{"_id":"@bolyra/receipts","_rev":"6-8e2fbca723942225fa60ecb657fae175","name":"@bolyra/receipts","dist-tags":{"latest":"0.11.0"},"versions":{"0.6.0":{"name":"@bolyra/receipts","version":"0.6.0","keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"license":"Apache-2.0","_id":"@bolyra/receipts@0.6.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"253c4bb810f3273df11c31d653d252f02d247662","tarball":"https://registry.npmjs.org/@bolyra/receipts/-/receipts-0.6.0.tgz","fileCount":16,"integrity":"sha512-IZG7sL9OZ6t/F2KYwRD+3ngLlk7F37+1dOux+nNDAte/yJ5GuOis+lwylyJsze+DJ8M356AYKLjKK7Mpy3c4Tw==","signatures":[{"sig":"MEYCIQDGwYgUAWSq9kRkJhye+h+1OohMKMdSoIqI3TZGMmmJQwIhAO2aPAev3jxB8kgQ4/WJ03bxjHhSYFjR5/rtDACvTYOX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22305},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"69b2bb457503f37565475434c19076433031701d","scripts":{"test":"jest --passWithNoTests","build":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"saneguy","email":"kondojuviswanadha@gmail.com"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.6.2","description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"@noble/hashes":"^1.7.0","@noble/secp256k1":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.6.0_1781361340442_0.48100810717531584","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@bolyra/receipts","version":"0.7.0","keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"license":"Apache-2.0","_id":"@bolyra/receipts@0.7.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"bolyra-receipt-verify":"dist/verify-cli.js"},"dist":{"shasum":"f03a8735e83cde8d6cff94fe204af842b30f7fb7","tarball":"https://registry.npmjs.org/@bolyra/receipts/-/receipts-0.7.0.tgz","fileCount":19,"integrity":"sha512-pU8kUcYh7Lm13k/ntKG2UaEL5KyVqCvHeBsAD24FbYFmpRASe6HAdeoAWedAdyDQJTFgV+QGtOAQi+eAXr4SZQ==","signatures":[{"sig":"MEQCIFbDKEa1uk7Vx7f5J2i67f0PU+QJZzydTlHCQgxPgSgxAiBSAtGnz4ZQq4XOcd+iuXUCpx5p4mLB5leomCEb8w2pfA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2freceipts@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":42035},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"9aeaf1f3a681003267d70eb9d0eadc20605337ea","scripts":{"test":"jest --passWithNoTests","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0c8bad22-2a5f-4639-b519-83a0df9a0b06"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.17.0","description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@noble/hashes":"^1.7.0","@noble/secp256k1":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.7.0_1781366277800_0.3615249714667177","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@bolyra/receipts","version":"0.8.0","keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"license":"Apache-2.0","_id":"@bolyra/receipts@0.8.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"bolyra-receipt-verify":"dist/verify-cli.js"},"dist":{"shasum":"bf5235bd848415c5fd52d0e791237df6fd1a2a35","tarball":"https://registry.npmjs.org/@bolyra/receipts/-/receipts-0.8.0.tgz","fileCount":23,"integrity":"sha512-0zeu21SIP2eDDbVxuxoBmSAH7iGeLJFLW8+h/+6uUOqQ7XQWKmqEnHF9z0lTH4ch3SurdlpW+fEyXgvuo7ruhw==","signatures":[{"sig":"MEUCIGnTtZ1OW64EZVk2netVYuURx6eVkXq5dUIGlLqzphY1AiEA68sm+KHaoH1mz/3eU9Iv3lUppxJ1NPpeH8URaPdhrQ4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2freceipts@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":78325},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"da2677189f09cbc59ff6cd3f0cdfb78e0b16fca9","scripts":{"test":"jest --passWithNoTests","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0c8bad22-2a5f-4639-b519-83a0df9a0b06"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.18.0","description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@noble/hashes":"^1.7.0","@noble/secp256k1":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.8.0_1783727333543_0.7349775047708185","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@bolyra/receipts","version":"0.9.0","keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"license":"Apache-2.0","_id":"@bolyra/receipts@0.9.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"bolyra-receipt-verify":"dist/verify-cli.js"},"dist":{"shasum":"be63b9501619e1988ff1b942a32e662ecae7ac08","tarball":"https://registry.npmjs.org/@bolyra/receipts/-/receipts-0.9.0.tgz","fileCount":26,"integrity":"sha512-m3G2+Dwud+SOSjBKFFNeGfyTcOL+VHLE9wk+MQ7axApwzYsuFGs6Fgdf3uwUrfQawB88BmSlekAcGWw1UNItFw==","signatures":[{"sig":"MEYCIQDyqFKms8OrXip0KTnMKpdRH8VAmdRoD/jIXRXsJZXwrwIhAL9MLE1KRgNuh+g9NMc1I1Eisgq4rYcQCi4iTeCoyf66","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2freceipts@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":86935},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"7f9ff79f06f9f9af6871c927e803be17e9b7f4de","scripts":{"test":"jest --passWithNoTests","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0c8bad22-2a5f-4639-b519-83a0df9a0b06"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.18.0","description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@noble/hashes":"^1.7.0","@noble/secp256k1":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.9.0_1783985890308_0.5939500852653692","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@bolyra/receipts","version":"0.10.0","keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"license":"Apache-2.0","_id":"@bolyra/receipts@0.10.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"bolyra-receipt-verify":"dist/verify-cli.js"},"dist":{"shasum":"bc791550f2cd5f47f1b4d1d1db4b8abe49dbdbc7","tarball":"https://registry.npmjs.org/@bolyra/receipts/-/receipts-0.10.0.tgz","fileCount":29,"integrity":"sha512-RXkq60OyrjX+3iGxBBTfv4yUnx66YmYRbU8QE2ZmE1UsKbhW89W5pSTp7WsFxg13T5pRPqlZOZUzKWmxDyON+Q==","signatures":[{"sig":"MEUCIQDDUdRNeQcwW4JilRFk2r4z2BdOJYTM781ciGOGeJ22JQIgS7na+KgpR37bRH+vrOczIAUKb9+4OTSNzLLw4K5NjXQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2freceipts@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":109127},"main":"dist/index.js","types":"dist/index.d.ts","gitHead":"37fb3c4cbe40cb33992d7e25a9e82f7258648e3f","scripts":{"test":"jest","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0c8bad22-2a5f-4639-b519-83a0df9a0b06"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git"},"_npmVersion":"11.19.0","description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"@noble/hashes":"^1.7.0","@noble/secp256k1":"^2.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^30.4.2","ts-jest":"^29.2.0","typescript":"^5.5.0","@types/jest":"^30.0.0","@types/node":"^25.9.1"},"_npmOperationalInternal":{"tmp":"tmp/receipts_0.10.0_1787626060208_0.3591197698287971","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@bolyra/receipts","version":"0.11.0","description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","main":"dist/index.js","types":"dist/index.d.ts","bin":{"bolyra-receipt-verify":"dist/verify-cli.js"},"scripts":{"build":"tsc","prepare":"tsc","test":"jest","typecheck":"tsc --noEmit"},"dependencies":{"@noble/secp256k1":"^2.2.0","@noble/hashes":"^1.7.0"},"devDependencies":{"@types/jest":"^30.0.0","@types/node":"^25.9.1","jest":"^30.4.2","ts-jest":"^29.2.0","tsx":"^4.20.0","typescript":"^5.5.0"},"repository":{"type":"git","url":"git+https://github.com/bolyra/bolyra.git"},"publishConfig":{"access":"public"},"keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"license":"Apache-2.0","gitHead":"a23e73a4d5a049ddb9e732f1d51dd405590de18a","_id":"@bolyra/receipts@0.11.0","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"homepage":"https://github.com/bolyra/bolyra#readme","_nodeVersion":"22.23.2","_npmVersion":"11.19.0","dist":{"integrity":"sha512-Mdm4Ljbx8liXDVw1LwdI22PkHsJgTL/vDXJYO1arziUJ/m4EAQyQdo5gt7eMnkcNgAVhuGM8/WKEpNGUepiEyw==","shasum":"7dfaaa8dc59309f322706e2a6c83ca948d71ca2e","tarball":"https://registry.npmjs.org/@bolyra/receipts/-/receipts-0.11.0.tgz","fileCount":29,"unpackedSize":111895,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2freceipts@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEbu9GYBHpJJJtipIN7jMji7shCHXYuDou4Gth8oO9wuAiEAu1gmmjrEkl/LVRjfP2KvTLJHcpBkTIm+2RcBQZDEuW0="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:0c8bad22-2a5f-4639-b519-83a0df9a0b06"}},"directories":{},"maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/receipts_0.11.0_1787652606590_0.1281235882668874"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-13T14:35:40.259Z","modified":"2026-08-25T10:10:07.139Z","0.6.0":"2026-06-13T14:35:40.609Z","0.7.0":"2026-06-13T15:57:57.947Z","0.8.0":"2026-07-10T23:48:53.717Z","0.9.0":"2026-07-13T23:38:10.440Z","0.10.0":"2026-08-25T02:47:40.337Z","0.11.0":"2026-08-25T10:10:06.798Z"},"bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"license":"Apache-2.0","homepage":"https://github.com/bolyra/bolyra#readme","keywords":["bolyra","receipts","zkp","secp256k1","signed-receipts","auth"],"repository":{"type":"git","url":"git+https://github.com/bolyra/bolyra.git"},"description":"Signed auth receipts for Bolyra ZKP verification decisions — canonical JSON, secp256k1 sign/verify, EVM-compatible r||s||v signatures.","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"readme":"# @bolyra/receipts\n\nTamper-evident signed receipts for Bolyra ZKP verification decisions — secp256k1 / ES256K signatures, canonical JSON, EVM-compatible r‖s‖v encoding.\n\n## Install\n\n```bash\nnpm install @bolyra/receipts\n```\n\n## Usage\n\n```typescript\nimport { createAuthReceipt, signReceipt, verifyReceipt } from '@bolyra/receipts';\n\n// 1. Build a receipt from a verification result\nconst payload = createAuthReceipt(\n  {\n    rootDid: 'did:bolyra:0xabc…',\n    actingDid: 'did:bolyra:0xdef…',\n    credentialCommitment: '0x1234…',\n    effectiveCommitment: '0x1234…',\n    humanProof: verifiedBundle.humanProof,\n    agentProof: verifiedBundle.agentProof,\n    humanPublicSignals: verifiedBundle.humanPublicSignals,\n    agentPublicSignals: verifiedBundle.agentPublicSignals,\n    allowed: true,\n    score: 95,\n    permissionBitmask: 3n,\n    chainDepth: 0,\n    bundleVersion: 1,\n    nonce: '0xdeadbeef',\n  },\n  { issuer: 'https://gateway.example.com', keyId: 'k1' },\n);\n\n// 2. Sign it with your secp256k1 private key\nconst signed = signReceipt(payload, {\n  privateKey: process.env.RECEIPT_SIGNING_KEY!,\n  keyId: 'k1',\n});\n\n// 3. Verify later (or on another service)\nconst ok = verifyReceipt(signed, '0xYourExpectedSignerAddress');\nconsole.log(ok); // true\n```\n\nThe `signed` object is JSON-serializable and can be stored in a database, forwarded to an audit log, or returned to the caller as proof of the verification decision.\n\n## Hash-chained logs (v0.8.0+)\n\nA signature makes each *receipt* tamper-evident; it does not make a *log* of\nreceipts tamper-evident — deleting or reordering whole entries leaves every\nremaining signature valid. `ReceiptChain` closes that gap:\n\n```typescript\nimport { ReceiptChain, verifyReceiptChain, GENESIS_PREV_RECEIPT_HASH } from '@bolyra/receipts';\n\n// Writer side: one chain per log. Each signed payload gains\n// chain: { seq, prevReceiptHash } — the fields are INSIDE the signed payload,\n// so they cannot be rewritten without breaking the signature.\nconst chain = new ReceiptChain();\nconst first = chain.sign(payload1, signerConfig);  // seq 0, prevReceiptHash = genesis sentinel\nconst second = chain.sign(payload2, signerConfig); // seq 1, prevReceiptHash = first.receiptHash\n\n// Verifier side: every signature AND the chain links.\nconst result = verifyReceiptChain([first, second], { expectedSigner: '0x…' });\nresult.ok;       // true\nresult.headHash; // pin this externally to detect tail truncation later\n```\n\nDetails:\n\n- **Genesis sentinel:** the first receipt in a log has `seq: 0` and\n  `prevReceiptHash: GENESIS_PREV_RECEIPT_HASH` (`0x` + 64 zeros).\n- **`receiptHash`** (envelope field) is `computeReceiptHash(receipt)`:\n  keccak256 over the canonical `{ payload, signature }` — it commits to the\n  exact signature bytes and excludes `id` and itself. Verifiers recompute it;\n  the stored copy is a convenience for linking and anchoring.\n- **Backward compatible:** all fields are additive. Chain-less receipts keep\n  verifying, chained receipts still pass the plain `verifyReceipt()`, and\n  chain verification is a separate step. Logs that START with pre-chaining\n  receipts verify with `{ allowUnchained: true }` (deletions among that\n  unchained prefix are, unavoidably, not detectable). Only a prefix is\n  tolerated: a chain-less receipt after any chained receipt always fails\n  (`unchained-after-chained`) — otherwise a validly signed chain-less receipt\n  could be spliced in undetected.\n- **What chain verification detects from the log alone:** edited receipts,\n  deleted lines, reordered lines, inserted lines, head truncation (missing\n  genesis), and a second chain spliced into the file.\n- **What it provably cannot detect from the log alone:** truncation from the\n  **tail** — a chain cut after any receipt is still internally consistent.\n  Detecting it requires an external expectation: pass `expectedCount` and/or\n  `expectedHeadHash` (e.g. from a periodically anchored checkpoint). The\n  anchoring mechanism and checkpoint cadence are deployment policy —\n  enterprise-configurable, not fixed by this library.\n\nCLI: `bolyra receipt verify-chain audit-log.jsonl` (from\n[`@bolyra/cli`](../cli/README.md)) runs the same verification over a JSONL\nfile, with `--signer`, `--expect-count`, `--expect-head`, and\n`--allow-unchained`.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}