{"_id":"@asqav/vercel-ai","name":"@asqav/vercel-ai","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@asqav/vercel-ai","version":"0.1.0","description":"Asqav guard for the Vercel AI SDK - sign and gate tool calls before they execute","keywords":["asqav","vercel-ai","ai-sdk","ai-governance","tool-calling","audit-trail"],"license":"MIT","author":{"name":"Asqav","email":"info@asqav.com"},"homepage":"https://asqav.com","repository":{"type":"git","url":"git+https://github.com/jagmarques/asqav-vercel-ai.git"},"type":"module","main":"dist/index.cjs","module":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"build":"tsup src/index.ts --format cjs,esm --dts --clean","prepare":"npm run build","test":"vitest run","lint":"tsc --noEmit"},"engines":{"node":">=18"},"dependencies":{"@asqav/sdk":"^0.8.0"},"devDependencies":{"@types/node":"^22.0.0","tsup":"^8.3.0","typescript":"^5.5.0","vitest":"^4.1.5"},"_id":"@asqav/vercel-ai@0.1.0","gitHead":"89749214788b96d484fe8d7ec6a2a35a93eb65e4","bugs":{"url":"https://github.com/jagmarques/asqav-vercel-ai/issues"},"_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-/zzN8aO038adN7/86Baz763plMXwkf6QjT9Ld62SAtwMXNaMKR/YXiqPHrIrycojkn+Tzb+agrGu5YK+hqTZkw==","shasum":"866c28d27814a3b01a433d681ec3a65a8b6e42f0","tarball":"https://registry.npmjs.org/@asqav/vercel-ai/-/vercel-ai-0.1.0.tgz","fileCount":7,"unpackedSize":21459,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDitKr4MSLiyWkLUOLYMiHa3OmVKmhZD5VtSEAR4wMF3QIhAM9MHdlFU0g/0y1B+y9kd8dKRwNLSyUr3ajUlLAgb+Je"}]},"_npmUser":{"name":"jagmarques","email":"joaoagm90@gmail.com"},"directories":{},"maintainers":[{"name":"jagmarques","email":"joaoagm90@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vercel-ai_0.1.0_1783781682628_0.8882922693639299"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-11T14:54:42.506Z","0.1.0":"2026-07-11T14:54:42.774Z","modified":"2026-07-11T14:54:42.944Z"},"maintainers":[{"name":"jagmarques","email":"joaoagm90@gmail.com"}],"description":"Asqav guard for the Vercel AI SDK - sign and gate tool calls before they execute","homepage":"https://asqav.com","keywords":["asqav","vercel-ai","ai-sdk","ai-governance","tool-calling","audit-trail"],"repository":{"type":"git","url":"git+https://github.com/jagmarques/asqav-vercel-ai.git"},"author":{"name":"Asqav","email":"info@asqav.com"},"bugs":{"url":"https://github.com/jagmarques/asqav-vercel-ai/issues"},"license":"MIT","readme":"<p align=\"center\">\n  <a href=\"https://asqav.com\"><img src=\"https://asqav.com/logo-text-white.png\" alt=\"Asqav\" width=\"150\"></a>\n</p>\n\n# @asqav/vercel-ai\n\nStop a rogue agent before it acts, and prove what it tried. This package guards [Vercel AI SDK](https://ai-sdk.dev) tool calls with Asqav. It signs the intended tool call before the tool's `execute` runs, and blocks the call when Asqav refuses. Every attempt becomes a tamper-evident receipt, signed server-side with NIST FIPS 204 ML-DSA-65. The agent never holds the signing key, so it cannot forge the record.\n\nAsqav governs the agents you wire through it. An agent that never routes through the governed path produces no receipt and is not detected.\n\nThis is a pre-execution gate. The guard runs at tool-execution time, signs `tool:start`, and throws when a call is refused so the tool never executes.\n\n## How it hooks in\n\nThe Vercel AI SDK defines a tool as `tool({ description, inputSchema, execute })`, where `execute` is `async (input, { toolCallId, messages, abortSignal }) => result`. The guard wraps `execute` only. It never touches your schema, so it works whether your `ai` version names the schema field `inputSchema` on v5 and v6 or `parameters` on v4. A tool with no `execute`, meaning a client-side or provider-executed tool, is returned unchanged.\n\nReferences, cold-verified:\n- [Tools foundation](https://ai-sdk.dev/docs/foundations/tools), covering `inputSchema` and `execute`\n- [Tool calling](https://ai-sdk.dev/docs/ai-sdk-core/tools-and-tool-calling), covering the `execute` second argument `toolCallId`, `messages`, and `abortSignal`\n\n## Install\n\nNot yet published to npm. Install from GitHub or a local path:\n\n```bash\nnpm install github:jagmarques/asqav-vercel-ai\n```\n\nOr clone and add as a local path dependency:\n\n```bash\ngit clone https://github.com/jagmarques/asqav-vercel-ai.git\n```\n\n```json\n{\n  \"dependencies\": {\n    \"@asqav/vercel-ai\": \"file:../asqav-vercel-ai\",\n    \"@asqav/sdk\": \"^0.5.5\"\n  }\n}\n```\n\n## Quick start\n\n```ts\nimport { generateText } from \"ai\";\nimport { openai } from \"@ai-sdk/openai\";\nimport { z } from \"zod\";\nimport { tool } from \"ai\";\nimport { init, Agent } from \"@asqav/sdk\";\nimport { wrapTools } from \"@asqav/vercel-ai\";\n\ninit({ apiKey: process.env.ASQAV_API_KEY! });\nconst agent = await Agent.create({ name: \"support-bot\" });\n\nconst refund = tool({\n  description: \"Refund a customer order\",\n  inputSchema: z.object({ orderId: z.string(), amount: z.number() }),\n  execute: async ({ orderId, amount }) => {\n    // your real refund call\n    return { refunded: amount, orderId };\n  },\n});\n\nconst result = await generateText({\n  model: openai(\"gpt-4o\"),\n  prompt: \"Refund order 1234 for 50 dollars\",\n  // Every tool call is signed before it runs. A refused call throws and\n  // the tool never executes.\n  tools: wrapTools({ refund }, { agent }),\n});\n```\n\n## Guard one tool\n\n```ts\nimport { asqavGuard } from \"@asqav/vercel-ai\";\n\nconst guarded = asqavGuard(refund, { agent, toolName: \"refund\" });\n```\n\n## Options\n\n`wrapTools(tools, options)` and `asqavGuard(tool, options)` accept:\n\n- `agent`, required: a pre-built Asqav `Agent` from `@asqav/sdk`.\n- `toolName`: the name on the signed receipt. `wrapTools` defaults to each tool's key.\n- `block`, defaulting to `true`: when a sign is refused, throw so the tool never runs. Set `false` for observe-only signing.\n- `preflight`: a custom `(actionType, input) => { allowed, reason }` check. Defaults to `agent.preflight`, which checks revocation, suspension, and active policies.\n- `failClosed`, defaulting to `false`: when a signing transport error occurs, block the tool. The default is fail-open so an unreachable Asqav never breaks a working agent. A real deny still blocks regardless.\n- `onError`: sink for signing transport errors. Defaults to `console.warn`.\n\n## How blocking works\n\nWhen the guard blocks, it throws `AsqavBlockedError`. The Vercel AI SDK surfaces a thrown `execute` as a failed tool result, so the model sees the block and can react. The receipt for the refused call records `policy_decision: \"deny\"`, giving you proof of what the agent tried.\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-972b86ec677a25fc0fa044642d86f627"}