{"_id":"@blockwavelabs/receipt-proof","_rev":"3-a3cddeadfafc13bde07442cb1314799f","name":"@blockwavelabs/receipt-proof","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.1":{"name":"@blockwavelabs/receipt-proof","version":"0.1.1","keywords":["paychain","settlement","receipt","merkle","verifier"],"author":"","license":"Apache-2.0","_id":"@blockwavelabs/receipt-proof@0.1.1","maintainers":[{"name":"sskys18","email":"jcs25822@gmail.com"}],"bin":{"paychain-verify":"dist/cli.js"},"dist":{"shasum":"5647d2768cb476c3e1c3bbfc536e579f11442aa4","tarball":"https://registry.npmjs.org/@blockwavelabs/receipt-proof/-/receipt-proof-0.1.1.tgz","fileCount":8,"integrity":"sha512-xK4jCk67y6ozR+cUxLHtzbhpWmxrFaAWNkxbCpEh7l9MY9XfA37bHG4WLRBZMpu8W+hHdWA9K2qranv6uBcjhA==","signatures":[{"sig":"MEUCIQCYg4Lufjd9c8qIKJdnwN/fK7j3CCtGXWY7MeDYYTdZ+gIgD/vL47JGFy8j22PbxhzuIKiqGjOCJCAv4RPiF+1o3BA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":33351},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"043e0760f1914a355e806d215625269942c5a177","scripts":{"test":"npm run build && node --test test/**/*.test.mjs","build":"tsc","clean":"node -e \"require('fs').rmSync('dist', { recursive: true, force: true })\"","prepack":"npm run build"},"_npmUser":{"name":"sskys18","email":"jcs25822@gmail.com"},"_npmVersion":"10.9.4","description":"Verify PayChain receipt inclusion and settlement anchors without depending on private PayChain packages.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"ethers":"^6.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipt-proof_0.1.1_1778652689360_0.41303224931249294","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@blockwavelabs/receipt-proof","version":"0.1.2","keywords":["paychain","settlement","receipt","merkle","verifier"],"author":"","license":"Apache-2.0","_id":"@blockwavelabs/receipt-proof@0.1.2","maintainers":[{"name":"sskys18","email":"jcs25822@gmail.com"}],"bin":{"paychain-verify":"dist/cli.js"},"dist":{"shasum":"f563c1c9e3d55bac6a998c9bf64b7e157d6b0bb9","tarball":"https://registry.npmjs.org/@blockwavelabs/receipt-proof/-/receipt-proof-0.1.2.tgz","fileCount":8,"integrity":"sha512-jXM685aKk9NkqAV4OacPzHK3m53EiXfLgGMWj9BSyUQyf1LV1WA2e05A+BgIhMvXxA3oq1MJdgXcSAvq0jkJ/w==","signatures":[{"sig":"MEUCIAEYN1dsvk7Cl4rpVps+l1IoILVlK3U+6AoHwBtNbqn5AiEAzJKBqkffHSnHjO8MQpk7AMgcN+M3mpAzgped2ek97YY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34739},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"043e0760f1914a355e806d215625269942c5a177","scripts":{"test":"npm run build && node --test test/**/*.test.mjs","build":"tsc","clean":"node -e \"require('fs').rmSync('dist', { recursive: true, force: true })\"","prepack":"npm run build"},"_npmUser":{"name":"sskys18","email":"jcs25822@gmail.com"},"_npmVersion":"10.9.4","description":"Verify PayChain receipt inclusion and settlement anchors without depending on private PayChain packages.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"ethers":"^6.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.3.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/receipt-proof_0.1.2_1778652840581_0.21950302452879966","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@blockwavelabs/receipt-proof","version":"0.1.4","description":"Verify receipt inclusion and settlement anchors without depending on private packages.","type":"module","main":"dist/index.js","types":"dist/index.d.ts","bin":{"receipt-proof":"dist/cli.js"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"publishConfig":{"access":"public"},"scripts":{"build":"tsc","prepack":"npm run build","test":"npm run build && node --test test/**/*.test.mjs","clean":"node -e \"require('fs').rmSync('dist', { recursive: true, force: true })\""},"keywords":["settlement","receipt","merkle","verifier","proof"],"author":"","license":"Apache-2.0","dependencies":{"ethers":"^6.9.0"},"devDependencies":{"@types/node":"^20.0.0","typescript":"^5.3.0"},"_id":"@blockwavelabs/receipt-proof@0.1.4","gitHead":"6743bb028a5ce26efdee451e7b76d7e3ad10dfce","_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-eTlevZqGtYJloenTA4b5nQ8nXJmxBlKVl1sMVcnZLczzhKSgBvzqupsFAENq3F3ZT0C1paljGtTl8yirYObFqQ==","shasum":"e108b37b47ea7b0c3eec5ce3ad97140f19ba9b5b","tarball":"https://registry.npmjs.org/@blockwavelabs/receipt-proof/-/receipt-proof-0.1.4.tgz","fileCount":8,"unpackedSize":38205,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBdzUsiaQJY1ty5lHSIWVbXlKyKABfOb7VCtfUKcnB8tAiBOY4vyF9cf2wKfDpLJkB7iPNBzNnUb/VfQ3VoBJA8ctw=="}]},"_npmUser":{"name":"sskys18","email":"jcs25822@gmail.com"},"directories":{},"maintainers":[{"name":"sskys18","email":"jcs25822@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/receipt-proof_0.1.4_1778676420763_0.3517739545566865"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-13T06:11:29.236Z","modified":"2026-05-13T12:47:01.071Z","0.1.1":"2026-05-13T06:11:29.515Z","0.1.2":"2026-05-13T06:14:00.759Z","0.1.4":"2026-05-13T12:47:00.958Z"},"license":"Apache-2.0","keywords":["settlement","receipt","merkle","verifier","proof"],"description":"Verify receipt inclusion and settlement anchors without depending on private packages.","maintainers":[{"name":"sskys18","email":"jcs25822@gmail.com"}],"readme":"# @blockwavelabs/receipt-proof\n\nVerify receipt inclusion proofs and settlement anchors without importing private packages.\n\nNpm package: https://www.npmjs.com/package/@blockwavelabs/receipt-proof\n\n## Package Contents\n\nThe npm artifact is intentionally dist-only: `dist/*.js`, `dist/*.d.ts`,\n`README.md`, `LICENSE`, `NOTICE`, and `package.json`. TypeScript `src/` files\nand source maps are not published.\n\n## Quickstart\n\n```sh\nnpm install @blockwavelabs/receipt-proof\n```\n\n## CLI\n\nFor the normal proof check, you need a receipt ID and the proof JSON evidence.\nNo API URL or RPC is required.\n\n```sh\nreceipt-proof rcpt_... --proof proof.json --json\n```\n\nThe `--proof` file can be a raw proof object or a `@blockwavelabs/demo-payer`\nJSON/JSONL result containing a nested `proof` object:\n\n```sh\nreceipt-proof rcpt_... --proof receipts.jsonl --json\n```\n\n## JavaScript API\n\nVerify a proof object or a `@blockwavelabs/demo-payer` result bundle:\n\n```ts\nimport { verifyReceiptProofInput } from '@blockwavelabs/receipt-proof';\n\nconst result = verifyReceiptProofInput(demoPayerResult, 'rcpt_...');\nconsole.log(result.checks.verified);\n```\n\nFetch proof evidence from an API when you are building an operator-side tool:\n\n```ts\nimport { SettlementVerifier } from '@blockwavelabs/receipt-proof';\n\nconst verifier = new SettlementVerifier({\n  baseUrl: 'https://api.example.com',\n  apiKey: process.env.RECEIPT_API_KEY,\n});\n\nconst result = await verifier.verifyReceipt('rcpt_...');\nconsole.log(result.verified, result.checks, result.evidence);\n```\n\n## Offline Proof JSON\n\nThe proof JSON is the evidence object returned by the proof API or exported by\nan operator. You can verify it without API or RPC access:\n\n```sh\nreceipt-proof proof proof.json rcpt_... --json\n```\n\nLow-level API:\n\n```ts\nimport { verifyReceiptProof } from '@blockwavelabs/receipt-proof';\n\nconst result = verifyReceiptProof(proofJson, 'rcpt_...');\n```\n\n## Optional On-Chain Anchor Check\n\nIf you want the CLI to fetch the proof JSON for you, pass an API URL.\nWhile the proof endpoint is API-key gated, pass an auditor/operator key.\n\n```sh\nreceipt-proof receipt rcpt_... \\\n  --api-url https://api.example.com \\\n  --api-key \"$RECEIPT_API_KEY\" \\\n  --json\n```\n\nFor a stronger check, the fetch mode can also verify the on-chain anchor if you\nadd your own RPC and the deployed `SettlementManager` address. These are\noptional; no default RPC is baked in.\n\n```sh\nreceipt-proof receipt rcpt_... \\\n  --api-url https://api.example.com \\\n  --api-key \"$RECEIPT_API_KEY\" \\\n  --rpc-url \"$SETTLEMENT_RPC_URL\" \\\n  --contract \"$SETTLEMENT_CONTRACT_ADDRESS\" \\\n  --confirmations 3 \\\n  --require-anchor \\\n  --json\n```\n\n## Verification Model\n\nThe verifier checks:\n\n- the proof response is bound to the requested `receiptId`\n- the Merkle proof recomputes to `merkleRoot`\n- `merkleRoot` equals the batch `payloadHash`\n- when RPC + contract address are configured, the anchor tx emitted `SettlementBatchCommitted(batchId, payloadHash, ...)`\n\nNo default RPC endpoint is baked in. External auditors should provide their own RPC.\n\n## Current v0.1 Limits\n\n- Leaf scheme is `receipt-id-keccak-v1`: `leafHash = keccak256(utf8(receiptId))`. It proves receipt ID inclusion, not payload binding. Payload-bound leaves require the ADR-035 leaf-scheme v2 migration.\n- The current proof endpoint is API-key gated. Public anonymous or ownership-scoped proof access is separate server work.\n- Current receipt IDs are timestamp/random strings, not UUIDv4. Public proof exposure should resolve sibling-hash leakage with UUIDv4 IDs or a batch-scoped salt before anonymous access.\n- Dist-only publishing does not make the verifier algorithm private. Published JavaScript remains inspectable, which is expected for the external verification path.\n","readmeFilename":"README.md"}