{"_id":"@axiorank/wix","name":"@axiorank/wix","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@axiorank/wix","version":"0.1.0","description":"AxioRank for Wix: verify and govern the AI agents that reach a Wix site. A thin client of the AxioRank inbound verify endpoint, with an Astro request middleware for Wix-managed headless projects.","license":"MIT","homepage":"https://axiorank.com","author":{"name":"AxioRank"},"type":"module","keywords":["wix","wix-headless","astro","astro-middleware","ai-agents","bot-verification","web-bot-auth","axiorank"],"main":"./dist/index.js","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./astro":{"types":"./dist/astro/index.d.ts","import":"./dist/astro/index.js"},"./crypto":{"types":"./dist/crypto/index.d.ts","import":"./dist/crypto/index.js"}},"sideEffects":false,"scripts":{"build":"tsup","typecheck":"tsc --noEmit","test":"vitest run","prepublishOnly":"tsup"},"engines":{"node":">=20.10.0"},"devDependencies":{"@types/node":"22.19.19","tsup":"8.5.1","typescript":"6.0.3","vitest":"4.1.8"},"_id":"@axiorank/wix@0.1.0","gitHead":"7c0f8016574b726844062b342bc64bf5f9efb742","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-T5NhWIwqLexVTZ//ef5y5WnzyzQcFc7GVmLatoTIkQz+tV7bZG0yvw/Wux8UUyyYi9PV9xRHcXVPNKILn3857w==","shasum":"9e2a4ed3255b734dc5aa9bbdfd094f79c008c488","tarball":"https://registry.npmjs.org/@axiorank/wix/-/wix-0.1.0.tgz","fileCount":14,"unpackedSize":83900,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC39wcB/5ggx9hkuOsxKCFEKT2VQW0qI3xs9eSzohU2mwIgZYDDxROzU13959c4hd5PVZfJFCDGbvj5qKAmnMk6RAU="}]},"_npmUser":{"name":"tejaswi.s","email":"tejaswi33@gmail.com"},"directories":{},"maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wix_0.1.0_1783452390276_0.28032964325347454"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-07T19:26:30.029Z","0.1.0":"2026-07-07T19:26:30.408Z","modified":"2026-07-07T19:26:30.692Z"},"maintainers":[{"name":"tejaswi.s","email":"tejaswi33@gmail.com"}],"description":"AxioRank for Wix: verify and govern the AI agents that reach a Wix site. A thin client of the AxioRank inbound verify endpoint, with an Astro request middleware for Wix-managed headless projects.","homepage":"https://axiorank.com","keywords":["wix","wix-headless","astro","astro-middleware","ai-agents","bot-verification","web-bot-auth","axiorank"],"author":{"name":"AxioRank"},"license":"MIT","readme":"# @axiorank/wix\n\nVerify and govern the AI agents that reach your Wix site with [AxioRank](https://axiorank.com), the security gateway for AI agents.\n\nThis package is a thin, fail-open client of the AxioRank inbound verify endpoint. It ships two things:\n\n- **The verify core**, shared with the AxioRank Wix App Market app: the request-envelope builder, the verify client, the bot-suspect gate, and the agent-rule model.\n- **An Astro request middleware** for Wix-managed headless projects, so every inbound request is verified server-side. This is the one place on Wix where AxioRank can enforce at the edge (a hosted Wix app cannot intercept requests; a headless Astro project owns its pipeline).\n\n## Install\n\n```bash\nnpm install @axiorank/wix\n```\n\n## Headless: verify every request\n\nWix-managed headless projects run on Astro. Add a `src/middleware.ts`:\n\n```ts\nimport { createAxioRankMiddleware } from \"@axiorank/wix/astro\";\n\nexport const onRequest = createAxioRankMiddleware({\n  siteKey: import.meta.env.AXIORANK_SITE_KEY,\n});\n```\n\nThen set your site key. Create a **Website** surface in the AxioRank dashboard (Inbound, then Surfaces), copy the `axr_site_...` key it shows once, and add it to your environment:\n\n```bash\n# .env\nAXIORANK_SITE_KEY=axr_site_xxxxxxxx\n```\n\nThat is it. By default the middleware only calls out for signed agents and bot-like user-agents, so ordinary visitors are never slowed down. It fails open: if the key is missing or AxioRank is unreachable, your site serves normally. Enforcement (block or challenge) happens only when the surface is in `enforce` posture, which you control from the AxioRank dashboard or the Wix app.\n\n### Options\n\n```ts\ncreateAxioRankMiddleware({\n  siteKey: import.meta.env.AXIORANK_SITE_KEY,\n  baseUrl: \"https://app.axiorank.com\", // apex host, the default\n  mode: \"auto\",                        // \"auto\" (signed or bot-like) or \"all\"\n  scopeBotUa: true,                    // verify bot-like user-agents\n  classifyScope: (url) =>              // optionally treat certain paths as sensitive\n    url.pathname.startsWith(\"/checkout\") ? \"checkout\" : null,\n  onVerdict: (verdict, url) => {       // optional telemetry hook\n    console.log(url.pathname, verdict.decision, verdict.verification.status);\n  },\n});\n```\n\n> Note on the apex host: point `baseUrl` at `https://app.axiorank.com`. A `www` host 308-redirects and drops the `Authorization` header.\n\n## Hosted Wix sites\n\nEditor and Studio sites cannot run third-party request middleware. Install the **AxioRank Agent Verification** app from the Wix App Market instead: it manages your agent rules in the dashboard, detects AI agents on your live site, and exposes a verify endpoint your own code can call. See the [Wix integration docs](https://app.axiorank.com/docs/integrations/wix).\n\n## Core exports\n\n`@axiorank/wix` also exports the framework-independent core:\n\n- `verifyRequest`, `postEnvelope`, `failOpen`, `isFailOpen`\n- `buildWebsiteEnvelope`, `collectHeaders`, `firstForwardedValue`\n- `shouldVerify`, `isBotUa`, `isSigned`, `BOT_UA_PATTERN`\n- the surface control-plane client: `listSurfacePolicies`, `createSurfacePolicy`, `getPosture`, `setPosture`, and more\n- the agent-rule model: `buildRuleInput`, `ruleConditionLabel`, `defaultRuleName`, and friends\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-969f3225d6dc69ca61b37b3e42f33d3c"}