQLZpUrCuDVXthYIGhpdfQNdaK9zmkgtyaBphPyP87PxxCQ9tIVDAuWJktiE+GcJ36TI+yJdg==","shasum":"75255231d77cb97ff9549d3b70d3f587a3cff1f9","tarball":"https://registry.npmjs.org/@algovoi/substrate-pqc/-/substrate-pqc-0.1.2.tgz","fileCount":33,"unpackedSize":343829,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIDSP+xFonusDhDxtAgQkjterKTGLmtqrYZ1r1HXWiDh6AiEA9paF15rnAsMP9g8gGJ04BmXr7FrsrI4wV1bRNzMzom4="}]},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"directories":{},"maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/substrate-pqc_0.1.2_1779859975479_0.7119350339964343"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-26T08:40:38.647Z","modified":"2026-05-27T05:32:55.744Z","0.1.0":"2026-05-26T08:40:38.973Z","0.1.1":"2026-05-26T14:19:34.399Z","0.1.2":"2026-05-27T05:32:55.636Z"},"bugs":{"url":"https://github.com/chopmob-cloud/algovoi-substrate-pqc/issues"},"author":{"name":"AlgoVoi","email":"chopmob@gmail.com","url":"chopmob-cloud"},"license":"Apache-2.0","homepage":"https://github.com/chopmob-cloud/algovoi-substrate-pqc","keywords":["pqc","post-quantum","falcon","ml-dsa","dilithium","jcs","rfc8785","ap2","x402","agentic-payments","substrate","canonicalisation"],"repository":{"type":"git","url":"git+https://github.com/chopmob-cloud/algovoi-substrate-pqc.git"},"description":"AlgoVoi substrate-author layer for JCS+PQC integration: signature_algorithm open-enum + cross-implementor byte-anchor convergence proof. TypeScript companion to algovoi-substrate-pqc on PyPI.","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"readme":"# @algovoi/substrate-pqc\n\n**TypeScript companion to `algovoi-substrate-pqc` on PyPI.**\n\nAlgoVoi-authored substrate convention for binding canonical-JSON-serialised\npayloads to post-quantum signature primitives, with a fail-closed verifier\ndiscipline over an open-enum `signature_algorithm` registry.\n\n```\nnpm install @algovoi/substrate-pqc\n```\n\n## What this package provides\n\n| Component | Author | What it is |\n|---|---|---|\n| `signature_algorithm` open-enum registry | **AlgoVoi** | 12-row recommended-values table (case-sensitive lookup per RFC 7517 §4.1) |\n| `UnknownSignatureAlgorithmError` fail-closed rule | **AlgoVoi** | Verifiers MUST reject unknown identifiers |\n| JCS+PQC integration pattern | **AlgoVoi** | Canonical bytes via RFC 8785 → signature via chosen scheme |\n| Cross-implementor byte-anchor convergence proof | **AlgoVoi** | One canonical payload, N schemes, byte-identical SHA-256 |\n\n## Upstream primitives (NOT AlgoVoi-authored)\n\n| Primitive | Implementation | Author / Source |\n|---|---|---|\n| Falcon-1024 (FIPS 206 / FN-DSA) | [@noble/post-quantum](https://github.com/paulmillr/noble-post-quantum) v0.6.1+ | Paul Miller (MIT) |\n| ML-DSA-65 (FIPS 204) | [@noble/post-quantum](https://github.com/paulmillr/noble-post-quantum) v0.6.1+ | Paul Miller (MIT) |\n| ES256 (P-256 + SHA-256) | [@noble/curves](https://github.com/paulmillr/noble-curves) v2+ | Paul Miller (MIT) |\n| Ed25519 | [@noble/curves](https://github.com/paulmillr/noble-curves) v2+ | Paul Miller (MIT) |\n| SHA-256 | [@noble/hashes](https://github.com/paulmillr/noble-hashes) v2+ | Paul Miller (MIT) |\n| JCS canonicalisation (RFC 8785) | [canonicalize](https://www.npmjs.com/package/canonicalize) v3+ | Anders Rundgren / Erdtman et al. (Apache-2.0) |\n\nThe Falcon algorithm itself is the work of Fouque, Hoffstein, Kirchner,\nLyubashevsky, Pornin, Prest, Ricosset, Seiler, Whyte, and Zhang\n(NIST PQC competition; standardised as NIST FIPS 206). The ML-DSA algorithm\n(Dilithium / CRYSTALS-Dilithium) is the work of Bai, Ducas, Kiltz, Lepoint,\nLyubashevsky, Schwabe, Seiler, and Stehlé (standardised as NIST FIPS 204).\n\n### Falcon-1024 patent disclosure\n\nPatent **US7308097B2** may be applicable to parts of Falcon. William Whyte\n(one of the Falcon designers and representative of OnBoard Security, the\ncurrent patent holder) has pledged, as part of the IP statements submitted to\nNIST for the PQC project, that — with Falcon now selected for standardisation\n(FIPS 206) — a worldwide non-exclusive license is granted for the purpose of\nimplementing the standard \"without compensation and under reasonable terms\nand conditions that are demonstrably free of any unfair discrimination\". This\nis a FRAND-style royalty-free pledge tied to FIPS 206 standardisation.\n\nThis package is a downstream consumer of `@noble/post-quantum` and is not a\nredistributor of patent-encumbered Falcon source code. The Falcon-1024\nprimitive is provided through the `@noble/post-quantum` MIT-licensed\nimplementation. Any deployment using Falcon-1024 should review the FRAND\npledge for their use case.\n\n## PQC cross-implementor contribution\n\nThe ML-DSA-65 cross-implementor fixture this TypeScript package verifies\nagainst was contributed by **PQSafe ([@rayc0](https://github.com/rayc0))**\nper [AP2 #250](https://github.com/google-agentic-commerce/AP2/issues/250)\nand the joint conformance fixture at\n[`chopmob-cloud/ap2-pq-conformance`](https://github.com/chopmob-cloud/ap2-pq-conformance).\nThe contribution scope is the\n[`pqsafe-side/`](https://github.com/chopmob-cloud/ap2-pq-conformance/tree/main/pqsafe-side)\nML-DSA-65 signature over the canonical bytes the AlgoVoi-side fixture signs.\n**Credit is scoped to that ML-DSA-65 contribution only; substrate-author\nwork for this package (signature_algorithm convention, JCS+PQC binding\npattern, fail-closed verifier discipline) is AlgoVoi's.**\n\n## Cross-implementation interop\n\nThe 26-test suite includes byte-for-byte cross-validation against the\n[`chopmob-cloud/ap2-pq-conformance`](https://github.com/chopmob-cloud/ap2-pq-conformance)\nfixture set, which is the joint AlgoVoi (ES256 + Ed25519 + Falcon-1024) +\nPQSafe (ML-DSA-65) deliverable for AP2 #250. Both fixtures use the identical\n501-byte JCS canonical anchored at `sha256:cc8315f7…e0`.\n\n| Implementation | Falcon-1024 | ML-DSA-65 | Verifies the same artefact? |\n|---|---|---|---|\n| Python `pqcrypto` (PQClean) | signer | signer | yes |\n| TypeScript `@noble/post-quantum` | verifier | verifier | yes |\n\nTwo independent PQC implementations agreeing on the same canonical bytes is\nthe substrate-determinism property the AlgoVoi-substrate convention rests on.\n\n## API surface (mirror of Python)\n\n```typescript\nimport {\n  // registry\n  lookupSignatureAlgorithm,\n  KNOWN_SIGNATURE_ALGORITHMS,\n  UnknownSignatureAlgorithmError,\n\n  // canonical bytes\n  jcsCanonicalBytes,\n  jcsCanonicalSha256Hex,\n\n  // sign (sign, then verify; or build cross-impl artefacts)\n  signES256,\n  signEd25519,\n  signFalcon1024,\n  signMLDSA65,\n  generateFalcon1024Keypair,\n  generateMLDSA65Keypair,\n  generateES256SecretKey,\n  generateEd25519SecretKey,\n\n  // verify\n  verifyES256,\n  verifyEd25519,\n  verifyFalcon1024,\n  verifyMLDSA65,\n  verifySignature,\n  verifyArtefact,\n\n  // cross-implementor convergence\n  buildConvergenceArtefact,\n  canonicalAnchorFromPayload,\n} from '@algovoi/substrate-pqc';\n```\n\n## Verifier discipline (fail-closed)\n\n> Verifiers MUST treat unknown `signature_algorithm` values as opaque and\n> refuse to verify.\n\nThis is the fail-closed normative rule. The TypeScript implementation\nsurfaces this as `UnknownSignatureAlgorithmError` thrown from\n`lookupSignatureAlgorithm`. Implementors MAY declare any value; verifiers\nMUST reject unknown values rather than guessing.\n\n## ECDSA signature normalisation note\n\nThis package's `verifyES256` accepts both low-S and high-S ECDSA signatures\n(passes `lowS: false` to `@noble/curves`). Many ECDSA implementations\n(notably Python `cryptography`) emit signatures without restricting `s` to\nthe lower half of the curve order. The AlgoVoi-substrate verifier\nprioritises cross-implementation interop: any valid ECDSA signature is\naccepted. Deployments that need signature-malleability defence should\npost-validate signatures with the strict `lowS: true` policy.\n\n## Conformance to the canonicalisation discipline\n\nThis package is the AlgoVoi-authored TypeScript reference implementation of\nthe v2 (PQC-aware) canonicalisation discipline at\n[`urn:x402:canonicalisation:jcs-rfc8785-v2`](https://docs.algovoi.co.uk/canonicalisation-substrate-v2),\nthe strictly-additive successor to\n[`urn:x402:canonicalisation:jcs-rfc8785-v1`](https://docs.algovoi.co.uk/canonicalisation-substrate).\nThe canonicalisation core (RFC 8785 JCS plus schema-normalisation rules) is\nunchanged between v1 and v2; v2 adds the `signature_algorithm` open-enum\nregistry and the fail-closed verifier discipline this package implements.\n\n> **IETF Internet-Draft status.** An IETF Internet-Draft formalising\n> `urn:x402:canonicalisation:jcs-rfc8785-v2` under the Independent Submissions\n> stream is **pending** an active IETF list thread (May 2026) on the\n> appropriate scope and use of the Independent Submissions stream for\n> x402-related substrate documentation. The v2 discipline is published on\n> `docs.algovoi.co.uk/canonicalisation-substrate-v2`, in this reference\n> implementation, and in the\n> [Substrate Adopters Registry](https://docs.algovoi.co.uk/adopters)\n> independently of that process.\n\n## Substrate adopters\n\nAlgoVoi is recorded in the [Substrate Adopters Registry](https://docs.algovoi.co.uk/adopters)\nas the substrate author (v1 and v2). Parties anchoring their own services\nor specifications to `canon_version: jcs-rfc8785-v2` are recorded in the\nregistry via the [submission process](https://docs.algovoi.co.uk/adopters#how-to-submit-an-adoption-entry).\nAlgoVoi validates submissions against the artefact's canonical bytes and\nadds qualifying entries. v1 adopters retain their registry position; adopting\nv2 adds a separate row pinned to `jcs-rfc8785-v2` rather than replacing the v1 row.\n\n## License\n\nApache 2.0.\n\n## Author\n\nAlgoVoi (chopmob-cloud) — chopmob@gmail.com\n","readmeFilename":"README.md"}