{"_id":"@auditrxyz/sdk","_rev":"3-f40ab7abc4fd33119cb619e67d58a1f2","name":"@auditrxyz/sdk","dist-tags":{"latest":"0.4.0"},"versions":{"0.2.0":{"name":"@auditrxyz/sdk","version":"0.2.0","keywords":["auditr","x402","web3","security","audit","usdc","eip-3009","agent","coinbase","agentkit"],"author":{"name":"Auditr","email":"info@auditr.xyz"},"license":"Apache-2.0","_id":"@auditrxyz/sdk@0.2.0","maintainers":[{"name":"auditrsdk","email":"info@auditr.xyz"}],"homepage":"https://auditr.xyz","bugs":{"url":"https://github.com/ChristopherPatrickKuntz/auditrsdk/issues"},"dist":{"shasum":"4a9cbe81708b8c1eae5ccf20e5b16053927f1aca","tarball":"https://registry.npmjs.org/@auditrxyz/sdk/-/sdk-0.2.0.tgz","fileCount":17,"integrity":"sha512-qn5X+OICyvQ1u15XsHUk6nX3/z0zD2ZHqxhUfz1sVGQXbELql3noFqK/+SH31DKDU7BquyfhF3GdWiNxhJyUnQ==","signatures":[{"sig":"MEUCIQCy1cUGyOWO7HLtTlUQIa9ppamfGqV1oGpaA/9a0/SVYgIgHPNg1BquuqqdPFdPHJoNHa2XIeQ0BIovh/HY7f/wtus=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":229892},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schema":{"types":"./dist/schema/index.d.ts","import":"./dist/schema/index.js"}},"gitHead":"34992999439df22c5966aa2ec97fa089ced8b1d6","scripts":{"lint":"eslint . --max-warnings 0","test":"vitest run","build":"tsup","format":"prettier --write .","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run typecheck:examples && npm run lint && npm run test && npm run build","typecheck:examples":"tsc -p tsconfig.examples.json --noEmit"},"_npmUser":{"name":"auditrsdk","email":"info@auditr.xyz"},"repository":{"url":"git+https://github.com/ChristopherPatrickKuntz/auditrsdk.git","type":"git"},"_npmVersion":"10.9.7","description":"TypeScript SDK for the Auditr x402 API. Pay per call in USDC for audits and monitoring, or provision Bearer tokens for the Auditr-hosted x402 facilitator at facilitator.auditr.xyz.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^3.23.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^8.57.0","vitest":"^1.5.0","prettier":"^3.2.5","typescript":"^5.4.0","@types/node":"^20.12.0","@typescript-eslint/parser":"^7.7.0","@typescript-eslint/eslint-plugin":"^7.7.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.2.0_1779993913655_0.05516105458156795","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@auditrxyz/sdk","version":"0.3.0","keywords":["auditr","x402","web3","security","audit","usdc","eip-3009","agent","coinbase","agentkit"],"author":{"name":"Auditr","email":"info@auditr.xyz"},"license":"Apache-2.0","_id":"@auditrxyz/sdk@0.3.0","maintainers":[{"name":"auditrsdk","email":"info@auditr.xyz"}],"homepage":"https://auditr.xyz","bugs":{"url":"https://github.com/ChristopherPatrickKuntz/auditrsdk/issues"},"dist":{"shasum":"3c43f3e855210d066fcd4a1839200a3428b78f79","tarball":"https://registry.npmjs.org/@auditrxyz/sdk/-/sdk-0.3.0.tgz","fileCount":17,"integrity":"sha512-/Vk7jkmIS0OswXQyvajzoR/J8U7+uecHA5p6n5Jvp79BRkfvdEdRe7BbzeDvMJT8TwsfbxWs/m5rajGCXjWXQA==","signatures":[{"sig":"MEUCIQDpauv3c5mFPRPEZxAmcGge6H7c/W7OAM5+as/XqmRikQIgQnhivjWV0CxPB20voWU38kxKb9x84/SfFcQjYWWegNg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@auditrxyz%2fsdk@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":245965},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schema":{"types":"./dist/schema/index.d.ts","import":"./dist/schema/index.js"}},"gitHead":"bafbfd6dde3b91152f55d341274a421dcff3e958","scripts":{"lint":"eslint . --max-warnings 0","test":"vitest run","build":"tsup","format":"prettier --write .","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run typecheck && npm run typecheck:examples && npm run lint && npm run test && npm run build","typecheck:examples":"tsc -p tsconfig.examples.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bdbb4723-d781-4f4e-908a-16e256a89f34"}},"repository":{"url":"git+https://github.com/ChristopherPatrickKuntz/auditrsdk.git","type":"git"},"_npmVersion":"11.16.0","description":"TypeScript SDK for the Auditr x402 API. Pay per call in USDC for audits and monitoring. Run x402 settlements through the Auditr-hosted facilitator: 25 free Solana settles/month + $10 USDC top-up, gas pass-through.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^3.23.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^8.57.0","vitest":"^1.5.0","prettier":"^3.2.5","typescript":"^5.4.0","@types/node":"^20.12.0","@typescript-eslint/parser":"^7.7.0","@typescript-eslint/eslint-plugin":"^7.7.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.3.0_1780002434272_0.196315054678333","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@auditrxyz/sdk","version":"0.4.0","description":"TypeScript SDK for the Auditr x402 API. Pay per call in USDC for audits and monitoring. Run x402 settlements through the Auditr-hosted facilitator: 25 free Solana settles/month + $10 USDC top-up, gas pass-through.","license":"Apache-2.0","author":{"name":"Auditr","email":"info@auditr.xyz"},"homepage":"https://auditr.xyz","repository":{"type":"git","url":"git+https://github.com/ChristopherPatrickKuntz/auditrsdk.git"},"bugs":{"url":"https://github.com/ChristopherPatrickKuntz/auditrsdk/issues"},"keywords":["auditr","x402","web3","security","audit","usdc","eip-3009","agent","coinbase","agentkit"],"type":"module","main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schema":{"types":"./dist/schema/index.d.ts","import":"./dist/schema/index.js"}},"engines":{"node":">=18"},"scripts":{"build":"tsup","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","typecheck:examples":"tsc -p tsconfig.examples.json --noEmit","lint":"eslint . --max-warnings 0","format":"prettier --write .","prepublishOnly":"npm run typecheck && npm run typecheck:examples && npm run lint && npm run test && npm run build"},"dependencies":{"zod":"^3.23.0"},"devDependencies":{"@types/node":"^20.12.0","@typescript-eslint/eslint-plugin":"^7.7.0","@typescript-eslint/parser":"^7.7.0","eslint":"^8.57.0","prettier":"^3.2.5","tsup":"^8.0.0","typescript":"^5.4.0","vitest":"^1.5.0"},"publishConfig":{"access":"public","provenance":true},"gitHead":"032d0104393744fa70abc0e747c560ca4d189d1a","_id":"@auditrxyz/sdk@0.4.0","_nodeVersion":"20.20.2","_npmVersion":"11.16.0","dist":{"integrity":"sha512-qK/XY7tBQc60bOmMFsfWXbc/9z03cvUkUOeKsJhlvIYEaWNPNIIqS6H/Qd15t4otQ7zfFs8F9Y9em0MUmt6WAA==","shasum":"dcd085a3e08bee81f86f7312132657f43a32d5a9","tarball":"https://registry.npmjs.org/@auditrxyz/sdk/-/sdk-0.4.0.tgz","fileCount":17,"unpackedSize":266342,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@auditrxyz%2fsdk@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCqLeIsXMvsEv/9B2yqYab6+7p29Z0s62wzbVYgjLy1gwIgKF612+uSueoAIj1DprlLNYf09VAftBya3O+N78FEm+0="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:bdbb4723-d781-4f4e-908a-16e256a89f34"}},"directories":{},"maintainers":[{"name":"auditrsdk","email":"info@auditr.xyz"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_0.4.0_1780428440982_0.7231557036885763"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-28T18:45:13.423Z","modified":"2026-06-02T19:27:21.416Z","0.2.0":"2026-05-28T18:45:13.809Z","0.3.0":"2026-05-28T21:07:14.414Z","0.4.0":"2026-06-02T19:27:21.151Z"},"bugs":{"url":"https://github.com/ChristopherPatrickKuntz/auditrsdk/issues"},"author":{"name":"Auditr","email":"info@auditr.xyz"},"license":"Apache-2.0","homepage":"https://auditr.xyz","keywords":["auditr","x402","web3","security","audit","usdc","eip-3009","agent","coinbase","agentkit"],"repository":{"type":"git","url":"git+https://github.com/ChristopherPatrickKuntz/auditrsdk.git"},"description":"TypeScript SDK for the Auditr x402 API. Pay per call in USDC for audits and monitoring. Run x402 settlements through the Auditr-hosted facilitator: 25 free Solana settles/month + $10 USDC top-up, gas pass-through.","maintainers":[{"name":"auditrsdk","email":"info@auditr.xyz"}],"readme":"# @auditrxyz/sdk\n\n[![npm](https://img.shields.io/npm/v/@auditrxyz/sdk.svg)](https://www.npmjs.com/package/@auditrxyz/sdk)\n[![license](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE)\n[![tests](https://github.com/ChristopherPatrickKuntz/auditrsdk/actions/workflows/ci.yml/badge.svg)](https://github.com/ChristopherPatrickKuntz/auditrsdk/actions/workflows/ci.yml)\n[![node](https://img.shields.io/node/v/@auditrxyz/sdk.svg)](https://nodejs.org)\n\nTypeScript SDK for the [Auditr](https://auditr.xyz) x402 API. Submit\na request, settle the EIP-3009 payment over HTTP 402, receive a\nstructured Web3 security audit. No API keys. No accounts. No human\nreview.\n\n## Install\n\n```bash\nnpm install @auditrxyz/sdk\n```\n\nNode 18 or newer. Works in the browser when paired with a wallet\nthat can sign EIP-3009 typed data.\n\n## Quick start\n\n```ts\nimport { Auditr } from '@auditrxyz/sdk';\nimport { mySigner } from './my-signer.js';\n\nconst auditr = new Auditr({ signer: mySigner });\n\nconst created = await auditr.audits.web3({\n  scanType: 'site',\n  target: 'https://example.com',\n  tosAccepted: true,\n});\n\nconst report = await auditr.audits.waitForCompletion(created.auditId);\n\nconsole.log(report.grade, report.severityCounts);\nfor (const finding of report.findings) {\n  console.log(`[${finding.severity}] ${finding.title}`);\n}\n```\n\n## What the SDK covers\n\n### Audits\n\n| Method                              | Tier            | Price   |\n| ----------------------------------- | --------------- | ------- |\n| `auditr.audits.quick(req)`          | Quick site scan | $1 USDC |\n| `auditr.audits.standard(req)`       | Standard site scan | $10 USDC |\n| `auditr.audits.web3(req)`           | Project audit (site + contract + token + wallets) | $25 USDC |\n| `auditr.audits.get(id)`             | Fetch the current report state | Free |\n| `auditr.audits.waitForCompletion(id)` | Poll until terminal | Free |\n\n### Monitoring\n\n| Method                                | Tier         | Price       |\n| ------------------------------------- | ------------ | ----------- |\n| `auditr.monitoring.basic(req)`        | Basic        | $10 USDC/mo |\n| `auditr.monitoring.pro(req)`          | Pro          | $25 USDC/mo |\n| `auditr.monitoring.enterprise(req)`   | Enterprise   | $50 USDC/mo |\n\n### Facilitator API (pay-as-you-go)\n\nRun x402 (verify + settle) through our facilitator at\n`https://facilitator.auditr.xyz` instead of operating one yourself.\nPay-as-you-go: each settle debits actual chain gas (in USDC) from a\nprepaid balance. No subscription, no markup, no account. 25 free\nSolana settles/month per wallet.\n\n| Method                                  | Price (USDC) | Notes |\n| --------------------------------------- | ------------ | ----- |\n| `auditr.facilitator.trial(req)`         | Free         | 25 settles/month, Solana-only, bound to a signed wallet |\n| `auditr.facilitator.topup({ keyId })`   | $10          | Credits 10,000,000 atomic USDC. Never expires. |\n| `auditr.facilitator.supported()`        | Free         | x402 discovery |\n| `auditr.facilitator.adminInfo(token)`   | Free         | Read balance + free quota usage |\n| `auditr.facilitator.pricing()`          | -            | Version-baked pricing snapshot |\n\n```ts\nimport { Auditr, buildTrialAuthMessage } from '@auditrxyz/sdk';\n\n// 1. Build + sign the canonical trial-authorization message with\n//    your wallet (EIP-191 for EVM, ed25519 for Solana).\n//    `buildTrialAuthMessage` is a byte-exact mirror of the server\n//    verifier, so a successful build guarantees a successful verify\n//    on the server.\nconst timestamp = new Date().toISOString();\nconst nonce = Array.from(\n  crypto.getRandomValues(new Uint8Array(16)),\n  (b) => b.toString(16).padStart(2, '0'),\n).join('');\n\nconst message = buildTrialAuthMessage({\n  walletAddress,\n  walletNetwork: 'svm',\n  timestamp,\n  nonce,\n});\nconst signature = await wallet.signMessage(message);\n\n// 2. Mint a wallet-bound trial key.\nconst key = await auditr.facilitator.trial({\n  label: 'my bot',\n  ownerContact: 'me@example.com',\n  walletAddress,\n  walletNetwork: 'svm',\n  timestamp,\n  nonce,\n  signature,\n});\n\n// 3. Top up when you need more credits.\nawait auditr.facilitator.topup({ keyId: key.keyId });\n\n// 4. Wire it into any x402-aware client. Python via x402-py:\n//\n//   bearer = {\"Authorization\": f\"Bearer {key.token}\"}\n//   auth = CreateHeadersAuthProvider(\n//       lambda: {\"verify\": bearer, \"settle\": bearer, \"supported\": {}}\n//   )\n//   facilitator = HTTPFacilitatorClient(\n//       FacilitatorConfig(url=\"https://facilitator.auditr.xyz\", auth_provider=auth)\n//   )\n```\n\n**Free quota is Solana-only.** A trial key bound to `walletNetwork: 'evm'`\nhas zero free settlements; it exists so you can `topup()` and then settle\non Base from your prepaid balance. Mint with `walletNetwork: 'svm'` if you\nwant the 25 free Solana settles per month.\n\nEach settle response includes the actual gas debited in USDC and an\n`ata_created` flag (Solana ATA rent is debited only on first-time\nrecipients). When the prepaid balance is exhausted, `/settle`\nreturns **HTTP 409 `topup_required`** (deliberately NOT 402, so x402\nclient middleware doesn't auto-loop into a new payment challenge).\nA gas circuit breaker returns **503 with `Retry-After`** during L1\nspikes or degraded price feeds. See\n[examples/facilitator-trial.ts](examples/facilitator-trial.ts) and\n[examples/facilitator-topup.ts](examples/facilitator-topup.ts) for\nworking snippets.\n\nThe SDK handles the HTTP 402 dance for you. A `POST` to a paid\nendpoint without a `PAYMENT-SIGNATURE` header receives a 402 with a\n`PAYMENT-REQUIRED` challenge. The SDK decodes the challenge, hands\nit to your `PaymentSigner`, and retries with the signed\n`PAYMENT-SIGNATURE`. The facilitator settles the payment on chain.\nYour code sees only the final result.\n\n## Bring your own signer\n\nThe SDK does not bundle a wallet. You supply an implementation of:\n\n```ts\ninterface PaymentSigner {\n  sign(challenge: PaymentRequired, accept: PaymentAccept): Promise<string>;\n}\n```\n\nThe returned string is the base64 value sent in the\n`PAYMENT-SIGNATURE` header. The `examples/` directory ships two\nreference implementations:\n\n- `examples/coinbase-agent-kit.ts` wraps Coinbase Agent Kit's\n  payment helper.\n- `examples/manual-eip3009.ts` builds the EIP-3009\n  `transferWithAuthorization` from scratch with a viem-compatible\n  wallet.\n\n## Validation\n\nEvery API response is validated against a Zod schema before being\nreturned. A mismatch raises `ValidationError` with the underlying\nschema failure as `cause`. Import the schema independently if you\nneed to validate stored or relayed reports:\n\n```ts\nimport { auditReportSchema } from '@auditrxyz/sdk/schema';\n\nconst parsed = auditReportSchema.parse(json);\n```\n\n## Errors\n\n| Error                  | When                                              |\n| ---------------------- | ------------------------------------------------- |\n| `PaymentRequiredError` | Internal 402 signal. Only seen if you call the `@internal` helpers directly. |\n| `SignerError`          | The `PaymentSigner` threw or returned invalid data |\n| `HttpError`            | Non 2xx response from the API                     |\n| `TimeoutError`         | `waitForCompletion` exceeded its budget           |\n| `ValidationError`      | Response failed schema validation                 |\n\nAll extend `AuditrError`.\n\n## Why x402\n\nx402 is a standard HTTP based payment protocol. The audit endpoints\nreturn `402 Payment Required` with structured challenges that a\nmachine can sign without human intervention. The facilitator settles\nthe on chain transfer, then your audit runs. Combined with EIP-3009\nthis is the cheapest known way to bill an autonomous agent without\ndeploying a smart contract on your side.\n\nSee [docs/x402-flow.md](docs/x402-flow.md) for the full request and\nresponse sequence.\n\n## Architecture\n\nThe SDK is a thin client. The runtime behavior (analyzer choice,\ngrading, summary generation) is governed by the Auditr backend. See\n[ARCHITECTURE.md](ARCHITECTURE.md) for the boundary the SDK respects.\n\n## Versioning\n\nThis package follows semantic versioning. Breaking changes ship in\nmajor releases with at least one prior minor that emits deprecation\nwarnings.\n\n## Security\n\nSee [SECURITY.md](SECURITY.md) for the security policy and\ndisclosure process.\n\n## License\n\nApache 2.0. See [LICENSE](LICENSE).\n","readmeFilename":"README.md"}