{"_id":"@askledger/receipts-sdk","_rev":"12-2714252a6e26f5090adb7d9ccb99ccd7","name":"@askledger/receipts-sdk","dist-tags":{"latest":"0.13.0"},"versions":{"0.6.0":{"name":"@askledger/receipts-sdk","version":"0.6.0","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.6.0","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"pl":"dist/cli.js","ledger-cli":"dist/cli.js"},"dist":{"shasum":"e2bdec7848824dfff56da47dee1c4152885e8172","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.6.0.tgz","fileCount":347,"integrity":"sha512-nNDoabkqhI0yMaWCu8HNf6zT4B0wvzYWH8jYI7I4w5mu+wAL5eLH/YBI6Ngr33Z8Pc3KbiaI7GMl4hIezqQD5w==","signatures":[{"sig":"MEYCIQCN2ZRDO4hLYeje9eP6KvPdeEFitjZ7n3kqpJnk8IXEYgIhAInXII3OxTUCjBCtjISX0ve3HjIMoomuYaEmMKwcNOlo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":760274},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"9e66854fd0cf60fd9263da53f7cc92484109938d","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"alirashed","email":"Alirashid2503@gmail.com"},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"22.22.1","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.6.0_1782611926097_0.4237640086229768","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@askledger/receipts-sdk","version":"0.8.0","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.8.0","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"249e5b2d23635136cf8d954e9b8ddd81d0415eff","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.8.0.tgz","fileCount":351,"integrity":"sha512-1Qs4c+PMuvAkjEWFZFY1n0z+w4BrxADzyLaaZntdvOq1nyh7khKyJ+y5qnz96QXBRuxTohmA6/dEKnhrWYkWbw==","signatures":[{"sig":"MEYCIQDZK9/B18erQoNGDryaZJJe9v4wCNaBfuQrr+venGr7wgIhAMfSkQ8vj/PKXSHdk2XKnSAZcMzPuTEekA0sXokAt+N2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":895691},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"a2b0d52b3e6304d774e48c74dcf8d7a061db43f5","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.8.0_1783447969949_0.41477471786536246","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@askledger/receipts-sdk","version":"0.9.0","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.9.0","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"bd820ee2650cc28ee01cf41ca056b2f6b80ed2b0","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.9.0.tgz","fileCount":355,"integrity":"sha512-cf3UVlbAO2gV6Na1+0cbjfvCvuugEHOvwKoOd2K6loB+WKYGV7NWoCfnvSJQphm87bh7ZvbQ/M9BUYUoqPK/oA==","signatures":[{"sig":"MEUCIQCiOb4zu8SMbccz69TqQWvwFAc6htoqPm6eOCEqB4S8vQIgd7K+Iw6zcwCvJmBrg7cwmEu6ZGKWMTISksixPL54wrM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":926601},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"9b9bbe716787cf19085d176d7545037fc1306dad","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.9.0_1783455483827_0.9730551837749801","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@askledger/receipts-sdk","version":"0.10.0","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.10.0","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"c4812af621240b4f39288bf09f3ecd84384d7509","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.10.0.tgz","fileCount":359,"integrity":"sha512-aXwZk4uLhngNvQt9Pcw5qgWgmhfmxDNrVAfsp88NmUZzlZKuDX8PpXYVHE+8/xcuLx3zg9pNLxMJLxezb/cTTw==","signatures":[{"sig":"MEQCIQDDUT4Aowt08icg530KjpKAsjFqKsxZl6Ko1lTIjzaLyAIfKYbkqDEbnejPMHnlSQwnW+gwjFfBxdjy8WngPulyIQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":955880},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"1edc333e4a378a0ebc6e1716315bbe310ab428e0","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.10.0_1783457658093_0.28271815448915527","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@askledger/receipts-sdk","version":"0.11.0","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.11.0","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"cc82915ea537df4c08bb62bbf2f3906f5c4402e3","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.11.0.tgz","fileCount":359,"integrity":"sha512-zX73zvYr15R4yhnAWrhBGw/GfC9Zd/cmKx7MUoKO/YQydqpQcAoPLN8cZgWTXwuPgoXAWdvDSOwqpVE66+AR8g==","signatures":[{"sig":"MEUCIQD3U6sIleJpI59n7etj1FtK22hPjLsZVOTsCLWmMLpFjQIgSxjmb71PMugjUMM2+ak8s2+voIJP/7tpreFK9ln0Wio=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":962021},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"eb22164052a44f9237c28c872109ab35440b5fda","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.11.0_1783499020829_0.7113320511037182","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@askledger/receipts-sdk","version":"0.12.0","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.12.0","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"13c8d5c2db72a2d869018522480daaa3bc73ac4f","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.12.0.tgz","fileCount":375,"integrity":"sha512-jYKPx+7LsBAE8cb5k929TQgSv4FOa0AHZPxPMNRSdMGBkbQfxBfxZ7bJTMdnb57OQsKp/4k5Er8VyLWCVr98og==","signatures":[{"sig":"MEUCIBzjACQ02vwvpdeLvJGPqLDsKRcdI9gscYVrSalJ5baxAiEAtk/4LNuuh3JHQIzYRKqTa5VmXXY308BKi9sMcEyTY5s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1064893},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"9a10d84478fb08d9698e7eb82d6b5790182c88c6","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.12.0_1783639025336_0.9949886068998213","host":"s3://npm-registry-packages-npm-production"}},"0.12.1":{"name":"@askledger/receipts-sdk","version":"0.12.1","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.12.1","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"f2ec531285de9dfa86be675bd47025da155231dd","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.12.1.tgz","fileCount":375,"integrity":"sha512-0zzd3RBI05is09Y75vthqISi3hOtQrJnt6VMnRZ/7zpBS6pJtxYd0e2BCeKpP7ckz5l8JySdQyFkfjs9tNvg1w==","signatures":[{"sig":"MEUCIQDt6X3DDq65xUjKKjkTKDSIwE8qPR9Pzs8k6xReF6QrnwIgch6tLWbcyVDQBDuPpKsQWVNVP2i9gvdoJ2qL/VkEvWc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.12.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1065056},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"e81768c5eafa3b3dcedcf7eea0d735d4ecce1598","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","demo:layers":"tsx examples/08-four-layers-end-to-end.ts","demo:savings":"tsx examples/09-prove-the-savings.ts","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.0","vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.12.1_1783695885816_0.6173762302084793","host":"s3://npm-registry-packages-npm-production"}},"0.12.2":{"name":"@askledger/receipts-sdk","version":"0.12.2","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.12.2","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"34a7c1729e6a5ff48cb7868b4d790406b120648d","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.12.2.tgz","fileCount":375,"integrity":"sha512-IN5cQHXKk/yC/6f1kEQP3VzuUp1BhudFcQVkplmI5btK0i+bLkD1J3Bp0cf4st7nikw7mebkagbthhxCcuSGag==","signatures":[{"sig":"MEUCIQCE8eo1U4NfSIlLya2mlryDF4mzZbcbBIDWaa7CNjGr5wIgecjojcjlp81FpY7qbVJvV5DLlANrEMSusWak3R31r6c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.12.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1064493},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"f42f26ee22f1b2750819110d984e4dc43c329fd3","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","demo:layers":"tsx examples/08-four-layers-end-to-end.ts","demo:savings":"tsx examples/09-prove-the-savings.ts","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts — RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.0","vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.12.2_1783710907455_0.7962106895848662","host":"s3://npm-registry-packages-npm-production"}},"0.12.3":{"name":"@askledger/receipts-sdk","version":"0.12.3","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.12.3","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"72b33600062c98fbcd96fc88339d28a7f8227efa","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.12.3.tgz","fileCount":375,"integrity":"sha512-XRDHNffV9xAr7PyceF/NYqyg2lRNAHT9fhjeZxjb727lbMvoQrJKS01aJiLBpoo2ELH9ff1WCgpP4hHsDKVANQ==","signatures":[{"sig":"MEQCIHrCSSvhHbQ3Ok9D4vvJ+Ry7GqFgiSBa21YDRPnI58MJAiBMR07dSq4WJfIW4efrN8JZuGmF1wjZqvXu4wddGOZwUw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.12.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1064485},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"0ba61a3345012dcead9cdcbaa485698e03676343","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","demo:layers":"tsx examples/08-four-layers-end-to-end.ts","demo:savings":"tsx examples/09-prove-the-savings.ts","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts: RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.0","vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.12.3_1783711154531_0.2861574908771449","host":"s3://npm-registry-packages-npm-production"}},"0.12.4":{"name":"@askledger/receipts-sdk","version":"0.12.4","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.12.4","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"f1858907d965699340c7bd4f47349006c5bb42a6","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.12.4.tgz","fileCount":375,"integrity":"sha512-TjGluyW6nLwIPeziXv5Z7QmVGLkAbPo3I5CsWKBxGW+GIdGGMvhckV3SD3p2D+YDxaCs3NBjA/hOjqXy7D2lqQ==","signatures":[{"sig":"MEQCICjokY7mMDf2xFNIFOwSlHwcyl+YlaATu4THyFJuhjABAiASbmRKdCYltiOJzvVgWGRR61bMLzqcBfzw3hXYNkvuAg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.12.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1064559},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"c2597f88b20270efd07815ae925ee71fb3d1aa36","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","demo:layers":"tsx examples/08-four-layers-end-to-end.ts","demo:savings":"tsx examples/09-prove-the-savings.ts","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts: RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.0","vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.12.4_1783723117335_0.10075892442141177","host":"s3://npm-registry-packages-npm-production"}},"0.12.5":{"name":"@askledger/receipts-sdk","version":"0.12.5","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","_id":"@askledger/receipts-sdk@0.12.5","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"dist":{"shasum":"a1972dea071a84b9540a63d5afc468158130ced0","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.12.5.tgz","fileCount":189,"integrity":"sha512-ikaZuNhxxxLgW13ekR9FFbgsmuFn+5AKreCDh8ktjN9QE44idJcYzLqLGv0DosD9/y78RycoY7l//+ObJJvjRA==","signatures":[{"sig":"MEUCIBDoAw26/3rvzOcimqRfILULtyTeSYs/sX8NL9NHoOK+AiEAyNCGVSpqo3xbI+xKTyLfYGyXVGgAbE2SXI7bxUx0h6c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askledger%2freceipts-sdk@0.12.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":623316},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./vendor-kit":{"types":"./dist/vendor-kit/index.d.ts","import":"./dist/vendor-kit/index.js"},"./adapters/fetch":{"types":"./dist/adapters/fetch.d.ts","import":"./dist/adapters/fetch.js"},"./adapters/openai":{"types":"./dist/adapters/openai.d.ts","import":"./dist/adapters/openai.js"},"./adapters/anthropic":{"types":"./dist/adapters/anthropic.d.ts","import":"./dist/adapters/anthropic.js"},"./adapters/langchain":{"types":"./dist/adapters/langchain.d.ts","import":"./dist/adapters/langchain.js"}},"gitHead":"e7c0a64c76556898673b8ae336039598d9875ec0","scripts":{"demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","lint":"tsc --noEmit","sbom":"node scripts/generate-sbom.mjs","test":"vitest run","bench":"npm run build && node scripts/bench.mjs","build":"tsc","keygen":"npm run build && node dist/cli.js keygen","test:watch":"vitest","demo:layers":"tsx examples/08-four-layers-end-to-end.ts","demo:savings":"tsx examples/09-prove-the-savings.ts","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2390d8ae-bae8-4406-be08-baff79f31f1b"}},"repository":{"url":"git+https://github.com/askledger/receipts-sdk.git","type":"git"},"_npmVersion":"11.18.0","description":"Cryptographic AI Decision Receipts: RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","directories":{},"_nodeVersion":"20.20.2","dependencies":{"uuid":"^11.0.0","commander":"^12.0.0","canonicalize":"^2.0.0","@noble/hashes":"^1.4.0","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.23.0","vitest":"^3.2.6","typescript":"^5.4.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipts-sdk_0.12.5_1783804705176_0.05314670662565746","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@askledger/receipts-sdk","version":"0.13.0","description":"Cryptographic AI Decision Receipts: RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","type":"module","main":"dist/index.js","types":"dist/index.d.ts","homepage":"https://github.com/askledger/receipts-sdk#readme","bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"bin":{"askledger":"dist/cli.js"},"exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"},"./vendor-kit":{"import":"./dist/vendor-kit/index.js","types":"./dist/vendor-kit/index.d.ts"},"./adapters/openai":{"import":"./dist/adapters/openai.js","types":"./dist/adapters/openai.d.ts"},"./adapters/anthropic":{"import":"./dist/adapters/anthropic.js","types":"./dist/adapters/anthropic.d.ts"},"./adapters/fetch":{"import":"./dist/adapters/fetch.js","types":"./dist/adapters/fetch.d.ts"},"./adapters/langchain":{"import":"./dist/adapters/langchain.js","types":"./dist/adapters/langchain.d.ts"}},"scripts":{"build":"tsc","test":"vitest run","test:watch":"vitest","demo":"npm run build && node dist/cli.js sign examples/event.json && node dist/cli.js verify .ledger/last-receipt.json","demo:layers":"tsx examples/08-five-layers-end-to-end.ts","demo:savings":"tsx examples/09-prove-the-savings.ts","keygen":"npm run build && node dist/cli.js keygen","bench":"npm run build && node scripts/bench.mjs","sbom":"node scripts/generate-sbom.mjs","lint":"tsc --noEmit","prepublishOnly":"npm run build && npm test"},"keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","engines":{"node":">=18.0.0"},"publishConfig":{"access":"public"},"dependencies":{"@noble/ed25519":"^2.1.0","@noble/hashes":"^1.4.0","canonicalize":"^2.0.0","commander":"^12.0.0","uuid":"^11.0.0"},"devDependencies":{"@types/node":"^20.0.0","tsx":"^4.23.0","typescript":"^5.4.0","vitest":"^3.2.6"},"repository":{"type":"git","url":"git+https://github.com/askledger/receipts-sdk.git"},"_id":"@askledger/receipts-sdk@0.13.0","gitHead":"48968bcf65957c392558e5382ae0071926560ef6","_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-7OhYcZDssSpEJKQDfsvbfOhj9bogeOLK/05Rf/jpqvqYcQlcEqOHHWRiCAE7ptTIsLQJky3DRazzyDMI1gTPKA==","shasum":"4f226d3341c31bc95563d647305da850c42aa71c","tarball":"https://registry.npmjs.org/@askledger/receipts-sdk/-/receipts-sdk-0.13.0.tgz","fileCount":195,"unpackedSize":728816,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEIzZFnTLv4N61WPUGIP9gjTk6Z0ftrtkd6w1R6A5b1KAiEAqum0R40jxZVOYPjKB/frtxPV5gbGdRi8TVAA26aX1Go="}]},"_npmUser":{"name":"alirashed","email":"Alirashid2503@gmail.com"},"directories":{},"maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/receipts-sdk_0.13.0_1784706017813_0.2519331879606157"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-28T01:58:45.933Z","modified":"2026-07-22T07:40:18.155Z","0.6.0":"2026-06-28T01:58:46.247Z","0.8.0":"2026-07-07T18:12:50.168Z","0.9.0":"2026-07-07T20:18:04.012Z","0.10.0":"2026-07-07T20:54:18.301Z","0.11.0":"2026-07-08T08:23:41.038Z","0.12.0":"2026-07-09T23:17:05.538Z","0.12.1":"2026-07-10T15:04:46.045Z","0.12.2":"2026-07-10T19:15:07.634Z","0.12.3":"2026-07-10T19:19:14.743Z","0.12.4":"2026-07-10T22:38:37.623Z","0.12.5":"2026-07-11T21:18:25.380Z","0.13.0":"2026-07-22T07:40:17.962Z"},"bugs":{"url":"https://github.com/askledger/receipts-sdk/issues"},"author":{"name":"AskLedger contributors"},"license":"Apache-2.0","homepage":"https://github.com/askledger/receipts-sdk#readme","keywords":["ai","governance","receipts","rfc-8785","jws","ed25519","hash-chain","cryptographic-accountability","audit","regulator","compliance"],"repository":{"type":"git","url":"git+https://github.com/askledger/receipts-sdk.git"},"description":"Cryptographic AI Decision Receipts: RFC 8785 canonical JSON, JWS Ed25519, hash-chained, regulator-verifiable","maintainers":[{"name":"alirashed","email":"Alirashid2503@gmail.com"}],"readme":"# AskLedger · Receipts SDK\n\nOpen-source, vendor-neutral cryptographic trust substrate for enterprise AI. Every AI invocation produces a signed, hash-chained, tamper-evident receipt that auditors, regulators, and insurers verify independently with only the public key. No platform dependency.\n\n**[Open spec · PL-RFC-001…010](spec/README.md)** · **[Conformance](conformance/README.md)** · **[Architecture](docs/ARCHITECTURE.md)** · **[Policy mapping](docs/POLICY_MAPPING.md)** · **[Security](SECURITY.md)** · **[Contributing](CONTRIBUTING.md)**\n\n[![License](https://img.shields.io/badge/license-Apache--2.0-blue)](LICENSE)\n[![Node](https://img.shields.io/badge/node-%3E%3D18-brightgreen)](https://nodejs.org)\n[![Spec](https://img.shields.io/badge/PL--RFC-001…010-blueviolet)](spec/README.md)\n[![Conformance](https://img.shields.io/badge/conformance-CL1%20(canonicalization)-blue)](conformance/README.md)\n[![Tests](https://img.shields.io/badge/tests-571%20passing-brightgreen)](#testing)\n[![Hardening](https://img.shields.io/badge/hardening-65%2F66%20documented%20(K.3%20open)-yellowgreen)](docs/security/HARDENING_CHECKLIST.md)\n\n---\n\n## See your wasted AI spend in 60 seconds\n\nNo instrumentation, no signup, nothing leaves your machine, point it at a usage\nexport you already have:\n\n```bash\n# 1. Export your usage as JSON:\n#      OpenAI    → platform.openai.com/usage → Export\n#      Anthropic → console.anthropic.com/settings/usage → Export\n# 2. Scan it:\nnpx @askledger/receipts-sdk scan ~/Downloads/usage.json\n```\n\nYou get a per-model spend breakdown and an over-tiering savings estimate, split\ninto **confident** (safe, same-family swaps) and **review** (heavy-context or\ncross-family, test a sample first). The confident number is the one we'd stake\nour name on. Then instrument your app to make the tracking continuous and the\nsavings **signed and verifiable**: that is the paid tier.\n\n---\n\n## Project status\n\n**v0.12 · live on npm.** The cryptographic core is hardened and\nindependently verifiable, shared conformance vectors enforce\nbyte-identical RFC 8785 canonicalization and SHA-256 across the\nTypeScript, Python, Go, Rust and Java SDKs, and a documented hardening\nchecklist is checked in CI. SDK,\nintegrations, browser extension, console, public verifier, specification,\nand conformance program are publicly available. A third-party\npenetration test and SOC 2 Type II report are scoped for Q4 2026 - Q1\n2027, and the hosted SaaS is in development. We are at the\n**design-partner stage** and welcome architectural review, pilot\ninterest, and standards-body co-authorship.\n\n- Package: [npm install @askledger/receipts-sdk](https://www.npmjs.com/package/@askledger/receipts-sdk)\n- Site: [askledger.org](https://askledger.org)\n- Source: [github.com/askledger/receipts-sdk](https://github.com/askledger/receipts-sdk)\n- Contact: [hello@askledger.org](mailto:hello@askledger.org)\n\n---\n\n## The five layers\n\nAskLedger is a five-layer model. Layers 1 to 4 are the cryptographic proof engine; layer 5 is the governance and ROI program built on top. **Every layer below ships in this SDK and is exported from the public API.**\n\n| Layer | What it does | Public API in this SDK |\n|---|---|---|\n| **L1 · Prevent** | Pre-execution guardian: an independent verdict (`approve` / `concerns` / `reject`) before an irreversible action, signed under its own key and bound to the exact action, so \"approve A, run B\" fails. Supports N-of-M review. | `signPreVerdict`, `verifyPreVerdict`, `assertActionCleared`, `reviewNofM` |\n| **L2 · Prove** | Cryptographic evidence: a signed, hash-chained receipt per AI action (Ed25519, RFC 8785 canonical JSON, RFC 3161 timestamp), independently verifiable with only a public key. | `signReceipt`, `verifyReceipt`, `verifyChain` |\n| **L3 · Trace** | Execution traceability: reconstruct and verify a multi-step workflow from its receipts, and group many receipts into one Merkle evidence bundle. | `reconstructWorkflow`, `verifyWorkflow` |\n| **L4 · Assure** | Rule-based assurance: classify each receipt on the L0–L3 ladder (Declared / Signed / Attested / Anchored) and check governing rules, computed from the evidence, not asserted. | `assuranceLevel`, `checkRules` |\n| **L5 · Govern** | Governance & ROI: turn the evidence chain into verified savings against a signed baseline, plus compliance-ready reporting. | `buildBaseline`, `proveSavings`, `verifyBaseline` |\n\nLayers 1 to 4 are cryptographically verifiable and open source here; layer 5's hosted governance, regulator portal, and evidence packs are the commercial layer (open-core).\n\n---\n\n## Install\n\n```bash\nnpm install @askledger/receipts-sdk\n```\n\nOr install from source:\n\n```bash\ngit clone https://github.com/askledger/receipts-sdk\ncd receipts-sdk\nnpm install\nnpm run build\n```\n\n## Sign your first receipt\n\n```ts\nimport { generateKeyPair, signReceipt, verifyReceipt } from \"@askledger/receipts-sdk\";\n\nconst keypair = generateKeyPair();\nconst receipt = signReceipt({\n  event: {\n    schema_version: \"1.0\",\n    tenant_id: \"acme\",\n    event_type: \"gateway.request\",\n    source_system: \"my-app\",\n    event_id: \"evt-001\",\n    captured_at: new Date().toISOString(),\n    subject: { ai_vendor: \"anthropic\", ai_model: \"claude-sonnet-4-6\" },\n    payload: { input_classification: \"internal\", output_classification: \"internal\" },\n  },\n  keypair,\n});\n\nconst result = verifyReceipt(receipt, {\n  publicKeys: { [keypair.kid]: keypair.public_key },\n});\nconsole.log(result.valid); // true\n```\n\nThat's it. Six lines and you have a regulator-verifiable receipt.\n\n## Wrap your AI vendor\n\n```ts\nimport OpenAI from \"openai\";\nimport { wrapOpenAI, generateKeyPair } from \"@askledger/receipts-sdk\";\n\nconst client = wrapOpenAI(new OpenAI({ apiKey }), {\n  tenantId: \"acme\",\n  keypair: generateKeyPair(),       // production: HSM-backed\n  onReceipt: async (r) => store.append(r),\n});\n\n// Your application code is unchanged.\nconst resp = await client.chat.completions.create({ model: \"gpt-5\", messages });\nconsole.log(resp.x_ledger_receipt_id);   // cryptographic evidence id\n```\n\nAdapters available today: `wrapOpenAI` · `wrapAnthropic` · `withReceipts(fetch)` (covers 11 vendors) · `ReceiptsCallbackHandler` for LangChain.\n\n## Try it without installing\n\n```bash\ngit clone https://github.com/askledger/receipts-sdk.git && cd receipts-sdk\nnpm install && npm run build\nnode dist/cli.js demo\n```\n\nYou'll see output like:\n\n```\n────────────────────────────────────────────────────────────────────────\nAskLedger, Receipts SDK · Demo\n────────────────────────────────────────────────────────────────────────\n\n1. Generating Ed25519 keypair…\n   kid: dev-3a7c9b2e8f4a\n\n2. Signing a sample AI event…\n   receipt_id:   01HXYZ123ABC...\n   receipt_hash: 9a4f8e0c2b1d3a6c...\n   chain_height: 1\n\n3. Verifying receipt independently (no Ledger server needed)…\n   ✓ canonical hash matches\n   ✓ Ed25519 signature valid\n\n✓ RECEIPT VALID\n```\n\nThat's it. The receipt is in `.ledger/last-receipt.json`. The keypair is in `.ledger/keys/default.json`. The chain state is in `.ledger/chains/`. **None of this required a network call to AskLedger.** A regulator verifying this receipt only needs the public key.\n\n---\n\n## How a receipt looks\n\n```json\n{\n  \"receipt\": {\n    \"schema_version\": \"1.0\",\n    \"receipt_id\": \"01HXYZ123ABC...\",\n    \"tenant_id\": \"demo-tenant\",\n    \"issued_at\": \"2026-05-13T10:30:00.123456789Z\",\n    \"event\": {\n      \"schema_version\": \"1.0\",\n      \"event_type\": \"ide.completion\",\n      \"source_system\": \"vs-code-plugin\",\n      \"captured_at\": \"2026-05-13T10:30:00.000Z\",\n      \"subject\": {\n        \"ai_vendor\": \"anthropic\",\n        \"ai_model\": \"claude-sonnet-4-6\",\n        \"ai_capability\": \"code-completion\"\n      },\n      \"payload\": {\n        \"input_hash\": \"9a4f8e0c2b1d3a6c...\",\n        \"input_classification\": \"internal\",\n        \"input_token_count\": 245\n      }\n    },\n    \"integrity\": {\n      \"previous_receipt_hash\": \"0000...0000\",\n      \"receipt_hash\": \"9a4f8e0c2b1d3a6c...\",\n      \"chain_height\": 1\n    }\n  },\n  \"signatures\": [\n    {\n      \"alg\": \"EdDSA\",\n      \"kid\": \"dev-3a7c9b2e8f4a\",\n      \"sig\": \"base64-encoded-Ed25519-signature...\"\n    }\n  ]\n}\n```\n\nEvery field is part of the canonical hash. Any modification to any field, including reordering keys, breaks the signature.\n\n### Optional: `evidence_refs`\n\nA receipt **MAY** carry an optional top-level `evidence_refs` array that references external evidence or attestation artifacts by digest (the artifact itself is never embedded). It is strictly additive, receipts without it sign and verify exactly as before, and when present it is part of the canonical bytes, so it is covered by both `integrity.receipt_hash` and the signature.\n\n```json\n\"evidence_refs\": [\n  {\n    \"kind\": \"attestation\",\n    \"hash\": \"3b1f...c9\",\n    \"alg\": \"sha256\",\n    \"uri\": \"https://evidence.example.com/artifacts/3b1f...c9\",\n    \"status\": \"pass\"\n  }\n]\n```\n\nOnly `kind` and `hash` are required per entry; `alg`, `uri`, and `status` are optional. Pass it via `signReceipt({ event, keypair, evidenceRefs: [...] })`.\n\n---\n\n## Programmatic usage\n\n```typescript\nimport {\n  generateKeyPair,\n  signReceipt,\n  verifyReceipt,\n} from \"@askledger/receipts-sdk\";\n\n// 1. Generate (or load) a keypair\nconst kp = generateKeyPair();\n\n// 2. Sign an AI event\nconst signed = signReceipt({\n  event: {\n    schema_version: \"1.0\",\n    tenant_id: \"tenant-001\",\n    event_type: \"ide.completion\",\n    source_system: \"vs-code-plugin\",\n    event_id: \"evt-123\",\n    captured_at: new Date().toISOString(),\n    subject: {\n      ai_vendor: \"anthropic\",\n      ai_model: \"claude-sonnet-4-6\",\n      ai_capability: \"code-completion\",\n    },\n  },\n  keypair: kp,\n});\n\n// 3. Anyone can verify with just the public key\nconst result = verifyReceipt(signed, {\n  publicKeys: { [kp.kid]: kp.public_key },\n});\n\nconsole.log(result.valid); // true\n```\n\n---\n\n## CLI reference\n\nThe CLI ships as a `bin`, so once the package is published you can run it\ndirectly with `npx`, no clone or build required:\n\n```bash\n# Verify a receipt against a public key (published form)\nnpx @askledger/receipts-sdk verify receipt.json\n\n# ...same for every subcommand\nnpx @askledger/receipts-sdk keygen --out .ledger/keys/default.json\nnpx @askledger/receipts-sdk sign examples/event.json\nnpx @askledger/receipts-sdk demo\n```\n\n> The `npx @askledger/receipts-sdk …` form works from the published package\n> (this `bin` ships with **0.8.0**). If you are working from a local clone,\n> build first (`npm run build`) and use the `node dist/cli.js …` form below.\n\n```bash\n# Generate a keypair (HSM-backed in production; JSON file in dev)\nnode dist/cli.js keygen --out .ledger/keys/default.json\n\n# Sign an event (auto-chains per tenant)\nnode dist/cli.js sign examples/event.json\n\n# Verify a receipt against a public key\nnode dist/cli.js verify .ledger/last-receipt.json\n\n# Verify chain continuity to a previous receipt\nnode dist/cli.js verify .ledger/last-receipt.json --prev .ledger/prev.json\n\n# Full demo cycle\nnode dist/cli.js demo\n```\n\n### End-to-end: keygen → sign → verify → bundle → verify-bundle\n\nThe CLI drives all three layers by hand, one keypair, a signed chain, and a\nsingle verifiable evidence bundle:\n\n```bash\n# 1) Key\nnode dist/cli.js keygen --out keys.json\n\n# 2) Sign, optionally BIND an external correctness proof (Layer 4, repeatable).\n#    file=<path> is read and SHA-256-hashed for you; or pass hash=<hexdigest>.\nnode dist/cli.js sign examples/event.json --key keys.json --out r1.json \\\n  --evidence-ref \"kind=rule-check,file=./rule-report.json,status=pass\"\nnode dist/cli.js sign examples/event.json --key keys.json --out r2.json\n\n# 3) Verify a single receipt (reports any attached evidence_refs)\nnode dist/cli.js verify r1.json --key keys.json\n\n# 4) Bundle many receipts into one Merkle-rooted evidence bundle.\n#    Accepts multiple single-receipt files OR one array-of-receipts file.\nnode dist/cli.js bundle r1.json r2.json --out bundle.json --title \"Q3 Evidence\"\n\n# 5) Verify the bundle: pack integrity + inclusion + (with --key) signatures.\n#    Exits non-zero on any failure.\nnode dist/cli.js verify-bundle bundle.json --key keys.json\n\n# 6) See what it all cost, a local, single-tenant usage & cost dashboard\n#    built from your own signed receipts (scans .ledger/ by default).\nnode dist/cli.js dashboard\nnode dist/cli.js dashboard --html   # writes a self-contained HTML report\n```\n\n**Three layers, one CLI:**\n\n- **Integrity**: `sign` / `verify` (RFC 8785 hash chain + Ed25519). The receipt is authentic and untampered.\n- **Traceability**: `bundle` / `verify-bundle` (Merkle evidence bundle). Many receipts → one artifact with a single root hash.\n- **Correctness**: `sign --evidence-ref` binds an **external** proof's digest into the signed body.\n\n> **Honest scope:** the SDK **binds** an external correctness proof into the signed\n> receipt (its digest is covered by the signature). It does **not** perform formal\n> verification, the proof is produced by an external prover; the SDK makes it\n> tamper-evident and auditable. An *evidence bundle* and an *evidence pack* are the\n> same artifact (the `buildEvidenceBundle` / `buildEvidencePack` API names are aliases).\n\n### See your spend & savings, the free local dashboard\n\n`dashboard` turns the receipts you already signed into the numbers a team wants\non day one, no account, no network, no hosted service:\n\n```bash\nnode dist/cli.js dashboard [paths...]   # defaults to scanning .ledger/\nnode dist/cli.js dashboard --html [path]\n```\n\n- **Spend & usage**: estimated cost, requests, tokens, and per-model / per-app\n  breakdowns, computed locally from the built-in pricing table.\n- **Savings opportunities**: flags *over-tiered* workloads (a premium model\n  doing short, simple calls) grouped by (model × application), and quantifies\n  each with an **exact counterfactual**: the same recorded calls repriced on the\n  cheaper same-vendor tier. It nudges only light workloads, so the big model\n  keeps the heavy, high-value calls.\n- **Integrity**: how many receipts are signed, the chain height, and how many\n  carry correctness bindings.\n\n> **Honest scope:** cost is an **estimate** from your instrumented receipts and\n> the local pricing table, not a bill. Unknown models are counted but excluded\n> and flagged, never guessed. This is single-tenant and blind to un-instrumented\n> (\"shadow\") AI; the savings figures are heuristic hints to **test**, not a\n> promise. Cross-system discovery, billing ingestion, and **verified savings**\n> (baseline → signed proof) are the hosted AskLedger platform.\n\n### Ask your receipts, natural-language query & alerts\n\nAsk a question in plain English and get an answer grounded in real receipts,\nevery result cites the receipt ids it came from, so it's checkable, never\ninvented:\n\n```bash\nnode dist/cli.js query \"how much did we spend by model?\"\nnode dist/cli.js query \"show the blocked loan decisions\"\nnode dist/cli.js query \"anything with pii?\"            # routes to alerts\nnode dist/cli.js query \"gpt-5 calls over $0.05 last week\" --llm   # free-form\nnode dist/cli.js alerts                                # flag the critical stuff\n```\n\n- **`query`**: an offline, deterministic parser handles common questions for\n  free (filter / count / aggregate over model, app, decision, time, cost and\n  token thresholds, sensitive data, evidence and signature state). `--llm`\n  handles free-form phrasing, the model only turns your words into a query; the\n  data always comes from signed receipts. It's **provider-neutral**: the CLI's\n  `--llm` uses `@anthropic-ai/sdk` (optional dep) + `ANTHROPIC_API_KEY` by\n  default, but programmatically you can plug in **any** model by passing a\n  `complete` function:\n\n  ```ts\n  import { parseQueryLLM, runQuery } from \"@askledger/receipts-sdk\";\n\n  const q = await parseQueryLLM(\"blocked loan decisions on opus last week\", {\n    complete: async ({ system, prompt }) => callYourModel(system, prompt), // OpenAI, Gemini, local, …\n  });\n  const result = runQuery(receipts, q); // grounded + cited, as always\n  ```\n- **`alerts`**: an explainable rules engine that flags what's worth a look:\n  blocked/denied decisions, sensitive data (pii/pci/mnpi), unsigned records,\n  high-stakes decisions with no bound evidence, over-tiering, and cost spikes.\n  Each alert names the exact receipt ids behind it. Ships honest defaults; add\n  your own rules programmatically via `runAlerts(receipts, { extraRules })`.\n\n> **Honest scope:** the NL layer decides *which* receipts to show and how to\n> summarize them, it never asserts anything the receipts don't already say, and\n> it reports how it interpreted the question. Local and single-tenant; hosted,\n> real-time, cross-system query and alerting is the enterprise tier.\n\n---\n\n## How it works · the cryptographic design\n\n| Layer | Choice | Why |\n|---|---|---|\n| **Canonicalization** | [RFC 8785 (JCS)](https://datatracker.ietf.org/doc/html/rfc8785) | Deterministic JSON byte representation. Independent verifiers compute identical hashes from identical data. The foundational requirement for regulator-independent verification. |\n| **Hashing** | SHA-256 | Standard, audited, well-understood security margin. |\n| **Signing** | Ed25519 ([EdDSA](https://datatracker.ietf.org/doc/html/rfc8032)) | Fast (~70µs/sig), deterministic (no random nonce reuse risk), used by Signal, WireGuard, Sigstore. |\n| **Encoding** | [JWS](https://datatracker.ietf.org/doc/html/rfc7515) base64 | Standard, parseable across platforms. |\n| **Chain** | Per-tenant append-only hash chain | Each receipt's `previous_receipt_hash` is SHA-256 of the prior receipt's canonical bytes. Tampering with any historical receipt breaks every subsequent one. |\n| **ID generation** | UUIDv7 | Sortable, embedded timestamp, collision-resistant. |\n| **Post-quantum readiness** | Hybrid signature scheme planned for v2 (Ed25519 + Dilithium) | Practical quantum threats are 8–12 years out; retention is 7–10 years. Migration plan documented. |\n\n**Implementation libraries:**\n- [`@noble/ed25519`](https://github.com/paulmillr/noble-ed25519), audited pure-TypeScript Ed25519\n- [`@noble/hashes`](https://github.com/paulmillr/noble-hashes), audited hashing\n- [`canonicalize`](https://www.npmjs.com/package/canonicalize), RFC 8785 implementation\n\n---\n\n## Standards & compatibility\n\nThis SDK composes with rather than competes against the standards already used in software supply-chain security:\n\n| Standard | Relationship |\n|---|---|\n| [Sigstore Model Signing (OMS)](https://github.com/sigstore/model-transparency) | Used for model identity verification within receipts |\n| [in-toto Attestation Framework (ITE-6)](https://github.com/in-toto/attestation) | Envelope format reference for provenance claims |\n| [SLSA](https://slsa.dev/) | Build-time attestation reference; receipts cover runtime |\n| [OpenTelemetry GenAI Semantic Conventions](https://opentelemetry.io/docs/specs/semconv/gen-ai/) | Event field alignment |\n| [OWASP AIBOM](https://owaspaibom.org/) | AI Bill of Materials populated from receipts |\n| [SPIFFE/SPIRE](https://spiffe.io/) | Workload identity for service-to-service calls |\n\nWe are not reinventing the cryptographic primitives. We are composing them into a layer specifically for **AI runtime accountability**: which none of the existing standards target.\n\n---\n\n## Roadmap\n\n### Shipped\n- Five language implementations, one wire format: TypeScript on npm; Python, Go, Rust and Java from source, all cross-verified against shared conformance vectors\n- The full five-layer model (see [The five layers](#the-five-layers)), prevent-first: L1 a pre-execution guardian (prevents the wrong action), L2 cryptographic evidence (proves what), L3 execution traceability (proves how), L4 rule-based assurance (proves why), and L5 governance and verified ROI (proves the value). Layers 1 to 4 are the open cryptographic proof engine; all are exported from the SDK\n- RFC 3161 timestamping, Merkle commitments and a transparency log, and HSM/KMS signing (AWS KMS, Azure Key Vault, GCP KMS, PKCS#11)\n- Verified savings (sign a baseline, prove the realized saving, verify it) and zero-instrumentation spend scan\n- Browser playground and verifier, plus SLSA provenance and a CycloneDX SBOM on every release\n\n### Next\n- Publish the Python, Rust and Java SDKs to their registries (PyPI, crates.io, Maven Central)\n- Transparency-log connector (Rekor)\n- Bridge to OpenTelemetry GenAI conventions\n- Customer-managed-key reference deployments\n\n### Toward v1.0\n- Stable wire format with versioning guarantees\n- Linux Foundation AI hosted standard\n- A third-party verifier ecosystem\n\n---\n\n## Try it without installing\n\nA browser-based playground and verifier ship in this repository at\n[`site/playground.html`](site/playground.html) and\n[`site/verify.html`](site/verify.html). Open either file in a browser\nto generate a keypair, sign a sample event, and verify the resulting\nreceipt, entirely client-side, no server, no install.\n\nA hosted version is live at\n[askledger.github.io/receipts-sdk/playground.html](https://askledger.github.io/receipts-sdk/playground.html).\n\n---\n\n## Documentation\n\n| Document | What's inside |\n|---|---|\n| [**Receipts Protocol Spec v0.1**](docs/RECEIPTS_PROTOCOL.md) | The formal envelope, schema, hashing and verification rules, IETF-style. Candidate for Linux Foundation AI hosting. |\n| [**Architecture**](docs/ARCHITECTURE.md) | Layered overview, file-by-file walk-through, design decisions, performance numbers. |\n| [**Examples folder**](examples/README.md) | End-to-end integration patterns. |\n| [**Python SDK**](python-sdk/README.md) | Wire-format compatible Python implementation. |\n| [**Conformance vectors**](test/conformance/README.md) | Shared cross-language test vectors. Any new SDK passes conformance by matching these byte-for-byte. |\n| [**CHANGELOG**](CHANGELOG.md) | Version history + roadmap to v1.0. |\n| [**Contributing**](CONTRIBUTING.md) | How to build, test, propose changes. |\n| [**Security policy**](SECURITY.md) | How to report vulnerabilities. |\n\n---\n\n## Auto-capture adapters, supporting any AI tool\n\nThe SDK ships drop-in capture adapters so every AI invocation in your stack emits a signed receipt without changing application code.\n\n| Adapter | What it wraps | One-liner |\n|---|---|---|\n| `wrapOpenAI(client, ctx)` | The official `openai` SDK and any OpenAI-compatible provider (LiteLLM, Groq, Together, Mistral OpenAI-compat, DeepSeek, Anyscale) | Wraps `chat.completions.create` + `embeddings.create` |\n| `wrapAnthropic(client, ctx)` | The official `@anthropic-ai/sdk` | Wraps `messages.create` |\n| `withReceipts(ctx)` | Any global `fetch` | Detects calls to OpenAI, Azure OpenAI, Anthropic, Google Gemini, Bedrock, Cohere, Hugging Face, Mistral, Groq, Together, Vercel AI Gateway. Custom endpoints via `extraPatterns`. |\n| `ReceiptsCallbackHandler` | LangChain.js | Implements `BaseCallbackHandler` surface; drop into any chain or agent |\n\nPattern:\n\n```ts\nimport OpenAI from \"openai\";\nimport { wrapOpenAI, generateKeyPair } from \"@askledger/receipts-sdk\";\n\nconst client = wrapOpenAI(new OpenAI({ apiKey }), {\n  tenantId: \"acme-corp\",\n  keypair: generateKeyPair(),\n  onReceipt: async (r) => store.append(r),  // ship to durable store\n});\n\n// Application code is unchanged\nconst resp = await client.chat.completions.create({...});\nconsole.log(resp.x_ledger_receipt_id);   // cryptographic evidence id\n```\n\nErrors from the wrapped client always propagate, receipts never take down the AI call they instrument.\n\n---\n\n## Evidence export · SIEM connectors\n\nYour SIEM stores logs your own systems wrote, mutable and self-attested. Receipts make what lands there **provable**. Push signed receipts into the platform your analysts and auditors already use; they remain independently verifiable after they arrive.\n\nShips with sinks for **Splunk HEC**, **syslog/CEF** (QRadar, ArcSight), a **generic webhook** (Microsoft Sentinel, Elastic, Chronicle, in-house pipelines), and a **JSONL file / object-storage drop** (the universal fallback every SIEM can ingest).\n\n```ts\nimport {\n  exportReceipts, SplunkHecSink, SyslogSink, WebhookSink, FileSink,\n} from \"@askledger/receipts-sdk\";\n\nconst report = await exportReceipts(receipts, {\n  sinks: [\n    new SplunkHecSink({ url: \"https://splunk.internal:8088\", token: process.env.HEC_TOKEN!, index: \"ai_evidence\" }),\n    new SyslogSink({ host: \"qradar.internal\", format: \"cef\" }),   // CEF for QRadar / ArcSight\n    new WebhookSink({ url: \"https://sentinel.internal/ingest\" }),\n    new FileSink({ path: \"/var/log/askledger/receipts.jsonl\" }),\n  ],\n  includeAssurance: true,  // attach the L0–L3 grade\n  includeReceipt: true,    // embed the signed receipt so the SIEM record stays verifiable\n  batchSize: 200,\n});\n\nreport.results; // per-sink delivery outcome; one failing sink never blocks the others\n```\n\n**Privacy by default:** the raw event payload (business data) is **excluded** unless you set `includePayload`. **Operator-configured only:** there is no default endpoint and the SDK never transmits anything you have not configured.\n\n---\n\n## Multi-language\n\n| SDK | Language | Status | Conformance |\n|---|---|---|---|\n| `@askledger/receipts-sdk` | TypeScript / Node 18+ / browsers | live on npm · 575 tests (571 pass, 4 HSM-live skipped) | Reference |\n| `askledger-receipts` (Python, import `askledger.receipts`) | Python 3.10+ | From source (not yet on PyPI) · cross-verified against TS vectors | Cross-verified |\n| `github.com/askledger/receipts-sdk/go-sdk` | Go 1.22+ | `go get` (git-based) · cross-verified against TS vectors | Cross-verified |\n| `askledger-receipts` (Rust crate) | Rust 1.75+ | From source (git dep, not yet on crates.io) · cross-verified against TS vectors | Cross-verified |\n| `org.askledger:receipts-sdk` (Java) | Java 17+ | From source (not yet on Maven Central) · cross-verified against TS vectors | Cross-verified |\n\nWire-format compatibility is enforced by [shared conformance vectors](test/conformance/) that every SDK must pass.\n\n---\n\n## Production hardening modules\n\nThese are the v0.2 surface that turns the reference SDK into a production-deployable substrate.\n\n| Module | What it provides | When you need it |\n|---|---|---|\n| `SoftwareSigningProvider` | In-memory Ed25519 keys | Dev, browser playground, SMB |\n| `HSMSigningProvider` | Interface for PKCS#11 / AWS CloudHSM / Azure Key Vault / GCP KMS | Regulated BFSI, FIPS-required deployments |\n| `TSAClient` (RFC 3161) | Real RFC 3161 TimeStampReq encoder + network client (default: FreeTSA; commercial TSAs via Basic Auth) | When you need independently provable \"when this was signed\" |\n| `buildBatch` / `verifyInclusion` (Merkle) | SHA-256 binary Merkle tree with inclusion proofs (RFC 9162 leaf/internal prefix scheme, second-preimage safe) | Batch commitment to a transparency log; prove a single receipt belonged to the committed set |\n| `PostgresChainStateStore` | Postgres backend for chain state with CAS concurrency, row-level security pattern | SaaS multi-tenant deployments past single-process |\n| `MemoryChainStateStore` | In-process backend | Tests, serverless |\n| `KeyRegistry` | Key rotation, retirement, revocation, historical-time-window-aware trusted set | Long-lived issuers (key rotation every 90 days per NIST SP 800-57) |\n\n---\n\n## Performance\n\nMeasured numbers from `npm run bench` (5000 iterations after warmup, Node 22, sandboxed Linux/arm64):\n\n| Operation | p50 | p95 | p99 |\n|---|---|---|---|\n| `canonicalize` (RFC 8785) | 5.4 µs | 7.7 µs | 13.2 µs |\n| `sha256` (canonical bytes) | 6.7 µs | 11.3 µs | 22.5 µs |\n| Ed25519 sign | 425 µs | 551 µs | 662 µs |\n| Ed25519 verify | 1.78 ms | 1.96 ms | 2.06 ms |\n| `signReceipt` end-to-end | 1.64 ms | 2.13 ms | 2.47 ms |\n| `verifyReceipt` end-to-end | 1.91 ms | 2.13 ms | 2.26 ms |\n\nNote: Ed25519 numbers reflect pure-TypeScript `@noble/ed25519` (zero native dependencies, audited). When deployed against a native libsodium binding or HSM, signing drops to ~70 µs. The dominant cost in `signReceipt` is canonicalization + file I/O for chain state, production deployments swap the file backend for Postgres + HSM and stay well within an enterprise gateway's latency budget.\n\n---\n\n## Ecosystem · related open-source projects\n\nAskLedger is not the only effort in cryptographic AI receipts. The following projects address overlapping problems and we acknowledge them openly:\n\n| Project | Focus area |\n|---|---|\n| [Sigstore Model Signing (OMS)](https://github.com/sigstore/model-transparency) | Build-time model artifact signing |\n| [in-toto](https://in-toto.io/) / [SLSA](https://slsa.dev/) | Build pipeline attestation |\n| [OWASP AIBOM](https://owaspaibom.org/) | AI Bill of Materials |\n| [OpenTelemetry GenAI](https://opentelemetry.io/docs/specs/semconv/gen-ai/) | Runtime telemetry conventions |\n| AgentMint, OrgKernel, Pipelock, ArkForge, Garl Protocol, AEGIS, Nono | Independent receipts/audit SDKs (various states of completeness) |\n\n**How we differentiate.** This SDK focuses on the **runtime AI decision receipt**: the cryptographic envelope that binds a single AI event to a tenant, a policy, a model identity, and a hash-chained position. We compose with build-time attestation (Sigstore, in-toto, SLSA), with the OWASP AIBOM, and with OpenTelemetry GenAI semantic conventions. The commercial AskLedger platform layers a verifier model, a regulator portal, evidence packs, and BFSI-MENA-specific framework mappings on top, open-core, Datadog / HashiCorp / Sentry pattern.\n\n---\n\n## Get involved\n\n- **GitHub Discussions**: questions, design proposals, use cases\n- **Issues**: bugs, enhancements, integration requests\n- **Pull Requests**: see [CONTRIBUTING.md](CONTRIBUTING.md)\n- **Security disclosures**: see [SECURITY.md](SECURITY.md) (private channel)\n\nWe are particularly interested in feedback from:\n- Bank CISOs and Chief Risk Officers preparing for CBUAE / SAMA / EU AI Act inspections\n- Auditors building AI evidence-collection methodologies\n- Standards body participants (OpenSSF, CNCF, LF AI, IETF)\n- Cryptographers reviewing the protocol design\n\n---\n\n## Honest production-readiness checklist · v0.12\n\n| Capability | Status |\n|---|---|\n| **Substrate** | |\n| RFC 8785 canonical JSON | ✅ Shipped, conformance-tested across 5 languages |\n| Ed25519 signing | ✅ Shipped (`@noble/ed25519`, `cryptography`, stdlib, `ed25519-dalek`, Bouncy Castle) |\n| SHA-256 | ✅ Shipped |\n| Per-tenant hash chain | ✅ Shipped, tamper-tested + fuzzed |\n| Independent third-party verifier | ✅ Shipped |\n| Receipts Protocol Spec v0.1 | ✅ Shipped, IETF-style |\n| Input validation + structured errors | ✅ Shipped |\n| **Tests** | |\n| 571 TypeScript tests | ✅ Passing (4 HSM-live skipped without hardware) |\n| 48 Python tests | ✅ Passing (conformance vectors, parametrized) |\n| 3 Go conformance tests | ✅ Passing |\n| Rust tests | ✅ Code shipped; cargo runs in CI |\n| Java tests | ✅ Code shipped; mvn runs in CI |\n| Cross-language conformance vectors | ✅ Canonicalization (43) + SHA-256 (4). Signed-receipt and chained vectors are NOT yet frozen, so CL2/CL3 are unearned |\n| Fuzz harness (200 random mutations) | ✅ Shipped |\n| **Crypto hardening** | |\n| RFC 3161 timestamping client (FreeTSA + commercial TSA) | ✅ Shipped |\n| Merkle batch commitments (RFC 9162 second-preimage safe) | ✅ Shipped, inclusion proofs |\n| Key rotation, retirement, revocation, historical verification | ✅ Shipped |\n| FIPS-mode crypto path (`FipsSigningProvider`, `requireFipsMode`) | ✅ Shipped |\n| **HSM / KMS** | |\n| AWS KMS driver | ✅ Shipped (`@askledger/receipts-sdk/hsm/aws-kms`) |\n| Azure Key Vault driver | ✅ Shipped |\n| GCP KMS driver | ✅ Shipped |\n| PKCS#11 driver (Thales, Entrust, CloudHSM, YubiHSM) | ✅ Shipped |\n| **Multi-language SDKs (wire-format compatible)** | |\n| TypeScript | ✅ Reference |\n| Python | ✅ Shipped |\n| Go | ✅ Shipped |\n| Rust | ✅ Shipped |\n| Java | ✅ Shipped |\n| **Scale + storage** | |\n| Postgres chain backend with CAS + RLS pattern | ✅ Shipped |\n| Memory chain store (tests + serverless) | ✅ Shipped |\n| Multi-tenant isolation | ✅ Shipped |\n| **Auto-capture** | |\n| OpenAI + 8 OpenAI-compatible providers | ✅ Shipped |\n| Anthropic | ✅ Shipped |\n| Generic fetch (11 vendors) | ✅ Shipped |\n| LangChain.js | ✅ Shipped |\n| **Zero Trust** | |\n| ZTA reference architecture document (NIST SP 800-207 aligned) | ✅ Shipped |\n| SPIFFE workload identity helpers | ✅ Shipped |\n| OPA decision client (decisions-as-receipts) | ✅ Shipped |\n| **Workflows** | |\n| Receipt pipeline (capture → policy → sign → TSA → persist → notify) | ✅ Shipped |\n| Approval workflow (N-of-M, expiry) | ✅ Shipped |\n| Evidence pack builder (Merkle batch + integrity hash) | ✅ Shipped |\n| **Enterprise UI** | |\n| Admin console (Next.js 14, App Router) | ✅ Shipped |\n| Design system (WCAG 2.2 AA, RTL, dark mode, design tokens) | ✅ Shipped |\n| Dashboard / Receipts Explorer / Policies / Keys / Workflows / Evidence / Tenants / Audit / Settings | ✅ All 9 pages shipped |\n| **Audit-ready artifacts** | |\n| Threat model (STRIDE + LINDDUN) | ✅ Shipped |\n| SOC 2 Trust Services Criteria control map | ✅ Shipped |\n| Zero Trust architecture doc | ✅ Shipped |\n| Design system spec | ✅ Shipped |\n| **Supply chain** | |\n| CycloneDX 1.5 SBOM | ✅ Shipped |\n| npm provenance publishing | ✅ Wired |\n| Sigstore Cosign image signing | ✅ Documented |\n| **Third-party gates (require external firms)** | |\n| External cryptographic audit (Trail of Bits / NCC Group / Cure53) | 🔴 Code + threat model ready; commissioning ~$80–120K, 4 weeks |\n| SOC 2 Type II report | 🔴 Control framework + evidence map ready; commission a CPA firm + 12 months of evidence |\n| NIST CMVP FIPS 140-3 validation | 🔴 Provider-delegated via AWS/Azure/GCP/Thales; no SDK-side certification needed |\n| **Future** | |\n| Quantum-resistant hybrid signatures (Ed25519 + Dilithium) | 🔴 v2.0 protocol revision |\n| Transparency log integration (Rekor) | 🟡 Merkle in place; log connector v0.4 |\n\nRows marked 🔴 require external parties (audit firms, CPA firms). The code and the audit-ready artifacts are shipped, what remains is hiring the firms and running their engagements.\n\n---\n\n## Citing this work\n\nIf you reference this protocol or implementation in research or industry writing:\n\n```\nAskLedger. (2026). AskLedger Receipts SDK:\nCryptographic AI Decision Receipts for enterprise AI.\nhttps://github.com/askledger/receipts-sdk\n```\n\n---\n\n## License\n\n[Apache-2.0](LICENSE).\n\nThe open-source license is deliberate: receipts are a moat through adoption, not lock-in. The commercial layer of AskLedger (verifier model, regulator portal, evidence packs, vendor benchmark data) is proprietary. **The protocol substrate is open.**\n\n---\n\n## Maintainers + governance\n\nSee [`MAINTAINERS.md`](MAINTAINERS.md) for the current maintainer list\nand the technical-steering-committee governance model. The project is\nunder multi-stakeholder governance preparation; we welcome\ncontributions from individuals and organisations who want a seat at\nthe standards table.\n\n**Contact**\n\n- General questions →\n  [GitHub Discussions](https://github.com/askledger/receipts-sdk/discussions)\n- Bug reports →\n  [GitHub Issues](https://github.com/askledger/receipts-sdk/issues)\n- Security disclosures →\n  [private GitHub Security Advisory](https://github.com/askledger/receipts-sdk/security/advisories/new)\n  (see [`SECURITY.md`](SECURITY.md))\n","readmeFilename":"README.md"}