{"_id":"@aroha-sdk/credentials","_rev":"6-9e6f9c66551fb5e949527ee4390607bb","name":"@aroha-sdk/credentials","dist-tags":{"latest":"1.3.0"},"versions":{"1.0.0":{"name":"@aroha-sdk/credentials","version":"1.0.0","_id":"@aroha-sdk/credentials@1.0.0","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"94ff4ea82171a24c83d6329b951760c6855968d0","tarball":"https://registry.npmjs.org/@aroha-sdk/credentials/-/credentials-1.0.0.tgz","fileCount":13,"integrity":"sha512-Nuq8c+5qulAst1w6xx7qWlIsuobXpOz1hEj8iUO7lxhPROOSITF4Vrp3/kz3yGflnun/0nLLbGKdvQhUpCbE3g==","signatures":[{"sig":"MEYCIQCsQrGJBgZ2qZe8kKCEOgElHNEcgdM5TSipHWMONMEdAgIhAJIyTrzcdxM+uOvnGkXell8D1BTpHjs4hG5lTFHkt8oI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":64735},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"67cbe687cd0664deb4374aaa75788c9d7119d74b","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rm -rf dist"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.13.0","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","directories":{},"_nodeVersion":"24.16.0","dependencies":{"uuid":"^10.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0","@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.0.0_1782173736452_0.594894045542576","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@aroha-sdk/credentials","version":"1.2.0","_id":"@aroha-sdk/credentials@1.2.0","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"8f4371d2f11ae77c8241b47562da59b0a652de9d","tarball":"https://registry.npmjs.org/@aroha-sdk/credentials/-/credentials-1.2.0.tgz","fileCount":56,"integrity":"sha512-47rxgrAEIU0h7wtsxJTFGFGaBGixDTV2RSZwJd/LG5PDqwXKDFNopTBrmU2u5qrAvdlYVqlhsNcTOg0i7KK9zg==","signatures":[{"sig":"MEUCIQCmsSV3HWp+yIrRdepcfoI7ISzhLDnv3SXfyUgMXeD/hAIgLwCVceEUFlFnz8PMmuI0MhSP0HrHg96SfL3owmbvIiQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":198832},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"3fd6d5ab883e07e6c38989dc642f87ef70bb6320","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rm -rf dist"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.13.0","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","directories":{},"_nodeVersion":"24.16.0","dependencies":{"uuid":"^10.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0","@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.2.0_1782181394043_0.8787703027029918","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@aroha-sdk/credentials","version":"1.2.1","license":"MIT","_id":"@aroha-sdk/credentials@1.2.1","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"81d100039f31af26e121e01cdceea55754fcb12f","tarball":"https://registry.npmjs.org/@aroha-sdk/credentials/-/credentials-1.2.1.tgz","fileCount":56,"integrity":"sha512-DkrZzx5hmgAF4r/4Gp8P4a/2suFhtGQFhnIR3cklBm4D06Rkyz5XXuO1I2z7R1tvD9o0xJQ+EbOWTb3X2gpLNg==","signatures":[{"sig":"MEUCIQCyRFIZkIo5TVUaerpUx2onbETghIfyQ1lMf+X+WjTuQgIgAhYH4khznnP73G3u/igxb9R8pjrHL9F0/kWbHwXMcgE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":197121},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ca0800d55b453d5e9b38ffce3dff055f010619eb","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rm -rf dist"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.16.0","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","directories":{},"_nodeVersion":"24.18.0","dependencies":{"uuid":"^10.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0","@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.2.1_1783119720927_0.5152577302526251","host":"s3://npm-registry-packages-npm-production"}},"1.2.2":{"name":"@aroha-sdk/credentials","version":"1.2.2","license":"MIT","_id":"@aroha-sdk/credentials@1.2.2","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"3296914ccfad7d65bada61fba61569902bb58437","tarball":"https://registry.npmjs.org/@aroha-sdk/credentials/-/credentials-1.2.2.tgz","fileCount":57,"integrity":"sha512-6oaQ88dAuyj0egyKxXkmjUxkQIcTrLDA57egQtyUsch2rwRiFGu7QeNuCI2u+/Ll4LuVAb99FwSU9rWk9xTIgA==","signatures":[{"sig":"MEUCIQCWkUbyAByewRPXAZUKp7G2C5LtrUmIojjSeZgJozqp6QIgYjjVcNwmg2SEOyCEL9I7m6p18otTejshIXN1WgNDy+I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":207956},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"59f177e5c55a3a25977c1fd9895040f339806fb7","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rm -rf dist"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.16.0","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","directories":{},"_nodeVersion":"24.18.0","dependencies":{"uuid":"^10.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0","@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.2.2_1783298873516_0.7467587367669277","host":"s3://npm-registry-packages-npm-production"}},"1.2.3":{"name":"@aroha-sdk/credentials","version":"1.2.3","license":"MIT","_id":"@aroha-sdk/credentials@1.2.3","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"3ebd0a27bdaa51403f6146837486762826f91d63","tarball":"https://registry.npmjs.org/@aroha-sdk/credentials/-/credentials-1.2.3.tgz","fileCount":82,"integrity":"sha512-4dSRQoxuRY1CL3ax4s5Ih3ugrRO2dt5eYc6Fz2Yu7F4M4JuM4VMuWFGVvrdPTrNlNynWhNg3bfVXItF8OBUuoQ==","signatures":[{"sig":"MEQCIEnY3IyzLY8QqW7S3amav/3dgilTXWpyMFeoZxLTE9FwAiBFaYCba01YEAKoMJg6Tppnyjsfu/o10Tv8GIW3NxKVSw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":392298},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ab12f436a63322ab52f1516f35184f264e803c7a","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","clean":"rm -rf dist"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.17.0","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0","@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/credentials_1.2.3_1786718283712_0.972789818004","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@aroha-sdk/credentials","version":"1.3.0","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc -p tsconfig.json","clean":"rm -rf dist","test":"vitest run"},"dependencies":{"@aroha-sdk/core":"^1.0.0","@noble/ed25519":"^2.1.0","@noble/hashes":"^1.4.0"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.4.0","vitest":"^1.6.0"},"license":"MIT","engines":{"node":">=18.0.0"},"gitHead":"8fa8563aea2cc73fcd7a82d1c56063a3d9edc7d6","_id":"@aroha-sdk/credentials@1.3.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-B0xuZwcyrCmHDNLapzvOehG8LrG5jfXvZedEakE/GlSzzg2N5B/7QkySCMVkFUkaHcMhzx1RPBniUaUSiFYTXA==","shasum":"90d36a077b16404190cdddb3d038cc7155988ceb","tarball":"https://registry.npmjs.org/@aroha-sdk/credentials/-/credentials-1.3.0.tgz","fileCount":82,"unpackedSize":445115,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD3NUCbTdSbywmTeTLUY9orgjbi3PDBN1enZI6ql81A7QIhAJ06EL18p7eELnjNZTM3A/dkzHJCi955jtmYk+3vLtQ2"}]},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"directories":{},"maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/credentials_1.3.0_1787073833451_0.15990731952000048"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-23T00:15:36.311Z","modified":"2026-08-18T17:23:53.765Z","1.0.0":"2026-06-23T00:15:36.588Z","1.2.0":"2026-06-23T02:23:14.174Z","1.2.1":"2026-07-03T23:02:01.062Z","1.2.2":"2026-07-06T00:47:53.652Z","1.2.3":"2026-08-14T14:38:03.944Z","1.3.0":"2026-08-18T17:23:53.587Z"},"license":"MIT","description":"Human credentials, RBAC, and credential registry for the Aroha Protocol","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"readme":"# @aroha-sdk/credentials\n\n![Stable](https://img.shields.io/badge/status-stable-brightgreen) ![npm](https://img.shields.io/npm/v/@aroha-sdk/credentials)\n\nIssue, attenuate, and verify cryptographically signed IntentMandates — the bounded-authority primitive for Aroha agent chains.\n\n## Install\n\n```bash\nnpm install @aroha-sdk/credentials\n```\n\n## Quick example\n\n```typescript\nimport { issueIntentMandate, attenuateToPayment, attenuateToCart, verifyMandate } from \"@aroha-sdk/credentials\";\n\n// Step 1: Human issues root mandate to orchestrator\nconst { mandate, token } = await issueIntentMandate(\n  humanDID,          // grantor\n  orchestratorDID,   // grantee\n  { spendLimitUsd: 500, allowedActions: [\"book-flights\", \"book-hotels\"] },\n  humanPrivateKey,\n  3_600_000,         // TTL: 1 hour in ms\n);\n\n// Step 2: Orchestrator narrows scope and delegates to flight agent\nconst flightMandate = await attenuateToPayment(\n  mandate,\n  flightAgentDID,\n  { spendLimitUsd: 300 },   // must be ≤ parent's 500\n  orchestratorPrivateKey,\n);\n\n// Step 3: Flight agent verifies before acting\nconst { valid, mandate: decoded, reason } = await verifyMandate(\n  flightMandate.token,\n  humanPublicKey,\n);\n// valid === true\n// decoded.constraints.spendLimitUsd === 300\n// Forging a $400 mandate → valid === false (signature mismatch)\n\n// Attenuate to a specific cart total\nconst cartMandate = await attenuateToCart(\n  mandate,\n  paymentAgentDID,\n  { spendLimitUsd: 299, cartId: \"cart_abc\" },\n  flightAgentPrivateKey,\n);\n```\n\n## Why this exists in the mandate chain\n\nThis is the core of Aroha's bounded-authority story. The attenuation principle means scope can only narrow as a mandate passes from orchestrator to sub-agent — it can never widen. Each delegation is Ed25519-signed, so forgery and scope escalation are cryptographically impossible without the delegator's private key.\n\n## API\n\n- `issueIntentMandate(grantorDID, granteeDID, constraints, privateKey, ttlMs)` — create a root mandate signed by the human or top-level orchestrator. Returns `{ mandate, signature, token }`.\n- `attenuateToPayment(parentMandate, granteeDID, constraints, delegatorPrivateKey)` — issue a child mandate with narrower payment scope. Returns `{ mandate, signature, token }`.\n- `attenuateToCart(parentMandate, granteeDID, constraints, delegatorPrivateKey)` — attenuate to a specific cart/transaction. Returns `{ mandate, signature, token }`.\n- `verifyMandate(token, issuerPublicKey)` — verify the full mandate chain. Returns `{ valid, mandate?, reason? }`.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}