{"_id":"@antivamp_io/sdk","_rev":"6-a1975521caed88616fe24ff42ff90131","name":"@antivamp_io/sdk","dist-tags":{"latest":"0.2.4"},"versions":{"0.1.0":{"name":"@antivamp_io/sdk","version":"0.1.0","keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"license":"MIT","_id":"@antivamp_io/sdk@0.1.0","maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"homepage":"https://antivamp.io/developers","bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"bin":{"antivamp-conformance":"bin/conformance.mjs"},"dist":{"shasum":"95abc4a4876dcd18717a4f45ca7023366ae5f956","tarball":"https://registry.npmjs.org/@antivamp_io/sdk/-/sdk-0.1.0.tgz","fileCount":24,"integrity":"sha512-OUCmmvgY5ubzdAZ+PrTfv6w+FkaEiKNgs7EAQ3mfE+PMr7CiurEHIxYKa2l0IHezPIZ1LLiX1MpgJMSwmgPdZw==","signatures":[{"sig":"MEYCIQCj7A/2yE2/C0/O08RTYaAStGOEzwpRefuJLW99OYuujQIhAKBdlGKOs94isnWdyB1tsLH0iEJGrAsrJnj5EQ/pUOIh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65861},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7bba85e8e4fef5b314cd1f5a7b7ba6b2e520fc58","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","smoke":"node scripts/smoke-pack.mjs","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run typecheck && npm run test && npm run build && npm run smoke"},"_npmUser":{"name":"antivamp","email":"calvin@antivamp.io"},"repository":{"url":"git+https://github.com/NoVamp-io/AntiVamp.git","type":"git","directory":"sdk"},"_npmVersion":"10.8.2","description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","directories":{},"sideEffects":false,"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^5","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.0_1785014632018_0.7518978157094822","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@antivamp_io/sdk","version":"0.2.0","keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"license":"MIT","_id":"@antivamp_io/sdk@0.2.0","maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"homepage":"https://antivamp.io/developers","bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"bin":{"antivamp-conformance":"bin/conformance.mjs"},"dist":{"shasum":"4392416932ecdbb15e3eab56c94b24164e4e31fc","tarball":"https://registry.npmjs.org/@antivamp_io/sdk/-/sdk-0.2.0.tgz","fileCount":24,"integrity":"sha512-gR/zKsG3tgYiLZwcfmQVHVHZAM4RE1/zeAL97OB6l7B/Tc8C/m6PTxN9o0LrWyPVokLTpqCkP9YSSCOFdi5bgw==","signatures":[{"sig":"MEYCIQCkx6EuPWSWCTIhyhbRwStN0lONLH+EtyOU6aOR+qlZ6wIhAMS95169gYRA0RXb5zKr6E+04PymBsJbMkmEQpXFdKg6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":77509},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"77cd4d6fc7114a4831b32d32ec0b162e998a5729","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","smoke":"node scripts/smoke-pack.mjs","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run typecheck && npm run test && npm run build && npm run smoke"},"_npmUser":{"name":"antivamp","email":"calvin@antivamp.io"},"repository":{"url":"git+https://github.com/NoVamp-io/AntiVamp.git","type":"git","directory":"sdk"},"_npmVersion":"10.8.2","description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","directories":{},"sideEffects":false,"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^5","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.0_1785016307830_0.11116464861866548","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@antivamp_io/sdk","version":"0.2.1","keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"license":"MIT","_id":"@antivamp_io/sdk@0.2.1","maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"homepage":"https://antivamp.io/developers","bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"bin":{"antivamp-conformance":"bin/conformance.mjs"},"dist":{"shasum":"b06ebc0ddf17d38ed40c550ea10e682d2935a60f","tarball":"https://registry.npmjs.org/@antivamp_io/sdk/-/sdk-0.2.1.tgz","fileCount":24,"integrity":"sha512-0FFybBOypLmOkxct7iNFpxC3HfZ/4r+eghvcWbBZMD9cGPpu0ofdM9BEr4qvrtXOzx8F+9X6yfJLQsT0vJGtaA==","signatures":[{"sig":"MEUCIHVXgf0wN4OHlVLbNUaUWL0z8s9oWzZh3k3eJhckEEW0AiEA9QO0lqQWhlsAnW09mvhu3ZgkhSBdb78uCZsbYCBacq8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":83801},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c3fc1abf69ed1d00acb7be594efba063f9d59cd5","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","smoke":"node scripts/smoke-pack.mjs","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run typecheck && npm run test && npm run build && npm run smoke"},"_npmUser":{"name":"antivamp","email":"calvin@antivamp.io"},"repository":{"url":"git+https://github.com/NoVamp-io/AntiVamp.git","type":"git","directory":"sdk"},"_npmVersion":"10.8.2","description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","directories":{},"sideEffects":false,"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^5","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.1_1785166009573_0.2765565155032459","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@antivamp_io/sdk","version":"0.2.2","keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"license":"MIT","_id":"@antivamp_io/sdk@0.2.2","maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"homepage":"https://antivamp.io/developers","bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"bin":{"antivamp-conformance":"bin/conformance.mjs"},"dist":{"shasum":"55f6f3450624c49a248b1b803fed5cbc013dfcbd","tarball":"https://registry.npmjs.org/@antivamp_io/sdk/-/sdk-0.2.2.tgz","fileCount":24,"integrity":"sha512-ZbtaGiJIt2GsBwe6Jj5JAyYSu5jV0Ul3G7nI6A1P0m+WPdww3/rC6teGninqD3N3WRpPNcBuU3MkCbMaM5VyuA==","signatures":[{"sig":"MEYCIQCys/+EQ8Sv/F13aQ4kykw3hsjykJ3YayIWrvFfqx/rWwIhAL/r0g+/zPnD7T+w3Q80g4iyybPEH7Dkzea7RF1lIevo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86582},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a2251865c3d8771cba1e629d88410ee878f06027","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","smoke":"node scripts/smoke-pack.mjs","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run typecheck && npm run test && npm run build && npm run smoke"},"_npmUser":{"name":"antivamp","email":"calvin@antivamp.io"},"repository":{"url":"git+https://github.com/NoVamp-io/AntiVamp.git","type":"git","directory":"sdk"},"_npmVersion":"10.8.2","description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","directories":{},"sideEffects":false,"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^5","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.2_1785172929705_0.1938680165505875","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@antivamp_io/sdk","version":"0.2.3","keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"license":"MIT","_id":"@antivamp_io/sdk@0.2.3","maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"homepage":"https://antivamp.io/developers","bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"bin":{"antivamp-conformance":"bin/conformance.mjs"},"dist":{"shasum":"a515d0e931cf22e11bb38500569288cfbaa01940","tarball":"https://registry.npmjs.org/@antivamp_io/sdk/-/sdk-0.2.3.tgz","fileCount":24,"integrity":"sha512-psHfyjvp3vlaxOr1+P0OTv+twZRbBpOCPLiEdpQKQ9w+455CA3pukgW3zStttQUi6v9W2V/TNrDKaJl4racBnQ==","signatures":[{"sig":"MEYCIQDP/5AfFHoew1C1PxBcvdfmrvd2QnJ08iAwa6YbZ82dKgIhALX3EYy6kZwMQf4KhSuMZd7gRE7tRn56yjViJbOjbd1y","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":87074},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"0eb365c746d22265edd21a690791076904b33f21","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","smoke":"node scripts/smoke-pack.mjs","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"npm run typecheck && npm run test && npm run build && npm run smoke"},"_npmUser":{"name":"antivamp","email":"calvin@antivamp.io"},"repository":{"url":"git+https://github.com/NoVamp-io/AntiVamp.git","type":"git","directory":"sdk"},"_npmVersion":"10.8.2","description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","directories":{},"sideEffects":false,"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^5","@types/node":"^22.20.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.3_1785176284545_0.9039570888772221","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@antivamp_io/sdk","version":"0.2.4","description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","license":"MIT","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"bin":{"antivamp-conformance":"bin/conformance.mjs"},"engines":{"node":">=18"},"sideEffects":false,"publishConfig":{"access":"public"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run","smoke":"node scripts/smoke-pack.mjs","prepublishOnly":"npm run typecheck && npm run test && npm run build && npm run smoke"},"keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"repository":{"type":"git","url":"git+https://github.com/NoVamp-io/AntiVamp.git","directory":"sdk"},"homepage":"https://antivamp.io/developers","bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"devDependencies":{"@types/node":"^22.20.1","typescript":"^5","vitest":"^4.1.10"},"_id":"@antivamp_io/sdk@0.2.4","gitHead":"fb5e8b41b26af8c434384324dc9602a9f5ad8619","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-9RUBL9RUj7mhfypie9vArOJFebGfbXGIAjOXGmbD3apxJerNzs+efUrc8H7QUUmvUIpBMv+/esdW/yBO3w0csA==","shasum":"b5fb2423359484b222b0bb45f88eeced11187df8","tarball":"https://registry.npmjs.org/@antivamp_io/sdk/-/sdk-0.2.4.tgz","fileCount":24,"unpackedSize":89615,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGb+mYz4WS7LfLukV7v/pPAEKJyIk19dxsTjXRNB7l7WAiEAkNsO18ZNqMlTy5hPic6kT6Eb4qckk/268digz8nCIf0="}]},"_npmUser":{"name":"antivamp","email":"calvin@antivamp.io"},"directories":{},"maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.2.4_1785203001483_0.2382530846821782"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-25T21:23:51.928Z","modified":"2026-07-28T01:43:21.785Z","0.1.0":"2026-07-25T21:23:52.163Z","0.2.0":"2026-07-25T21:51:47.973Z","0.2.1":"2026-07-27T15:26:49.712Z","0.2.2":"2026-07-27T17:22:09.864Z","0.2.3":"2026-07-27T18:18:04.730Z","0.2.4":"2026-07-28T01:43:21.640Z"},"bugs":{"url":"https://github.com/NoVamp-io/AntiVamp/issues"},"license":"MIT","homepage":"https://antivamp.io/developers","keywords":["antivamp","solana","launchpad","token","identity","anti-vamp"],"repository":{"type":"git","url":"git+https://github.com/NoVamp-io/AntiVamp.git","directory":"sdk"},"description":"Official AntiVamp SDK — cross-chain token identity protection for launchpads. Validate launches, verify signed decisions and webhooks, report lifecycle events.","maintainers":[{"name":"antivamp","email":"calvin@antivamp.io"}],"readme":"# @antivamp_io/sdk\n\nOfficial TypeScript SDK for [AntiVamp](https://antivamp.io) — cross-chain token\nidentity protection for launchpads. Validate launches, verify signed decisions\nand webhooks, and report lifecycle events.\n\nNode.js >= 18. Server-side only — **never ship your API key in browser code.**\n\n```bash\nnpm install @antivamp_io/sdk\n```\n\nDo not hand-port this package. Decision verification, the canonical signing\npayload, webhook HMAC and the normalization fold all have to agree byte for byte\nwith the server, and a copy that agrees today drifts silently the first time any\nof them changes — the failure mode is a launchpad that accepts decisions it\nshould reject. If your deploy target cannot see the dependency (a build context\nscoped below the repo root, say), fix the dependency path rather than the code.\n\n## Quickstart\n\n```ts\nimport { AntiVampClient, AntiVampFailClosedError } from \"@antivamp_io/sdk\";\n\nconst antivamp = new AntiVampClient({\n  apiKey: process.env.ANTIVAMP_API_KEY, // av_sbx_… or av_live_…\n});\n\n// Before accepting a launch — always send the wallet that will actually deploy:\ntry {\n  const gate = await antivamp.enforceLaunch({\n    chain: \"solana\",\n    launchpad: \"your-launchpad\",\n    name: creator.tokenName,\n    ticker: creator.tokenTicker,\n    launcher: creator.wallet,\n  });\n\n  // enforceLaunch verifies the Ed25519 signature and expiry, then maps every\n  // decision exhaustively. It proceeds ONLY on a verified `allow`.\n  if (gate.block) {\n    rejectLaunch(gate.reason);\n  } else {\n    proceed();\n  }\n} catch (err) {\n  if (err instanceof AntiVampFailClosedError) rejectLaunch(\"validation unavailable\");\n  else throw err;\n}\n```\n\n`allow_authorized_only` means the identity is protected and you have not supplied\n(or have not matched) the authorized launcher — `enforceLaunch` blocks it. When\nthe launcher you send **is** the authorized wallet, the server returns `allow`.\nNever treat `allow_authorized_only` as permission to launch; re-validate with the\nconnected wallet and require a fresh verified `allow`.\n\n## Reporting bonds and milestones needs a keeper token\n\n`reportBond` and `reportMilestone` extend on-chain protection, so in production\nthey require a keeper attestation on top of your partner key — otherwise any\npartner key could forge lock extensions. Sandbox does not need one.\n\n```ts\nconst antivamp = new AntiVampClient({\n  apiKey: process.env.ANTIVAMP_API_KEY,       // av_live_…\n  keeperToken: process.env.ANTIVAMP_KEEPER_TOKEN,\n});\n```\n\n`keeperToken` defaults to `ANTIVAMP_KEEPER_TOKEN`, so setting that variable is\nenough. It is sent as `X-AntiVamp-Keeper: Bearer …` on those two calls only.\n\nWithout it, a production report is refused **before** the request goes out.\nThat is deliberate: the server would return `403 keeper_required`, and a 403 on\nan event report is not a visible failure — the launch still succeeds, the copycat\nlock just never lands, and the only symptom is protection that quietly does not\nexist. Fail loudly at the call site instead.\n\n## EVM: resolve registry addresses, don't hardcode them\n\nOn EVM chains the reservation gate is a contract, and your factory has to be the\none that registry trusts. Two addresses have to agree:\n\n- your factory's `reservationRegistry()` must be AntiVamp's registry, and\n- that registry's `factory()` must be your factory.\n\nIf either drifts, `markLaunched` reverts `NotFactory` and **every launch fails**.\nThere is no soft failure and no warning beforehand. This has happened twice in\nproduction, both times because an address was copied into a launchpad's `.env`\nand a later cutover moved on without it.\n\nSo resolve at runtime:\n\n```ts\nconst registry = await antivamp.getReservationRegistry(\"base\");\n// → the registry the live factory actually consults, right now\n```\n\nPoint your reserve UI, your indexer and your factory at that one address. If you\nmust cache it, cache it with a TTL and re-read on boot — never bake it into a\nbuild. And after any change, verify the loop closes in both directions before\nyou consider the integration live.\n\n## API\n\n### `new AntiVampClient(options)`\n`apiKey`, `baseUrl` (default `https://antivamp.io`), `timeoutMs` (8000),\n`maxRetries` (2, exponential backoff on network/5xx/429), `publicKeys` (pin\ndecision keys instead of fetching), `fetch` (custom).\n\n### Methods\n- `enforceLaunch(req)` → `{ block, reason, enforceable, failClosed, raw }`.\n  **Recommended gate.** Validates, verifies the signature, and blocks anything\n  that is not a verified `allow`.\n- `validateLaunch(req)` → signed `ValidationDecision`. **Fails closed**: throws\n  `AntiVampFailClosedError` on outage — treat as \"do not launch\".\n- `checkIdentity(req)` → public `IdentityCheckResult` (no key required).\n- `getIdentityStatus(identityKey)` → status by identity key (no key required).\n- `reportLaunch(req)`.\n- `reportBond(req)` / `reportMilestone(req)` — **production requires a keeper\n  token**, see below.\n- `getChains()` → `ChainInfo[]`: per-chain reservation registry, graduated\n  registry and status (no key required, cached 5 min).\n- `getReservationRegistry(chainId)` → the registry address for one chain, or\n  `null` for chains without one. Throws on an unknown chain id.\n- `listProtectedIdentities(query)` / `iterateProtectedIdentities(query)` →\n  the public registry, cursor-paginated (no key required).\n- `quoteReservation(req)` / `prepareReservation(req)` /\n  `getReservationStatus(query)` / `confirmReservation(body)` /\n  `listReservations(wallet)` / `createReservation(body)`.\n- `verifyValidationDecision(decision, opts?)` → `{ valid, reason }`. Checks the\n  Ed25519 signature against the published public key plus expiry/clock-skew.\n- `verifyWebhook(secret, rawBody, signatureHeader)` → boolean.\n- `normalizeIdentity(name, ticker)` → `{ normalizedName, normalizedTicker, identityKey }`.\n- `getPublicKeys()` → current verification keys (cached 5 min).\n\n### Errors\n`AntiVampApiError` (structured `status`/`code`), `AntiVampTimeoutError`,\n`AntiVampNetworkError`, `AntiVampFailClosedError`, base `AntiVampError`.\n\n## Signed decisions\nDecisions are Ed25519-signed over a canonical field ordering (see\n`canonicalDecision`) and expire after 5 minutes. Verification uses only the\npublic key from `GET /v1/keys` — rotate keys without redistributing secrets.\nRe-validate once a decision expires; never launch on a stale `allow`.\n\n## Webhooks\n`X-AntiVamp-Signature: t=<unix>,v1=<hmac-sha256 over \"<t>.<rawBody>\">`. Pass the\n**raw** body string to `verifyWebhook` (do not re-serialize).\n","readmeFilename":"README.md"}