{"_id":"@bedrockcompliance/notary","_rev":"3-47d07f88056da8c0048b494b0d5f548f","name":"@bedrockcompliance/notary","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@bedrockcompliance/notary","version":"0.1.0","keywords":["bedrock","ledger","verification","audit","immutable","ecdsa","p-256","consumer-duty","fca","compliance","hash-chain","canonical-json"],"author":{"name":"Luke Bettridge"},"license":"Apache-2.0","_id":"@bedrockcompliance/notary@0.1.0","maintainers":[{"name":"lukebettridge","email":"lukebettridge@hotmail.co.uk"}],"homepage":"https://bedrockcompliance.co.uk/docs/concepts/notary","bugs":{"url":"https://github.com/bedrockcompliance/notary/issues"},"dist":{"shasum":"7bcb39e7eb30b2d289a9a698ba20400588dd7245","tarball":"https://registry.npmjs.org/@bedrockcompliance/notary/-/notary-0.1.0.tgz","fileCount":37,"integrity":"sha512-yLL331WmmRjtSlHRns6aLor80l/395VUeVUPIDQRRx+8fTCATeU6ogwvlCRBQ3wUJy96Kx8DW2Hk2e80UGm0Ow==","signatures":[{"sig":"MEYCIQDB3stFdVMYo/PIgrH/O/zhI4X2fabi4ESzXwpIkI9ZQwIhALr+32HzPVWeL91Ix5vfIIHvug7YOtq0cAMF3pcUcL3y","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61294},"main":"./dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"5cdebbef3ce315a595a48eac17df704f2134cacc","scripts":{"lint":"eslint --ext .ts src/","test":"vitest run --coverage","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit","test:watch":"vitest","gen:fixtures":"tsx scripts/gen-fixtures.ts"},"_npmUser":{"name":"lukebettridge","email":"lukebettridge@hotmail.co.uk"},"repository":{"url":"git+https://github.com/bedrockcompliance/notary.git","type":"git"},"_npmVersion":"11.12.1","description":"Hash and signature engine for the Bedrock immutable advice ledger — computes and verifies record hashes, chain hashes and ECDSA P-256 signatures.","directories":{},"_nodeVersion":"25.8.1","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","eslint":"^8.56.0","vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^20.0.0","@vitest/coverage-v8":"^1.2.0","@typescript-eslint/parser":"^7.0.0","@typescript-eslint/eslint-plugin":"^7.0.0"},"_npmOperationalInternal":{"tmp":"tmp/notary_0.1.0_1775742235282_0.028644954995323157","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @bedrockgovernance/notary"},"0.1.1":{"name":"@bedrockcompliance/notary","version":"0.1.1","keywords":["bedrock","ledger","verification","audit","immutable","ecdsa","p-256","consumer-duty","fca","compliance","hash-chain","canonical-json"],"author":{"name":"Luke Bettridge"},"license":"Apache-2.0","_id":"@bedrockcompliance/notary@0.1.1","maintainers":[{"name":"lukebettridge","email":"lukebettridge@hotmail.co.uk"}],"homepage":"https://bedrockcompliance.co.uk/docs/concepts/notary","bugs":{"url":"https://github.com/bedrockcompliance/notary/issues"},"dist":{"shasum":"4059ec9bf857dd35523483402c75c4442f19cf86","tarball":"https://registry.npmjs.org/@bedrockcompliance/notary/-/notary-0.1.1.tgz","fileCount":37,"integrity":"sha512-IhVwoZGa+wGRV29SXoDqXJE1I7esjQ8t0dINxp8xkjBBotQn6XZ8HmYxESpZo90PJwAD3ce69QCgIpX+AKbTsA==","signatures":[{"sig":"MEUCIQD5zuAhECF5p9WhtFtYCyMHRzLaLGRWfdKRpFLmjp83nwIgfzW5XMAKwQOdz1PKXk/a4ZSFfzwreGZrBZJBZbfcoVI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bedrockcompliance%2fnotary@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":63680},"main":"./dist/index.js","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"7007d6e714189cf8bffe0aed064439e09e61af74","scripts":{"lint":"eslint --ext .ts src/","test":"vitest run --coverage","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit","test:watch":"vitest","gen:fixtures":"tsx scripts/gen-fixtures.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:8d91aefa-eca7-4405-84de-278f6d957e7f"}},"repository":{"url":"git+https://github.com/bedrockcompliance/notary.git","type":"git"},"_npmVersion":"11.12.1","description":"Hash and signature engine for the Bedrock immutable advice ledger — computes and verifies record hashes, chain hashes and ECDSA P-256 signatures.","directories":{},"_nodeVersion":"20.20.2","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","eslint":"^8.56.0","vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^20.0.0","@vitest/coverage-v8":"^1.2.0","@typescript-eslint/parser":"^7.0.0","@typescript-eslint/eslint-plugin":"^7.0.0"},"_npmOperationalInternal":{"tmp":"tmp/notary_0.1.1_1775811551994_0.1775065537477749","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @bedrockgovernance/notary"}},"time":{"created":"2026-04-09T13:43:55.172Z","modified":"2026-07-10T14:43:02.749Z","0.1.0":"2026-04-09T13:43:55.423Z","0.1.1":"2026-04-10T08:59:12.142Z"},"bugs":{"url":"https://github.com/bedrockcompliance/notary/issues"},"author":{"name":"Luke Bettridge"},"license":"Apache-2.0","homepage":"https://bedrockcompliance.co.uk/docs/concepts/notary","keywords":["bedrock","ledger","verification","audit","immutable","ecdsa","p-256","consumer-duty","fca","compliance","hash-chain","canonical-json"],"repository":{"url":"git+https://github.com/bedrockcompliance/notary.git","type":"git"},"description":"Hash and signature engine for the Bedrock immutable advice ledger — computes and verifies record hashes, chain hashes and ECDSA P-256 signatures.","maintainers":[{"name":"lukebettridge","email":"lukebettridge@hotmail.co.uk"}],"readme":"# @bedrockcompliance/notary\n\n> The hash and signature engine behind the\n> [Bedrock](https://bedrockcompliance.co.uk) immutable advice ledger.\n\n`@bedrockcompliance/notary` contains the canonical JSON serialiser, the\nrecord and chain hash functions, and the ECDSA P-256 signature\nverifier that underpin the Bedrock ledger. The Bedrock platform\nimports it on both the **write path** (computing hashes when records\nare created) and the **verify path** (checking signatures when\ncertificates are verified), so there is no internal copy of the\nalgorithm — anyone running this package is running the same code\nthat runs in production.\n\nNo signing implementations, no private keys, no networking.\n\n[![License: Apache 2.0](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\n## Install\n\n```sh\nnpm install @bedrockcompliance/notary\n```\n\n## Quickstart\n\n### Compute a record hash (same function the Bedrock writer uses)\n\n```ts\nimport { computeRecordHash, computeChainHash, GENESIS_HASH } from '@bedrockcompliance/notary';\n\nconst recordHash = computeRecordHash(payload);\nconst chainHash = computeChainHash(recordHash, previousHash ?? GENESIS_HASH);\n```\n\n### Verify a certificate\n\n```ts\nimport { verifyCertificate } from '@bedrockcompliance/notary';\n\nconst response = await fetch(\n  `https://api.bedrockcompliance.co.uk/v1/verify/${certificateId}`,\n);\nconst { certificate, record } = await response.json();\n\nconst result = verifyCertificate({ certificate, record });\nif (!result.valid) {\n  throw new Error(`Certificate invalid: ${result.reason}`);\n}\n```\n\n### Verify a chain\n\n```ts\nimport { verifyChain } from '@bedrockcompliance/notary';\n\nconst result = verifyChain(records, firmId);\n```\n\n## API\n\n**Compute:**\n- `canonicalise(value)` — Bedrock's canonical JSON serialiser.\n- `sha256(string)` / `sha256Buffer(buffer)` — SHA-256 helpers.\n- `computeRecordHash(payload)` — `sha256(canonicalise(payload))`.\n- `computeChainHash(recordHash, previousHash)` — chain binding.\n\n**Verify:**\n- `verifyChain(records, firmId)` — full chain integrity check.\n- `verifySignature(record, options?)` — ECDSA P-256 verification\n  with optional `trustedPublicKey` pinning.\n- `verifyCertificate(input, options?)` — end-to-end certificate check.\n\n**Constants:**\n- `GENESIS_HASH`, `SIGNING_ALGORITHM`, `ChainInvalidReason`, `Signer`.\n\n## License\n\n[Apache 2.0](./LICENSE). See [`SECURITY.md`](./SECURITY.md) for\nvulnerability reporting.\n","readmeFilename":"README.md"}