{"_id":"@bizbionic/x402-guard","_rev":"4-fb9e08c8bfe12ff89b5718aedf86a5d9","name":"@bizbionic/x402-guard","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@bizbionic/x402-guard","version":"0.1.0","keywords":["x402","guard","bizbionic","attestation","ed25519"],"author":{"name":"BizBionic"},"license":"MIT","_id":"@bizbionic/x402-guard@0.1.0","maintainers":[{"name":"bizbionic","email":"bizbionicguard@agentmail.to"}],"homepage":"https://guard.bizbionic.com/v1/agent.json","bugs":{"url":"https://github.com/davedn/x402-guard/issues"},"dist":{"shasum":"8b29fa02825edde7457c7250acd35dc770ebb107","tarball":"https://registry.npmjs.org/@bizbionic/x402-guard/-/x402-guard-0.1.0.tgz","fileCount":42,"integrity":"sha512-3P42L43exx/kV96fAud7m1UlHCAUlzYoV8nRhpD4hEtTTko8w00R4cZtpsg1Sig1k4VQT2vzKKBgZxYKQBjPyw==","signatures":[{"sig":"MEYCIQDuNiMWrAzUb/kBDGsMGL8kCNvHN5q33bGH/ew/pbMYRQIhAJtE0ZDGQzxJTcca4EQZZEJVfgTqlj4TxPOwO4TacU2s","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":72752},"main":"./src/index.ts","type":"module","types":"./src/index.ts","engines":{"node":">=20"},"exports":{".":{"types":"./src/index.ts","import":"./src/index.ts","default":"./src/index.ts"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"bizbionic","email":"bizbionicguard@agentmail.to"},"repository":{"url":"git+https://github.com/davedn/x402-guard.git","type":"git","directory":"packages/x402-guard"},"_npmVersion":"9.2.0","description":"Fail-closed npm client for BizBionic x402 Guard. Decide → verify short-TTL ed25519 attestation → only then sign PAYMENT-SIGNATURE.","directories":{},"_nodeVersion":"20.19.2","dependencies":{"@noble/hashes":"^1.8.0","@noble/ed25519":"^2.3.0"},"publishConfig":{"main":"./dist/index.js","types":"./dist/index.d.ts","access":"public","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}}},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2"},"_npmOperationalInternal":{"tmp":"tmp/x402-guard_0.1.0_1787544828989_0.2602336388144211","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@bizbionic/x402-guard","version":"0.1.1","keywords":["x402","guard","bizbionic","attestation","ed25519"],"author":{"name":"BizBionic"},"license":"MIT","_id":"@bizbionic/x402-guard@0.1.1","maintainers":[{"name":"bizbionic","email":"bizbionicguard@agentmail.to"}],"homepage":"https://guard.bizbionic.com/v1/agent.json","bugs":{"url":"https://github.com/davedn/x402-guard/issues"},"dist":{"shasum":"ad38ad0dd3fe91117fe1640b49f05d801c86c834","tarball":"https://registry.npmjs.org/@bizbionic/x402-guard/-/x402-guard-0.1.1.tgz","fileCount":42,"integrity":"sha512-/pIEigOV3NELogWOSdneAtEa6N6eic99U9pXAftqlE1Lv90WJHzBb1qOK20Uw8zZFqohqFeLhnNN/OH5wJd1RQ==","signatures":[{"sig":"MEUCIQDEKqyFIrXFNqbqW0E0NNCMFHXKZShp6ZMtmxF40S5OtgIgR5mFk0Lfx/vCldywvZ0GepKeTUKTHpQizJrwk5EKbmg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":72318},"main":"./src/index.ts","type":"module","types":"./src/index.ts","engines":{"node":">=20"},"exports":{".":{"types":"./src/index.ts","import":"./src/index.ts","default":"./src/index.ts"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"bizbionic","email":"bizbionicguard@agentmail.to"},"repository":{"url":"git+https://github.com/davedn/x402-guard.git","type":"git","directory":"packages/x402-guard"},"_npmVersion":"9.2.0","description":"Fail-closed npm client for BizBionic x402 Guard. Decide → verify short-TTL ed25519 attestation → only then sign PAYMENT-SIGNATURE.","directories":{},"_nodeVersion":"20.19.2","dependencies":{"@noble/hashes":"^1.8.0","@noble/ed25519":"^2.3.0"},"publishConfig":{"main":"./dist/index.js","types":"./dist/index.d.ts","access":"public","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}}},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2"},"_npmOperationalInternal":{"tmp":"tmp/x402-guard_0.1.1_1787545691300_0.9042890430559625","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@bizbionic/x402-guard","version":"0.1.2","keywords":["x402","guard","bizbionic","attestation","ed25519"],"author":{"name":"BizBionic"},"license":"MIT","_id":"@bizbionic/x402-guard@0.1.2","maintainers":[{"name":"bizbionic","email":"bizbionicguard@agentmail.to"}],"homepage":"https://guard.bizbionic.com/v1/agent.json","bugs":{"url":"https://github.com/davedn/x402-guard/issues"},"dist":{"shasum":"044d007c5ce5e45c551e7346746a2b205a6181ef","tarball":"https://registry.npmjs.org/@bizbionic/x402-guard/-/x402-guard-0.1.2.tgz","fileCount":42,"integrity":"sha512-Im/i/EIQFG/b7AIXT8mZjCCtiHDntcYQEl9PhqhLzNMdwLb5UXQaJgqvjWukSS/g+mz1OUMA3bRgDess8JMbtw==","signatures":[{"sig":"MEYCIQDD5CiECca1XXPPzSBsqneAk3MtPeDdP1gA1V1YKLsA9QIhAJUDYqKubNjSO31uApB7uLG/pV0pEPUjpQrfYZm0xp/7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":72712},"main":"./src/index.ts","type":"module","types":"./src/index.ts","engines":{"node":">=20"},"exports":{".":{"types":"./src/index.ts","import":"./src/index.ts","default":"./src/index.ts"}},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","prepublishOnly":"npm test && npm run build"},"_npmUser":{"name":"bizbionic","email":"bizbionicguard@agentmail.to"},"repository":{"url":"git+https://github.com/davedn/x402-guard.git","type":"git","directory":"packages/x402-guard"},"_npmVersion":"10.9.3","description":"Fail-closed npm client for BizBionic x402 Guard. Decide → verify short-TTL ed25519 attestation → only then sign PAYMENT-SIGNATURE.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"@noble/hashes":"^1.8.0","@noble/ed25519":"^2.3.0"},"publishConfig":{"main":"./dist/index.js","types":"./dist/index.d.ts","access":"public","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}}},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2"},"_npmOperationalInternal":{"tmp":"tmp/x402-guard_0.1.2_1787556608684_0.46356034716147176","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@bizbionic/x402-guard","version":"0.1.3","description":"Fail-closed npm client for BizBionic x402 Guard. Decide → verify short-TTL ed25519 attestation → only then sign PAYMENT-SIGNATURE.","type":"module","license":"MIT","author":{"name":"BizBionic"},"repository":{"type":"git","url":"git+https://github.com/davedn/x402-guard.git","directory":"packages/x402-guard"},"homepage":"https://guard.bizbionic.com/v1/agent.json","bugs":{"url":"https://github.com/davedn/x402-guard/issues"},"main":"./src/index.ts","types":"./src/index.ts","exports":{".":{"types":"./src/index.ts","import":"./src/index.ts","default":"./src/index.ts"}},"scripts":{"test":"vitest run","typecheck":"tsc --noEmit","build":"tsc -p tsconfig.build.json","prepublishOnly":"npm test && npm run build"},"dependencies":{"@noble/ed25519":"^2.3.0","@noble/hashes":"^1.8.0"},"devDependencies":{"typescript":"^5.9.2","vitest":"^3.2.4"},"engines":{"node":">=20"},"publishConfig":{"access":"public","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}}},"keywords":["x402","guard","bizbionic","attestation","ed25519"],"_id":"@bizbionic/x402-guard@0.1.3","_nodeVersion":"22.18.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-7aUfw2YNIECvJLjRcSD6xZ6l9O7Ht0YLhTeHI/LcdhR/RLOV5OT/zQBEEexkSBIoz/p7LVT/KVRlATvxmgC7ow==","shasum":"0efde882640fa335b17a961f0d460c486cff486e","tarball":"https://registry.npmjs.org/@bizbionic/x402-guard/-/x402-guard-0.1.3.tgz","fileCount":42,"unpackedSize":72596,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDiADp3fSzxkY0cJfZzj/bDQN2nWPknrrxb9TB4Q8VwrAIhANoJApRIkNCMt6vaSGiqjku4ECm7H8ANxnl3sNUVvX5e"}]},"_npmUser":{"name":"bizbionic","email":"bizbionicguard@agentmail.to"},"directories":{},"maintainers":[{"name":"bizbionic","email":"bizbionicguard@agentmail.to"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/x402-guard_0.1.3_1787589928053_0.4628400057405919"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-24T04:13:48.820Z","modified":"2026-08-24T16:45:28.385Z","0.1.0":"2026-08-24T04:13:49.123Z","0.1.1":"2026-08-24T04:28:11.425Z","0.1.2":"2026-08-24T07:30:08.820Z","0.1.3":"2026-08-24T16:45:28.196Z"},"bugs":{"url":"https://github.com/davedn/x402-guard/issues"},"author":{"name":"BizBionic"},"license":"MIT","homepage":"https://guard.bizbionic.com/v1/agent.json","keywords":["x402","guard","bizbionic","attestation","ed25519"],"repository":{"type":"git","url":"git+https://github.com/davedn/x402-guard.git","directory":"packages/x402-guard"},"description":"Fail-closed npm client for BizBionic x402 Guard. Decide → verify short-TTL ed25519 attestation → only then sign PAYMENT-SIGNATURE.","maintainers":[{"name":"bizbionic","email":"bizbionicguard@agentmail.to"}],"readme":"# @bizbionic/x402-guard\n\nClient so agents cannot sign `PAYMENT-SIGNATURE` until Guard returns a\nshort-TTL ed25519 attestation **and** this client verifies it against the\npublished pubkey.\n\nMissing, invalid, expired, or mismatched attestation → refuse. There is no\nsoft-allow path.\n\n## Install\n\n```bash\nnpm i @bizbionic/x402-guard\n```\n\nDesign-partner install and pay path:\n**https://guard.bizbionic.com/partners**\n\n## Machine card\n\nLive endpoints, price, and TTL:\n\n**https://guard.bizbionic.com/v1/agent.json**\n\n| Field | Live value |\n| --- | --- |\n| `pricing.decideUsd` | `0.001` (USDC on Base, `eip155:8453`) |\n| `trust.ttlSeconds` | `60` |\n| `endpoints.decide` | `POST /v1/guard/decide` |\n| `endpoints.pubkey` | `GET /v1/.well-known/guard-pubkey` |\n\nUnpaid `POST /v1/guard/decide` returns HTTP 402 with `PAYMENT-REQUIRED`. The\n`payTo` fee receiver is published on that 402 (and `GET /v1/guard/pay-to`).\nPay the decide fee on Base, then follow `PAYMENT-REQUIRED`.\n\nTo attribute decide and preflight calls to your operator account (instead of\nthe anonymous shared pool), sign in to `/ops` → **Create API key** → send as\n`X-Guard-Api-Key`. A wrong key returns HTTP 401. Decide stays reachable\nwithout a key so the fee gate can collect; those writes stay in the anonymous\npool. A request body cannot choose whose account is used.\n\nThis package does **not** spend USDC for you. You supply `payGuardFee` (Guard\ndecide fee) and `getSigner` (resource payment) only after you choose to pay.\n\n## Minimal usage\n\n```ts\nimport { createGuardedFetch } from \"@bizbionic/x402-guard\";\n\nconst guard = createGuardedFetch({\n  guardBaseUrl: \"https://guard.bizbionic.com\",\n  policyId: \"policy_demo\",\n  agentId: \"agent_demo\",\n  // Optional: pay Guard's decide fee (live $0.001 USDC on Base).\n  // payGuardFee: async (paymentRequired) => createPaymentSignature(paymentRequired),\n  getSigner: async ({ offer }) => createResourcePaymentSignature(offer),\n});\n\n// Example x402 resource (Otto weather; returns HTTP 402 until paid).\nconst res = await guard.fetch(\"https://x402.ottoai.services/weather?location=London\");\n```\n\n`getSigner` runs **only** after decide allows **and** the attestation verifies\nagainst `GET /v1/.well-known/guard-pubkey`. If Guard blocks, `guard.fetch`\nthrows `GuardBlockError` with `reasons`.\n\n### Wallet integration without wrapping fetch\n\n```ts\nimport {\n  createGuardedFetch,\n  assertCanSign,\n  signIfAttested,\n  WalletRefuseError,\n} from \"@bizbionic/x402-guard\";\n\nconst guard = createGuardedFetch({\n  guardBaseUrl: \"https://guard.bizbionic.com\",\n  policyId: \"policy_demo\",\n  agentId: \"agent_demo\",\n});\n\nconst { attestation, publicKeyHex } = await guard.decideAndAssert({\n  scheme: \"exact\",\n  network: \"eip155:8453\",\n  asset: \"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913\",\n  amount: \"1000\",\n  payTo: \"0x0E84dDEdAaE6A779c462C22a59F301EC31B6b808\",\n  resource: \"https://x402.ottoai.services/weather?location=London\",\n});\n\nawait assertCanSign({\n  attestation,\n  publicKeyHex,\n  intended: {\n    amount: \"1000\",\n    network: \"eip155:8453\",\n    asset: \"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913\",\n    payTo: \"0x0E84dDEdAaE6A779c462C22a59F301EC31B6b808\",\n    resource: \"https://x402.ottoai.services/weather?location=London\",\n  },\n});\n\nconst intended = {\n  amount: \"1000\",\n  network: \"eip155:8453\",\n  asset: \"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913\",\n  payTo: \"0x0E84dDEdAaE6A779c462C22a59F301EC31B6b808\",\n  resource: \"https://x402.ottoai.services/weather?location=London\",\n};\n\nconst paymentSignature = await signIfAttested({\n  attestation,\n  publicKeyHex,\n  intended,\n  sign: () => createResourcePaymentSignature(intended),\n});\n```\n\n`assertCanSign` / `signIfAttested` use the same refuse rules as the Guard\nsigning gate: no attestation, bad signature, expired TTL, or\nnetwork/asset/payTo/amount/resource mismatch → `WalletRefuseError`.\n\n## Refuse-to-sign defaults\n\n- No attestation → refuse (`no_attestation`)\n- Signature does not verify against the **published** pubkey → refuse\n  (`verifyAttestation` requires `publicKeyHex`; it never falls back to\n  `attestation.publicKey`)\n- `exp` in the past (default TTL 60s) → refuse\n- Intended payment does not match the attestation → refuse\n- Allow attestation `policyId` ≠ requested `policyId` → refuse (`policy_mismatch`)\n- `guardBaseUrl` must be `https` (http only for `localhost` / `127.0.0.1` / `[::1]`)\n- Decide HTTP 402 without `payGuardFee` → refuse (`guard_fee_required`)\n- Decide `block` → `GuardBlockError` with `reasons` (no sign path)\n\nNever treat a 402 resource as payable until this client has a verified\nattestation. Do not disable these checks.\n\n`createGuardedFetch` strips any caller `PAYMENT-SIGNATURE` / `X-PAYMENT` and\nonly attaches a signature after decide + published-pubkey verify.\n\n## Contributing\n\nPartner install path: [guard.bizbionic.com/partners](https://guard.bizbionic.com/partners).\n","readmeFilename":"README.md"}