{"_id":"@altimist/did-web-client","_rev":"10-805f2f99d538b3eaa7cf7ec041a53ae7","name":"@altimist/did-web-client","dist-tags":{"latest":"0.9.0"},"versions":{"0.1.0":{"name":"@altimist/did-web-client","version":"0.1.0","_id":"@altimist/did-web-client@0.1.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"b4350c12c1545c459f1c0b8cf58b13005a213f3e","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.1.0.tgz","fileCount":21,"integrity":"sha512-6HUKJxLoOoY6Yz5c7ITPCCh7GncSAYhJsygDlMODI7Ct/GX/kOwHqdgbg8MRQNaiaW9Yi1yRRYEdOhsSHmIsRQ==","signatures":[{"sig":"MEQCIDw6BYifPeM3A9vO34bEHGzEILnlbyIffB0h23xFCXvPAiAiay59M2MrPVmybkkgb1my0YGsMrxTrfW02AOBr2vYzg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28932},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"578a6e9c84e5502184a722705ed3c0d783567138","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side helpers for verifying Altimist users (did:web) and team Verifiable Credentials without calling altimist-id at request time. Phase 2a of F-010 (M7).","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.1.0_1777550961420_0.7166392969701454","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@altimist/did-web-client","version":"0.2.0","_id":"@altimist/did-web-client@0.2.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"a8a96c8ad4a904235b21e2f137d9388f15156d22","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.2.0.tgz","fileCount":30,"integrity":"sha512-Ra357tO/XOR8HOY6eqQdL5pPs9FSRSXKwNN8DGrjqahCIlaZDz6Xda4M7qUVPaOhktUNz0V3PlboDKnPbc703A==","signatures":[{"sig":"MEUCIQCpIGs43ytz7wUugajuODvzF7FUH+3RgUW6I+pbAeUtqAIgKcYcAdO9IREVWVDx1Vc75vmAhsxmqLi1I5OKas+lAhM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49575},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"e546502495043242af72fdc795d28f78301ccbc8","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, plus the SE-signed JWT bridge for MCP. Phase 2a of F-010 (M7+M8).","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.2.0_1777562318622_0.10456295457268694","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@altimist/did-web-client","version":"0.4.0","_id":"@altimist/did-web-client@0.4.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"44b89c755d44d798841f47938e9629b2a38f43e3","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.4.0.tgz","fileCount":36,"integrity":"sha512-H0DsgCfKr3vxIbNrCLuvPcyymkVjN5dXxiLSBVNS4C5pvHWKE2Go6hcnXXLuqFX8qvUFXFFwEnZAypFzJpq50w==","signatures":[{"sig":"MEUCID1nQp1po5PnedffqEgdHatJP5ijSZrJ8SNXFJXoP/VEAiEAhAfGJGqnxbfb4jxCI4J4ghnDQOAb/Nhy5XtHx3qFxbY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70493},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"99cf652a20eeeca5c2d51e67742ef17b749796ed","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. Phase","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.4.0_1778082826475_0.14599533536650444","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@altimist/did-web-client","version":"0.5.0","_id":"@altimist/did-web-client@0.5.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"b0cd3c581745122090010b9f3585b43e95e0de3b","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.5.0.tgz","fileCount":36,"integrity":"sha512-+7PihInIZc5s3FyuFJiTDy5FsROsaq1bQg+fH3lvlc0RmM3dA5hn2uOzKznf3w2mXCC5QxhTdBmcMU1NHNmvrA==","signatures":[{"sig":"MEQCIC2Mi70SEvyv42PodVO2fcwIRXTu4rxQlx9drl3FDx4qAiAGCS8CPguNoBjQoN1U6E9HfE8ojcXi4vgrrSkXDVLJnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":72780},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"c668df844cabfdd872d86527470957851c5f3a8b","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.6.2","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. Phase","directories":{},"_nodeVersion":"24.12.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.5.0_1778253288863_0.6800087195378017","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@altimist/did-web-client","version":"0.6.0","_id":"@altimist/did-web-client@0.6.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"9ec2ea9a3a2d3edd21ee59d6486075f677451a43","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.6.0.tgz","fileCount":39,"integrity":"sha512-sCnlbCYChB+LYr6iUZSab8oSLXwnOhDxC0guBCSLXOOvjbusd/5nn4KawjLjlRX8T3vQ7WkK6JoOCyAjpq4dqw==","signatures":[{"sig":"MEQCIFBO6lepqI7DWxyqbI8LYj8gB98aFFgjEkyahkvEQFo8AiBcThcXWv+tbigSa1fiN51e6iuWZSAie8Rm5hFWIcUMwQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":77114},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"ede883c9f1efee20a74b46dc5465548ee5c40e8c","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. Phase","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.6.0_1778586654633_0.5793675240585137","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@altimist/did-web-client","version":"0.7.0","_id":"@altimist/did-web-client@0.7.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"0aadb72c2c22852567a1ea35504ce2de58c080fd","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.7.0.tgz","fileCount":42,"integrity":"sha512-S+EN+42INUNHfwgJRY+1nuTcGwez+wMpUiwQYygQ0R6V34x7oE8JFEqIHrx5upiCbIaE7s0xK+CnoR3wb2mLrA==","signatures":[{"sig":"MEUCIC6ZOo9TJ3Rix5Ves2s61YeVSLHzxieIbpZQpRqA9EnaAiEA/RplBRE1SCnxZ5MlvplWw58f6qV1ztLQLfrg42Q1mDQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":88519},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"b1f231389408316bafbf2cdb970dd79d86ee8ed5","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. F-020","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.7.0_1778679707605_0.5721634186406164","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@altimist/did-web-client","version":"0.7.1","_id":"@altimist/did-web-client@0.7.1","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"f4ba17d117e64925b5cad35d2f595147997d018d","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.7.1.tgz","fileCount":42,"integrity":"sha512-31mKrsmnht2lEhgAV0u/hiorDx4KJXyrOnXPbwxpkxHqtAUUpKTmsgwsrlXnGqB3dOemejVN3UurSG5MtAfNNQ==","signatures":[{"sig":"MEYCIQCN/ryyg8MBHVUH0b3PcNzotYbv9hXxxuyUw2fQPRtxGAIhAPWqa24itzUpSXU/qhAo/SVR3c1etxqKvImHfKzY5R3N","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89362},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"8817cf5d46ab16e15af43313243fdd7c8ddf4b27","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. F-020","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.7.1_1778680820279_0.05554144648860859","host":"s3://npm-registry-packages-npm-production"}},"0.7.2":{"name":"@altimist/did-web-client","version":"0.7.2","_id":"@altimist/did-web-client@0.7.2","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"cd4b6e822df6b879396d996cb30e4651b8f65212","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.7.2.tgz","fileCount":42,"integrity":"sha512-rsger0OZ9STFAs2cJSfKgmC4SSjgmx53IJCso3LfVR5E2+9e1cUXKM9L13yApd5OEcIL3ZdUfwNXHdwHTONR1g==","signatures":[{"sig":"MEYCIQDb3aK0wA3pnAUK/WRFqttAkZrxggiDhVljG9HP1+oTXQIhAOGQIEBcMwI/CgH/xXZLeb+RR3+sgKmhqUmZZvRsExfx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89811},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"a5b88ce6946de04ead133db774210f55cd78fd97","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. F-020","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.7.2_1778689087305_0.0656298149041381","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@altimist/did-web-client","version":"0.8.0","_id":"@altimist/did-web-client@0.8.0","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"dist":{"shasum":"babf77e931169e6e382589880925dc589e0c8fe2","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.8.0.tgz","fileCount":42,"integrity":"sha512-yNywKWyfJ3l72kCd9FdUEKSWV3nipKrR+EEXCe3Q5sHzbjKMnpWmdppCrVNYGqw3IQjNOhbnCQyum02T7Gtx8Q==","signatures":[{"sig":"MEUCIQCKOd280O5uXzW1bdBDnMa1UxuP3b5yHrj/4SGPJiQmGwIgYKKL1qxNeK+3V1dACNMAOQ8LZQdHIuV5uJESuy4rnqk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":96943},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"gitHead":"bee00212310db9a9a7b23185d6c2fd88b788d0d4","private":false,"scripts":{"lint":"echo \"(no lint configured)\" && exit 0","test":"vitest run","build":"tsc","test:cov":"vitest run --coverage","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"_npmVersion":"11.7.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. F-020","directories":{},"_nodeVersion":"24.13.0","dependencies":{"jose":"^6.2.3","@simplewebauthn/server":"^13.3.0","@simplewebauthn/browser":"^13.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0"},"_npmOperationalInternal":{"tmp":"tmp/did-web-client_0.8.0_1782221797755_0.011503669966404395","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@altimist/did-web-client","version":"0.9.0","description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. F-020","private":false,"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js"}},"engines":{"node":">=20.0.0"},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest","test:cov":"vitest run --coverage","lint":"echo \"(no lint configured)\" && exit 0","prepublishOnly":"npm test && npm run build"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"dependencies":{"@simplewebauthn/browser":"^13.3.0","@simplewebauthn/server":"^13.3.0","jose":"^6.2.3"},"devDependencies":{"@types/node":"^22.10.0","@vitest/coverage-v8":"^2.1.0","typescript":"^5.7.0","vitest":"^2.1.0"},"gitHead":"2ab244a17da55c3555dcad14c52b24b19daf3830","_id":"@altimist/did-web-client@0.9.0","_nodeVersion":"24.13.0","_npmVersion":"11.7.0","dist":{"integrity":"sha512-WgwbcN91PEHAIpQhLwXct4NvaTXdFcxvYplc65Pzpw6a/WCM13GdbHRPs5PV3O2B3zeHQCZHd9IhosQiQpgIQA==","shasum":"d9636ea26bd6b2e334bc87604a1b860391517f97","tarball":"https://registry.npmjs.org/@altimist/did-web-client/-/did-web-client-0.9.0.tgz","fileCount":48,"unpackedSize":128058,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAOmzyCGI/IOtWz2I9wkSUXOiU4ReWhupVR/6UKpuRtJAiBTtNp1w8uxBTytXaRa31N1D+qneSGGK7oRp9L5OZuMtw=="}]},"_npmUser":{"name":"altimistdev","email":"developer@altimist.com"},"directories":{},"maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/did-web-client_0.9.0_1784724971566_0.926381080223708"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-30T12:09:21.296Z","modified":"2026-07-22T12:56:11.848Z","0.1.0":"2026-04-30T12:09:21.572Z","0.2.0":"2026-04-30T15:18:38.781Z","0.4.0":"2026-05-06T15:53:46.626Z","0.5.0":"2026-05-08T15:14:48.997Z","0.6.0":"2026-05-12T11:50:54.776Z","0.7.0":"2026-05-13T13:41:47.785Z","0.7.1":"2026-05-13T14:00:20.500Z","0.7.2":"2026-05-13T16:18:07.474Z","0.8.0":"2026-06-23T13:36:37.897Z","0.9.0":"2026-07-22T12:56:11.700Z"},"description":"Server-side + browser helpers for verifying Altimist users (did:web) and team Verifiable Credentials, tier-2 read helpers for inline identity-status rendering, the SE-signed JWT bridge for MCP, and the F-016 release-vcs client for scoped VC release. F-020","maintainers":[{"name":"altimistdev","email":"developer@altimist.com"}],"readme":"# `@altimist/did-web-client`\r\n\r\nDrop this library into any app — yours or third-party — to authenticate Altimist users without redirecting them anywhere or running a central session. Verification happens locally; the user signs a challenge with their device, you check the signature against their public DID document, done.\r\n\r\n```bash\r\nnpm install @altimist/did-web-client\r\n```\r\n\r\n## What this is\r\n\r\n- **A verifier library.** Your app uses it to check that someone holds a particular Altimist DID, holds a particular team credential, or hasn't had their credentials revoked.\r\n- **Server + browser, ESM, no runtime dependencies on altimist-id.** Server-side functions for verifying signatures and credentials; a small browser-side helper for the WebAuthn ceremony.\r\n- **The protocol implementation of [F-010](https://github.com/altimist/altimist-id/blob/main/docs/specs/F-010-finternet-native-identity-phase-2a.md).** Counterpart to [`@altimist/did-publisher`](https://github.com/altimist/did-publisher) (the publisher-side library used by the [altimist-com-router](https://github.com/altimist/altimist-com-router) Cloudflare Worker that hosts DIDs at `*.altimist.com`).\r\n\r\n## What this is *not*\r\n\r\n- **Not an OAuth provider, OIDC client, or session library.** No redirect flow. No central session store. No bearer tokens issued by an Altimist server. You generate challenges, the user signs them locally, you verify locally. Period.\r\n- **Not a place to send users to \"log in.\"** Users authenticate against *your* app, not against altimist.id. altimist.id is where users went once, to *create* their identity — like signing up for a Gmail account. Subsequent sign-ins to your app happen between your app and the user's device, mediated by this library.\r\n- **Not a profile or marketing surface.** Identity profiles live at `<handle>.altimist.com`, owned by the corporate website. This library doesn't render anything.\r\n\r\n## Trust model\r\n\r\nThis library is designed so altimist.id is **never on the request path** between your app and your users. The diagram is short:\r\n\r\n```\r\nyour app  ──── WebAuthn challenge ────►  user's browser  ────►  user's Secure Enclave (signs)\r\n   ▲                                         │                          │\r\n   │                                         ▼                          │\r\n   │  ◄──── signed assertion ───────────  ────────────────────────────  │\r\n   │\r\n   └──── fetch did.json ──────────────►  patrick.altimist.com (Cloudflare-cached, public)\r\n```\r\n\r\naltimist-id wrote the user's `did.json` to `patrick.altimist.com` once (when the user enrolled their first device) and updates it when the user adds/revokes a device. After that, your app reads it the same way any verifier in the world does — over HTTPS, with no token, no rate limit, no API key.\r\n\r\n**Implications:**\r\n- Your app's auth latency is dominated by Cloudflare cache. Sub-50ms typical.\r\n- altimist-id can be down without breaking auth on your app.\r\n- altimist-id can't see who's signing in to your app — no telemetry pipe.\r\n- The only \"shared secret\" between your app and altimist is the user's published public key in their DID doc. That's it.\r\n\r\n## Prerequisites\r\n\r\nBefore this library is useful for a given user, the user needs to **already have an Altimist DID**. They get one by signing up at [altimist.id](https://altimist.id) (the operator's onboarding surface), where they pick a handle and enrol a device using their browser's passkey support. After that, `did:web:<handle>.altimist.com/.well-known/did.json` exists and is publicly resolvable, and your app can authenticate them.\r\n\r\nYou don't need to know about altimist.id beyond pointing your users at it. If a user lands in your sign-in flow without an Altimist DID yet, send them to `https://altimist.id/signup`.\r\n\r\n## Quick start: add Altimist sign-in to a Next.js app\r\n\r\nTwo server routes plus a browser-side button. Total: ~50 lines of glue.\r\n\r\n### 1. Server: issue the challenge\r\n\r\n```ts\r\n// app/api/auth/altimist/challenge/route.ts\r\nimport { issueChallenge } from \"@altimist/did-web-client\";\r\nimport { NextResponse } from \"next/server\";\r\n\r\nexport async function POST(req: Request) {\r\n  const { handle } = await req.json();\r\n  const options = await issueChallenge({\r\n    handle,\r\n    rpID: \"yourapp.com\",          // your app's domain\r\n  });\r\n\r\n  // Persist options.challenge alongside the user's session — you'll\r\n  // re-check it on /verify. iron-session, cookies, or a short-lived\r\n  // server-side cache all work.\r\n  await persistChallenge(handle, options.challenge);\r\n\r\n  return NextResponse.json(options);\r\n}\r\n```\r\n\r\n### 2. Server: verify the assertion\r\n\r\n```ts\r\n// app/api/auth/altimist/verify/route.ts\r\nimport { verifyChallenge } from \"@altimist/did-web-client\";\r\nimport { NextResponse } from \"next/server\";\r\n\r\nexport async function POST(req: Request) {\r\n  const { handle, response } = await req.json();\r\n  const expectedChallenge = await readPersistedChallenge(handle);\r\n\r\n  const result = await verifyChallenge({\r\n    handle,\r\n    expectedChallenge,\r\n    expectedOrigin: \"https://yourapp.com\",\r\n    expectedRPID: \"yourapp.com\",\r\n    response,                       // AuthenticationResponseJSON from browser\r\n  });\r\n\r\n  if (!result.ok) {\r\n    return NextResponse.json({ error: result.reason }, { status: 401 });\r\n  }\r\n\r\n  // result.kid = the device key id that signed this challenge.\r\n  // Issue your own session cookie / JWT here.\r\n  return NextResponse.json({ handle, kid: result.kid });\r\n}\r\n```\r\n\r\n### 3. Browser: drive the WebAuthn ceremony\r\n\r\n```tsx\r\n// app/components/sign-in-button.tsx\r\n\"use client\";\r\nimport { startAuthentication } from \"@simplewebauthn/browser\";\r\n\r\nexport function SignInWithAltimist({ handle }: { handle: string }) {\r\n  async function handleClick() {\r\n    const optionsRes = await fetch(\"/api/auth/altimist/challenge\", {\r\n      method: \"POST\",\r\n      body: JSON.stringify({ handle }),\r\n    });\r\n    const options = await optionsRes.json();\r\n\r\n    const response = await startAuthentication({ optionsJSON: options });\r\n\r\n    const verifyRes = await fetch(\"/api/auth/altimist/verify\", {\r\n      method: \"POST\",\r\n      body: JSON.stringify({ handle, response }),\r\n    });\r\n    if (verifyRes.ok) window.location.href = \"/dashboard\";\r\n  }\r\n  return <button onClick={handleClick}>Sign in with Altimist</button>;\r\n}\r\n```\r\n\r\nThat's the whole sign-in flow. The user clicks, their device prompts for biometric (Touch ID, Windows Hello, 1Password), and your app gets their authenticated handle.\r\n\r\nYou install `@simplewebauthn/browser` separately (`npm install @simplewebauthn/browser`); this library doesn't bundle it.\r\n\r\n## Authorisation: checking team membership\r\n\r\nSign-in proves \"this is patrick.\" Authorisation answers \"what is patrick allowed to do?\" — answered by checking a Verifiable Credential issued by an Altimist team-hub.\r\n\r\n```ts\r\nimport { fetchTeamIssuer, verifyMembershipVC, isRevoked } from \"@altimist/did-web-client\";\r\n\r\nconst { jwk } = await fetchTeamIssuer(\"altimist\");        // public key\r\nconst result = await verifyMembershipVC({\r\n  vcJwt: presentedVC,\r\n  issuerPublicJwk: jwk,\r\n  subjectDid: `did:web:${handle}.altimist.com`,\r\n});\r\nif (!result.ok) return forbid(\"invalid VC\");\r\n\r\nif (await isRevoked(result.vcHash)) return forbid(\"revoked\");\r\n\r\nif (!result.scopes.includes(\"capital.trader\")) return forbid(\"missing scope\");\r\n```\r\n\r\nThe VC is presented to your app by the user (typically in a header or query param after sign-in). Your app verifies the signature locally — no network call to altimist-id, just `fetchTeamIssuer` to get the public key from `altimist.com/.well-known/team-issuers/altimist.json`, which is heavily cached.\r\n\r\n## MCP / agent-to-server bridge (v0.2+)\r\n\r\nFor machine-to-machine calls where the user's authenticated agent needs to authenticate to a downstream server (e.g. an MCP server) without a browser in the loop:\r\n\r\n**Mint (browser, after the user is signed in):**\r\n\r\n```ts\r\nimport { mintBridgeJwt } from \"@altimist/did-web-client/browser\";\r\n\r\nconst token = await mintBridgeJwt({\r\n  handle: \"patrick\",\r\n  kid: \"<cred id from did.json>\",\r\n  rpID: \"yourapp.com\",\r\n});\r\n// Use as: Authorization: Bearer <token>\r\n```\r\n\r\n**Verify (server-side, on the receiving end of the bridge):**\r\n\r\n```ts\r\nimport { verifyBridgeJwt } from \"@altimist/did-web-client\";\r\n\r\nconst result = await verifyBridgeJwt({\r\n  token: bearerToken,\r\n  expectedOrigin: \"https://yourapp.com\",\r\n  expectedRPID: \"yourapp.com\",\r\n});\r\nif (!result.ok) return res.status(401).json({ reason: result.reason });\r\n// result.handle, result.kid, result.vc?, result.jti, result.iat, result.exp\r\n```\r\n\r\nThe bridge JWT carries a 60-second lifetime by default and a `jti` so the receiver can implement replay protection if needed. **It's not a vanilla JWT** — the signature uses Secure Enclave WebAuthn rather than a server-side key, so off-the-shelf JWT libraries won't verify it. Always use `verifyBridgeJwt`.\r\n\r\n## Full API\r\n\r\n| Function | Purpose |\r\n|---|---|\r\n| `resolveDid(handle, opts?)` | Fetch + parse `<handle>.altimist.com/.well-known/did.json` (subdomain form) |\r\n| `parseDid(did)` | Parse a `did:web:` identifier into `{ form, host, handle, url }`. Recognises both subdomain (`did:web:<handle>.<host>`) and F-011 path form (`did:web:<host>:users:<handle>`) |\r\n| `getDidDocument(did)` | Same as `resolveDid` but takes a full `did:web:` identifier (either form) — uses `parseDid` to derive the URL. Validates the round-trip (`doc.id === input did`) |\r\n| `getDevices(handle, opts?)` | Tier-2 helper: returns the user's active devices as `{ kid, publicKeyJwk }[]` for inline display |\r\n| `getAlsoKnownAs(handle, opts?)` | Tier-2 helper: returns the user's bound alternative DIDs (display-only) |\r\n| `getMemberships(handle, vcs, opts?)` | Tier-2 helper: filters presented JWT-VCs to only those that verify against the user's identity AND aren't revoked |\r\n| `issueChallenge({ handle, rpID })` | WebAuthn auth options for `navigator.credentials.get()` — `allowCredentials` is drawn from the user's did.json |\r\n| `verifyChallenge({ ... })` | Verify a WebAuthn assertion against the JWK published in did.json |\r\n| `fetchTeamIssuer(team, opts?)` | Fetch the team-hub public JWK from `altimist.com/.well-known/team-issuers/<team>.json` |\r\n| `verifyMembershipVC({ ... })` | Verify a JWT-VC (W3C VC 2.0) signed by a team-hub. Pure function — no network |\r\n| `isRevoked(hash, opts?)` | Check `altimist.com/.well-known/revocations.json` |\r\n| `mintBridgeJwt({ ... })` (browser) | Mint an SE-signed JWT for machine-to-machine auth |\r\n| `verifyBridgeJwt({ ... })` | Verify a bridge JWT |\r\n| `getPaymentDescriptor(handle, { asset, network })` | Money path (F-024): resolve the `FinternetPay` pointer, fetch a per-payment descriptor, verify its ES256 proof end to end. Returns the verified descriptor or `null` |\r\n| `getWalletEndpoint(handle, { asset, network })` | **Deprecated** — use `getPaymentDescriptor`. Static `FinternetWallet` address for `(asset, network)` |\r\n| `getWallets(handle, opts?)` | **Deprecated** — use `getPaymentDescriptor`. All published `FinternetWallet` endpoints |\r\n| `getContacts(handle, opts?)` | All published `FinternetContact` endpoints |\r\n\r\nAll fetchers accept an optional `{ baseUrl }` (template with `{handle}` / `{team}` substitution) so staging environments can override the apex (e.g. `altimist.dev` for testing).\r\n\r\n### Tier-2 helpers — inline identity-status rendering\r\n\r\nFor the auth-vs-display split: tier-2 helpers let consumer apps render identity state inline without redirecting users to altimist.id. Use them on your own account/profile pages.\r\n\r\n```ts\r\nimport { getDevices, getMemberships, getAlsoKnownAs } from \"@altimist/did-web-client\";\r\n\r\n// \"Patrick · 3 devices\" inline\r\nconst devices = await getDevices(\"patrick\");\r\n\r\n// \"Patrick holds: staff.admin, capital.trader\"\r\nconst memberships = await getMemberships(\"patrick\", presentedVcs);\r\n\r\n// \"Also known as: did:web:patrickjv.com\"\r\nconst akas = await getAlsoKnownAs(\"patrick\");\r\n```\r\n\r\nAll three are server-only, fail-closed (resolver errors throw `ResolverError`), and accept the same `{ baseUrl }` template option for staging overrides. `getMemberships` additionally accepts `teamIssuerBaseUrl` and `revocationsUrl` for fully custom staging.\r\n\r\nFor sensitive identity *mutations* (add device, revoke device, bind alt-DID, account recovery), don't use this library — those happen at altimist.id via deep-link from your app. See [F-012 spec](https://github.com/altimist/altimist-id/blob/main/docs/specs/F-012-consumer-app-integration-toolkit.md) for the tier-3 deep-link pattern.\r\n\r\n### Money path: signed payment descriptors (F-024)\r\n\r\n`getPaymentDescriptor` replaces the static `FinternetWallet` address with a **send-only** `FinternetPay` pointer plus a per-payment, short-TTL, ES256-signed descriptor. Publishing a reusable address in a world-readable did.json let anyone map a handle → address → full on-chain history; the descriptor model derives a fresh address per request and signs it.\r\n\r\n```ts\r\nimport { getPaymentDescriptor } from \"@altimist/did-web-client\";\r\n\r\nconst d = await getPaymentDescriptor(\"patrickjv\", { asset: \"bch\", network: \"chipnet\" });\r\nif (d === null) {\r\n  // handle publishes no FinternetPay pointer, or has no source for this (asset, network)\r\n} else {\r\n  // d = { did, asset, network, address, issuedAt, expiresAt, requestId }\r\n  // pay d.address BEFORE d.expiresAt — it's scoped to this single payment.\r\n}\r\n```\r\n\r\nIt resolves did.json (with the same doc-id integrity check as the other getters), POSTs `{ asset, network }` to `<FinternetPay endpoint>/descriptors`, then verifies **before returning**: the proof `kid` is a `capabilityInvocation`-only key in the document (never a sign-in key), `alg` is `ES256`, the signature verifies over the RFC 8785 (JCS) canonical descriptor, `descriptor.did` matches the resolved document, `asset`/`network` match the request, `expiresAt` is in the future, and `address` is non-empty. Any violation throws `DescriptorError`; a missing pointer or `no_payment_source` returns `null`; an unknown handle propagates `ResolverError`.\r\n\r\n`getWalletEndpoint` and `getWallets` are **deprecated** in favour of `getPaymentDescriptor` and kept only through the migration window (until `FinternetWallet` entries are gone from published documents). `getContacts` is unaffected.\r\n\r\n#### Security note — SSRF on the FinternetPay endpoint\r\n\r\nThe `FinternetPay` endpoint URL lives in a world-readable, issuer-controlled did.json. `getPaymentDescriptor` fetches it server-side, so before any request it enforces `https:`, rejects IP-literal hosts that are loopback / link-local (incl. the `169.254.169.254` cloud-metadata address) / private / IPv4-mapped-IPv6 forms of those, rejects the literal `localhost`, and refuses to follow redirects (`redirect: \"manual\"`).\r\n\r\n**Accepted residual — DNS rebinding is NOT defended against.** These are literal-host checks only; a public hostname that resolves to an internal IP at connection time bypasses them, and there is no portable way to resolve-then-pin DNS across this library's Node / edge / browser targets. If you run this in a security-sensitive server environment, put the consuming service behind **network-level egress controls** (an egress proxy/firewall limiting outbound connections to known-good destinations) — that layer sees the resolved IP at connect time, which this library cannot.\r\n\r\n## Common gotchas\r\n\r\n- **`expectedOrigin` and `expectedRPID` must match what the user's browser saw.** WebAuthn binds credentials to (origin, RP_ID) pairs. If your app is `yourapp.com`, set both. If you have a staging host, keep separate values for that environment. Mismatches surface as `result.ok === false` with `reason: \"origin\"` or `reason: \"rpid\"`.\r\n- **Persist the challenge between issue and verify.** The challenge is single-use, short-lived (~60s), and stateless from this library's perspective. Use a session cookie, iron-session, Redis, or a short-lived DB row.\r\n- **Don't put the kid in your session cookie if you can avoid it.** Use it transiently for revocation checks at sign-in time, then issue your app's normal session token. Storing per-device kids in long-lived cookies leaks user-device-fingerprint info if your cookies leak.\r\n- **Revocation is fail-closed by default.** If the apex revocations endpoint is unreachable, `isRevoked` returns `true` (treats credentials as revoked) rather than passing through. Pass `{ failOpen: true }` if you'd rather degrade open during an outage. Discuss with your security stakeholders before flipping.\r\n- **`@simplewebauthn/browser` versions matter.** This library was tested against `@simplewebauthn/browser` v10+. Earlier versions have different API shapes.\r\n\r\n## Versioning\r\n\r\nThis library follows semver. Pin to a specific version (`\"@altimist/did-web-client\": \"0.3.x\"`) until 1.0 — the API surface is stable but internal types may move.\r\n\r\n## Phase 2a status\r\n\r\n- **v0.1** — initial publish. Identity verification (`resolveDid`, `issueChallenge`, `verifyChallenge`), VC verification (`fetchTeamIssuer`, `verifyMembershipVC`), revocation check (`isRevoked`).\r\n- **v0.2** — bridge JWT mint + verify (M8). VC revocation cross-check at verify time (M9).\r\n- **v0.3 (F-012)** — tier-2 read helpers (`getDevices`, `getMemberships`, `getAlsoKnownAs`) for inline rendering of identity status in consumer apps without redirects. Foundation for the [E-002 consumer-app onboarding epic](https://github.com/altimist/altimist-id/blob/main/docs/epics/E-002-consumer-app-onboarding.md).\r\n- **v0.6 (F-011)** — dual-form did:web parsing. `parseDid(did)` + `getDidDocument(did)` recognise both `did:web:<handle>.<host>` (subdomain) and `did:web:<host>:users:<handle>` (path) and fetch from the right URL transparently. `resolveDid(handle, opts?)` is unchanged for callers that already have the handle string.\r\n- **v0.9 (F-024, #13)** — key-purpose segregation (a `capabilityInvocation`-only key is excluded from every sign-in / bridge-JWT candidate set, so an org-held FinternetPay signing key can never impersonate the holder) + `getPaymentDescriptor` (send-only signed payment descriptors). `getWalletEndpoint` / `getWallets` deprecated.\r\n\r\nSee [F-010 milestones](https://github.com/altimist/altimist-id/blob/main/docs/specs/F-010-milestones.md) for the broader plan and [F-012 spec](https://github.com/altimist/altimist-id/blob/main/docs/specs/F-012-consumer-app-integration-toolkit.md) for the tier-2 + tier-3 design.\r\n","readmeFilename":"README.md"}