{"_id":"@bedrockgovernance/notary","name":"@bedrockgovernance/notary","dist-tags":{"latest":"0.2.0"},"versions":{"0.2.0":{"name":"@bedrockgovernance/notary","version":"0.2.0","description":"Hash and signature engine for the Bedrock immutable advice ledger — computes and verifies record hashes, chain hashes and ECDSA P-256 signatures.","license":"Apache-2.0","author":{"name":"Luke Bettridge"},"homepage":"https://bedrockgovernance.com/docs/concepts/notary","repository":{"type":"git","url":"git+https://github.com/bedrockgovernance/notary.git"},"bugs":{"url":"https://github.com/bedrockgovernance/notary/issues"},"keywords":["bedrock","ledger","verification","audit","immutable","ecdsa","p-256","consumer-duty","fca","compliance","hash-chain","canonical-json"],"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"engines":{"node":">=18"},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","test":"vitest run --coverage","test:watch":"vitest","lint":"eslint --ext .ts src/","gen:fixtures":"tsx scripts/gen-fixtures.ts","prepare":"tsc"},"dependencies":{},"devDependencies":{"@types/node":"^20.0.0","@typescript-eslint/eslint-plugin":"^7.0.0","@typescript-eslint/parser":"^7.0.0","@vitest/coverage-v8":"^1.2.0","eslint":"^8.56.0","tsx":"^4.7.0","typescript":"^5.3.0","vitest":"^1.2.0"},"gitHead":"aff4da42f2f2f72a3c3e54992dc2778039233714","_id":"@bedrockgovernance/notary@0.2.0","_nodeVersion":"25.8.1","_npmVersion":"11.12.1","dist":{"integrity":"sha512-NI2SR7u3KIV7hb0WPhS3h42vGZ02pMyv198clNpUztc7+PI3nPapaFysfl3H8cEDhTZSce+6MQFVp3dClxY8Eg==","shasum":"365d2d69cdeff514f65bd4c5c259bb48d9c1e04e","tarball":"https://registry.npmjs.org/@bedrockgovernance/notary/-/notary-0.2.0.tgz","fileCount":37,"unpackedSize":67099,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFEmLo+zy9RF2qXyZihEwY596MGM856xW914nyyFHA0UAiEAlgKumXhuYT63EYmWy45WKV5twd41ZIgzrGthOvjJhv4="}]},"_npmUser":{"name":"lukebettridge","email":"luke.bettridge@outlook.com"},"directories":{},"maintainers":[{"name":"lukebettridge","email":"luke.bettridge@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/notary_0.2.0_1783694348104_0.36368814554638673"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-10T14:39:07.927Z","0.2.0":"2026-07-10T14:39:08.248Z","modified":"2026-07-10T14:39:08.488Z"},"maintainers":[{"name":"lukebettridge","email":"luke.bettridge@outlook.com"}],"description":"Hash and signature engine for the Bedrock immutable advice ledger — computes and verifies record hashes, chain hashes and ECDSA P-256 signatures.","homepage":"https://bedrockgovernance.com/docs/concepts/notary","keywords":["bedrock","ledger","verification","audit","immutable","ecdsa","p-256","consumer-duty","fca","compliance","hash-chain","canonical-json"],"repository":{"type":"git","url":"git+https://github.com/bedrockgovernance/notary.git"},"author":{"name":"Luke Bettridge"},"bugs":{"url":"https://github.com/bedrockgovernance/notary/issues"},"license":"Apache-2.0","readme":"# @bedrockgovernance/notary\n\n> The hash and signature engine behind the\n> [Bedrock](https://bedrockgovernance.com) immutable advice ledger.\n\n`@bedrockgovernance/notary` contains the canonical JSON serialiser, the\nrecord and chain hash functions, and the ECDSA P-256 signature\nverifier that underpin the Bedrock ledger. The Bedrock platform\nimports it on both the **write path** (computing hashes when records\nare created) and the **verify path** (checking signatures when\ncertificates are verified), so there is no internal copy of the\nalgorithm — anyone running this package is running the same code\nthat runs in production.\n\nNo signing implementations, no private keys, no networking.\n\n[![License: Apache 2.0](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\n## Install\n\n```sh\nnpm install @bedrockgovernance/notary\n```\n\n## Quickstart\n\n### Compute a record hash (same function the Bedrock writer uses)\n\n```ts\nimport { computeRecordHash, computeChainHash, GENESIS_HASH } from '@bedrockgovernance/notary';\n\nconst recordHash = computeRecordHash(payload);\nconst chainHash = computeChainHash(recordHash, previousHash ?? GENESIS_HASH);\n```\n\n### Verify a certificate\n\n```ts\nimport { verifyCertificate } from '@bedrockgovernance/notary';\n\nconst response = await fetch(\n  `https://api.bedrockgovernance.com/v1/verify/${certificateId}`,\n);\nconst { certificate, record } = await response.json();\n\nconst result = verifyCertificate({ certificate, record });\nif (!result.valid) {\n  throw new Error(`Certificate invalid: ${result.reason}`);\n}\n```\n\n### Verify a chain\n\n```ts\nimport { verifyChain } from '@bedrockgovernance/notary';\n\nconst result = verifyChain(records, firmId);\n```\n\n## API\n\n**Compute:**\n- `canonicalise(value)` — Bedrock's canonical JSON serialiser.\n- `sha256(string)` / `sha256Buffer(buffer)` — SHA-256 helpers.\n- `computeRecordHash(payload)` — `sha256(canonicalise(payload))`.\n- `computeChainHash(recordHash, previousHash)` — chain binding.\n\n**Verify:**\n- `verifyChain(records, firmId)` — full chain integrity check.\n- `verifySignature(record, options?)` — ECDSA P-256 verification\n  with optional `trustedPublicKey` pinning.\n- `verifyCertificate(input, options?)` — end-to-end certificate check.\n\n**Constants:**\n- `GENESIS_HASH`, `SIGNING_ALGORITHM`, `ChainInvalidReason`, `Signer`.\n\n## License\n\n[Apache 2.0](./LICENSE). See [`SECURITY.md`](./SECURITY.md) for\nvulnerability reporting.\n","readmeFilename":"README.md","_rev":"1-a945e5f1225ba5bccd8abd81ae46115a"}