{"_id":"@attestto/mesh","name":"@attestto/mesh","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@attestto/mesh","version":"0.1.0","description":"Public Digital Infrastructure — distributed P2P mesh for sovereign identity state over libp2p, anchored on Solana","homepage":"https://attestto.org","license":"Apache-2.0","type":"module","main":"dist/index.cjs","module":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","require":"./dist/index.cjs","types":"./dist/index.d.ts"}},"scripts":{"build":"tsup","dev":"tsup --watch","test":"vitest run","test:watch":"vitest","test:coverage":"vitest run --coverage","type-check":"tsc --noEmit","lint":"eslint src tests","demo":"tsx demo/proof-of-logic.ts","demo:alpha":"tsx demo/proof-of-logic.ts --role alpha --port 4001","demo:beta":"tsx demo/proof-of-logic.ts --role beta","prepublishOnly":"pnpm run lint && pnpm test && pnpm run build"},"dependencies":{"@chainsafe/libp2p-gossipsub":"^14.1.2","@chainsafe/libp2p-noise":"^17.0.0","@chainsafe/libp2p-yamux":"^8.0.1","@libp2p/bootstrap":"^12.0.15","@libp2p/circuit-relay-v2":"^4.1.7","@libp2p/crypto":"^5.1.14","@libp2p/identify":"^4.0.14","@libp2p/interface":"^3.1.1","@libp2p/kad-dht":"^16.1.7","@libp2p/ping":"^3.0.14","@libp2p/tcp":"^11.0.14","@libp2p/webrtc":"^6.0.15","better-sqlite3":"^12.2.0","libp2p":"^3.1.7","multiformats":"^13.3.3","uint8arrays":"^5.1.0"},"peerDependencies":{"@solana/web3.js":"^1.95.0"},"peerDependenciesMeta":{"@solana/web3.js":{"optional":true}},"devDependencies":{"@solana/web3.js":"^1.98.0","@eslint/js":"^10.0.1","@types/better-sqlite3":"^7.6.13","@types/node":"^22.10.0","@vitest/coverage-v8":"^3.2.6","eslint":"^10.2.0","tsup":"^8.3.0","tsx":"^4.21.0","typescript":"~5.7.0","typescript-eslint":"^8.58.0","vite":"^6.4.2","vitest":"^3.2.6"},"engines":{"node":">=20"},"repository":{"type":"git","url":"git+https://github.com/Attestto-com/attestto-mesh.git"},"pnpm":{"onlyBuiltDependencies":["better-sqlite3","esbuild"]},"keywords":["public-digital-infrastructure","pdi","sovereign-identity","decentralized-identity","did","verifiable-credentials","libp2p","mesh","p2p","distributed-systems","solana","web5","dht","gossipsub","blind-courier","national-resilience"],"gitHead":"7786b9ec97fa5d07a8848518b04c9e871789276f","_id":"@attestto/mesh@0.1.0","bugs":{"url":"https://github.com/Attestto-com/attestto-mesh/issues"},"_nodeVersion":"25.6.1","_npmVersion":"11.9.0","dist":{"integrity":"sha512-6NgtYHzfJIWA0lYAJ8g9URbaagcespIpi6IyBBEh40DI8fPI96toF3evNIbCJ5Ma3wqd9jk1s0L8bfzkveWlPA==","shasum":"0f95e4d2f03c81c908e1696db53862168255932f","tarball":"https://registry.npmjs.org/@attestto/mesh/-/mesh-0.1.0.tgz","fileCount":9,"unpackedSize":474695,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAJhVnY+UgQ+TI9b5BCZSq4ZTDVWXxoCyK1qVF0XzmXcAiBTnWH4wHV0XEVsHXPs2Upyy2FjQNqd3me1A3TRELO58g=="}]},"_npmUser":{"name":"chongkan","email":"e.chongkan@gmail.com"},"directories":{},"maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mesh_0.1.0_1786504036343_0.27425860924300816"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-12T03:07:16.149Z","0.1.0":"2026-08-12T03:07:16.530Z","modified":"2026-08-12T03:07:16.875Z"},"maintainers":[{"name":"chongkan","email":"e.chongkan@gmail.com"}],"description":"Public Digital Infrastructure — distributed P2P mesh for sovereign identity state over libp2p, anchored on Solana","homepage":"https://attestto.org","keywords":["public-digital-infrastructure","pdi","sovereign-identity","decentralized-identity","did","verifiable-credentials","libp2p","mesh","p2p","distributed-systems","solana","web5","dht","gossipsub","blind-courier","national-resilience"],"repository":{"type":"git","url":"git+https://github.com/Attestto-com/attestto-mesh.git"},"bugs":{"url":"https://github.com/Attestto-com/attestto-mesh/issues"},"license":"Apache-2.0","readme":"# attestto-mesh\n\n[![npm version](https://img.shields.io/npm/v/@attestto/mesh.svg)](https://www.npmjs.com/package/@attestto/mesh)\n[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](./LICENSE)\n[![Sponsor](https://img.shields.io/badge/sponsor-%E2%9D%A4-db61a2)](https://github.com/sponsors/Attestto-com)\n\n> Public digital infrastructure for sovereign identity — a peer-to-peer data layer that keeps citizens' identity state available even when government servers go offline.\n\n`@attestto/mesh` is an open-source, decentralized state-sync layer for identity data. Every participating device contributes storage to form a resilient mesh that protects verifiable credentials, cryptographic proofs, and secure messages without depending on any centralized server. This is not a blockchain. This is not a file system. This is **distributed identity infrastructure** for nations. Learn more at [attestto.org](https://attestto.org).\n\n## Architecture\n\n```mermaid\ngraph LR\n    subgraph Device[\"Citizen's Device\"]\n        Vault[\"Private Vault<br/>(keys, prefs)<br/>Never leaves device\"]\n    end\n\n    subgraph Mesh[\"The Mesh\"]\n        State[\"Encrypted State<br/>(VCs, proofs, msgs)<br/>50+ peer copies\"]\n    end\n\n    subgraph Solana[\"Solana Ledger\"]\n        Anchor[\"Public Anchor<br/>(hash proofs, timestamps)\"]\n    end\n\n    Vault -->|PUT| State\n    State -->|GET| Vault\n    State -->|anchor| Anchor\n```\n\n**Three-layer resolution:**\n1. **Local cache** — 0ms (data on your device)\n2. **Mesh peers** — <100ms (DHT lookup, nearby nodes serve encrypted blobs)\n3. **Solana anchor** — 200-500ms (immutable proof-of-existence)\n\nIf any layer fails, the others keep working. Graceful degradation by design.\n\n## Quick start\n\n### Prerequisites\n\n- Node.js 18+\n- pnpm (or npm)\n\n### Install\n\n```bash\npnpm install @attestto/mesh\n```\n\n### Try it\n\n```typescript\nimport { MeshNode, MeshStore, MeshProtocol } from '@attestto/mesh'\n\n// Initialize storage\nconst store = new MeshStore('/path/to/mesh/data')\n\n// Start a P2P node\nconst node = new MeshNode({\n  dataDir: '/path/to/mesh/data',\n  bootstrapPeers: ['/ip4/203.0.113.1/tcp/4001/p2p/Qm...'],\n  listenPort: 4001,\n})\nawait node.start()\n\n// Wire up the protocol layer\nconst protocol = new MeshProtocol(node, store)\n\n// Publish encrypted data to the mesh\nconst contentHash = await protocol.put({\n  didOwner: 'did:sns:maria.sol',\n  path: 'credentials/drivers-license',\n  version: 1,\n  ttlSeconds: 0,\n  signature: '...',\n  solanaAnchor: null,\n}, encryptedBlob)\n\n// Retrieve from any peer\nconst result = await protocol.get('did:sns:maria.sol', 'credentials/drivers-license')\n```\n\nRun the demo to see it work end-to-end:\n\n```bash\npnpm demo              # Two nodes in one process, 15 seconds\npnpm demo:alpha        # Multi-machine setup\npnpm demo:beta --peer /ip4/192.168.1.X/tcp/4001/p2p/...\ndocker compose up      # Zero dependencies, Docker only\n```\n\n## Key concepts\n\n### API: MeshNode, MeshStore, MeshProtocol\n\n| Component | Purpose | Technology |\n|-----------|---------|-----------|\n| **MeshNode** | P2P networking, peer discovery, gossip propagation | libp2p, Kademlia DHT, GossipSub |\n| **MeshStore** | Local encrypted blob storage with SQLite index | SQLite + `.enc` files |\n| **MeshProtocol** | PUT/GET/UPDATE/TOMBSTONE operations | Content-addressed, signature-verified |\n| **Conflict Resolution** | Deterministic version arbitration | Solana anchor > version > timestamp > hash |\n| **Garbage Collection** | Automatic cleanup with safety rails | TTL expiry, version pruning, LRU (6-holder minimum) |\n\n### Protocol operations\n\n```typescript\n// Publish\nconst hash = await protocol.put({\n  didOwner: 'did:sns:citizen.sol',\n  path: 'credentials/driving-license',\n  version: 1,\n  ttlSeconds: 0,           // 0 = permanent\n  signature: '...',        // Ed25519 signature\n  solanaAnchor: null,\n}, encryptedBlob)\n\n// Retrieve\nconst result = await protocol.get(\n  'did:sns:citizen.sol',\n  'credentials/driving-license'\n)\n\n// Update\nawait protocol.update(...)\n\n// Revoke\nawait protocol.tombstone(...)\n```\n\n### The Blind Courier principle\n\nEvery node stores encrypted data it mathematically cannot read. Privacy is not a policy — it is a cryptographic guarantee. No single node, no combination of nodes, can access plaintext identity data without the citizen's private key.\n\n### What gets stored\n\n| Data | Size | Storage | Why |\n|------|------|---------|-----|\n| DID Documents | 1–2 KB | Mesh | Public identity, resolvable by anyone |\n| Verifiable Credentials | 1–5 KB | Mesh | Backup, recovery, third-party presentation |\n| Secure Messages (DIDComm) | <2 KB | Mesh | Temporary, deleted after recipient acks |\n| Audit Receipts | <500 B | Mesh | Permanent Solana-anchored trail |\n| Private Keys | <1 KB | Device only | Never touches the network |\n| User Preferences | 200 B | Device only | Stays in local wallet |\n\n**Total per citizen: ~120 KB.** A national mesh of 5 million people fits in ~600 GB across thousands of nodes.\n\n### Multi-country mesh isolation\n\nThe `meshId` configuration isolates meshes by country. Same protocol, different networks — no cross-country data leakage.\n\n```typescript\n// Costa Rica\nnew MeshNode({ meshId: 'attestto-cr', dataDir: '/data/mesh' })\n\n// Panama\nnew MeshNode({ meshId: 'attestto-pa', dataDir: '/data/mesh' })\n```\n\nEach mesh ID creates a separate gossip topic. Nodes only peer with others on the same mesh.\n\n## Ecosystem\n\n| Repo | Role | Relationship |\n|------|------|--------------|\n| [`attestto-app`](../attestto-app) | Mobile PWA wallet | Connects to mesh for credential sync and recovery |\n| [`attestto-desktop`](../attestto-desktop) | Electron station | Heavy signing, mesh node operations (250 MB contribution) |\n| [`vc-sdk`](../vc-sdk) | Credential library | Issues and verifies VCs stored in the mesh |\n| [`did-sns-spec`](https://github.com/Attestto-com/did-sns-spec) | DID standard | `did:sns` method on Solana |\n| [`cr-vc-schemas`](https://github.com/Attestto-com/cr-vc-schemas) | Credential schemas | Costa Rica credential type definitions |\n\n## Build with an LLM\n\nThis repo ships a [`llms.txt`](./llms.txt) context file — a machine-readable summary of the API, data structures, and integration patterns designed to be read by AI coding assistants.\n\n### Recommended setup\n\nUse the [`attestto-dev-mcp`](../attestto-dev-mcp) server to give your LLM active access to the ecosystem:\n\n```bash\ncd ../attestto-dev-mcp\nnpm install && npm run build\n```\n\nThen add it to your Claude / Cursor / Windsurf config and ask:\n\n> *\"Explore the Attestto ecosystem and help me extend [this component]\"*\n\n### Which model?\n\nWe recommend **[Claude](https://claude.ai) Pro** (5× usage vs free) or higher. Long context, strong TypeScript reasoning, and libp2p familiarity handle this codebase well. The MCP server works with any LLM that supports tool use.\n\n> **Quick start:** Ask your LLM to read `llms.txt` in this repo, then describe what you want to build. It will find the right archetype, generate boilerplate, and walk you through the first run.\n\n## Contributing\n\nSee [`TECHNICAL.md`](./TECHNICAL.md) for:\n- API reference\n- Project structure\n- Testing and builds\n- Architecture decisions\n\nContributions welcome. All code Apache 2.0.\n\n## License\n\n[Apache 2.0](./LICENSE) — Use it, fork it, deploy it. No vendor lock-in.\n\nBuilt by [Attestto](https://attestto.com) as Public Digital Infrastructure for Costa Rica and beyond.\n","readmeFilename":"README.md","_rev":"1-f08e77711c5a47a15e3981e32de94c12"}