{"_id":"@arko05roy/stellar-confidential","name":"@arko05roy/stellar-confidential","dist-tags":{"preview":"0.1.0-preview.1","latest":"0.1.0-preview.1"},"versions":{"0.1.0-preview.1":{"name":"@arko05roy/stellar-confidential","version":"0.1.0-preview.1","description":"Unified buyer, seller, transport, and facilitator primitives for confidential Stellar x402 payments","license":"Apache-2.0","type":"module","sideEffects":false,"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./client":{"types":"./dist/client.d.ts","import":"./dist/client.js"},"./server":{"types":"./dist/server.d.ts","import":"./dist/server.js"},"./seller":{"types":"./dist/seller.d.ts","import":"./dist/seller.js"},"./transport":{"types":"./dist/transport.d.ts","import":"./dist/transport.js"},"./proof":{"types":"./dist/proof.d.ts","import":"./dist/proof.js"},"./facilitator":{"types":"./dist/facilitator.d.ts","import":"./dist/facilitator.js"},"./package.json":"./package.json"},"engines":{"node":">=22"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run","prepack":"npm run build && npm test"},"dependencies":{"@noble/curves":"1.9.7","@stellar/stellar-sdk":"16.2.0","@x402/core":"2.20.0","@x402/stellar":"2.20.0"},"devDependencies":{"@types/node":"24.2.0","typescript":"5.9.2","vitest":"3.2.7"},"_id":"@arko05roy/stellar-confidential@0.1.0-preview.1","gitHead":"c3c3e1936b3549ea1e23e12920f239a71fc6a97b","_nodeVersion":"24.10.0","_npmVersion":"11.6.0","dist":{"integrity":"sha512-PCVPIKTuTC7smcNMuBsIewCebIif4PDG9+5FSIkc2Kx3oSmBi4aqOeQ9J7dLwvu4kqGl0El5hRETN+acgnSwcQ==","shasum":"a08f21f90c7d4e20f4658cf9f1a4c0cb10f5dda9","tarball":"https://registry.npmjs.org/@arko05roy/stellar-confidential/-/stellar-confidential-0.1.0-preview.1.tgz","fileCount":32,"unpackedSize":66553,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCUoOZ5eJBC9KEwNVYpKEBuhDjCgAGJOCaYqaR0PFvdYAIgEgecHzMXwzRD3SDp10M7ZjHDydIOCIc3JFUwZqiOlGs="}]},"_npmUser":{"name":"arko05roy","email":"arkoroy302@gmail.com"},"directories":{},"maintainers":[{"name":"arko05roy","email":"arkoroy302@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/stellar-confidential_0.1.0-preview.1_1787384507878_0.6563637923429917"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-22T07:41:47.661Z","0.1.0-preview.1":"2026-08-22T07:41:48.017Z","modified":"2026-08-22T07:41:48.204Z"},"maintainers":[{"name":"arko05roy","email":"arkoroy302@gmail.com"}],"description":"Unified buyer, seller, transport, and facilitator primitives for confidential Stellar x402 payments","license":"Apache-2.0","readme":"# `@arko05roy/stellar-confidential`\n\nOne testnet-only SDK for both sides of an x402 confidential payment:\n\n- **buyer** — canonical x402 client scheme, quote-binding proof and JSON-body paid retry;\n- **seller** — payment requirements, API metadata, 402 responses and facilitator calls;\n- **facilitator** — shared proof parsing/verification and confidential event validation;\n- **transport** — body transport for proofs that exceed common HTTP header limits.\n\nThe package reuses `@x402/core` and `@x402/stellar`. It does not fork the x402\nprotocol. `scheme` remains `exact`; `extra.confidentialExact` declares the\nOpenZeppelin preview version and required transport.\n\n> This is an unaudited developer preview. It is deliberately restricted to\n> `stellar:testnet` and the pinned OpenZeppelin `oz-preview-v1` wire format.\n\nCurrent conformance scope is the x402 integration layer and quote-binding\nproof. OpenZeppelin's upstream `docs/SDK.md` is presently an obligations\nspecification rather than a published JavaScript implementation, and its\nUltraHonk backend is marked unfinished. Accordingly, this package does not\nclaim holder-wallet or prover conformance: applications must supply a reviewed,\nversion-pinned `ConfidentialTransferBuilder` implementation.\n\n## Seller\n\n```ts\nimport { HTTPFacilitatorClient } from \"@x402/core/http\";\nimport {\n  ConfidentialExactSeller,\n  createConfidentialResource,\n} from \"@arko05roy/stellar-confidential/seller\";\n\nconst resource = createConfidentialResource(\n  { amount: \"400\", payTo: process.env.STELLAR_PAY_TO! },\n  {\n    url: \"https://api.example.com/weather\",\n    description: \"Confidential weather inference\",\n    mimeType: \"application/json\",\n    serviceName: \"Weather\",\n    tags: [\"weather\", \"confidential\"],\n  },\n);\nconst seller = new ConfidentialExactSeller(\n  resource,\n  new HTTPFacilitatorClient({ url: process.env.FACILITATOR_URL! }),\n);\n\n// Unpaid request:\nreturn seller.paymentRequired(request.url);\n```\n\nThe response advertises:\n\n```json\n{\n  \"scheme\": \"exact\",\n  \"network\": \"stellar:testnet\",\n  \"extra\": {\n    \"areFeesSponsored\": true,\n    \"confidentialExact\": {\n      \"version\": \"oz-preview-v1\",\n      \"transport\": \"json-body\"\n    }\n  }\n}\n```\n\nUse `seller.verify(paymentPayload)` before producing the protected result and\n`seller.settle(paymentPayload)` immediately before returning it.\n\n## Buyer\n\nThe OpenZeppelin confidential wallet/prover owns private balance openings,\nrecovery and UltraHonk proving. The SDK keeps that version-sensitive component\nbehind `ConfidentialTransferBuilder` instead of embedding an unpinned prover.\n\n```ts\nimport { ConfidentialExactStellarScheme } from \"@arko05roy/stellar-confidential/client\";\nimport { fetchWithConfidentialPayment } from \"@arko05roy/stellar-confidential/transport\";\n\nconst scheme = new ConfidentialExactStellarScheme(openZeppelinBuilder, {\n  maxAmount: 1_000n,\n  allowedRecipients: [process.env.EXPECTED_SELLER!],\n});\nconst response = await fetchWithConfidentialPayment(\n  \"https://api.example.com/weather?city=London\",\n  undefined,\n  {\n    scheme,\n    createPaidBody: paymentPayload => ({ city: \"London\", paymentPayload }),\n  },\n);\n```\n\nThe buyer validates the asset, recipient and maximum before invoking the prover.\nOn a successful paid retry it also requires and validates `PAYMENT-RESPONSE`,\nincluding the network, optional payer/amount fields and transaction hash.\n\n`ConfidentialTransferBuilder.buildTransfer()` must return the final signed-auth\ntransaction XDR, `C_tx`, and its private blinding. The SDK checks that the\nblinding opens `C_tx` to the quoted amount, binds the proof to the complete x402\nstatement and never sends the blinding to the seller or facilitator.\n\n## Imports\n\n| Import | Role |\n| --- | --- |\n| `@arko05roy/stellar-confidential/client` | Buyer x402 scheme |\n| `@arko05roy/stellar-confidential/server` | Standard resource-server scheme |\n| `@arko05roy/stellar-confidential/seller` | Metadata, 402 and facilitator facade |\n| `@arko05roy/stellar-confidential/transport` | JSON-body paid fetch |\n| `@arko05roy/stellar-confidential/proof` | Shared quote-binding proof |\n| `@arko05roy/stellar-confidential/facilitator` | Facilitator verification helpers |\n\n## Privacy boundary\n\nThe OpenZeppelin token hides balances and transfer amounts. Participant\naddresses, transaction timing, the public x402 quote and the seller/facilitator\nHTTP request remain visible to their respective observers.\n\nWallet recovery is load-bearing: clients must retain private openings or use a\nconforming event archive/indexer and verify reconstructed openings against the\non-chain commitments before spending.\n","readmeFilename":"README.md","_rev":"1-c99cd9fc5ea1ffa77f59cfa3c33d303b"}