{"_id":"@astrifer-ai/agent-os-management","name":"@astrifer-ai/agent-os-management","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@astrifer-ai/agent-os-management","version":"0.1.0","description":"TypeScript SDK for Astrifer Agent OS tenant management.","homepage":"https://am.astrifer.ai","license":"Apache-2.0","type":"module","sideEffects":false,"engines":{"node":">=18"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"build":"tsup --config tsup.config.ts","check":"npm run check:branding && npm run check:openapi && npm run check:metadata && npm run check:boundaries && npm run typecheck && npm test && npm run build && npm run check:surface","check:boundaries":"tsx ../../scripts/check-module-boundaries.ts","check:metadata":"tsx ../../scripts/check-package-metadata.ts --package management-sdk","check:openapi":"tsx scripts/gen-openapi.ts --check","check:surface":"tsx scripts/check-surface.ts --check","clean":"rm -rf dist coverage","gen:openapi":"tsx scripts/gen-openapi.ts","gen:surface":"tsx scripts/check-surface.ts","lint":"biome check .","pack:dry":"npm pack --dry-run","prepack":"npm run check","test":"vitest run --config vitest.config.ts","sync:openapi":"tsx scripts/gen-openapi.ts --sync","typecheck":"tsc --project tsconfig.json --noEmit","check:branding":"tsx ../../scripts/check-branding.ts"},"keywords":["ariadra","sdk","management"],"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"repository":{"type":"git","url":"git+https://github.com/vibengine-ai/ariadra-sdk-typescript.git","directory":"packages/management-sdk"},"gitHead":"ed283e23739ae90856c76eed2a0f47a4a5c4b455","_id":"@astrifer-ai/agent-os-management@0.1.0","bugs":{"url":"https://github.com/vibengine-ai/ariadra-sdk-typescript/issues"},"_nodeVersion":"26.8.1","_npmVersion":"11.19.0","dist":{"integrity":"sha512-bKKBgLlUFikzABhMDHmIuagODz3nHl8X7fLOm2vN1f5GjO9WJdn9pouINDPV2rA5I4AXSpijxakJIwP/2Hz5wA==","shasum":"01a5c87d801b6a8d110e9e484b1c58a4a19db7d3","tarball":"https://registry.npmjs.org/@astrifer-ai/agent-os-management/-/agent-os-management-0.1.0.tgz","fileCount":7,"unpackedSize":386858,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDtrMdwoRJWs43BkVg6QP8dEyA4LiAGMcum/+fnG0g7jQIhAO5v8jxOtHQn6qNvM8oUlBgYQbpE7Wek1zb47VNPrCDd"}]},"_npmUser":{"name":"yf36","email":"yifan.fan.1983@gmail.com"},"directories":{},"maintainers":[{"name":"yf36","email":"yifan.fan.1983@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-os-management_0.1.0_1788846490518_0.8414130151514376"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-08T05:48:10.372Z","0.1.0":"2026-09-08T05:48:10.700Z","modified":"2026-09-08T05:48:10.910Z"},"maintainers":[{"name":"yf36","email":"yifan.fan.1983@gmail.com"}],"description":"TypeScript SDK for Astrifer Agent OS tenant management.","homepage":"https://am.astrifer.ai","keywords":["ariadra","sdk","management"],"repository":{"type":"git","url":"git+https://github.com/vibengine-ai/ariadra-sdk-typescript.git","directory":"packages/management-sdk"},"bugs":{"url":"https://github.com/vibengine-ai/ariadra-sdk-typescript/issues"},"license":"Apache-2.0","readme":"# Astrifer Agent OS Management SDK\n\nTyped enterprise Tenant Management SDK for Astrifer Agent OS.\n\n```bash\nnpm install @astrifer-ai/agent-os-management\n```\n\nCurrent source targets Tenant Management OpenAPI contract `0.21.0`; the\ninitial package version is `0.1.0`.\n\n`CONTRACT_VERSION` is the Tenant Management document version. The HTTP\n`x-ariadra-api-version` header is still the shared platform-v1 transport\nversion until the platform adds a dedicated Tenant Management negotiation\nheader.\n\nUse `@astrifer-ai/agent-os-management` with an `ariadra_mgmt_*` API key for\ntenant-scoped automation:\n\n- member list/create\n- namespace create/list/update\n- tenant-management API key issue/list/revoke\n- LLM provider credential create/list/get/delete/refresh and\n  credential-scoped exact-model listing\n- Event Bus adapter installation lifecycle, Runtime grants, controlled\n  subscription teardown, and short-lived Link Authorization issuance\n\nUse `@astrifer-ai/agent-os` for API-key data-plane workflows such as sessions, events,\nVolume, AgentSpec/EnvironmentSpec, and `GET /v1/llm-provider-credentials`\nsession credential discovery.\n\n```ts\nimport { AgentOSManagement } from \"@astrifer-ai/agent-os-management\";\n\nconst management = new AgentOSManagement({\n  apiKey: \"ariadra_mgmt_...\",\n  baseURL: process.env.ARIADRA_BASE_URL!,\n  maxRetries: 2, // opt in to transient retries for eligible requests\n});\n\nconst keys = await management.apiKeys.list();\n\nconst models = await management.llmProviderCredentials.models.list(\"cred_...\", {\n  runtime_driver: \"codex_cli\",\n});\n\nawait management.llmProviderCredentials.refresh(\"cred_...\");\n```\n\nEvent Bus control-plane operations live under\n`management.eventBus.adapterInstallations`. Installation, grant, and lifecycle\nmutations carry a caller-generated `operation_id`; the SDK marks these commands\nas safe for transport retry when `maxRetries > 0`, while preserving the exact\nrequest body.\n\n```ts\nconst installation = await management.eventBus.adapterInstallations.create({\n  operation_id: \"install_01K...\",\n  connector_kind: \"slack\",\n  metadata: {},\n  initial_grant: {\n    subject_kind: \"service_principal\",\n    subject_id: \"spr_01K...\",\n    permissions: [\"event_bus.subscribe\", \"event_bus.delivery.ack\"],\n    namespace_ids: [\"default\"],\n  },\n});\n\nconst authorization =\n  await management.eventBus.adapterInstallations.linkAuthorizations.issue(\n    installation.installation.adapter_installation_id,\n    {\n      operation_id: \"link_01K...\",\n      action: \"link\",\n      authorized_subject_kind: \"service_principal\",\n      authorized_subject_id: \"spr_01K...\",\n    },\n  );\n\nif (authorization.data.replayed) {\n  // The original bearer handle is intentionally unavailable. Start a new\n  // issue operation with a new operation_id if the first response was lost.\n  throw new Error(\"Link Authorization was replayed without its secret handle\");\n}\n\nconst authorizationHandle = authorization.data.authorization_handle;\n\nlet afterSubscriptionId: string | undefined;\nfor (;;) {\n  const page =\n    await management.eventBus.adapterInstallations.subscriptions.list(\n      installation.installation.adapter_installation_id,\n      {\n        limit: 50,\n        ...(afterSubscriptionId === undefined\n          ? {}\n          : { after_subscription_id: afterSubscriptionId }),\n      },\n    );\n\n  for (const subscription of page.data) {\n    const receipt =\n      await management.eventBus.adapterInstallations.subscriptions.deprovision(\n        installation.installation.adapter_installation_id,\n        subscription.subscription_id,\n        {\n          force_discard: false,\n          operation_id: `inspect-${subscription.subscription_id}`,\n          reason: \"retire connector installation\",\n        },\n      );\n    if (receipt.needs_force_discard) {\n      // A destructive follow-up requires explicit operator approval and a new\n      // operation_id. Do not silently promote this request to force_discard.\n    }\n  }\n\n  if (!page.has_more) break;\n  if (page.next_after_subscription_id === null) {\n    throw new Error(\"subscription page omitted its continuation cursor\");\n  }\n  afterSubscriptionId = page.next_after_subscription_id;\n}\n```\n\nTyped grant subjects pair `service_principal` with an `spr_*` ID or\n`data_plane_api_key` with an `ak_*` ID. Tenant Management 0.17 removes the\ndeprecated `{ api_key_id: \"ak_*\" }` grant and no-subject Link Authorization\nshapes; every request and response now uses an exact typed subject.\n\nInstallation archive is allowed only after every owned subscription reaches\n`deprovisioned`. A `force_discard: true` teardown is destructive and audited.\nWith `maxRetries > 0`, the SDK can safely retry an operation-ID-backed\ndeprovision request without changing its intent. Applications must still use\n`subscriptions.list(...)` to observe current state because a replay returns the\noriginal immutable receipt. Always exhaust all list pages before attempting to\narchive an installation.\n\nThe Link Authorization handle is a short-lived bearer secret returned only in\nthe first successful response. The SDK never automatically retries this issue\nrequest: a same-operation replay returns `replayed: true` and omits the handle.\nDo not log or persist the handle beyond the connector action that consumes it.\n\nThe package does not include UserJWT `/v1/auth/*` or `/v1/users/me/*` flows,\nstaff `/v1/admin/*` endpoints, platform plan-tier administration, global audit\nviews, Event Bus data-plane delivery/binding/inbound operations, or platform\nmodel catalog mutation.\n\nThe package owns its client and resource wrappers under `src/`, while reusing\nonly package-neutral transport primitives from the repository's\n`internal/sdk-core` directory. Builds bundle those primitives, so the published\npackage is self-contained and does not depend on `@astrifer-ai/agent-os`.\n\n```ts\nawait management.members.create({\n  email: \"ops@example.test\",\n  password: \"temporary-password\",\n  role: \"admin\",\n});\n```\n\nFor newly added management endpoints that do not have typed wrappers yet, use\nthe low-level request escape hatch. The escape hatch is intentionally restricted\nto `/v1/tenant/*` paths:\n\n```ts\nconst result = await management.request({\n  method: \"GET\",\n  path: \"/v1/tenant/api-keys\",\n});\n```\n\nCurated methods apply generated public input limits before transport and throw\n`InputValidationError` with a stable field path, unit, limit, and reason. The\nerror never contains the submitted value, API key, provider secret, token, or\nraw server error. Inputs are rejected rather than truncated or normalized.\n`management.request(...)` deliberately bypasses this SDK preflight; it remains\npath-restricted, and the Platform is always the final validation authority.\n\nWhen using both `@astrifer-ai/agent-os` and `@astrifer-ai/agent-os-management` in the same\napp, prefer `isAgentOSError(err)` / `isHasOpenTurnError(err)` over\ncross-package `instanceof APIError` checks. The two packages bundle their own\ncopy of the error classes; the helper functions use a global symbol marker and\nwork across packages.\n","readmeFilename":"README.md","_rev":"1-a50da86d195e2b95312c8d7478e3c124"}