{"_id":"@arbiterhq/sdk","_rev":"8-b4e6776198a34776158687b698ad791b","name":"@arbiterhq/sdk","dist-tags":{"latest":"0.3.5"},"versions":{"0.2.0":{"name":"@arbiterhq/sdk","version":"0.2.0","keywords":["arbiter","ai-governance","agent-governance","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.2.0","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://github.com/sumitbirru1-halo/arbiter-sdk#readme","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"a8b60af3b0745df78c566c08628eae86e28f3c2b","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.2.0.tgz","fileCount":59,"integrity":"sha512-4fuOsHHl7LFDiWMbrSXlR00WBcWIeKrARWG+Tkz0OO5RV8svftRgytOGGCtyTVV+qef3vrs3u9raOSJAIdNaXw==","signatures":[{"sig":"MEUCIBrADKgKvDByyREhm2DcpTNTAWO6Prnx+6w7F4NOcLaZAiEAz2pGgGkS9YZLrPfZg+oZBeSwhGmeaZ13NmbYg1kr2lM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":141825},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"187e4b8a0358651f4f76fcc00e41a8b018df01aa","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the Arbiter AI governance API","directories":{},"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.0_1782668779162_0.0408764027372257","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@arbiterhq/sdk","version":"0.2.1","keywords":["arbiter","ai-governance","agent-governance","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.2.1","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://github.com/sumitbirru1-halo/arbiter-sdk#readme","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"365303c1a6c32bef2371d420754742a579f89b0b","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.2.1.tgz","fileCount":59,"integrity":"sha512-0sw99RfHHxGKCAoqHw9Ai9qdHqwFxnuTQFzel5LyxrfyLwn+//7Evd+k/8aYmea8maG1mbJGva9RT3jvgHn88A==","signatures":[{"sig":"MEUCIAqPVEuuC0f5ClllxfO8TvlutH46lP1Dx02Mp+CR0o3eAiEA70LAP69HmJzB+cwWtFLYZuao0Eini1pdU7Z77iwdQzY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":145928},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"bd88cf15a1770339b993560ad09d93250d7d0676","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the Arbiter AI governance API","directories":{},"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.1_1783524396270_0.9797112344559493","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@arbiterhq/sdk","version":"0.3.0","keywords":["arbiter","ai-governance","agent-governance","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.3.0","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://github.com/sumitbirru1-halo/arbiter-sdk#readme","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"3b105b7725cfbd88dd9e9ca08a3cd8b70b8842cb","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.3.0.tgz","fileCount":63,"integrity":"sha512-bEmgJYyl+pNZ1jYG2e3cSmAEqUzuMMGUb2szxEUDU9EnQ/BjHUssYAl+n2MJ2sdGmI8Zo9YSEhA7Ex9/YGhJMg==","signatures":[{"sig":"MEQCIEQW1fza2yY1ft7AcBlov2dcfE6bRFJORcDhk+6im6weAiBh6/EDPlCfZWSu2iwr794QI2KSziuTTW2w6+dLN1dbBQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":163259},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"5ae02fa1f03e0ef79adc16a957b714dee085f76f","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the Arbiter AI governance API","directories":{},"_nodeVersion":"26.0.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.0_1783781321937_0.42434503118650735","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@arbiterhq/sdk","version":"0.3.1","keywords":["arbiter","control-plane","ai-agents","runtime-evaluation","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.3.1","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://arbitertrust.com","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"c3cf5d7a8576be3ac64bd92ef2f6baec2925e64c","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.3.1.tgz","fileCount":63,"integrity":"sha512-xeO7Oa8eZTCh7fYcIgXbXggxZY7p68xDJMDJf0keWdPGTuWHeirVG8lT+HPOTv+Devcj0WitGIe2TbYUieXYJQ==","signatures":[{"sig":"MEUCIHiiRhXI5zc7fNZsVqsyQOCiZrY6qsqpPLBa649CWQRvAiEAhZqVJgvkSI9EolmcrA1LFmC+jU/GIHm8CqylEYTZI6Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":163997},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"943a233fc937eac28c323dc7511e98b817cbcf65","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.16.0","description":"Official TypeScript SDK for the Arbiter Control Plane for AI Agents","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.1_1784313457751_0.6107560364103575","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@arbiterhq/sdk","version":"0.3.2","keywords":["arbiter","control-plane","ai-agents","runtime-evaluation","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.3.2","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://arbitertrust.com","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"d2b6e4eb343af4f0193d02314cad4eb2c2e71dda","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.3.2.tgz","fileCount":64,"integrity":"sha512-3U4cQnAuzhwJbVI63BqllvxQhzaftyb6AH6Uccz4BYO7FfeivSPKHUjxM4Qj4cYH6JJOEIREfrAhS93lgWqG3A==","signatures":[{"sig":"MEQCICBfrLgi1jxesGHX4/66+vSbaeIdb48XOxDLfKXSeSwMAiBAXSFulYRNxB7A4A73coR/IH0piureB+c5BLw9eSr10g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165134},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"943a233fc937eac28c323dc7511e98b817cbcf65","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.16.0","description":"Official TypeScript SDK for the Arbiter Control Plane for AI Agents","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.2_1784315732458_0.8571702162161559","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@arbiterhq/sdk","version":"0.3.3","keywords":["arbiter","control-plane","ai-agents","runtime-evaluation","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.3.3","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://arbitertrust.com","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"9db0eaa111e3402679af84d2d5682a866b70f2d7","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.3.3.tgz","fileCount":64,"integrity":"sha512-OZs3NyWZ+c3pTyrn/uJRNX6lj8Y+eIo7AmTvL4PSuP8hZHvIiA6N5jCsEpwoPJs/COiQMaLgc/y1uHlNXiHStg==","signatures":[{"sig":"MEQCICOgHIBxplTNXadKQ51y28CTwu0C9seG1UkKwHYtsB0OAiBVmWEw5lDOkhmNBkxJ9psDU8Puh6rgW+a6nLWbYhnh7A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":166222},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"07b36295bb71535f539a4a2edabcc0916d0bbcfa","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.16.0","description":"Official TypeScript SDK for the Arbiter Control Plane for AI Agents","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.3_1784535200079_0.27489823015231063","host":"s3://npm-registry-packages-npm-production"}},"0.3.4":{"name":"@arbiterhq/sdk","version":"0.3.4","keywords":["arbiter","control-plane","ai-agents","runtime-evaluation","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","_id":"@arbiterhq/sdk@0.3.4","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"homepage":"https://arbitertrust.com","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"dist":{"shasum":"239e4252b33f3e78c3f2e892b0d1c8f6c06405cb","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.3.4.tgz","fileCount":64,"integrity":"sha512-Je+aL42KJG+wtLdpMMTiIcPgcmeoM3JsWwXzhXb/17K6Vb8bE0aa/3Y0dt4iYyP2p/z895kmh/rOfGWw9Y3JAA==","signatures":[{"sig":"MEQCIACqfES+qytW7owtvDrhsm/ohEGd/pahVqBG/Uyd0c4pAiBvpP1oG8bp7dODozC61+p+ZEOBL6HUW77LMionwuY9Jw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":177126},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"82f08601f9c2fc7c16f002fbf95076f710073641","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"rm -rf dist && tsc -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"repository":{"url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","type":"git","directory":"packages/sdk"},"_npmVersion":"11.16.0","description":"Official TypeScript SDK for the Arbiter Control Plane for AI Agents","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.3","typescript":"^6.0.3","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.4_1784712950833_0.9830843052965912","host":"s3://npm-registry-packages-npm-production"}},"0.3.5":{"name":"@arbiterhq/sdk","version":"0.3.5","description":"Official TypeScript SDK for the Arbiter Control Plane for AI Agents","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"rm -rf dist && tsc -p tsconfig.json","test":"node --import tsx/esm --test 'src/**/*.test.ts'","prepublishOnly":"npm run build"},"publishConfig":{"access":"public"},"keywords":["arbiter","control-plane","ai-agents","runtime-evaluation","policy-engine","sdk","typescript"],"author":{"name":"Arbiter"},"license":"ISC","homepage":"https://arbitertrust.com","bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"repository":{"type":"git","url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","directory":"packages/sdk"},"engines":{"node":">=18"},"devDependencies":{"@types/node":"^25.9.1","tsx":"^4.20.3","typescript":"^6.0.3"},"gitHead":"67c37ddb762cd0d2bea9cd603c61a969e736b642","_id":"@arbiterhq/sdk@0.3.5","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-9WW8PoiH3fgxemmBuw5vf/BfQoYXoT+/Uilw3YxEtCsgqgwpHknIXa0W1Q9yT/lZ94Rcc0xqgcPbWTZ7uuDIlg==","shasum":"2049294c0ae6bdb89c1c2f1fe38fad1d5fb920ee","tarball":"https://registry.npmjs.org/@arbiterhq/sdk/-/sdk-0.3.5.tgz","fileCount":64,"unpackedSize":177863,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDLaa24nAZqQmmqcieD2++edWIQVr0ewOTM1wPZNqF7RwIhALYGsa8i2yDqEtgX8XkhQ19zT0nbEhEP0lfOK7wGOxSc"}]},"_npmUser":{"name":"arbitertrust","email":"founder@arbitertrust.com"},"directories":{},"maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.3.5_1786268849965_0.2803945161111834"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-28T17:46:18.973Z","modified":"2026-08-09T09:47:30.308Z","0.2.0":"2026-06-28T17:46:19.307Z","0.2.1":"2026-07-08T15:26:36.429Z","0.3.0":"2026-07-11T14:48:42.068Z","0.3.1":"2026-07-17T18:37:37.904Z","0.3.2":"2026-07-17T19:15:32.636Z","0.3.3":"2026-07-20T08:13:20.217Z","0.3.4":"2026-07-22T09:35:50.962Z","0.3.5":"2026-08-09T09:47:30.115Z"},"bugs":{"url":"https://github.com/sumitbirru1-halo/arbiter-sdk/issues"},"author":{"name":"Arbiter"},"license":"ISC","homepage":"https://arbitertrust.com","keywords":["arbiter","control-plane","ai-agents","runtime-evaluation","policy-engine","sdk","typescript"],"repository":{"type":"git","url":"git+https://github.com/sumitbirru1-halo/arbiter-sdk.git","directory":"packages/sdk"},"description":"Official TypeScript SDK for the Arbiter Control Plane for AI Agents","maintainers":[{"name":"arbitertrust","email":"founder@arbitertrust.com"}],"readme":"# @arbiterhq/sdk\n\nOfficial TypeScript SDK for **Arbiter — The Control Plane for AI Agents**.\n\n**Current package:** `@arbiterhq/sdk@0.3.5` (companion: `@arbiterhq/cli@0.3.0`, `@arbiterhq/gate@0.1.0`).\n\nRuntime Evaluation returns Allow, Hold, or Deny. Use `ArbiterRuntime` for agent\nexecution and `ArbiterAdmin` for registry, manifest, and Control Plane operations.\n\nArbiter governs agents you build elsewhere. It is **not** an agent framework,\nworkflow engine, observability platform, or chatbot product.\n\n**Canonical onboarding:** [`arbiter connect`](../cli/README.md) (Authority Connect) via `@arbiterhq/cli@0.3.0`, then use this SDK in your runtime. For MCP gateway observe / enforce from the terminal, use the same CLI. Python: `pip install arbiter-sdk==0.1.0`.\n\nTwo clients:\n\n- **`ArbiterRuntime`** — autonomous agent execution. Accepts **`arb_agent_*`** (production) or **`arb_test_*`** (discovery bootstrap). Constructor option: **`credential`** (not `apiKey`).\n- **`ArbiterAdmin`** — control plane (`arb_test_*`) including manifest plan/drift. Constructor option: **`apiKey`**.\n\n### Runtime authentication model\n\n```\nAuthority Connect (canonical)\n  arbiter login → arbiter connect → arbiter connect --apply\n        ↓\n  Workspace API Key (arb_test_*) + ARBITER_AGENT in .env\n        ↓\n  runtime.connect() / runtime.evaluate()\n        ↓\n  Automatic Agent Discovery\n        ↓\n  Adopt Agent (dashboard) — Connect does not auto-Adopt\n        ↓\n  Keep using arb_test_* — no reconnect required\n        ↓\n  Optional: issue Agent Credential (arb_agent_*) for\n  advanced per-agent identity / production hardening\n```\n\n**Canonical design-partner path:** create a workspace API key (`arb_test_*`), enable Runtime Discovery, run Authority Connect (`arbiter connect` / `--apply`), then `runtime.connect()` → `evaluate()`. After adoption the runtime stays on the workspace API key.\n\n**Optional production hardening:** issue `arb_agent_*` and set `ARBITER_AGENT_CREDENTIAL` when you want dedicated per-agent secrets. Workspace-key calls to runtime routes currently receive a `Deprecation` response header with a ~90-day sunset horizon — plan migration to agent credentials before enforcement.\n\nFor stable discovery identity, set **`ARBITER_AGENT`** (or pass `connect({ agent })`). Package name and hostname fallbacks exist for local development only — do not rely on them in production.\n\n## Requirements\n\n- Node.js 18+\n- A running Arbiter backend instance\n\n## Install\n\n```bash\nnpm install @arbiterhq/sdk\n```\n\n**Optional:** If you load credentials from a local `.env` file, install `dotenv` separately. It is not a dependency of `@arbiterhq/sdk`.\n\n```bash\nnpm install dotenv\n```\n\n```dotenv\n# .env\nARBITER_API_KEY=arb_test_xxxxxxxxx\nARBITER_BASE_URL=https://api.arbitertrust.com\n```\n\n```typescript\nimport \"dotenv/config\";\n\nconst runtime = new ArbiterRuntime({\n  credential: process.env.ARBITER_API_KEY!,\n});\n```\n\n**Discovery-first prerequisite:** Enable **Runtime Discovery** in workspace settings before using a workspace API key with `runtime.connect()`.\n\n## Base URL\n\nThe SDK resolves the API base URL in this order:\n\n1. `baseUrl` passed to the client constructor\n2. `ARBITER_BASE_URL` environment variable\n3. Production default: `https://api.arbitertrust.com`\n\n**Production** — omit `baseUrl` or set `ARBITER_BASE_URL=https://api.arbitertrust.com`.\n\n**Local development** — set `ARBITER_BASE_URL=http://localhost:3001` or pass `baseUrl: 'http://localhost:3001'` explicitly.\n\n## Credentials\n\n| Variable | Used by | Purpose |\n|----------|---------|---------|\n| `ARBITER_AGENT_CREDENTIAL` | `ArbiterRuntime` | Agent runtime auth (`arb_agent_*`) |\n| `ARBITER_AGENT` | `ArbiterRuntime` | Stable agent externalId for discovery bootstrap with workspace API key |\n| `ARBITER_API_KEY` | `ArbiterAdmin`, discovery-first `ArbiterRuntime` | Workspace control plane (`arb_test_*`) |\n| `ARBITER_HUMAN_TOKEN` | `ArbiterAdmin.approve()` / `reject()` | Human session token for authorization actions |\n| `ARBITER_BASE_URL` | Both clients | Override API endpoint |\n\n## Onboarding paths\n\nThere are two onboarding paths:\n\n1. **Discovery-first** — use a workspace API key with `ArbiterRuntime`, call `runtime.connect()` to discover the agent, call `runtime.evaluate()` to record unknown actions while the agent is pending review, adopt the agent in the Discovery Inbox, then adopt the permissions that appear automatically.\n2. **Registry-first** — register agents and permissions with `ArbiterAdmin`, issue an agent credential, then connect with `ARBITER_AGENT_CREDENTIAL`.\n\nBoth paths converge on the same governed runtime loop after adoption.\n\n## Automatic Discovery\n\nDiscovery is fully automatic — there are no `discoverAgent()` or `discoverPermission()` APIs.\n\n### Agent discovery (at connect)\n\n```\nWorkspace API Key\n      ↓\nruntime.connect()\n      ↓\nAgent Discovery\n      ↓\nDiscovery Inbox\n      ↓\nAdopt\n      ↓\nRegistry\n      ↓\n(Optional) Agent Credential issued for production\n```\n\nWhen `ArbiterRuntime` is constructed with a workspace API key (`arb_test_*`), `runtime.connect()` sends the agent identity to the backend. If the agent is unknown and workspace discovery is enabled, it appears in the Discovery Inbox as `pending_review`.\n\n### Permission discovery (at evaluate)\n\n```\nConnect Runtime\n      ↓\nAgent appears in Discovery Inbox\n      ↓\nRuntime evaluates unknown actions\n      ↓\nActions recorded while agent is pending review\n      ↓\nOperator adopts agent\n      ↓\nPreviously observed permissions appear in Discovery Inbox\n      ↓\nOperator adopts permissions\n      ↓\nGovernance begins\n```\n\nUnknown actions attempted via `runtime.evaluate()` are recorded while the agent is pending review. When the operator adopts the agent, those previously observed actions appear in the Permission Discovery Inbox — no second discovery run is required for those actions. New unknown actions after adoption are discovered through the normal `runtime.evaluate()` path.\n\n### Production identity (`ARBITER_AGENT`)\n\nProduction deployments should set **`ARBITER_AGENT`** to maintain a stable runtime identity across restarts and replicas.\n\nWhen using a workspace API key, the SDK resolves the agent externalId in this order:\n\n1. `connect({ agent })` — explicit argument\n2. `ARBITER_AGENT` environment variable\n3. `ARBITER_AGENT_EXTERNAL_ID` environment variable\n4. `npm_package_name` from `package.json`\n5. Hostname (development convenience only)\n\nFallbacks (package name / hostname) exist for local development convenience. Do not rely on them in production — set `ARBITER_AGENT` explicitly.\n\n### Discovery-first quickstart\n\n```typescript\nimport { ArbiterRuntime, SDK_VERSION } from '@arbiterhq/sdk';\n\n// Workspace API key — discovery bootstrap (not production runtime auth)\nconst runtime = new ArbiterRuntime({\n  credential: process.env.ARBITER_API_KEY!,\n});\n\n// Set ARBITER_AGENT in production for stable identity\nawait runtime.connect({\n  agent: process.env.ARBITER_AGENT ?? 'my-agent',\n  framework: 'custom',\n  runtimeType: 'node',\n  runtimeVersion: process.version,\n  sdkVersion: SDK_VERSION,\n});\n\n// Agent appears in Discovery Inbox\nconst decision = await runtime.evaluate({ action: 'send_payment', amount: 500 });\n// Unknown actions recorded while agent is pending review\n// After adopting the agent, observed permissions appear in Discovery Inbox\n```\n\nSee [`../../examples/discovery-first/`](../../examples/discovery-first/) for the canonical onboarding script.\n\n## MCP Permission Gateway\n\nGateway HTTP APIs live on the backend (`/gateway/*`). From agent code you typically:\n\n1. Observe tools via **`arbiter gateway observe`** (`@arbiterhq/cli`)\n2. Adopt in the dashboard **Discovery → MCP Tool Authority Map**\n3. Evaluate with `runtime.evaluate()` on the adopted permission action, or `arbiter gateway enforce`\n\nSee [CLI gateway quickstart](../cli/README.md#mcp-permission-gateway-quickstart).\n\n## Complete runtime flow\n\nEnd-to-end governed execution: connect → heartbeat → evaluate → Approval HOLD → completeHeldEvaluation → receipt.\n\n```typescript\nimport { ArbiterAdmin, ArbiterRuntime, SDK_VERSION } from '@arbiterhq/sdk';\n\n// Production: omit baseUrl. Local dev: baseUrl: 'http://localhost:3001'\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY!,\n});\n\nconst runtime = new ArbiterRuntime({\n  credential: process.env.ARBITER_AGENT_CREDENTIAL!,\n  environment: 'production',\n});\n\nawait runtime.connect({\n  framework: 'custom',\n  runtimeType: 'node',\n  runtimeVersion: process.version,\n  sdkVersion: SDK_VERSION,\n});\n\nawait runtime.heartbeat();\n\nconst evaluationPayload = {\n  action: 'send_payment',\n  amount: 5000,\n} as const;\n\nconst decision = await runtime.evaluate(evaluationPayload);\n\nif (decision.decision === 'hold') {\n  switch (decision.kind) {\n    case 'approval': {\n      // Human operator approves via admin + session token\n      await admin.approve(decision.approvalRequestId, {\n        humanToken: process.env.ARBITER_HUMAN_TOKEN!,\n      });\n\n      // Canonical HOLD completion (ADR-003) — prefer this over manual wait+consume.\n      // Transport adapters must use completeHeldEvaluation exclusively.\n      const completed = await runtime.completeHeldEvaluation({\n        hold: decision,\n        originalPayload: evaluationPayload,\n        includeReceipt: true,\n      });\n\n      console.log(completed.release.evaluationId);\n      console.log(completed.receipt?.receiptHash);\n      break;\n    }\n    case 'discovery':\n      // No ApprovalRequest — wait for an administrator to adopt the permission,\n      // then retry evaluate. Do not call waitForApproval / completeHeldEvaluation.\n      console.log('Discovery HOLD: permission pending administrator adoption');\n      break;\n  }\n}\n```\n\nObtain `ARBITER_HUMAN_TOKEN` from a workspace session (`POST /auth/session` or dashboard login). Obtain `ARBITER_AGENT_CREDENTIAL` via `createAgentCredentialByExternalId()` or the dashboard.\n\n## Runtime Quickstart\n\n```typescript\nimport { ArbiterRuntime, SDK_VERSION } from '@arbiterhq/sdk';\n\nconst runtime = new ArbiterRuntime({\n  credential: process.env.ARBITER_AGENT_CREDENTIAL!,\n});\n\nawait runtime.connect({\n  framework: 'langgraph',\n  runtimeType: 'node',\n  runtimeVersion: process.version,\n  sdkVersion: SDK_VERSION,\n  environment: 'production',\n});\n\nconst result = await runtime.evaluate({\n  action: 'send_payment',\n  amount: 5000,\n});\n\nconsole.log(result.decision, result.evaluationId);\n```\n\n### Local development\n\n```typescript\nconst runtime = new ArbiterRuntime({\n  credential: process.env.ARBITER_AGENT_CREDENTIAL!,\n  baseUrl: 'http://localhost:3001',\n});\n```\n\n## Admin Quickstart\n\n```typescript\nimport { ArbiterAdmin } from '@arbiterhq/sdk';\n\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY!,\n});\n\nawait admin.registerAgent({ externalId: 'finance-agent' });\nawait admin.registerPermission({ action: 'send_payment' });\nawait admin.grantPermission({ agent: 'finance-agent', action: 'send_payment' });\n\nconst { credential } = await admin.createAgentCredentialByExternalId({\n  externalId: 'finance-agent',\n  name: 'Runtime credential',\n  createdByUserId: 'owner-user-id',\n});\n```\n\n### Local development\n\n```typescript\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY!,\n  baseUrl: 'http://localhost:3001',\n});\n```\n\n## Manifest lifecycle\n\nManifest SDK methods accept a typed **`ManifestWorkspace`** object — not a YAML string, file path, or full `arbiter.yaml` document.\n\n```\narbiter.yaml\n    ↓\nparse YAML\n    ↓\ndoc.spec\n    ↓\nManifestWorkspace\n    ↓\nplan()\n    ↓\nsyncRegistryManifest()\n```\n\nThe SDK does **not** read files. The CLI reads and parses `arbiter.yaml` for you. When using the SDK directly, parse the file, extract `doc.spec`, and optionally validate with `validateManifestWorkspace()`.\n\n```typescript\ninterface ManifestWorkspace {\n  agents: ManifestAgent[];\n  permissions: ManifestPermission[];\n  policies: ManifestPolicy[];\n}\n```\n\nUse `validateManifestWorkspace(manifest)` before calling SDK methods to get actionable validation errors that mirror the backend contract.\n\n## Manifest fields\n\n### Agent (`agents[]`)\n\n| Field | Required | Description |\n|-------|----------|-------------|\n| `externalId` | For sync/plan | Stable agent identifier used by sync and plan |\n| `name` | Yes | Display name |\n| `description` | No | Human-readable summary |\n| `source` | No | Provenance: `dashboard`, `sdk`, `discovered` |\n| `management` | No | Ownership mode: `dashboard`, `sdk`, `manifest`, `discovered` |\n| `owner` | No | Structured owner `{ slug, type }` where `type` is `user`, `team`, or `service_account` |\n| `ownerSlug` | No | Owner slug when not using the `owner` object |\n| `ownerType` | No | Owner type when using `ownerSlug` |\n| `riskTier` | No | `low`, `medium`, `high`, or `critical` |\n| `status` | No | `pending_review`, `active`, `disabled`, `expired`, or `archived` |\n| `expiresAt` | No | ISO 8601 datetime |\n| `approvedBy` | No | Approver identity for governed onboarding |\n| `grants` | No | Permission grants to apply with the agent (see Grants) |\n\n### Permission (`permissions[]`)\n\n| Field | Required | Description |\n|-------|----------|-------------|\n| `action` | Yes | Snake_case action identifier |\n| `description` | No | Human-readable summary |\n| `defaultDecision` | No | Runtime posture when no policy matches: `allow`, `hold`, or `deny` |\n| `status` | No | Deprecated posture alias (`allowed`→allow, `approval_required`→hold, `denied`→deny). Prefer `defaultDecision`. |\n| `source` | No | Provenance: `dashboard`, `sdk`, `discovered` |\n| `management` | No | Ownership mode: `dashboard`, `sdk`, `manifest`, `discovered` |\n| `assignedAgents` | No | Agent `externalId` values assigned to this permission |\n| `displayName` | No | UI-friendly label |\n| `category` | No | Grouping label (for example Financial) |\n| `documentation` | No | Documentation URL |\n| `tags` | No | String tags for discovery and filtering |\n| `metadata` | No | Arbitrary key/value metadata object |\n\n### Policy (`policies[]`)\n\n| Field | Required | Description |\n|-------|----------|-------------|\n| `id` | For sync/plan | Stable policy slug |\n| `action` | Yes | Snake_case action this policy governs |\n| `field` | Legacy style | Field path for single-condition policies |\n| `operator` | Legacy style | Comparison operator |\n| `value` | Legacy style | Scalar or array value |\n| `conditions` | Modern style | Array of `{ field, operator, value?, type? }` |\n| `conditionOperator` | Modern style | `AND` or `OR` when using multiple `conditions` |\n| `priority` | No | Integer priority (lower runs first) |\n| `displayName` | No | UI-friendly label |\n| `decision` | Yes | `allow`, `deny`, or `hold` |\n| `source` | No | Provenance: `dashboard`, `sdk`, `discovered` |\n| `management` | No | Ownership mode: `dashboard`, `sdk`, `manifest`, `discovered` |\n\nEvery policy must declare **either** legacy `field` + `operator` + `value` **or** a non-empty `conditions[]` array.\n\n#### Legacy policy style\n\nUse a single field comparison when the rule is simple:\n\n```yaml\n- id: payment-amount-hold\n  action: send_payment\n  field: amount\n  operator: '>'\n  value: 1000\n  decision: hold\n```\n\n#### Modern policy style\n\nUse `conditions[]` when you need multiple predicates or richer operators:\n\n```yaml\n- id: payment-region-deny\n  action: send_payment\n  conditions:\n    - field: region\n      operator: in\n      value: [sanctioned, blocked]\n    - field: amount\n      operator: '>='\n      value: 100\n  conditionOperator: AND\n  decision: deny\n```\n\nPrefer legacy style for single comparisons. Prefer modern style for compound rules or operator sets like `in`, `between`, and valueless operators (`exists`, `is_null`, etc.).\n\n### Grants\n\n`grants` on an agent replace that agent's permission grants during sync:\n\n```yaml\ngrants:\n  - action: send_payment\n    grantedBy: platform-ops\n    grantedReason: Baseline finance automation access\n```\n\nEach grant requires `action` (snake_case). Optional `grantedBy` and `grantedReason` document provenance.\n\n### Ownership and risk\n\n- **`owner`** — structured `{ slug, type }` for accountable ownership\n- **`ownerSlug` / `ownerType`** — flat alternative to the `owner` object\n- **`riskTier`** — classifies agent blast radius: `low`, `medium`, `high`, `critical`\n\n### Source and management semantics\n\n- **`source`** — where the record originated (`dashboard`, `sdk`, `discovered`)\n- **`management`** — who may mutate the record (`dashboard`, `sdk`, `manifest`, `discovered`)\n\nManifest-managed resources typically use `management: manifest` so the CLI/SDK owns changes and the dashboard stays read-only for those records.\n\n## Manifest SDK workflow\n\nInstall a YAML parser in your project:\n\n```bash\nnpm install yaml\n```\n\n### Plan\n\n```javascript\nimport fs from 'node:fs';\nimport { parse as parseYaml } from 'yaml';\nimport { ArbiterAdmin, validateManifestWorkspace } from '@arbiterhq/sdk';\n\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY,\n});\n\nconst doc = parseYaml(fs.readFileSync('./arbiter.yaml', 'utf8'));\nconst manifest = validateManifestWorkspace(doc.spec);\n\nconst plan = await admin.plan(manifest);\nconsole.log(JSON.stringify(plan, null, 2));\n```\n\n### Sync (apply manifest)\n\nHigh-level API — pass a parsed `ManifestWorkspace`:\n\n```javascript\nimport fs from 'node:fs';\nimport { parse as parseYaml } from 'yaml';\nimport { ArbiterAdmin, validateManifestWorkspace } from '@arbiterhq/sdk';\n\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY,\n});\n\nconst doc = parseYaml(fs.readFileSync('./arbiter.yaml', 'utf8'));\nconst manifest = validateManifestWorkspace(doc.spec);\n\nconst applied = await admin.syncRegistryManifest(manifest);\nconsole.log(JSON.stringify(applied, null, 2));\n```\n\n### Drift\n\nDrift is workspace-scoped — no manifest input:\n\n```javascript\nimport { ArbiterAdmin } from '@arbiterhq/sdk';\n\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY,\n});\n\nconst drift = await admin.getDrift();\nconsole.log(JSON.stringify(drift, null, 2));\n```\n\n### State signature\n\n```javascript\nimport { ArbiterAdmin } from '@arbiterhq/sdk';\n\nconst admin = new ArbiterAdmin({\n  apiKey: process.env.ARBITER_API_KEY,\n});\n\nconst signature = await admin.getStateSignature();\nconsole.log(signature.stateSignature);\n```\n\n## Manifest API surface\n\n| API | Level | Input | Use when |\n|-----|-------|-------|----------|\n| `plan(manifest)` | High-level | `ManifestWorkspace` | Preview changes from parsed manifest |\n| `syncRegistryManifest(manifest)` | High-level | `ManifestWorkspace` | Apply parsed manifest to workspace |\n| `getDrift()` | High-level | none | Compare live workspace drift |\n| `getStateSignature()` | High-level | none | Read workspace governance fingerprint |\n| `syncRegistry(input)` | Low-level transport | `SyncRegistryInput` | You already built the typed sync payload |\n\nPrefer **`syncRegistryManifest()`** for manifest-driven workflows. Use **`syncRegistry()`** only when you construct the transport payload yourself.\n\n## Runnable examples\n\nSee [`../../examples/discovery-first/`](../../examples/discovery-first/) for the canonical discovery-first onboarding flow.\n\nSee [`../../examples/manifest/`](../../examples/manifest/) for complete manifest scripts:\n\n- `plan.mjs` — preview manifest changes\n- `sync.mjs` — apply manifest changes\n- `drift.mjs` — inspect workspace drift\n- `state-signature.mjs` — read workspace governance fingerprint\n- `loadManifest.mjs` — shared YAML loader with SDK validation\n- `arbiter.yaml` — canonical manifest demonstrating supported fields\n\n```bash\ncd examples/manifest\nnpm install\nexport ARBITER_API_KEY=your_key\nnpm run plan\nnpm run sync\nnpm run drift\nnpm run state-signature\n```\n\n## API Reference\n\n### `ArbiterRuntime`\n\n| Method | Description |\n|--------|-------------|\n| `connect(input?)` | `POST /runtime/connect` — agent discovery with workspace API key |\n| `heartbeat()` | `POST /runtime/heartbeat` |\n| `evaluate(input)` | `POST /evaluate` — permission discovery for unknown actions |\n| `getApproval(id)` | `GET /approvals/:id` |\n| `waitForApproval(result | id, options?)` | Wait until an Approval HOLD is approved/rejected/expired |\n| `pollApproval(result | id, options?)` | **Deprecated** — alias of `waitForApproval` |\n| `consumeRelease(input)` | `POST /releases/consume` |\n| `completeHeldEvaluation(input)` | **Canonical HOLD completion (ADR-003):** wait → consume → optional receipt |\n| `getReceipt(evaluationId)` | `GET /evaluations/:id/receipt` |\n\n### `ArbiterAdmin`\n\n| Method | Description |\n|--------|-------------|\n| `registerAgent` | `POST /sdk/register-agent` |\n| `registerPermission` | `POST /sdk/register-permission` |\n| `grantPermission` | `POST /sdk/register-agent-permission` |\n| `registerPolicy` | `POST /sdk/register-policy` |\n| `plan(manifest)` | `POST /sdk/plan` — requires `ManifestWorkspace` |\n| `syncRegistryManifest(manifest)` | `POST /sdk/sync-registry` — requires `ManifestWorkspace` |\n| `syncRegistry(input)` | `POST /sdk/sync-registry` — low-level typed payload |\n| `getDrift()` | `GET /manifest/drift` |\n| `getStateSignature()` | `GET /state-signature` |\n| `createAgentCredential` | `POST /agents/:id/credentials` |\n| `createAgentCredentialByExternalId` | Resolve agent + create credential |\n| `approve` / `reject` | Human session required |\n\n## License\n\nISC\n","readmeFilename":"README.md"}