{"_id":"@allowly/verifier","_rev":"10-220ccb4b9280c63abb35ab8b0814d649","name":"@allowly/verifier","dist-tags":{"latest":"4.1.0"},"versions":{"1.0.0":{"name":"@allowly/verifier","version":"1.0.0","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@1.0.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"edc661a65027fc09bbc7ccb96b43a41874a90b6f","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-1.0.0.tgz","fileCount":6,"integrity":"sha512-z7bJCTfFGHoIdZVltsIUHRASUA8lxVPfLzovxWjOlQ/+Q9C85qCY9djVbOIkurY+r1309j1WgB5bpY1tzYWKjQ==","signatures":[{"sig":"MEYCIQC5NLwt0c++iSlXAti99HNVbrnMv+AYyYwgCi0Iyc+uJAIhAKzjGNMJ/qmZ6ANL/bz5J2FPqeIGAa60QEIYSDyeca0h","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24254},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"c6e92276a5f7128dd54e615b9d83eaafedfc64c8","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"yevgeny.alianov","email":"support@allowly.ai"},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"10.9.2","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"23.10.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_1.0.0_1781458101652_0.8024272989457852","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@allowly/verifier","version":"1.0.1","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@1.0.1","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"d6d4d9271bab993f61d92e05d48cd1d83c00d30d","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-1.0.1.tgz","fileCount":6,"integrity":"sha512-6drhi7n5VMVylXqznz827Qa5xSd2NQwq8+CA6BtOkNqyCW0hYwH1ieTa/iBsmfX4/8OQAo8UrHRwNdEFPj5x7A==","signatures":[{"sig":"MEQCICuP4AuxsIzExvlJfl80KBa5lqArnrySTwxbOhBil529AiAUC8WxIyz2/MuaCq7gVDUxUPniqjuIHw7yMFp927OQVw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":24254},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"ea17bc3ba1541f3cc4ee4ee1a7d11f77944125fb","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.13.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.16.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_1.0.1_1781466549128_0.7995394116295151","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@allowly/verifier","version":"1.0.2","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@1.0.2","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"7c00e26f917cf1cf3c4c72ad604311d16ea93af4","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-1.0.2.tgz","fileCount":6,"integrity":"sha512-jBvSuV11IIsnBAuw0qvhs57Hdzo54ajO4aDMKkW5GZjgFLNiDw/kcccN36OHMfYQQOXobAh+dQ1c5zxT8lbP5g==","signatures":[{"sig":"MEQCIBcJfkXl561LjaXCcSNuClS4CDIi/VFSaTK9pZ1Y2fIKAiATfGc6dTEfDZLGnBfVZtAA723LWoDwP56jCqZvxHTXmA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":24258},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"18f20cbf6107a730f1fa6d067396ce7a7bbc85a0","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.13.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.16.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_1.0.2_1781472411103_0.07719569166276519","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@allowly/verifier","version":"1.0.5","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@1.0.5","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"785f05a6e4948eb05c6c0aab333a8c6d643032d8","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-1.0.5.tgz","fileCount":6,"integrity":"sha512-pyJiT1q4T/c3uhzbhpa8C/PN2dS7tliFcSydwpEn3Az8dqL6Nttb4+XjRYYTHCJ3dkSJPHow+bPpnmxMhed1hA==","signatures":[{"sig":"MEYCIQDbfR0UfMiEZaX1Eb2J4/FPBouEBuEp9UoWZBcayxv5ZwIhAIldyivkJBxD8LKQgtE7cNiKhvCi2m+5RcTe+8YmoksW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@1.0.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":24258},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"bb85558cdf0fbefa8dbca9f8a774a7e08bf9c016","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.13.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.16.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_1.0.5_1781835715524_0.6535400348111637","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@allowly/verifier","version":"2.0.0","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@2.0.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"958b4fc8132a8dba93fc214ccaa57539db7ddb11","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-2.0.0.tgz","fileCount":6,"integrity":"sha512-yEwqO5E40TsIrvKlNeCqUvL9IBkiQ4K/QFY142r8itb4P7Nqf4kH5ARlKG5aEEuM98j4GAKbo7Hr7pOob+0BYQ==","signatures":[{"sig":"MEQCICJE61T3IPjKFoEowGq5uEs56ixXxD6mrwPU4bOPHUvdAiAe4q57iuFi7hLB0X7EovfUfnAC8sSSfg1Wpln3T9l4sA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@2.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":31411},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"81b2ad951c5c0ad4694b759e861a3e7b43f61961","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.16.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_2.0.0_1784606620336_0.22759299177319448","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"@allowly/verifier","version":"2.1.0","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@2.1.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"f4252a8d1dc322897a4a6edb18929e2553a3adb8","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-2.1.0.tgz","fileCount":8,"integrity":"sha512-uz7W54127jeXIGG48MVzeJWv6wOmcmSIKDKcuLThIMimE8IhSUKbjLZYjcQsgxMgnfXmzigdaFJ92nWUf+zREg==","signatures":[{"sig":"MEUCIQChpPnHnj5fs50c+n5711XE5zXeHwWUmfZ6MqsRZEhoAgIgUFoFi5sAYBMjbUYcP/W2+9k/lX2gLbp/fbwA5VrtzxQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@2.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":38678},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"66b076d2d7da116812733529f4a82f33c253369f","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json && node dist/test_pseudonym_refs.js","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.16.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_2.1.0_1784749499942_0.9339405723030902","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"@allowly/verifier","version":"3.0.0","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@3.0.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"07c50286322704335b42f875719324c427611e15","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-3.0.0.tgz","fileCount":8,"integrity":"sha512-AgWnQcHZm5bxOGd8Wmcs4y/BUBw9tBtwHiV49CqDkk54D9HazK1MHPd/RfimX9tjrLy9dVDK9II5JxkR+kvssQ==","signatures":[{"sig":"MEYCIQDbC88XCEL7C5ixXu17PdBnOR0ZjSUTabcJcB9JjnqJEAIhAIXWM3nOwuZt4S/QThrjMNnZm380/XyXcqYDlVlKOFdj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@3.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":38743},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"a2222cbeaf8c431d597333664c852d53baa0232a","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json && node dist/test_pseudonym_refs.js","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.16.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_3.0.0_1784775439810_0.7563201175948273","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"@allowly/verifier","version":"4.0.0","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@4.0.0","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"83aef41429d15afee2290c28235e461f18310380","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-4.0.0.tgz","fileCount":8,"integrity":"sha512-Sq/brl/RVffuO+ZjOC6PgJmVCfQfVbZLwppl1DYzxY0u/3sCQbi6fSXrb+asUmxSjT8GicAm12LCxSx+Fhk5NQ==","signatures":[{"sig":"MEUCIQCo3VDEfN4IKLxq0lQttbWLc9vyPw4C76I02T1ir+gJ2QIgGeF/OIL0+WcUSVVCXqjx/xmpSB8tJ0j7ysxs4wikT1c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@4.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":63647},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"a7e535e920c9a44a5b997c24aee11d696478e49a","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json && node dist/test_pseudonym_refs.js","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.16.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_4.0.0_1785654878976_0.09494416802353389","host":"s3://npm-registry-packages-npm-production"}},"4.0.1":{"name":"@allowly/verifier","version":"4.0.1","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","_id":"@allowly/verifier@4.0.1","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"homepage":"https://github.com/Allowly-AI/allowly-receipt-format","bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dist":{"shasum":"bbd6a957cb93787a37e9dab7163b4ffafd09e514","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-4.0.1.tgz","fileCount":8,"integrity":"sha512-fUFcmESQTDA399TR0ch3Q0XoXD89yHXU5lRRUFbgwimmf3k3N26jNgQxGSwK3iap0nYyfYDBOL4EZO+GySpufw==","signatures":[{"sig":"MEQCIBir4Hpoi1Cw/Ivk+XlIHEqHbeqf1fe7RunEovUjBdt5AiBNb9dRhusmNWb5Idd5bGxLHq9fI7gudh+EhJzN+zAxlw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@4.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":66320},"main":"./dist/verifier.js","type":"module","types":"./dist/verifier.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"}},"gitHead":"731c9003bf130e94a30d757a9565dfd2b7568a4f","scripts":{"test":"npm run build && node dist/test_vectors.js ../../test-vectors.json && node dist/test_pseudonym_refs.js","build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"repository":{"url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","type":"git","directory":"verifiers/typescript"},"_npmVersion":"11.16.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier_4.0.1_1785880490126_0.8961398969128169","host":"s3://npm-registry-packages-npm-production"}},"4.1.0":{"name":"@allowly/verifier","version":"4.1.0","description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","type":"module","main":"./dist/verifier.js","types":"./dist/verifier.d.ts","exports":{".":{"types":"./dist/verifier.d.ts","import":"./dist/verifier.js"},"./vectors/seal/profile-v1.json":"./dist/vectors/seal/profile-v1.json","./vectors/seal/verification-v1.json":"./dist/vectors/seal/verification-v1.json"},"scripts":{"build":"tsc && node scripts/copy-seal-vectors.mjs","test":"npm run build && node dist/test_vectors.js ../../test-vectors.json && node dist/test_pseudonym_refs.js && node dist/test_seal.js ../../vectors/seal/profile-v1.json ../../vectors/seal/verification-v1.json","prepublishOnly":"npm run build"},"engines":{"node":">=20"},"keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"license":"Apache-2.0","homepage":"https://github.com/Allowly-AI/allowly-receipt-format","repository":{"type":"git","url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","directory":"verifiers/typescript"},"bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"dependencies":{"canonicalize":"^3.0.0","lossless-json":"^4.0.1"},"devDependencies":{"@stryker-mutator/core":"10.0.0","@types/node":"^20.0.0","typescript":"^5.4.0"},"gitHead":"b89c8fb781a9bee39611df2e42e96c928fda03de","_id":"@allowly/verifier@4.1.0","_nodeVersion":"24.20.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-my5P54cBN52iVTvRKCEy3z0VDqtiyjMvPNPL1RJOaqHvizhpTB3cSGt5rH27psj0rqhGa0DHD9dev7rXmJwaDQ==","shasum":"086dd6f99a9a73699617ba404ae6f37b6ebaee82","tarball":"https://registry.npmjs.org/@allowly/verifier/-/verifier-4.1.0.tgz","fileCount":15,"unpackedSize":130108,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@allowly%2fverifier@4.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCVohqitz6SvXhdu0rIr+ukCU3rdXXvSQEcCgYhpQ4XVQIhAMNQv1LjJnsLi8hVni8DPliXS2TncmMndqcJnGTa5C8w"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9489a4aa-6a4e-41b4-9b44-e16569387fe9"}},"directories":{},"maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/verifier_4.1.0_1789586417613_0.21922574778551085"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-14T17:28:21.412Z","modified":"2026-09-16T19:20:18.137Z","1.0.0":"2026-06-14T17:28:21.794Z","1.0.1":"2026-06-14T19:49:09.266Z","1.0.2":"2026-06-14T21:26:51.253Z","1.0.5":"2026-06-19T02:21:55.658Z","2.0.0":"2026-07-21T04:03:40.566Z","2.1.0":"2026-07-22T19:45:00.089Z","3.0.0":"2026-07-23T02:57:19.966Z","4.0.0":"2026-08-02T07:14:39.134Z","4.0.1":"2026-08-04T21:54:50.284Z","4.1.0":"2026-09-16T19:20:17.767Z"},"bugs":{"url":"https://github.com/Allowly-AI/allowly-receipt-format/issues"},"license":"Apache-2.0","homepage":"https://github.com/Allowly-AI/allowly-receipt-format","keywords":["allowly","receipt","ed25519","verification","audit","ai-agents","authorization"],"repository":{"type":"git","url":"git+https://github.com/Allowly-AI/allowly-receipt-format.git","directory":"verifiers/typescript"},"description":"Reference verifier for the Allowly Receipt Format. Verifies signed receipts of AI agent authorization decisions.","maintainers":[{"name":"yevgeny.alianov","email":"support@allowly.ai"}],"readme":"# @allowly/verifier\n\nTypeScript reference verifier for [Allowly Receipt Format wire version 4](https://github.com/Allowly-AI/allowly-receipt-format).\n\nUses Node.js's built-in WebCrypto for Ed25519 verification, plus focused RFC\n8785 canonicalization and strict JSON parsing dependencies for SEAL records.\n\n## Install\n\n```bash\nnpm install @allowly/verifier\n```\n\nRequires Node.js 20+.\n\n## Usage\n\n```typescript\nimport { verifyReceipt, VerificationError, loadKeysFromJson } from \"@allowly/verifier\";\n\nconst receipt = JSON.parse(receiptJson);\nconst keysDoc = JSON.parse(keysJson);\nconst configuredWorkspaceId = process.env.ALLOWLY_WORKSPACE_ID;\nconst configuredKeyFingerprint = process.env.ALLOWLY_TRUSTED_KEY_FINGERPRINT;\nif (!configuredWorkspaceId) throw new Error(\"ALLOWLY_WORKSPACE_ID is required\");\nif (!configuredKeyFingerprint) throw new Error(\"ALLOWLY_TRUSTED_KEY_FINGERPRINT is required\");\nif (keysDoc.workspace_id !== configuredWorkspaceId) {\n  throw new Error(\"key document workspace does not match configuration\");\n}\nconst keys = loadKeysFromJson(keysDoc);\n\ntry {\n  await verifyReceipt(receipt, keys, {\n    expectedWorkspaceId: configuredWorkspaceId,\n    trustedKeyFingerprints: new Set([configuredKeyFingerprint]),\n  });\n  console.log(\"valid\");\n} catch (e) {\n  if (e instanceof VerificationError) {\n    console.log(`invalid: ${e.message}`);\n  } else {\n    throw e;\n  }\n}\n```\n\n## Fetching the public keys\n\n```typescript\nconst configuredWorkspaceId = process.env.ALLOWLY_WORKSPACE_ID;\nif (!configuredWorkspaceId) throw new Error(\"ALLOWLY_WORKSPACE_ID is required\");\nconst res = await fetch(`https://api.allowly.ai/v1/workspaces/${configuredWorkspaceId}/keys`);\nconst keysDoc = await res.json();\nif (keysDoc.workspace_id !== configuredWorkspaceId) {\n  throw new Error(\"key document workspace does not match configuration\");\n}\nconst keys = loadKeysFromJson(keysDoc);\n```\n\nHonor the issuer's `Cache-Control` header. Allowly currently returns `no-store`,\nso do not HTTP-cache the response; retain trusted key material separately for\noffline audits.\n\n## API\n\n### `verifyReceipt(receipt, publicKeys, opts?)`\n\nVerifies a receipt. Resolves on success, throws `VerificationError` on any failure.\n\n- `receipt` — the full receipt object (payload + signature).\n- `publicKeys` — array of `PublicKey` objects. Get these via `loadKeysFromJson`.\n- `opts.now` — optional `Date` override for time checks. Defaults to `new Date()`.\n- `opts.expectedWorkspaceId` — optional. If set, the receipt's `workspace_id` must equal it. Pass a caller-trusted configured workspace ID, never one copied from the receipt or key document (spec §7, \"Workspace binding\"); a `key_id` alone does not bind a receipt to a workspace.\n- `opts.trustedKeyFingerprints` — optional `ReadonlySet<string>`. If set, the\n  selected receipt key must match a caller-trusted `sha256:<64 lowercase hex>`\n  fingerprint. Include every trusted rotation key that may have signed the\n  selected receipts.\n\n### `canonicalize(payload)`\n\nProduces the canonical JSON byte sequence per spec §4. Exposed for implementers building signers in TypeScript.\n\n### `verifyCheckpoint(checkpoint, receipts, publicKeys, opts)`\n\nVerifies the checkpoint and member signatures, exact UTC-day period, count,\nMerkle root, and optional prior checkpoint linkage. `opts.expectedWorkspaceId`\nis required and must come from caller-trusted configuration. Pass caller-trusted\nrotation keys through `opts.trustedKeyFingerprints`; the pins are applied to the\ncheckpoint, every member, and the optional prior checkpoint. Success proves the\nsupplied set matches the signed commitment; without external anchoring it does\nnot prove issuer-registry or real-world completeness.\n\n### `loadKeysFromJson(doc)`\n\nParses the `/v1/workspaces/{id}/keys` response into a `PublicKey[]`. It requires\na non-empty `workspace_id`, requires every key's `alg` to equal `Ed25519`, and\nvalidates any advertised `public_key_fingerprint` against the decoded key.\nBundled fingerprint values are not caller-trusted merely because they accompany\nthe receipts.\n\n### `publicKeyFingerprint(key)`\n\nReturns the canonical `sha256:<64 lowercase hex>` fingerprint over the key's\ndecoded raw 32-byte Ed25519 public key.\n\n### SEAL hashing and verification\n\n`hashSealJson(rawJson)` accepts a `string` or `Uint8Array`, strictly parses the\nraw JSON, applies the `allowly.seal.jcs-sha256.v1` RFC 8785 profile, and returns\nthe 64-character lowercase SHA-256 digest. Prefer it at untrusted input\nboundaries because it can reject duplicate decoded object keys and\nprecision-losing number tokens. `hashSealValue(record)` is the explicit\nalready-parsed boundary; parsing has already erased those details.\n\n`verifySealJson` and `verifySealValue` first verify the full wire-4 receipt,\nincluding a caller-supplied `expectedWorkspaceId` and optional trusted key\nfingerprints. They then require the fixed SEAL action and identities, the\nsigned profile and digest, and a matching local record. The result keeps\n`signatureVerified` separate from `recordMatches` and includes a stable\n`failureReason`.\n\nThe package publishes the exact shared JSON vectors at these stable subpaths:\n\n```typescript\nimport profileVectors from \"@allowly/verifier/vectors/seal/profile-v1.json\" with { type: \"json\" };\nimport verificationVectors from \"@allowly/verifier/vectors/seal/verification-v1.json\" with { type: \"json\" };\n```\n\nThey are copied from the repository's canonical `vectors/seal/` files during\nthe package build; integrations should consume these fixtures instead of\nmaintaining a second source.\n\n### `matchesRef(key, fieldName, value, ref)`\n\nImplements the optional `hmac-v1` keyed-pseudonym convention in specification\nAppendix A. Decode the show-once integration key, then match locally — no call\nto Allowly:\n\n```typescript\nimport { matchesRef } from \"@allowly/verifier\";\n\nconst key = Buffer.from(encodedKeyB64url, \"base64url\"); // per-integration pseudonym key\nconst ok = matchesRef(key, \"record\", \"MRN-48291\", receipt.context.record_ref);\n```\n\n`key` is a `Uint8Array` of at least 16 bytes; `fieldName` is one of `project`,\n`record`, `actor`, `full_tuple`. The value is used exactly as supplied — no\ntrimming, case folding, or Unicode normalization — and comparison is\nconstant-time. Use `context.ref_key_version` to select the retained key\nversion. This helper is unrelated to signature verification and does not touch\nthe receipt schema, canonicalization, or wire version.\n\n`verifyReceipt` accepts an already-parsed object. `JSON.parse` cannot report\nduplicate member names or preserve whether an integer was written as `1`,\n`1.0`, or `1e0`; reject those forms at the raw-JSON boundary when the original\nreceipt text is untrusted (spec §4.2).\n\n## What verification proves\n\nA valid receipt proves that the selected private key signed the exact recorded decision and timestamp for the recorded subject/action. It does **not** independently prove when signing happened, that the action actually happened, that the user's authorization was informed, or that the `user_id` corresponds to any real-world person. See spec §7.1.\n\n## Browser builds for the dashboard and website\n\n`browser/sealJson.ts` owns their shared strict JSON parsing and hashing.\n`npm test` checks it against the same SEAL vectors as the Node verifier.\nAfter building this directory, run `python3 scripts/refresh-verifier.py` in\neach consumer repo. Those wrappers use `scripts/build-browser.py` here to\ngenerate the self-hosted receipt verifier and JSON helper; edit these sources\ninstead of the generated consumer files.\n\n## License\n\nApache 2.0. Contributions welcome — see [CONTRIBUTING.md](https://github.com/Allowly-AI/allowly-receipt-format/blob/main/CONTRIBUTING.md).\n","readmeFilename":"README.md"}