{"_id":"@apilium/altretta-plugin","_rev":"2-671b24cedccb50f66d1c9e3c6fe8b565","name":"@apilium/altretta-plugin","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@apilium/altretta-plugin","version":"1.0.0","keywords":["altretta","plugin","sign","cli","apilium"],"author":{"name":"Apilium"},"license":"Apache-2.0 OR Commercial","_id":"@apilium/altretta-plugin@1.0.0","maintainers":[{"name":"apilium-ai","email":"it@apilium.com"}],"homepage":"https://github.com/ApiliumCode/altretta-plugins-legacy#readme","bugs":{"url":"https://github.com/ApiliumCode/altretta-plugins-legacy/issues"},"bin":{"altretta-plugin":"bin/altretta-plugin.mjs"},"dist":{"shasum":"72f28857dc35d95a8c4bf0aa85c9a19ebf7e81c5","tarball":"https://registry.npmjs.org/@apilium/altretta-plugin/-/altretta-plugin-1.0.0.tgz","fileCount":4,"integrity":"sha512-O39FvySZN9LO6OxkvlArmixOMvZ07rDfEZsgB5B9Q4+ZMIsPN56beZ9zm/9P5kfdFAoqwhgF/OPGG8n4MCCn4Q==","signatures":[{"sig":"MEUCIQCKfbJXJVSXyg6zwyqohMhAwNHxq7mRgz1kXf4VouC/hgIgJxhteXWWWGp7gisZfiL1zHn3KqcGVLHYY6KTFYOOSq8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":8036},"type":"module","engines":{"node":">=18"},"gitHead":"b58c97913ccc0e89e7b686d9f3199f22a67d4cc6","scripts":{"test":"node --test"},"_npmUser":{"name":"apilium-ai","email":"it@apilium.com"},"repository":{"url":"git+https://github.com/ApiliumCode/altretta-plugins-legacy.git","type":"git","directory":"altretta-plugin-cli"},"_npmVersion":"11.16.0","description":"The altretta-plugin author CLI: keygen, pack (sign), and verify Altretta plugins. Ships a prebuilt native binary per platform, resolved at run time.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@apilium/altretta-plugin-linux-x64":"1.0.0","@apilium/altretta-plugin-win32-x64":"1.0.0","@apilium/altretta-plugin-darwin-x64":"1.0.0","@apilium/altretta-plugin-darwin-arm64":"1.0.0"},"_npmOperationalInternal":{"tmp":"tmp/altretta-plugin_1.0.0_1785423104220_0.8236657129838791","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@apilium/altretta-plugin","version":"1.0.1","description":"The altretta-plugin author CLI: keygen, pack (sign), and verify Altretta plugins. Ships a prebuilt native binary per platform, resolved at run time.","type":"module","bin":{"altretta-plugin":"bin/altretta-plugin.mjs"},"engines":{"node":">=18"},"scripts":{"test":"node --test"},"optionalDependencies":{"@apilium/altretta-plugin-darwin-arm64":"1.0.1","@apilium/altretta-plugin-darwin-x64":"1.0.1","@apilium/altretta-plugin-linux-x64":"1.0.1","@apilium/altretta-plugin-win32-x64":"1.0.1"},"keywords":["altretta","plugin","sign","cli","apilium"],"author":{"name":"Apilium"},"license":"Apache-2.0 OR Commercial","publishConfig":{"access":"public"},"homepage":"https://github.com/ApiliumCode/altretta-plugins-legacy#readme","repository":{"type":"git","url":"git+https://github.com/ApiliumCode/altretta-plugins-legacy.git","directory":"altretta-plugin-cli"},"bugs":{"url":"https://github.com/ApiliumCode/altretta-plugins-legacy/issues"},"gitHead":"b58c97913ccc0e89e7b686d9f3199f22a67d4cc6","_id":"@apilium/altretta-plugin@1.0.1","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-MLAQSDTHhMAkmIWybTcKsc8PBANepnyv+yTDWb+VLbVAbP70zrzcQF7YFx7haNYL56v7Ut9EYX/BXq1UJzqkzw==","shasum":"e21dcf931895c64ae9692d891338eab785cff09d","tarball":"https://registry.npmjs.org/@apilium/altretta-plugin/-/altretta-plugin-1.0.1.tgz","fileCount":4,"unpackedSize":11291,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCihVwOVpAJ9241LBeWaPgdn7pO57DmCH/jgeI0GJr+CAIhAIpCWKEOKK8k0PhjPbX620fRb9cwHb0Pvi2kR9aqpVkK"}]},"_npmUser":{"name":"apilium-ai","email":"it@apilium.com"},"directories":{},"maintainers":[{"name":"apilium-ai","email":"it@apilium.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/altretta-plugin_1.0.1_1785423817255_0.5599569108710432"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-30T14:51:43.947Z","modified":"2026-07-30T15:03:37.569Z","1.0.0":"2026-07-30T14:51:44.392Z","1.0.1":"2026-07-30T15:03:37.387Z"},"bugs":{"url":"https://github.com/ApiliumCode/altretta-plugins-legacy/issues"},"author":{"name":"Apilium"},"license":"Apache-2.0 OR Commercial","homepage":"https://github.com/ApiliumCode/altretta-plugins-legacy#readme","keywords":["altretta","plugin","sign","cli","apilium"],"repository":{"type":"git","url":"git+https://github.com/ApiliumCode/altretta-plugins-legacy.git","directory":"altretta-plugin-cli"},"description":"The altretta-plugin author CLI: keygen, pack (sign), and verify Altretta plugins. Ships a prebuilt native binary per platform, resolved at run time.","maintainers":[{"name":"apilium-ai","email":"it@apilium.com"}],"readme":"<p align=\"center\">\r\n  <img src=\"https://raw.githubusercontent.com/ApiliumCode/altretta-plugins/main/assets/altretta-logo.svg\" width=\"96\" height=\"96\" alt=\"Altretta\" />\r\n</p>\r\n\r\n<h1 align=\"center\">@apilium/altretta-plugin</h1>\r\n\r\n<p align=\"center\">\r\n  <b>The author CLI for Altretta plugins.</b><br />\r\n  Generate a signing key, pack a plugin into a signed <code>.altplugin</code>, and verify it —<br />\r\n  no Rust toolchain, no global install.\r\n</p>\r\n\r\n<p align=\"center\">\r\n  <img alt=\"Ecosystem: Altretta\" src=\"https://img.shields.io/badge/ecosystem-Altretta-6366F1?style=flat-square\" />\r\n  <img alt=\"Plugins: signed · sandboxed · scoped\" src=\"https://img.shields.io/badge/plugins-signed%20%C2%B7%20sandboxed%20%C2%B7%20scoped-475569?style=flat-square\" />\r\n  <img alt=\"License\" src=\"https://img.shields.io/badge/license-Apache--2.0%20OR%20Commercial-8b949e?style=flat-square\" />\r\n</p>\r\n\r\n---\r\n\r\n> **Altretta** is your local-first, encrypted second brain — a knowledge vault with a\r\n> semantic engine that runs on your machine. This CLI is how you **build and sign the\r\n> plugins that extend it**.\r\n\r\n## Install\r\n\r\n```bash\r\nnpx @apilium/altretta-plugin keygen --out author.key\r\nnpx @apilium/altretta-plugin pack . --key author.key --out my-plugin.altplugin --deny-warnings\r\nnpx @apilium/altretta-plugin verify my-plugin.altplugin\r\n```\r\n\r\nOne `npx` and it runs. The binary is resolved per-platform at run time (see below), so there\r\nis no `postinstall` and no network at install time.\r\n\r\n## The Altretta plugin model\r\n\r\nA plugin is one JavaScript file plus a `manifest.json`. It runs in a hardened sandbox — a\r\nfrozen [SES](https://github.com/endojs/endo) compartment inside a worker, with no DOM, no\r\nnetwork, and no filesystem. Its only way to reach the app is one injected `altretta` object,\r\nand every call goes through a permission check. **Plugins can't betray you** — not by\r\npolicy, by construction:\r\n\r\n- **Signed.** Every plugin carries an author signature over its exact code and manifest.\r\n  Change one byte and it stops verifying.\r\n- **Verifiable.** Apilium reviews a plugin and counter-signs the same bytes for the Verified\r\n  badge, without ever seeing the author's private key.\r\n- **Revocable.** A compromised plugin is disabled everywhere through a signed revocation\r\n  list, with anti-downgrade protection.\r\n- **Scoped.** Grant a plugin `ReadNotes` and `WriteNotes` and it can never open a socket.\r\n  The permissions you see are the whole contract.\r\n\r\nThis CLI is the toolchain behind that trust model: it mints your author key, packs your code\r\ninto a signed `.altplugin`, and verifies the result.\r\n\r\n## Scaffold a plugin in seconds\r\n\r\nDon't start from scratch. The scaffolder wires this CLI in as a `devDependency` so a fresh\r\nproject is ready to pack:\r\n\r\n```bash\r\nnpx @apilium/create-altretta-plugin my-plugin\r\ncd my-plugin\r\nnpm install\r\nnpm run keygen     # once: creates author.key\r\nnpm run pack       # builds, then signs into my-plugin.altplugin (--deny-warnings)\r\nnpm run verify     # confirms author_ok: true\r\n```\r\n\r\nThen load it in **Altretta → Plugins → Developer Mode → Load plugin folder**, consent to its\r\npermissions, and watch it run.\r\n\r\n## Commands\r\n\r\n| Command | What it does |\r\n| --- | --- |\r\n| `keygen --out <file>` | Generate an Ed25519 author signing key. |\r\n| `pack <dir> --key <file> --out <file> [--deny-warnings]` | Pack a plugin folder into a signed `.altplugin`. |\r\n| `countersign <file> --key <apilium-key> --out <sig>` | Apilium-side: counter-sign reviewed bytes for the Verified badge. |\r\n| `verify <file> [--apilium-sig <sig>]` | Confirm the author (and Apilium) signature. |\r\n| `bundle <file> --out <dir>` | Produce a Hub-ready bundle folder. |\r\n\r\n## Per-platform binaries\r\n\r\nThis package is a thin launcher — it ships **no** binary itself. Each supported platform has\r\na companion package carrying the matching prebuilt native binary, declared as\r\n`optionalDependencies` so `npm install` fetches only the one that matches your machine (the\r\nesbuild / Biome distribution model):\r\n\r\n| Platform | Package |\r\n| --- | --- |\r\n| macOS (Apple Silicon) | `@apilium/altretta-plugin-darwin-arm64` |\r\n| macOS (Intel) | `@apilium/altretta-plugin-darwin-x64` |\r\n| Linux (x64) | `@apilium/altretta-plugin-linux-x64` |\r\n| Windows (x64) | `@apilium/altretta-plugin-win32-x64` |\r\n\r\nOn an unsupported platform the launcher prints a clear message naming the\r\n`<platform>-<arch>` combo and how to request it.\r\n\r\n## No terminal? Use the app\r\n\r\nThe same signing engine is built into the Altretta desktop app. If you prefer a GUI, use\r\n**Package & sign** in Altretta Developer Mode: it creates your author identity once, packs,\r\nverifies, and saves a `.altplugin` for you.\r\n\r\n## The bigger picture\r\n\r\nAltretta is more than plugins — it's a connected second brain:\r\n\r\n- 🧠 **[Altretta](https://apilium.com/en/products/altretta)** — the local-first, encrypted\r\n  vault with a semantic engine. Your notes, decisions, and knowledge, on your machine.\r\n- 🤖 **[Altretta Skill](https://github.com/ApiliumCode/altretta-skill)** — give your AI a\r\n  second brain. One command (`npx skills add ApiliumCode/altretta-skill`) connects your\r\n  vault to Claude Code, Codex, Cursor, Gemini CLI, and 60+ more agents, with cited,\r\n  grounded retrieval.\r\n- 🧩 **[Altretta Plugins](https://github.com/ApiliumCode/altretta-plugins)** — the official\r\n  catalog of signed, sandboxed, permission-scoped extensions. This CLI is how you author\r\n  them.\r\n\r\n## License\r\n\r\nApache-2.0 OR Commercial. Built by [Apilium](https://apilium.com).\r\n","readmeFilename":"README.md"}