{"_id":"@bluefoxedge/verify-receipt","_rev":"2-deb6e6e58a00c43d087ea1ff95a25b50","name":"@bluefoxedge/verify-receipt","dist-tags":{"latest":"0.0.3"},"versions":{"0.0.1":{"name":"@bluefoxedge/verify-receipt","version":"0.0.1","keywords":["bluefox","receipt","verification","ed25519","rfc8785","jcs","offline","agents"],"author":{"name":"BlueFox AI","email":"ethan@bluefoxedge.ai"},"license":"MIT","_id":"@bluefoxedge/verify-receipt@0.0.1","maintainers":[{"name":"ethanholien","email":"ethanholien@mac.com"}],"homepage":"https://www.bluefoxedge.ai/docs/verify-a-receipt","bugs":{"url":"https://github.com/ethanholien/bluefox-edge/issues"},"bin":{"bluefoxedge-verify-receipt":"bin/verify-receipt.js"},"dist":{"shasum":"9d00bc0d699c44a1bf85eff5e11ff0eab79dd867","tarball":"https://registry.npmjs.org/@bluefoxedge/verify-receipt/-/verify-receipt-0.0.1.tgz","fileCount":5,"integrity":"sha512-D2kZcSFAxKDKdgNeYjEbXXbQnmrgOfET5DuOMbRWHnsUYfFV14DD5Tt4c367mtJ8yTImj8I7Yy/qz5VkWtk09Q==","signatures":[{"sig":"MEQCIFFfuVNLNjwRwGcoG3cMK9ic0J6SWAFE/Nj+Zh12uCKyAiBfu25kmNcxUTVSkKI2F+8l1mCAlQ6L6esymOk2xPAZ/w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6491},"main":"./index.js","_from":"file:dist/bluefoxedge-verify-receipt-0.0.1.tgz","engines":{"node":">=18.0.0"},"exports":{".":"./index.js","./package.json":"./package.json"},"_npmUser":{"name":"ethanholien","email":"ethanholien@mac.com"},"_resolved":"/Users/ethanhomem5prolaptop/repos/bluefox-strat/September 10th reports/SS115/jj115_stubs/npm-bluefoxedge-verify-receipt/dist/bluefoxedge-verify-receipt-0.0.1.tgz","_integrity":"sha512-D2kZcSFAxKDKdgNeYjEbXXbQnmrgOfET5DuOMbRWHnsUYfFV14DD5Tt4c367mtJ8yTImj8I7Yy/qz5VkWtk09Q==","repository":{"url":"git+https://github.com/ethanholien/bluefox-edge.git","type":"git"},"_npmVersion":"11.19.0","description":"The BlueFox Edge offline receipt checker under the @bluefoxedge scope: bluefox-verify-receipt 1.1.0, pinned exactly and re-exported. One file, no client, no account.","directories":{},"_nodeVersion":"26.8.1","dependencies":{"bluefox-verify-receipt":"1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/verify-receipt_0.0.1_1789194266949_0.8042304353096743","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"_id":"@bluefoxedge/verify-receipt@0.0.3","bin":{"bluefoxedge-verify-receipt":"bin/verify-receipt.js"},"bugs":{"url":"https://www.bluefoxedge.ai/contact","email":"support@bluefoxedge.ai"},"dist":{"shasum":"f154186de33283c5839413d1faeafa8750c08f2d","tarball":"https://registry.npmjs.org/@bluefoxedge/verify-receipt/-/verify-receipt-0.0.3.tgz","fileCount":5,"integrity":"sha512-wO2bkisGuXiPDHa04sWfqL4GFA8Aw8BPF87gdYowmmWb98b+J7IIzV1DuwUjYUoMpCmwdqnD6Eb0J14hZJ4V5w==","signatures":[{"sig":"MEQCIFvi30sRzjQK9GfK3+98ln2L6B/ff3F60An3MhGOMUOQAiARb7H0BuLKaTcifGkB6FH50J5FInYsckMweNbUtxshIw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIAmO4Wi7BTykC8pR6u+o5pXsDlmsGOSXdmUGDePvSLFoAiEAjh/CT0YzP/q8Q3ZDeBcH8vTQkQ6M2MR6k6s3FOfwfEs="}],"unpackedSize":8056},"main":"./index.js","name":"@bluefoxedge/verify-receipt","_from":"file:bluefoxedge-verify-receipt-0.0.3.tgz","author":{"name":"BlueFox AI","email":"ethan@bluefoxedge.ai"},"engines":{"node":">=18.0.0"},"exports":{".":"./index.js","./package.json":"./package.json"},"license":"MIT","version":"0.0.3","_npmUser":{"name":"ethanholien","email":"ethanholien@mac.com"},"homepage":"https://www.bluefoxedge.ai/docs/verify-a-receipt","keywords":["bluefox","receipt","verification","ed25519","rfc8785","jcs","offline","agents"],"_resolved":"/private/tmp/t117-ceremony/dist/bluefoxedge-verify-receipt-0.0.3.tgz","_integrity":"sha512-wO2bkisGuXiPDHa04sWfqL4GFA8Aw8BPF87gdYowmmWb98b+J7IIzV1DuwUjYUoMpCmwdqnD6Eb0J14hZJ4V5w==","_npmVersion":"11.19.0","description":"The BlueFox Edge offline receipt checker under the @bluefoxedge scope: bluefox-verify-receipt 1.2.0, pinned exactly and re-exported. One file, no client, no account.","directories":{},"maintainers":[{"name":"ethanholien","email":"ethanholien@mac.com"}],"_nodeVersion":"26.8.1","dependencies":{"bluefox-verify-receipt":"1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/verify-receipt_0.0.3_1789444093332_0.053141226619675574"}}},"time":{"created":"2026-09-12T06:24:26.806Z","modified":"2026-09-15T03:48:13.567Z","0.0.1":"2026-09-12T06:24:27.087Z","0.0.3":"2026-09-15T03:48:13.413Z"},"bugs":{"url":"https://www.bluefoxedge.ai/contact","email":"support@bluefoxedge.ai"},"author":{"name":"BlueFox AI","email":"ethan@bluefoxedge.ai"},"license":"MIT","homepage":"https://www.bluefoxedge.ai/docs/verify-a-receipt","keywords":["bluefox","receipt","verification","ed25519","rfc8785","jcs","offline","agents"],"description":"The BlueFox Edge offline receipt checker under the @bluefoxedge scope: bluefox-verify-receipt 1.2.0, pinned exactly and re-exported. One file, no client, no account.","maintainers":[{"name":"ethanholien","email":"ethanholien@mac.com"}],"readme":"# @bluefoxedge/verify-receipt\n\n**0.0.3 — the published checker, under the `@bluefoxedge` scope, pinned to 1.2.0.** This package\nre-exports [`bluefox-verify-receipt`](https://www.npmjs.com/package/bluefox-verify-receipt)\n1.2.0, pinned exactly — the BlueFox Edge offline receipt checker. 1.2.0 reaches npm in the\nsame ceremony as this release, and this package installs only once it is there (the pin is\nexact, so an earlier install refuses with `notarget` rather than resolving a different\nversion). The street serves a sibling cut of the same checker at\n<https://api.bluefoxedge.ai/verify_receipt.js> (as of 2026-09-15 its `.sha256` reads\n`e7580e77…0c67b`; the 1.2.0 file hashes `8c215ff1…40e49`, 67,905 bytes) — same steps, same\norder, same one-sentence verdicts; 1.2.0 has `--json`, `-q`, `--help`, TypeScript types and a\nshipped conformance corpus, and refuses a receipt whose unsigned top-level `chain_prev`\ndisagrees with the signed envelope's; the served cut has `--bind-record`. Compare the served\n`.sha256` with the file at `checkerPath()` any time.\n\n```bash\nnpm install @bluefoxedge/verify-receipt\nnpx @bluefoxedge/verify-receipt my-receipt.json\n```\n\nAfter `npm install`, the command on PATH is `bluefoxedge-verify-receipt`. Same steps, same\norder, same one-sentence verdicts as `npx bluefox-verify-receipt@1.2.0` and as the Python\nchecker; every passing run prints the ten `NOT VERIFIED by this run` lines before the pass\nsentence. Exit 0 means the check passed.\n\n```js\nconst vr = require(\"@bluefoxedge/verify-receipt\");\n// vr.run / vr.main / vr.jcs / vr.sha256 ... are the checker's own exports\nconsole.log(vr.version, vr.checkerPath());\n```\n\n## Why a scoped copy\n\n`@bluefoxedge` is the scope BlueFox Edge packages publish under from here on. This first\nscoped release exists so the scope carries a real, working package from its first day.\nThe unscoped `bluefox-verify-receipt` stays published and is the same checker; use\nwhichever name you prefer.\n\n## What it checks\n\nA BlueFox Edge receipt is a signed record of one API answer: the envelope is\ncanonicalized (RFC 8785 / JCS), hashed (SHA-256), chained, and signed (Ed25519) with a\npublished key. The checker recomputes every signed field from the file's own bytes and\nrefuses — in a sentence, never a stack trace — on any disagreement. Fully offline:\n\n```bash\ncurl -sSo pinned-jwks.json https://api.bluefoxedge.ai/.well-known/jwks.json\nnpx @bluefoxedge/verify-receipt --jwks pinned-jwks.json my-receipt.json\n```\n\nThe receipt never names its own key source; `--jwks` is the operator's hand. How to\nread what a receipt does and does not say: <https://www.bluefoxedge.ai/docs/verify-a-receipt>.\n\n## What changed since 0.0.1\n\n- **0.0.3 (this release).** The pin moves from `bluefox-verify-receipt` 1.1.0 to 1.2.0 — the\n  release whose every passing run prints what it did not verify — and the served-copy sentence\n  above is re-dated: the API's 2026-09-14 deploy moved the served checker to a cut that 1.1.0 no\n  longer matched. The module and the command are otherwise unchanged.\n- **0.0.2 (staged 2026-09-13, never reached npm; its changes ride here).** The 0.0.1 bytes\n  (published 2026-09-12) carried an internal review banner in this README and in `index.js`,\n  and their repository metadata pointed at a private repository that answers 404 to anyone\n  outside the house. Both are gone.\n\nLicense: MIT. Author: BlueFox AI (Format Dynamics, Inc.). Questions and issues:\n<support@bluefoxedge.ai> · <https://www.bluefoxedge.ai/contact> · security reports per\n<https://www.bluefoxedge.ai/.well-known/security.txt>.\n","readmeFilename":"README.md"}