{"_id":"@algovoi/tap-verifier","_rev":"2-d1fcf922438dcbd4875c0bf2d8f0c3c4","name":"@algovoi/tap-verifier","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@algovoi/tap-verifier","version":"0.1.0","keywords":["trusted-agent-protocol","tap","visa","receipt","audit","jcs","rfc8785","ed25519","verifier"],"author":{"name":"AlgoVoi"},"license":"Apache-2.0","_id":"@algovoi/tap-verifier@0.1.0","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"homepage":"https://docs.algovoi.co.uk/keystone","bin":{"algovoi-tap-verifier":"dist/cli.js"},"dist":{"shasum":"23051275662b38258c3b4b94cdabba622b49a1dd","tarball":"https://registry.npmjs.org/@algovoi/tap-verifier/-/tap-verifier-0.1.0.tgz","fileCount":13,"integrity":"sha512-adgIeUwUlKGwKN7zXqkh3MCzjih86kB6vPi35sqHd+m2yORe+RchoPo1P8mDJMcuqvnZbAidh+Ch9qM/aZIIqw==","signatures":[{"sig":"MEUCIQCDpw98UgdL48i+8ddPfrdtftbiy38WbqqgQ/vF9KkOjwIgeMNWtzAlbSiudmLzbAcZqVOTAp6tuXeYSii2V9xKDxA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25806},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc","clean":"rimraf dist","prepublishOnly":"npm run clean && npm run build && npm test"},"_npmUser":{"name":"algovoi","email":"chopmob@gmail.com"},"_npmVersion":"11.6.2","description":"Offline verifier for AlgoVoi TAP receipts (Visa Trusted Agent Protocol post-authentication audit trail). Re-derives the JCS RFC 8785 receipt_id and checks the Ed25519 signature with public libraries only. Byte-identical to algovoi-tap-verifier (PyPI). Apa","directories":{},"_nodeVersion":"24.12.0","dependencies":{"canonicalize":"^3.0.0"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^5.0.0","vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/tap-verifier_0.1.0_1782408633262_0.0336168929040388","host":"s3://npm-registry-packages-npm-production"},"deprecated":"No longer maintained on npm. AlgoVoi keystone packages are now distributed via PyPI. See https://algovoi.co.uk"}},"time":{"created":"2026-06-25T17:30:33.103Z","modified":"2026-06-30T19:45:44.761Z","0.1.0":"2026-06-25T17:30:33.394Z"},"author":{"name":"AlgoVoi"},"license":"Apache-2.0","homepage":"https://docs.algovoi.co.uk/keystone","keywords":["trusted-agent-protocol","tap","visa","receipt","audit","jcs","rfc8785","ed25519","verifier"],"description":"Offline verifier for AlgoVoi TAP receipts (Visa Trusted Agent Protocol post-authentication audit trail). Re-derives the JCS RFC 8785 receipt_id and checks the Ed25519 signature with public libraries only. Byte-identical to algovoi-tap-verifier (PyPI). Apa","maintainers":[{"name":"algovoi","email":"chopmob@gmail.com"}],"readme":"# @algovoi/tap-verifier\n\nVerify an **AlgoVoi TAP receipt** offline, with no AlgoVoi software. For the Visa Trusted Agent\nProtocol ecosystem ([trusted-agent-protocol#16](https://github.com/visa/trusted-agent-protocol/issues/16),\npost-authentication receipt signing). Byte-identical to [`algovoi-tap-verifier`](https://pypi.org/project/algovoi-tap-verifier/) (PyPI).\n\nAn AlgoVoi TAP receipt is a JCS-canonical (RFC 8785) preimage carrying the two-sided audit fact\n(`authorization_ref` + `transaction_hash` + timestamp/sequence), a content-addressed `receipt_id`, an\n**Ed25519** signature (TAP-native), and optionally a **Falcon-1024** post-quantum signature. This\npackage re-derives `receipt_id` and checks Ed25519 with only the `canonicalize` (RFC 8785) package and\nNode's built-in `crypto`. No dependency on any AlgoVoi package.\n\n## Install\n\n```\nnpm install @algovoi/tap-verifier\n```\n\n## Use\n\n```ts\nimport { verifyTapReceipt } from '@algovoi/tap-verifier';\n\nconst r = verifyTapReceipt(receipt, { ed25519PublicKey: ed25519RawPublicKey /* 32 bytes */ });\nr.ok;        // true iff every check passed\nr.checks;    // [{ check, ok, note? }, ...]\n```\n\n```\nnpx algovoi-tap-verifier receipt.json --ed25519 <b64>      # CLI\n```\n\nThe Falcon-1024 signature (when present) is reported as skipped in this JS build (no standard JS\nFalcon library); the Ed25519 check alone is conclusive for TAP-native verification. To also check\nFalcon-1024, use the Python verifier with the `pqc` extra.\n\nApache-2.0. Receipt *emission* (keystone -> signed TAP receipt) is a separate commercial AlgoVoi product.\n","readmeFilename":"README.md"}