{"_id":"@attestinfra/sdk","_rev":"3-dd8a3f395b56bf6beb553b97aa99b89a","name":"@attestinfra/sdk","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@attestinfra/sdk","version":"0.1.0","keywords":["attest","verification","machine-activity","AI","provenance","audit","OTLP"],"license":"MIT","_id":"@attestinfra/sdk@0.1.0","maintainers":[{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"}],"homepage":"https://attestinfra.com","bugs":{"url":"https://github.com/danielmiessler/Mooni/issues"},"dist":{"shasum":"d99d0255612cdda2cdb071471ee31138e9caa829","tarball":"https://registry.npmjs.org/@attestinfra/sdk/-/sdk-0.1.0.tgz","fileCount":6,"integrity":"sha512-bTb57j44EjK0vuwQHmOHEa2C6IDMGYREiu+FOyHO2XtQM7MRfuEBmoW0ARvTE0/DpfZRndTZdA5aa3CJv/GzoA==","signatures":[{"sig":"MEYCIQCE8D/oTsL2St8BeOpRcPUSFRwKTxI+08Tb+uyKsT2/5wIhAIzCYP6wJ5zLaCGHO9Mgk99sSlZ0fdwbF1CFAR49vr4U","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12478},"main":"src/index.js","types":"src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./src/index.d.ts","import":"./src/index.js","require":"./src/index.js"}},"gitHead":"1b3b889ba98ca1aa89956cd5e3e0f5d865e1479a","scripts":{"test":"node --test test/*.test.js","pack:check":"npm pack --dry-run","smoke:production":"node scripts/production-smoke.js"},"_npmUser":{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"},"repository":{"url":"git+https://github.com/danielmiessler/Mooni.git","type":"git","directory":"packages/sdk"},"_npmVersion":"10.8.2","description":"Server-side JavaScript SDK for verifiable records of machine activity with attest","directories":{},"_nodeVersion":"20.18.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.0_1788668808564_0.5441613556738734","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@attestinfra/sdk","version":"0.1.1","keywords":["attest","verification","machine-activity","AI","provenance","audit","OTLP"],"license":"MIT","_id":"@attestinfra/sdk@0.1.1","maintainers":[{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"}],"homepage":"https://attestinfra.com","bugs":{"url":"https://github.com/danielmiessler/Mooni/issues"},"dist":{"shasum":"01e329647f9f241522027c90e30e3823b821b41e","tarball":"https://registry.npmjs.org/@attestinfra/sdk/-/sdk-0.1.1.tgz","fileCount":6,"integrity":"sha512-OUmuOXVDJcaZu3moE/CmteVedQXHzsBK7o86TX/1NaXGlTgdQD8WkaMVA1FhdssIlqcRh09teJFWcoiS39gN/A==","signatures":[{"sig":"MEYCIQDwetizuI9LUbPpPCSs34eamB+zA7JeDNvjN/N4zsf+UQIhAOk3CAh74C97eg9adofmoQMg/7v5skLGKLTfzOPG1IoL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12566},"main":"src/index.js","types":"src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./src/index.d.ts","import":"./src/index.js","require":"./src/index.js"}},"gitHead":"1b3b889ba98ca1aa89956cd5e3e0f5d865e1479a","scripts":{"test":"node --test test/*.test.js","pack:check":"npm pack --dry-run","smoke:production":"node scripts/production-smoke.js"},"_npmUser":{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"},"repository":{"url":"git+https://github.com/danielmiessler/Mooni.git","type":"git","directory":"packages/sdk"},"_npmVersion":"10.8.2","description":"Server-side JavaScript SDK for verifiable records of machine activity with attest","directories":{},"_nodeVersion":"20.18.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/sdk_0.1.1_1788669222492_0.5831859836470401","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"_id":"@attestinfra/sdk@0.2.0","bugs":{"url":"https://github.com/Yonsbuild/Mooni/issues"},"dist":{"shasum":"b99bf5c26feb6d0ee5733da8531b6362affd4b7e","tarball":"https://registry.npmjs.org/@attestinfra/sdk/-/sdk-0.2.0.tgz","fileCount":7,"integrity":"sha512-nBBqmxnrpG5/Yfadj0ULTtUCEJLgv/rM3fmFzJEhf/8Gi+h1arxC1l28w8ti0rUhaLMcBXEucJbgg5bUTOKbeA==","signatures":[{"sig":"MEQCIFlw5HjnAq78lBEj6JlfoO7e6ITO6UBIPH8d0IMLHsWtAiAMIjVSmm2K8A5HP5nKkJuDV0ovac/BPC/c52DK/dk+ow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDKycvbgMhhJNVGKAYKHAdOw1UkGkPyMKHlvdSpdI5MuAIgbP8fL5MnFMyTQOfQpl37h9VGA00sU1U2zpCseELIwpc="}],"unpackedSize":33681},"main":"src/index.js","name":"@attestinfra/sdk","types":"src/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./src/index.d.ts","import":"./src/index.js","require":"./src/index.js"}},"gitHead":"b092e5db4873c9dc1a0ade237c050507a753e403","license":"MIT","scripts":{"test":"node --test test/*.test.js","pack:check":"npm pack --dry-run","smoke:production":"node scripts/production-smoke.js"},"version":"0.2.0","_npmUser":{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"},"homepage":"https://attestinfra.com","keywords":["attest","verification","machine-activity","AI","provenance","audit","OTLP"],"repository":{"url":"git+https://github.com/Yonsbuild/Mooni.git","type":"git","directory":"packages/sdk"},"_npmVersion":"10.8.2","description":"Server-side JavaScript SDK for verifiable records of machine activity with attest","directories":{},"maintainers":[{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"}],"_nodeVersion":"20.18.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.2.0_1789632077513_0.6941450087816983"}}},"time":{"created":"2026-09-06T04:26:48.354Z","modified":"2026-09-17T08:01:17.805Z","0.1.0":"2026-09-06T04:26:48.714Z","0.1.1":"2026-09-06T04:33:42.622Z","0.2.0":"2026-09-17T08:01:17.599Z"},"bugs":{"url":"https://github.com/Yonsbuild/Mooni/issues"},"license":"MIT","homepage":"https://attestinfra.com","keywords":["attest","verification","machine-activity","AI","provenance","audit","OTLP"],"repository":{"url":"git+https://github.com/Yonsbuild/Mooni.git","type":"git","directory":"packages/sdk"},"description":"Server-side JavaScript SDK for verifiable records of machine activity with attest","maintainers":[{"name":"dsg_yons","email":"work.danielsolutions@gmail.com"}],"readme":"# attest JavaScript SDK\n\nServer-side JavaScript SDK for creating verifiable records of machine activity with attest.\n\nCurrent release candidate: `@attestinfra/sdk@0.2.0`.\n\n## Install\n\n```bash\nnpm install @attestinfra/sdk@0.2.0\n```\n\n## Configure\n\n```js\nimport { Attest } from \"@attestinfra/sdk\";\n\nconst attest = new Attest({\n  apiKey: process.env.ATTEST_API_KEY\n});\n```\n\nKeep `att_live_` and `att_test_` credentials server-side. Never expose them in browser or client code.\n\n## Verify a machine action\n\n```js\nconst result = await attest.verify({\n  eventType: \"ai.model.inference\",\n  source: \"ai-gateway\",\n  action: \"inference\",\n  actorType: \"model\",\n  model: \"example-model\",\n  eventId: \"inference-123\"\n});\n```\n\n`eventType` describes what happened. `action` is the source-native action. `source` identifies where the claim originated. `eventId` is the caller's stable replay identity. The legacy `name` field remains an alias for `eventType`; if both are supplied, they must match.\n\nThe response reports server-authoritative accepted and duplicate counts plus usage. The SDK does not calculate billing.\n\n## Replay identity\n\nSupply a stable `eventId` when the caller needs retry safety. Exact replay is deduplicated by attest and does not create a second Verification Pass. The SDK does not retry automatically.\n\n## Boundary witness\n\n`witness()` records an assembly observation before a business operation, records delivery afterward, and finalizes the pair into authoritative reconciliation.\n\n```js\nconst { result, witness } = await attest.witness({\n  eventType: \"transfer.requested\",\n  source: \"checkout\",\n  destination: \"payments\",\n  action: \"transfer\",\n  evidence: {\n    actionId: \"transfer_82\",\n    amount: 500,\n    currency: \"USD\"\n  }\n}, () => transferFunds());\n```\n\nFinalized witness authority reports one of:\n\n```text\nmatched\ndivergent\nincomplete\norphaned\n```\n\nThe canonical reconciliation format is `attest-witness-reconciliation-v1`. Finalized responses may expose `reconciliationFormat`, `reconciliationDigest`, and `finalizedAt` alongside the observation state.\n\nBoundary witnessing preserves and reconciles independently recorded machine states. It does not prove the objective truth, legality, or correctness of the underlying real-world action.\n\n## Durable witness workflows\n\n`witness()` is the convenience path. It is not crash-recoverable because its generated pair identity is not available to persist before execution.\n\nFor durable workflows, prepare and persist the exact assembly identity before allowing side effects:\n\n```js\nconst prepared = attest.prepareWitness(event); // synchronous; no network request\nawait persist(prepared.pairId, prepared.assemblyIdentity);\n\nconst { result, witness } = await prepared.execute(() => transferFunds());\n```\n\nIf a process restarts, reconstruct the exact prepared assembly from your persisted copy. `execute()` will refuse to rerun the business operation when attest reports that the assembly already exists.\n\n```js\nconst replay = attest.prepareWitness(await loadAssemblyIdentity());\n\ntry {\n  await replay.execute(() => transferFunds());\n} catch (error) {\n  if (error.code === \"WITNESS_ASSEMBLY_EXISTS\") {\n    const state = await attest.resumeWitness(replay.pairId);\n    // inspect state; do not infer that the business operation did or did not execute\n  }\n}\n```\n\n`AttestWitnessAssemblyExistsError` exposes:\n\n- `pairId`\n- `currentInvocationOperationExecuted: false`\n- `priorExecutionStatus: \"unknown\"`\n- `assemblyStatus: \"already_exists\"`\n\nAttest does not provide exactly-once execution across process death. Durable observations cannot prove whether a real-world operation completed between the last accepted observation and a crash.\n\n## Recovery\n\n```js\nconst state = await attest.resumeWitness(pairId);\n```\n\nRecovery is deliberately conservative:\n\n- it never reruns the business operation;\n- it never fabricates a delivery observation;\n- it always reports `executionState: \"unknown\"`;\n- an assembly-only OPEN pair returns `recoveryStatus: \"delivery_required\"`;\n- explicit `finalizeWitness(pairId)` may intentionally terminalize a one-sided pair as `incomplete` or `orphaned` according to the persisted authority.\n\nIf the caller persisted a legitimate delivery observation that attest does not yet hold, it may supply it to recovery:\n\n```js\nawait attest.resumeWitness(pairId, { deliveryObservation });\n```\n\nA post-execution delivery-recording failure throws `AttestWitnessDeliveryError` with the pair ID and recoverable delivery observation. Persist that observation before attempting recovery.\n\n## Low-level witness methods\n\nThe SDK also exposes:\n\n```js\nawait attest.witnessAssembly(event, options);\nawait attest.witnessDelivery(event, options);\nawait attest.getWitness(pairId);\nawait attest.finalizeWitness(pairId);\n```\n\nUse these only when the application intentionally owns the witness lifecycle.\n\n## Witness replay timestamps\n\nA witness timestamp is part of the immutable observation identity. SDK helpers generate the timestamp before their first request when omitted. Exact retries must reuse the same prepared observation, including timestamp.\n\nRaw HTTP witness callers must supply a UTC timestamp in `YYYY-MM-DDTHH:mm:ss.sssZ` form. The seconds-only `...ssZ` form deterministically normalizes to `.000Z`.\n\nAssembly and delivery timestamps normally differ. They identify the individual observations and are not themselves treated as a reconciliation divergence.\n\n## Witness evidence JSON contract\n\nWitness `evidence` must have a plain-object root and uses `attest-canonical-json-v1`.\n\nAccepted nested values are:\n\n- `null`\n- boolean\n- string\n- finite number\n- dense array\n- plain data object (`Object.prototype` or null prototype)\n\nObject keys sort deterministically, array order remains material, Unicode is preserved, and `-0` normalizes to `0`. The evidence commitment is SHA-256 over the canonical UTF-8 approved JSON bytes. This format does not claim RFC 8785/JCS conformance.\n\nLimits:\n\n- 8 nested container levels below the root\n- 512 total object keys plus array elements\n- 8,192 characters per string\n- 128 characters per object key\n- 64 KiB canonical UTF-8 JSON\n\nRejected values include cycles, sparse arrays, accessors, non-enumerable or symbol properties, `undefined`, `NaN`, infinities, `BigInt`, symbols, functions, and non-plain values such as `Date`, `Map`, `Set`, `Buffer`, typed arrays, class instances, `RegExp`, `Error`, and `Promise`. At any depth, `__proto__`, `constructor`, and `prototype` keys are rejected.\n\nSDK witness helpers validate evidence locally before sending. The server independently enforces the same contract.\n\nSend minimal boundary invariants, hashes, or pointers—not raw payloads, secrets, credentials, payment data, documents, or sensitive records.\n\n## Universal HTTP\n\nAny machine that can make an authenticated HTTPS request can use attest directly:\n\n```sh\ncurl https://attestinfra.com/v1/events -X POST \\\n  -H \"Authorization: Bearer $ATTEST_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"eventType\":\"machine.job.completed\",\"source\":\"factory-controller\",\"action\":\"complete\",\"actorType\":\"device\",\"eventId\":\"job-123\"}'\n```\n\nOTLP remains supported through `POST /v1/traces`.\n\n## Pricing\n\nOne unique successfully verified Production event produces one Verification Pass at **$0.001 per Verification Pass**. Exact duplicates do not create an additional pass.\n\nWitness observation billing follows the server-authoritative accepted-observation ledger. Finalization, reconciliation, trust projection, and checkpoint creation do not create additional Verification Passes.\n\n## Error model\n\nErrors use typed subclasses of `AttestError` for validation, authentication, server/rate-limit, network/timeout, malformed-response, and witness-recovery failures.\n\nThe SDK intentionally avoids automatic retries for operations whose execution state may be ambiguous.\n\n## Production state for 0.2.0\n\nThe server-side Witness F-series through F-7 is deployed and production-validated, including:\n\n- deterministic witness replay identity;\n- strict witness evidence normalization;\n- PostgreSQL observation/pair immutability;\n- authoritative reconciliation;\n- truthful recovery for incomplete state;\n- durable trust projection;\n- checkpoint continuity for finalized witness authority.\n\nMigrations through `012_witness_schema_reconciliation.sql` are part of the deployed production history. Applied migrations are immutable; future schema changes must use new migration numbers.\n\n## Release validation\n\nBefore publishing `0.2.0`:\n\n```bash\ncd packages/sdk\nnpm test\nnpm pack --dry-run\n```\n\nConfirm the package reports version `0.2.0`, Node `>=18`, only the intended package files are present, and no private signing material is included.\n\nThe published artifact must then be tested from a clean project outside the Attest repository:\n\n```bash\nnpm install @attestinfra/sdk@0.2.0\n```\n\nThe customer-style smoke should exercise at least:\n\n- `verify()`\n- `prepareWitness()`\n- a matched witness flow\n- recovery-state inspection\n\nPublish only from `packages/sdk/`:\n\n```bash\nnpm publish --access public\n```\n","readmeFilename":"README.md"}