{"_id":"@aopslabs/artifact-trust-contracts","_rev":"5-87763359e750c56f1056a044916e854c","name":"@aopslabs/artifact-trust-contracts","dist-tags":{"latest":"0.3.3"},"versions":{"0.2.0":{"name":"@aopslabs/artifact-trust-contracts","version":"0.2.0","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/artifact-trust-contracts@0.2.0","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/aops-platform#readme","bugs":{"url":"https://github.com/eeemzs/aops-platform/issues"},"dist":{"shasum":"a6c6124efcdc815a1c366e3dcd2300b85cd22cdf","tarball":"https://registry.npmjs.org/@aopslabs/artifact-trust-contracts/-/artifact-trust-contracts-0.2.0.tgz","fileCount":52,"integrity":"sha512-QdYzQ5w5QO0HkEjWISIrpkwVHUVuJJ7W96lBYuYY+QoHYZ6age8VnCd+AYw3mc10bVUXD0n7WyI9KlmKdtVjHg==","signatures":[{"sig":"MEUCIQDc3JzB6CJkGHUj0arivm2Brir4mcQqbC8+S6353L35fAIgcoCuLeqaCuo8Gonxit+kmofZrVOswrMUoRO4eO3KWiI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":509975},"main":"./dist/index.js","type":"module","_from":"file:S:/dev-js2/tmp/aops-public-closure-20260804-rr6/aopslabs-artifact-trust-contracts-0.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"test":"pnpm run build && node --test test/*.test.mjs","build":"tsc -b tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"_npmUser":{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"},"_resolved":"S:\\dev-js2\\tmp\\aops-public-closure-20260804-rr6\\aopslabs-artifact-trust-contracts-0.2.0.tgz","_integrity":"sha512-QdYzQ5w5QO0HkEjWISIrpkwVHUVuJJ7W96lBYuYY+QoHYZ6age8VnCd+AYw3mc10bVUXD0n7WyI9KlmKdtVjHg==","repository":{"url":"git+https://github.com/eeemzs/aops-platform.git","type":"git","directory":"apps/aops/packages/artifact-trust-contracts"},"_npmVersion":"11.6.4","description":"Private AOPS artifact, receipt, lease, and admission contracts.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"tslib":"^2.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/artifact-trust-contracts_0.2.0_1785880862534_0.12488165400627582","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aopslabs/artifact-trust-contracts","version":"0.3.0","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/artifact-trust-contracts@0.3.0","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/aops-platform#readme","bugs":{"url":"https://github.com/eeemzs/aops-platform/issues"},"dist":{"shasum":"33ce0f29a1655b7cb02f3a92add3f330787d24f1","tarball":"https://registry.npmjs.org/@aopslabs/artifact-trust-contracts/-/artifact-trust-contracts-0.3.0.tgz","fileCount":56,"integrity":"sha512-U26Eqvx9tAxaP4r71QeftPdjL9/gOjSoDixe+XyTLynb/nrwVADtklpHHhNHovcjcpwEVrhEe+LsFUXyf5QtdQ==","signatures":[{"sig":"MEQCIHxgT2MUTEXf4DoIQdhiG19P4Ax9pZWNWChxB4V8vaNuAiBTP0QFMKw0y40kDVevI9CegoCMRGnzMcnz79ChFrvdLQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":550240},"main":"./dist/index.js","type":"module","_from":"file:C:/Users/mzs/AppData/Local/Temp/aops-task-180-d25e18d/aopslabs-artifact-trust-contracts-0.3.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"test":"pnpm run build && node --test test/*.test.mjs","build":"tsc -b tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"_npmUser":{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"},"_resolved":"C:\\Users\\mzs\\AppData\\Local\\Temp\\aops-task-180-d25e18d\\aopslabs-artifact-trust-contracts-0.3.0.tgz","_integrity":"sha512-U26Eqvx9tAxaP4r71QeftPdjL9/gOjSoDixe+XyTLynb/nrwVADtklpHHhNHovcjcpwEVrhEe+LsFUXyf5QtdQ==","repository":{"url":"git+https://github.com/eeemzs/aops-platform.git","type":"git","directory":"apps/aops/packages/artifact-trust-contracts"},"_npmVersion":"11.6.4","description":"Private AOPS artifact, receipt, lease, and admission contracts.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"tslib":"^2.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/artifact-trust-contracts_0.3.0_1786038308404_0.38289440484390846","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@aopslabs/artifact-trust-contracts","version":"0.3.1","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/artifact-trust-contracts@0.3.1","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/aops-platform#readme","bugs":{"url":"https://github.com/eeemzs/aops-platform/issues"},"dist":{"shasum":"14d55c0e0df1a48155c1059d1d8b1550a68602ea","tarball":"https://registry.npmjs.org/@aopslabs/artifact-trust-contracts/-/artifact-trust-contracts-0.3.1.tgz","fileCount":56,"integrity":"sha512-2KntqWYIWTP/PYlw05pj8glcOG1LxsQxoorkWdFLA4Ne+99PsO5S7uXCKGt+swAnqmCdWcwQTGmG6ma7qON4Jw==","signatures":[{"sig":"MEQCICJAFr6+W0k57eP2vAOShxsEYJ4vjZfmsryXzBpiIUzvAiBek8zRyuV1LAlDCf27gfTY6DzR5zcu6rXYTkRBJyp4AA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":552896},"main":"./dist/index.js","type":"module","_from":"file:S:/dev-js2/apps/aops-platform/.aops/review-artifacts/task198/leaf-candidates/91f44c05f59f776e83e8790a3d615e29203d4121/aopslabs-artifact-trust-contracts-0.3.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"test":"pnpm run build && node --test test/*.test.mjs","build":"tsc -b tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit"},"_npmUser":{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"},"_resolved":"S:\\dev-js2\\apps\\aops-platform\\.aops\\review-artifacts\\task198\\leaf-candidates\\91f44c05f59f776e83e8790a3d615e29203d4121\\aopslabs-artifact-trust-contracts-0.3.1.tgz","_integrity":"sha512-2KntqWYIWTP/PYlw05pj8glcOG1LxsQxoorkWdFLA4Ne+99PsO5S7uXCKGt+swAnqmCdWcwQTGmG6ma7qON4Jw==","repository":{"url":"git+https://github.com/eeemzs/aops-platform.git","type":"git","directory":"apps/aops/packages/artifact-trust-contracts"},"_npmVersion":"11.6.4","description":"Private AOPS artifact, receipt, lease, and admission contracts.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"tslib":"^2.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/artifact-trust-contracts_0.3.1_1786229398761_0.38525748225320533","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@aopslabs/artifact-trust-contracts","version":"0.3.2","license":"SEE LICENSE IN LICENSE","_id":"@aopslabs/artifact-trust-contracts@0.3.2","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"homepage":"https://github.com/eeemzs/tsapps#readme","bugs":{"url":"https://github.com/eeemzs/tsapps/issues"},"dist":{"shasum":"3490680d3b280b5a119b2373fc6f374b291fff8f","tarball":"https://registry.npmjs.org/@aopslabs/artifact-trust-contracts/-/artifact-trust-contracts-0.3.2.tgz","fileCount":56,"integrity":"sha512-1IC1SuAWKOF8CFbPYM9/5p+Di/VOXlx3Vucx2QyQCegZyYYJya9Ow9Tsmzuqth3pBHmjdpbwO2wB1g7xh3eh1g==","signatures":[{"sig":"MEUCIQD6pnrsF70TxXE48i1jTeKiArm0807xwmNV2q+f32CY9QIgfzdr2FS85YJ+/KiHickoBPhxl63WmkzQgZvhfefijkU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":553107},"main":"./dist/index.js","type":"module","_from":"file:/tmp/tsapps-aops-publish-kxBErE/packs/aopslabs-artifact-trust-contracts-0.3.2.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"private":false,"scripts":{"test":"node --test test/*.test.mjs","build":"tsc -b tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit --incremental false --composite false"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9c785e8-d003-48b2-b39f-bbd72b3eb1eb"}},"_resolved":"/tmp/tsapps-aops-publish-kxBErE/packs/aopslabs-artifact-trust-contracts-0.3.2.tgz","_integrity":"sha512-1IC1SuAWKOF8CFbPYM9/5p+Di/VOXlx3Vucx2QyQCegZyYYJya9Ow9Tsmzuqth3pBHmjdpbwO2wB1g7xh3eh1g==","repository":{"url":"git+https://github.com/eeemzs/tsapps.git","type":"git","directory":"apps/aops-platform/apps/aops/packages/artifact-trust-contracts"},"_npmVersion":"11.9.0","description":"Private AOPS artifact, receipt, lease, and admission contracts.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"tslib":"^2.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.9.3","@types/node":"^25.3.0"},"_npmOperationalInternal":{"tmp":"tmp/artifact-trust-contracts_0.3.2_1787777459745_0.7816983417121894","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"_id":"@aopslabs/artifact-trust-contracts@0.3.3","bugs":{"url":"https://github.com/eeemzs/tsapps/issues"},"dist":{"shasum":"0c68e32098c7fb576ef088291f615e7ff227f150","tarball":"https://registry.npmjs.org/@aopslabs/artifact-trust-contracts/-/artifact-trust-contracts-0.3.3.tgz","fileCount":56,"integrity":"sha512-Er8HlCoMIKp7pgQ8ntFjOZnrXj2rX/Qcm8sXqkHniNds6sJjg/WxuoK0+UYVyKM8N+5mbA2kfSOwz7s40TpbHg==","signatures":[{"sig":"MEQCICfjB+H5ZUyLXxHgcHYlEGOiykGEGB8q12FPUMR67Og1AiBHSf1J/J5vkAOnh52uheP5QVv4WhFutFuxe1432eFVBQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEYyEVPym6TGvfkjyVnaz5aCMzg49NBeGo8x/peDwUMbAiB+KIHVSWemYw96dJD2a/M0kQc/++/YOG0EKG2Y7P/VXQ=="}],"unpackedSize":553070},"main":"./dist/index.js","name":"@aopslabs/artifact-trust-contracts","type":"module","_from":"file:/home/runner/work/_temp/release-candidates/publication/aopslabs-artifact-trust-contracts-0.3.3.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"},"./package.json":"./package.json"},"license":"SEE LICENSE IN LICENSE","private":false,"scripts":{"test":"node --test test/*.test.mjs","build":"tsc -b tsconfig.lib.json","typecheck":"tsc -p tsconfig.lib.json --noEmit --incremental false --composite false"},"version":"0.3.3","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a9c785e8-d003-48b2-b39f-bbd72b3eb1eb"}},"homepage":"https://github.com/eeemzs/tsapps#readme","_resolved":"/home/runner/work/_temp/release-candidates/publication/aopslabs-artifact-trust-contracts-0.3.3.tgz","_integrity":"sha512-Er8HlCoMIKp7pgQ8ntFjOZnrXj2rX/Qcm8sXqkHniNds6sJjg/WxuoK0+UYVyKM8N+5mbA2kfSOwz7s40TpbHg==","repository":{"url":"git+https://github.com/eeemzs/tsapps.git","type":"git","directory":"apps/aops-platform/apps/aops/packages/artifact-trust-contracts"},"_npmVersion":"11.9.0","description":"Private AOPS artifact, receipt, lease, and admission contracts.","directories":{},"maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"_nodeVersion":"24.20.0","dependencies":{"tslib":"^2.3.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"5.9.3","@types/node":"^25.3.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/artifact-trust-contracts_0.3.3_1789262283940_0.18032717869513593"}}},"time":{"created":"2026-08-04T22:01:02.384Z","modified":"2026-09-13T01:18:04.209Z","0.2.0":"2026-08-04T22:01:02.692Z","0.3.0":"2026-08-06T17:45:08.572Z","0.3.1":"2026-08-08T22:49:58.920Z","0.3.2":"2026-08-26T20:50:59.912Z","0.3.3":"2026-09-13T01:18:04.036Z"},"bugs":{"url":"https://github.com/eeemzs/tsapps/issues"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/eeemzs/tsapps#readme","repository":{"url":"git+https://github.com/eeemzs/tsapps.git","type":"git","directory":"apps/aops-platform/apps/aops/packages/artifact-trust-contracts"},"description":"Private AOPS artifact, receipt, lease, and admission contracts.","maintainers":[{"name":"mzsonmez","email":"mzsonmez2@hotmail.com"}],"readme":"# AOPS Artifact Trust Contracts\n\nPublic-neutral contracts and verifier primitives for signed release closures,\nhost-owned installation receipts, entitlement leases, and immutable admission\nsnapshots.\n\nCustomer-owned domains use a third, explicit admission authority. South issues\nan entitlement lease with schema v3, the exact feature\n`aops.customer-domains.run`, and structured namespace/quota constraints. V3\npreserves the installation-key and activation bindings from v2. The customer\nverifier accepts no degraded/grace mode, no wildcard string interpretation,\nand no capability other than `domain.operation`; v1/v2 commercial leases keep\ntheir existing behavior.\n\nA customer registration receipt is created only after an authenticated\ntenant-administrator action, then signed by the installation key. Its payload\nbinds the exact tenant, installation, owner namespace, domain, package name and\nversion, package integrity, plugin entrypoint, operation-catalog digest,\nregistration revision, and issue time. The signature proves installation\nownership, not vendor authenticity. Callers must re-read current package bytes\nand catalog data and provide those exact values to the verifier.\n\nOptional usage attestations expose only a namespace, active count, and a\ndomain-separated Merkle commitment over canonical domain/package/catalog\ntuples. They are audit evidence and never lease or renewal authority. The\ntamper-evident last-known-good record is separately installation-key signed and\nbound to the exact lease JTI, entitlement epoch, revocation epoch, and receipt\nkey thumbprint. A new authority tuple cannot reuse an older LKG.\n\nOffline activation uses a self-signed Ed25519 installation challenge and a\ncontrol-plane-issued schema-v2 entitlement lease. The signed lease binds the exact\nchallenge digest and RFC 7638-style installation-key thumbprint; copying only a\nlease, receipt, or response file cannot satisfy the neutral verifier without\nthe matching challenge/key lineage. This challenge/response check proves\npossession at request creation; load-time proof that the private key is still\npresent is a separate host check. Challenge replay storage and entitlement\nauthorization remain control-plane responsibilities.\n\nThe installation signature is not tenant, product, or SKU authority. A control\nplane must compare those challenge fields with its authenticated operator\ncontext and durable entitlement records before it issues the bound lease.\n\nLoad and renewal proof-of-possession uses a separate short-lived installation\nproof. The verifier supplies a fresh nonce; the installation key signs that\nnonce together with the exact lease token digest, activation-challenge digest,\ninstallation/host identities, and active receipt/release closure. Proofs are\nephemeral and must not be persisted as reusable authority. Losing the private\nkey requires explicit reactivation; a receipt or public key cannot recreate it.\n\nOffline leases are host-capped at 90 days of full use from `nbf`, followed by\nat most 14 days of signed degraded use. An issuer may shorten either window but\ncannot lengthen it. `exp` is the final hard boundary: degraded use is inside the\nsigned lease and never means accepting an expired token. Wall-clock rollback\ndetection is a separate host-state responsibility.\n\nThis package contains no control-plane endpoint, issuer policy, credential,\nproduction key, or private package dependency. It is a transitive runtime\ndependency of the public CLI/server closure; publication still requires the\noperator's separate registry-mutation approval.\n\nCommercial release manifests use schema v2 for executable closure roles. One\nand only one closure package is the bundled `runtime-node`; optional `cli`,\n`server`, and `cockpit` roles each bind a package-relative POSIX entrypoint and\nan accepted bundled-runtime range. Entrypoints must be files in the signed\npacklist, every declared runtime dependency must be present in the exact\nclosure, and unknown or duplicate roles fail closed.\n\nThe commercial store remains the only immutable runtime and activation\nauthority. Managed launch readback always starts from the MAC-protected active\nreceipt, re-verifies the full signed closure, resolves the absolute bundled\nNode and role entrypoints inside that store, and re-derives the untrusted\n`current-release.json` support pointer. Launch specs always use array argv,\n`shell: false`, a minimal environment with the global Node/npm/pnpm surfaces\nremoved, and per-role mutable state/config/cache/log roots outside the store.\nThis isolation is intentional: `HOME` and, on Windows, `USERPROFILE` plus\n`HOMEDRIVE`/`HOMEPATH` are pinned to the managed role config root, while\n`TEMP`/`TMP` are pinned to the managed role cache root. Windows variables that\nlibuv otherwise copies from the parent are explicitly present with spec-owned\nvalues; child readback proves the spawn-environment keys and non-secret values,\nnot later process-local variables added by the Server or Cockpit adapter.\nThey are bound to the accepted `aops.setup-installer-plan/v2` plan identity;\nPostgreSQL credentials and all other secrets remain outside manifests,\nreceipts, pointers, environments, and argv.\n\nPostgreSQL setup selection is a separate closed, secret-free contract with\nexactly three explicit modes: an existing loopback database, an external\nTLS-verified database, or an AOPS-managed loopback container. Discovery is\nadvisory only and never chooses a mode or coordinates. Existing databases get\nonly a fixed read-only identity/schema preflight; setup never creates, drops,\nalters, or resets operator-owned PostgreSQL objects. The managed mode binds a\ndigest-pinned image, deterministic installation labels, exact container and\nvolume names, and one explicit port into the plan identity. Apply rechecks the\nactual state, rejects foreign or ambiguous ownership, never auto-increments a\nport, and preserves the volume on every rollback path. Credentials are passed\nonly by OS credential-store reference or the inherited setup apply channel;\ncredential values never enter the plan, receipt, URL, argv, log, or environment\nprojection.\n\nSetup readiness composes those sealed PostgreSQL results with migration,\nofficial-catalog, and global agent-asset identities read back from the verified\ncommercial store. It does not introduce another signature authority: the\ncatalog and asset inputs must be objects in the existing KR-RELEASE closure,\nand migration execution is available only through the existing production\nrunner's narrow forward-only port. Live PostgreSQL semantic state is the sole\nreadiness authority; local receipts are hints and cannot cause reset,\ndowngrade, or destructive repair. Applied migration checksum drift, unknown or\nnewer migration state, lock contention, and post-apply readback drift fail\nclosed. Required AuthV2 system identity is explicitly bound in the plan; demo\nor business-row seeding is forbidden and a fresh apply must preserve a zero\nbusiness-row count. Official catalog reconciliation is additive\ninsert-or-verify, and agent assets are installed only by digest-addressed\nbindings into qualified runtime roots. The concrete PostgreSQL/container and\nfilesystem adapters remain a separate integration boundary; this contract\nexposes no generic SQL, process, rollback, reset, delete, or store-write escape\nhatch.\n\nFinal setup readiness is a fresh live proof, not a startup-success flag. Launch\nspecifications are runtime sealed so the supervisor accepts only the exact\nabsolute bundled-Node command, array arguments, working directory, scrubbed\nenvironment, and mutable roots produced by the commercial-store authority.\nServer and Cockpit are independently supervised with bounded restart and\nshutdown behavior. The final gate requires direct Server health, Cockpit root\nand static health, honest proxied-API failure while Server is stopped, proxy\nrecovery after Server restarts without restarting Cockpit, and loopback-only\norigins. It then re-inspects migrations, catalog, and agent assets from live\nauthorities and compares the fresh digest to the runtime-sealed readiness\nreceipt. A recursive immutable-store digest must remain unchanged across the\nreal supervised run; any drift quarantines the installation.\n\nRenewal telemetry is an explicit pure projection, not an implicit network\nsink. Tenant, product, and installation identifiers are emitted only as\ndomain-separated HMAC-SHA256 pseudonyms under a host-owned key of at least 256\nbits. Events may contain verified lease mode, entitlement/revocation epochs,\nthe refresh flag, and strict decision/stage/reason codes. They never project\nthe raw lease token, JTI, issuer, subscription, feature list, signing or\npseudonym key, file path, URL, or unrelated PII. Key storage, retention,\ntransport, sampling, and backend selection remain operator-owned.\n","readmeFilename":"README.md"}