{"_id":"@allowly/sdk","_rev":"7-5d5f21b0d414b6a38eb107724e5b9252","name":"@allowly/sdk","dist-tags":{"bootstrap":"0.2.0-bootstrap.0","latest":"0.5.0"},"versions":{"0.2.0-bootstrap.0":{"name":"@allowly/sdk","version":"0.2.0-bootstrap.0","license":"MIT","_id":"@allowly/sdk@0.2.0-bootstrap.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"17123b1d3ab8367ee25904ee6735d4dc8f858f9b","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.2.0-bootstrap.0.tgz","fileCount":10,"integrity":"sha512-+3XejuljfK0uF/q95tB9njJD0NC5OBFlEJlV5WXC9IsxVA8xl3pvS7OSNgcMMWvAwnvwHF/lLu7HpB3xarvwCw==","signatures":[{"sig":"MEQCIHZDF0OwU5DBrMWJYnJbbRMTor1oc45hE3jF1qk39Z0aAiATzbHgTXH0+Se2q9/ubsSoAdH+OTxcOamjyPUAOuCZ/A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":43813},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"4565075175a335c91fa82fa407689d5c65e6636b","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"_npmUser":{"name":"yevgeny.alianov","email":"support@allowly.ai"},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"10.9.2","description":"TypeScript SDK for the Allowly API","directories":{},"_nodeVersion":"23.10.0","dependencies":{"@allowly/verifier":"^3.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.0-bootstrap.0_1785385028440_0.471253493554568","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@allowly/sdk","version":"0.2.0","license":"MIT","_id":"@allowly/sdk@0.2.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"6b7335bfb43ba87160787476e01a6bb4f1bfb590","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.2.0.tgz","fileCount":10,"integrity":"sha512-hYjy7XV46W48vH4XxBVXh/HotCZJ2B8bPFrr/uDUN0leaLaHAzu6OrfWPiwDrNJVVsBHk63HVqWdoV0AUWahtg==","signatures":[{"sig":"MEUCIBcqgPCK9+PlZBdex8FKF3ApyLEKkCD/JrJKI36WfdyWAiEA7MfvCZRhuFI0mW9Jh7iiSUVwKuex5tsVAVBDm5rCLnw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fsdk@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":43801},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"4565075175a335c91fa82fa407689d5c65e6636b","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6de3fe47-b7bf-4566-9d0e-4013fe280d9d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"11.16.0","description":"TypeScript SDK for the Allowly API","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@allowly/verifier":"^3.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.0_1785385456578_0.48156733915945993","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@allowly/sdk","version":"0.3.0","license":"MIT","_id":"@allowly/sdk@0.3.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"57f0150cfa6ef20aea8ad33e3262df38cc0fa7a3","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.3.0.tgz","fileCount":10,"integrity":"sha512-PkFOLue5vmkOOuZu6b0W9/l88Ktg6oCe/7HDGVKd6EZQM+1BAPQ80cg3wqeb97zIYeRnwY3q2dpVjyFbJuloCg==","signatures":[{"sig":"MEUCIQCn2lH7GPmkfqMl1Fc/c4YrkFOcktVhPRu3q4cnK3cPwAIgeYSMjpM9vFZmG7GXGhNTIk/bpY72lsGxbn/Niq/bhvk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fsdk@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":43801},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"32868be3d1b64a7c802a2a870ecc15fb1a120234","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6de3fe47-b7bf-4566-9d0e-4013fe280d9d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"11.16.0","description":"TypeScript SDK for the Allowly API","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@allowly/verifier":"^4.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.0_1785656241651_0.9860702768080571","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@allowly/sdk","version":"0.3.1","license":"MIT","_id":"@allowly/sdk@0.3.1","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"981b2ce8e96153c7a29c4c6b69fd62229183fa34","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.3.1.tgz","fileCount":10,"integrity":"sha512-kojRZkB6ItXuOx8oADyfTtYWDHPUmcgny60aL6O8ECSE4KeYnX68Em27IqLRAN9M7DqoRzkEL1Nwtu0hp4Aqng==","signatures":[{"sig":"MEYCIQCNPXT+daucc5+ABNuBjUukBj+LIcA7YvV5SHrvPyzKNAIhAJb+q0GuDOG0MCYk/4jKHzY7G5jL2JOlV1dU8L/xJAAs","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fsdk@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":43801},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a28b24b34932c5d468544a36f60e336f9e6d2a23","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6de3fe47-b7bf-4566-9d0e-4013fe280d9d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"11.16.0","description":"TypeScript SDK for the Allowly API","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@allowly/verifier":"^4.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.1_1785895465421_0.7316959594933563","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@allowly/sdk","version":"0.3.2","license":"MIT","_id":"@allowly/sdk@0.3.2","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"0282fca1d3d900e3a4a2e341d4c32ec925627bc7","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.3.2.tgz","fileCount":10,"integrity":"sha512-/9UWAK/iShPAgMIEel91a8PJx6MyQ96nzYXb3jeQMLi9NdBT/B6XJQD3BaYtRVnknL5KP5gwgGUypaNJL4YDUw==","signatures":[{"sig":"MEUCIQCyUCP54hWJPhPENXolyl+/H29dZtCzp1qO+MM8pxOcHwIgAlyC9e1qtpTKJD3SOXrVuyE5bIGkT1JBZ2r7xHU7zCs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fsdk@0.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":43918},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"fb18f229e75a1cfe6beb5e3c8296dea2452ae89a","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6de3fe47-b7bf-4566-9d0e-4013fe280d9d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"11.17.0","description":"TypeScript SDK for the Allowly API","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@allowly/verifier":"^4.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.2_1787382249524_0.21940722423888714","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@allowly/sdk","version":"0.4.0","license":"MIT","_id":"@allowly/sdk@0.4.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"7f1d4ecc6b4c899ded375cb52a11941fa15eb4dd","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.4.0.tgz","fileCount":10,"integrity":"sha512-08JdbLUubgBncKhZajcEeDo/CNbk3JdRvSI7EXQaPKmT1815ti2O9E+YSXJNWbjoPrE8AvqRrlF0BqdEV4cR6g==","signatures":[{"sig":"MEUCICZ7V2o0sGafIPmUtn0JXGBPjjwsNDNKxTFjXJg2frW6AiEAldWW0lNyzapDf6mhFEoYQtOVpGxSVxM1Hswsi8Cwar4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fsdk@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":43992},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d8a25404a8860fafe013a0245afc1d79e3526a1f","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6de3fe47-b7bf-4566-9d0e-4013fe280d9d"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"11.17.0","description":"TypeScript SDK for the Allowly API","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@allowly/verifier":"^4.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.4.0_1788409318769_0.6200134017203838","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"_id":"@allowly/sdk@0.5.0","bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"dist":{"shasum":"38dc619fdc738c52e8cb7f422cef31e80578f7d8","tarball":"https://registry.npmjs.org/@allowly/sdk/-/sdk-0.5.0.tgz","fileCount":11,"integrity":"sha512-kI8EA23yJoHUvlnN4cBZjk67e8UKy5g9okKaLVC2F7Z+PKiQgbG01PutXUgplHUfmKnB3L46XhG08+zfAAjz8g==","signatures":[{"sig":"MEYCIQC6KFNz90zRuVv1M+3ywp3VRm3pNQBGGE1aDceBjOuTewIhAN/b1/e16uq8GU1RDb09Ubc7h0XZroJ8rpvWHgzCcIIO","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC4Un+FrFhJcqzG7ojyOOPZyfMmtgNf277k9NfNUvBuEwIhAM3FBQbiFIBU3sjkc6K1hOE/Pz4FwgCDF/v90GOxirnx"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fsdk@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":64436},"main":"./dist/index.js","name":"@allowly/sdk","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"082e8ef990706fb359f215f0af7634e4dab7d7ed","license":"MIT","scripts":{"test":"vitest run","build":"tsup src/index.ts --format esm --clean && tsc --emitDeclarationOnly","prepack":"npm run build && node --input-type=module -e \"const sdk = await import('@allowly/sdk'); if (typeof sdk.Allowly !== 'function') process.exit(1)\"","typecheck":"tsc -p tsconfig.typecheck.json"},"version":"0.5.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6de3fe47-b7bf-4566-9d0e-4013fe280d9d"}},"homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"_npmVersion":"11.19.0","description":"TypeScript SDK for the Allowly API","directories":{},"maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"_nodeVersion":"24.20.0","dependencies":{"@allowly/verifier":"^4.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^20.19.40"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.5.0_1789588471341_0.716362383892535"}}},"time":{"created":"2026-07-30T04:17:08.142Z","modified":"2026-09-16T19:54:31.855Z","0.2.0-bootstrap.0":"2026-07-30T04:17:08.572Z","0.2.0":"2026-07-30T04:24:16.760Z","0.3.0":"2026-08-02T07:37:21.805Z","0.3.1":"2026-08-05T02:04:25.557Z","0.3.2":"2026-08-22T07:04:09.668Z","0.4.0":"2026-09-03T04:21:58.914Z","0.5.0":"2026-09-16T19:54:31.473Z"},"bugs":{"url":"https://github.com/Allowly-AI/allowly-sdk-ts/issues"},"license":"MIT","homepage":"https://github.com/Allowly-AI/allowly-sdk-ts#readme","repository":{"url":"git+https://github.com/Allowly-AI/allowly-sdk-ts.git","type":"git"},"description":"TypeScript SDK for the Allowly API","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"readme":"# @allowly/sdk\n\nTypeScript SDK for the Allowly runtime API. Check an agent action before it\nruns, handle allow/deny/confirm/escalate decisions, and verify signed receipts.\n\nRequires Node.js 20 or newer. This package is ESM-only.\n\n## Install\n\n```bash\nnpm install @allowly/sdk\n```\n\n## Check an action\n\n```typescript\nimport { Allowly } from \"@allowly/sdk\";\n\nconst allowly = new Allowly({\n  apiKey: process.env.ALLOWLY_API_KEY!,\n});\n\nconst result = await allowly.check({\n  authorizationId: \"auth_...\",\n  actions: [\"email.send\"],\n  resource: \"gmail:thread:abc\",\n  context: { initiated_by: \"user\" },\n});\n\nconst decision = result.results[\"email.send\"];\nif (decision.decision === \"allow\") {\n  await sendTheEmail();\n} else {\n  // deny stops; confirm and escalate pause for your application's resolution flow.\n  throw new Error(`Action not allowed: ${decision.decision} (${decision.reason})`);\n}\n```\n\nOnly `allow` permits execution. Unavailable checks fail closed unless that\naction has an explicit `fail_open` fallback configured.\n\n## Create an authorization\n\nCreate one authorization for the subject and store its ID in your application:\n\n```typescript\nconst authorization = await allowly.authorizations.create({\n  userId: \"subject_abc123\",\n  policyId: \"research_agent\",\n  expiresAt: \"2026-12-31T00:00:00.000Z\",\n});\n\nawait saveAuthorizationId(authorization.authorizationId);\n```\n\nUse opaque internal subject IDs. Avoid putting raw names, emails, documents, or\nother sensitive data into receipt fields unless that data is intentionally part\nof the audit record.\n\n## Send JSON through a private SEAL webhook\n\nCopy the private URL from the dashboard's **SEAL** page. The URL is the only\ncredential this client sends; it does not use an ordinary API key.\n\n```typescript\nimport { SealWebhookClient } from \"@allowly/sdk\";\n\nconst webhook = new SealWebhookClient(process.env.ALLOWLY_SEAL_WEBHOOK_URL!);\nlet delivery = await webhook.send(rawJson, {\n  idempotencyKey: eventId,\n  type: \"invoice\",\n  reference: \"INV-1042\",\n  statement: \"Approved for payment\",\n});\nwhile (delivery.status === \"received\" || delivery.status === \"signing\") {\n  await new Promise((resolve) => setTimeout(resolve, 1_000));\n  delivery = await webhook.getDelivery(delivery.attemptId);\n}\nif (delivery.status !== \"sealed\") {\n  throw new Error(delivery.errorCode ?? \"SEAL delivery failed\");\n}\nawait saveEvidence(delivery.receipt, await webhook.getKeys());\n```\n\nThe webhook processes your JSON to create a fingerprint; Allowly stores the\nfingerprint and signed receipt. Keep the original record in your workflow.\nReceipt details are sent in the three explicit `Allowly-Seal-*` headers. Their\nvalues must use printable ASCII, may contain interior spaces, and must not have\nleading or trailing whitespace. The client rejects invalid values instead of\nchanging them. Direct API metadata still supports its existing Unicode values.\nWhen a signed receipt is present, the client returns its signed metadata and\nrejects a conflicting top-level delivery projection.\nTreat the full URL like a password and keep it out of logs, tickets, and source\ncontrol. Regenerating or disabling it stops the old URL. Delivery associations\nand status remain available for 7 days; preserve signed receipts and keys under\nyour own retention policy. With no `idempotencyKey`, retrying after a lost\nresponse can create another seal.\n\n## Seal a JSON record with local hashing\n\n`seal` hashes strict raw JSON in your process, sends only its digest to Allowly,\nand waits for the full signed receipt. Generate and persist `requestId` in your\nworkflow so a retry recovers the same seal:\n\n```typescript\nimport { randomUUID } from \"node:crypto\";\n\nconst requestId = randomUUID();\nconst sealed = await allowly.seal(rawJson, {\n  requestId,\n  metadata: { source: \"invoice-workflow\" },\n});\nawait saveBesideRecord(sealed.receipt);\n```\n\nUse `sealValue(parsedJson, ...)` only when the original JSON text is no longer\navailable. A parsed value cannot reveal duplicate object names or the original\nnumber spelling, so `seal` is the safer input boundary.\n\nVerify later with the authenticated `workspaceId` response and keys fetched\nfrom Allowly through an authenticated or previously trusted source:\n\n```typescript\nimport { loadKeysFromJson, verifySealJson } from \"@allowly/sdk\";\n\nconst result = await verifySealJson(rawJson, sealed.receipt, loadKeysFromJson(keysDoc), {\n  expectedWorkspaceId: sealed.workspaceId,\n  trustedKeyFingerprints: configuredKeyFingerprints,\n});\nif (!result.signatureVerified || !result.recordMatches) {\n  throw new Error(result.failureReason ?? \"SEAL verification failed\");\n}\n```\n\n## Verify a signed receipt\n\n```typescript\nimport { fetchKeysDoc, loadKeysFromJson, verifyReceipt } from \"@allowly/sdk\";\n\nconst receipt = await allowly.receipts.fetchSigned(receiptId);\nconst workspaceId = process.env.ALLOWLY_WORKSPACE_ID!;\nconst keys = loadKeysFromJson(await fetchKeysDoc(workspaceId));\n\nawait verifyReceipt(receipt, keys, { expectedWorkspaceId: workspaceId });\n```\n\nTake the expected workspace ID from trusted application configuration, not from\nthe receipt being verified.\n\n## Documentation\n\n- [TypeScript SDK guide](https://allowly.ai/docs/sdk/typescript)\n- [Agent integration loop](https://allowly.ai/docs/sdk/agent-loop)\n- [MCP middleware](https://allowly.ai/docs/sdk/mcp)\n","readmeFilename":"README.md"}