{"_id":"@awarevue/license-verifier","name":"@awarevue/license-verifier","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@awarevue/license-verifier","version":"1.0.0","description":"Read, validate and cryptographically verify AwareVue license files in Node.js.","license":"MIT","author":{"name":"Linc Security Systems"},"repository":{"type":"git","url":"git+https://github.com/Linc-Security-Systems/partner-network.git","directory":"packages/license-verifier"},"homepage":"https://github.com/Linc-Security-Systems/partner-network/tree/main/packages/license-verifier#readme","bugs":{"url":"https://github.com/Linc-Security-Systems/partner-network/issues"},"keywords":["license","licensing","ed25519","signature","verification","awarevue"],"type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"engines":{"node":">=18"},"sideEffects":false,"publishConfig":{"access":"public"},"scripts":{"build":"tsup","clean":"rm -rf dist","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest","prepublishOnly":"npm run clean && npm run build && npm run test"},"devDependencies":{"@types/node":"^20.11.0","tsup":"^8.0.2","typescript":"^5.3.3","vitest":"^1.6.0"},"_id":"@awarevue/license-verifier@1.0.0","gitHead":"029eb590fc3a35458aa73106b20ec77d7de09a00","_nodeVersion":"22.21.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-Lv46lvmb/hK/v0t9NVgKg8k4drKggqn7jytKaFwENDbwg79HLYjU/E2m2cwpWnEoXGoUtjxBWWAMHW/FK4Ccaw==","shasum":"a49b72cf39c6ff1bfe3f6449095cec4946bf2eeb","tarball":"https://registry.npmjs.org/@awarevue/license-verifier/-/license-verifier-1.0.0.tgz","fileCount":9,"unpackedSize":112622,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIECoFeHgf/8A5j7vBqktYJCiTx/Mfd7REmTKDhJZLdNSAiEAg/pQS8dHCM8HmI6UrPHdw6jr1WPmEADbNiYeq30HIIo="}]},"_npmUser":{"name":"yaserawajan","email":"yaser@linc.uk.com"},"directories":{},"maintainers":[{"name":"yaserawajan","email":"yaser@linc.uk.com"},{"name":"markleonard","email":"m.leonard@linc.uk.com"},{"name":"vania.toperich","email":"vania@linc.uk.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/license-verifier_1.0.0_1785403308255_0.7298126112149173"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-30T09:21:48.036Z","1.0.0":"2026-07-30T09:21:48.389Z","modified":"2026-07-30T09:21:48.635Z"},"maintainers":[{"name":"yaserawajan","email":"yaser@linc.uk.com"},{"name":"markleonard","email":"m.leonard@linc.uk.com"},{"name":"vania.toperich","email":"vania@linc.uk.com"}],"description":"Read, validate and cryptographically verify AwareVue license files in Node.js.","homepage":"https://github.com/Linc-Security-Systems/partner-network/tree/main/packages/license-verifier#readme","keywords":["license","licensing","ed25519","signature","verification","awarevue"],"repository":{"type":"git","url":"git+https://github.com/Linc-Security-Systems/partner-network.git","directory":"packages/license-verifier"},"author":{"name":"Linc Security Systems"},"bugs":{"url":"https://github.com/Linc-Security-Systems/partner-network/issues"},"license":"MIT","readme":"# @awarevue/license-verifier\n\nRead, validate and cryptographically verify AwareVue license files in Node.js.\n\nLicense files are issued from the AwareVue partner portal and downloaded as\n`LIC-XXXXXXXX.license.json`. This package reads such a file, checks its Ed25519\nsignature, and gives you typed access to the entitlements it grants.\n\n```sh\nnpm install @awarevue/license-verifier\n```\n\nRequires Node.js 18 or later. No runtime dependencies. Ships ESM and CommonJS builds.\n\n## Usage\n\n```ts\nimport { readLicenseFile } from '@awarevue/license-verifier';\n\nconst license = await readLicenseFile('/etc/awarevue/site.license.json', {\n  publicKey: process.env.AWAREVUE_LICENSE_PUBLIC_KEY!,\n});\n\nconsole.log(license.licenseNumber);        // 'LIC-4KQ7T2WM'\nconsole.log(license.accountName);          // 'Acme Security Ltd'\nconsole.log(license.siteName);             // 'Main Office'\nconsole.log(license.getQuantity('camera')); // 64\nconsole.log(license.hasComponent('awarevue')); // true\nconsole.log(license.isCareActive());       // true\n```\n\n`readLicenseFile` throws if the signature does not verify, so any license you hold\nafterwards is authentic. Use `safeVerifyLicense` if you would rather branch on a\nresult than catch.\n\n```ts\nimport { readFileSync } from 'node:fs';\nimport { safeVerifyLicense } from '@awarevue/license-verifier';\n\nconst result = safeVerifyLicense(JSON.parse(readFileSync(path, 'utf8')), { publicKey });\n\nif (!result.ok) {\n  console.error(`License rejected: ${result.error.message}`);\n  process.exit(1);\n}\n```\n\n## Supplying the public key\n\n**The public key does not come from the license file.** The file carries only a\n`keyId` naming which key signed it. Your application must supply the key from a\nsource you trust — an environment variable, your config system, or a file you ship.\n\nThis is what makes the signature meaningful. If the key travelled inside the file,\nanyone could edit the entitlements, sign the result with a key of their own, and\nattach that key. Verification would pass and the signature would prove nothing.\n\nThe key is accepted as a PEM string, a base64-wrapped PEM string (the same form the\nportal backend stores in `LICENSE_SIGNING_PUBLIC_KEY_BASE64`), a `Buffer`, or a\n`crypto.KeyObject`.\n\nTo trust more than one key during a rotation, pass a map and the right key will be\nselected by `keyId`:\n\n```ts\nconst license = await readLicenseFile(path, {\n  publicKey: {\n    'awarevue-2025-key': OLD_KEY_PEM,\n    'awarevue-2026-key': NEW_KEY_PEM,\n  },\n});\n```\n\nPass `expectedKeyId` to pin a single key and reject anything else.\n\n## Entitlements\n\nLicenses grant two kinds of subject: `ASSET_TYPE` (physical devices such as cameras\nand doors) and `SOFTWARE_COMPONENT` (licensable software).\n\n```ts\nlicense.entitlements;        // every grant\nlicense.assetTypes;          // ASSET_TYPE grants only\nlicense.softwareComponents;  // SOFTWARE_COMPONENT grants only\n\nlicense.getQuantity('camera');                    // across both types\nlicense.getQuantity('gateway', 'ASSET_TYPE');     // disambiguated\nlicense.hasComponent('awarevue');\nlicense.hasAssetType('camera');\n```\n\nQuantities are a **snapshot taken when the file was generated**. If a time-boxed\ngrant was active at that moment its quantity is included, and the file will keep\nreporting it after that grant lapses. Regenerate the license in the portal to get\ncurrent figures.\n\n## Care coverage\n\nSoftware ownership is perpetual: an expired care enrollment never revokes an\nentitlement. Care covers support and updates, and is the only part of a license with\na validity window.\n\n```ts\nlicense.isCareActive();                              // now\nlicense.isCareActive(new Date('2027-06-01'));        // at a given moment\nlicense.careWindow;                                  // { status, reason, startDate, endDate } | null\n```\n\n`careWindow` is `null` when the site has no active enrollment. Boundaries are\ninclusive.\n\n## Errors\n\nAll errors extend `LicenseError`:\n\n| Error | Meaning |\n| --- | --- |\n| `LicenseFileError` | Unreadable, oversized, or not valid JSON |\n| `LicenseFormatError` | Parsed, but not shaped like a license |\n| `UnsupportedAlgorithmError` | Declares an algorithm other than Ed25519 |\n| `UnsupportedSchemaVersionError` | Payload is newer than this package understands |\n| `LicenseKeyError` | Key missing, malformed, not Ed25519, or `keyId` not trusted |\n| `LicenseSignatureError` | Signature does not match the payload |\n\n## Scope\n\nVerification is entirely offline: this package makes no network calls. It therefore\ncannot know whether a license was revoked or suspended after it was issued. If that\nmatters, check licence status against the portal API separately.\n\nSigning is not included. Private keys stay on the portal backend.\n\n## API\n\n| Export | Description |\n| --- | --- |\n| `readLicenseFile(path, options)` | Read and verify a file, async |\n| `readLicenseFileSync(path, options)` | Read and verify a file, sync |\n| `verifyLicenseString(json, options)` | Verify license JSON held as a string |\n| `verifyLicense(parsed, options)` | Verify an already-parsed object |\n| `safeVerifyLicense(parsed, options)` | As above, returning a result instead of throwing |\n| `License` | The verified license accessor |\n| `canonicalize(value)` | The canonical JSON used to derive signed bytes |\n\nOptions: `publicKey` (required), `expectedKeyId`, and `maxBytes` (file readers only,\ndefault 1 MiB).\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-0918cf9de9d5d5f43f8083d44af185bf"}