{"_id":"@burnt-labs/provider-registry-types","_rev":"7-a979765654b4a65e0794baf3535424ec","name":"@burnt-labs/provider-registry-types","dist-tags":{"latest":"0.6.0","next":"0.5.1-rc.10"},"versions":{"0.0.0":{"name":"@burnt-labs/provider-registry-types","version":"0.0.0","_id":"@burnt-labs/provider-registry-types@0.0.0","maintainers":[{"name":"burntfilament","email":"filament@burnt.com"},{"name":"burnt_val","email":"val@burnt.com"},{"name":"zaphodthebeebs","email":"zaphod@burnt.com"},{"name":"devops.burnt.com","email":"devops@burnt.com"}],"dist":{"shasum":"b7afcaa830099612d98c7aa8f5b502a749f58faa","tarball":"https://registry.npmjs.org/@burnt-labs/provider-registry-types/-/provider-registry-types-0.0.0.tgz","fileCount":1,"integrity":"sha512-AE61YJTsxYsvBXmrTWjvXImDglmQTAq8jJZF8cAOZwW3ezpjCBIZANJYDjUJ25TVrPF2Ek6cOvWQKHO3doUsuA==","signatures":[{"sig":"MEQCIFkuJ1/Flxk2WyUf8jGUPBFsiPBzOTQOyKukOFiCJE8LAiARN7zJ3rnvxJqJ+hOp+lX4MMGeL4+BzJNas/BgZEs6Gw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":138},"_npmUser":{"name":"devops.burnt.com","email":"devops@burnt.com"},"_npmVersion":"11.17.0","description":"bootstrap placeholder","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/provider-registry-types_0.0.0_1787317658873_0.27033457077306977","host":"s3://npm-registry-packages-npm-production"}},"0.0.1":{"name":"@burnt-labs/provider-registry-types","version":"0.0.1","_id":"@burnt-labs/provider-registry-types@0.0.1","maintainers":[{"name":"burntfilament","email":"filament@burnt.com"},{"name":"burnt_val","email":"val@burnt.com"},{"name":"zaphodthebeebs","email":"zaphod@burnt.com"},{"name":"devops.burnt.com","email":"devops@burnt.com"}],"dist":{"shasum":"39e2344e720a670aba962169ae58d545b01ead25","tarball":"https://registry.npmjs.org/@burnt-labs/provider-registry-types/-/provider-registry-types-0.0.1.tgz","fileCount":1,"integrity":"sha512-VNV3q+Qto4fhozF7GTVjLGSMGhLtoUWeyCiNsdFvdwaJ8o4fJ6l16LV9DwyFsB34Re8l3U8mruJ3nvbLydcYhA==","signatures":[{"sig":"MEQCICCQoKIUuL0VDWb6ZhL+RVHUdyzyXOv5xmpBVkpYzr9LAiAo6a2Xtoso5jkSegWQIdiuxIX0IY2DcfuvcTuKdMQNCA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":138},"_npmUser":{"name":"devops.burnt.com","email":"devops@burnt.com"},"deprecated":"bootstrap placeholder","_npmVersion":"11.17.0","description":"bootstrap placeholder","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/provider-registry-types_0.0.1_1787317925841_0.9462114510623858","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@burnt-labs/provider-registry-types","version":"0.5.0","license":"MIT","_id":"@burnt-labs/provider-registry-types@0.5.0","maintainers":[{"name":"burntfilament","email":"filament@burnt.com"},{"name":"burnt_val","email":"val@burnt.com"},{"name":"zaphodthebeebs","email":"zaphod@burnt.com"},{"name":"devops.burnt.com","email":"devops@burnt.com"}],"homepage":"https://github.com/burnt-labs/provider-devtool#readme","bugs":{"url":"https://github.com/burnt-labs/provider-devtool/issues"},"dist":{"shasum":"d738bea7ac9cf78322f5d738107dc1b8196bc392","tarball":"https://registry.npmjs.org/@burnt-labs/provider-registry-types/-/provider-registry-types-0.5.0.tgz","fileCount":14,"integrity":"sha512-7RdhNehQMUp5cdsVHckybXfRT1Jc0hh2hcVCVsu76msJTWlzatgyPaJV1bnqJsQYpivTSKySMam5VupL4J2ETg==","signatures":[{"sig":"MEQCIGDk0lANQmjTCOzIt4b6FcBQoZ1GpLYAcn/knM2pLaWFAiAX4RygbfE9f0WdINcGrsrgHLa+nH1k+VMWWRrYM4Pb9g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":789494},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./schema.json":"./dist/schema.json"},"gitHead":"02b9098169dbaef839ca546b8275d921e10e866b","scripts":{"build":"tsc -p tsconfig.json && npm run generate:json-schema","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build","generate:json-schema":"tsx scripts/generate-json-schema.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:00384bed-c191-44af-9ac3-02e36305be16"}},"repository":{"url":"git+https://github.com/burnt-labs/provider-devtool.git","type":"git","directory":"packages/provider-registry-types"},"_npmVersion":"12.0.2","description":"Types, zod schemas and JSON Schema for the Burnt provider registry artifact served at api.provider-registry.burnt.com.","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","allowScripts":{"esbuild@0.28.1":true,"fsevents@2.3.3":true},"dependencies":{"redos-detector":"6.1.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","zod":"3.25.76","typescript":"^5.7.2"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/provider-registry-types_0.5.0_1787331464825_0.7461004195028595","host":"s3://npm-registry-packages-npm-production"}},"0.5.1-rc.10":{"name":"@burnt-labs/provider-registry-types","version":"0.5.1-rc.10","license":"MIT","_id":"@burnt-labs/provider-registry-types@0.5.1-rc.10","maintainers":[{"name":"burntfilament","email":"filament@burnt.com"},{"name":"burnt_val","email":"val@burnt.com"},{"name":"zaphodthebeebs","email":"zaphod@burnt.com"},{"name":"devops.burnt.com","email":"devops@burnt.com"}],"homepage":"https://github.com/burnt-labs/provider-devtool#readme","bugs":{"url":"https://github.com/burnt-labs/provider-devtool/issues"},"dist":{"shasum":"018b3a396c06750d7578b4aba3a57d9ec3d0e0cf","tarball":"https://registry.npmjs.org/@burnt-labs/provider-registry-types/-/provider-registry-types-0.5.1-rc.10.tgz","fileCount":14,"integrity":"sha512-zwwrmGKKYkufkUSX/8fI+2efcAVmUcIUVVYRmNS7hOnbLxKvg4yqmmyGdH6LhHVKTYWvHRBIB6YS761cOmxfiw==","signatures":[{"sig":"MEUCIQCxg8fcabTQ+J9hSH4vescGQ+UKI8lzjo1Sb+WXXWxnVwIgU37YTZxPA5+q8CJc3f6aiFTzi9/9qkQZCQzQDxVwxAI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":789500},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./schema.json":"./dist/schema.json"},"gitHead":"6455ee137d326f52994026bf803844d4ce348c1f","scripts":{"build":"tsc -p tsconfig.json && npm run generate:json-schema","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build","generate:json-schema":"tsx scripts/generate-json-schema.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:00384bed-c191-44af-9ac3-02e36305be16"}},"repository":{"url":"git+https://github.com/burnt-labs/provider-devtool.git","type":"git","directory":"packages/provider-registry-types"},"_npmVersion":"12.0.2","description":"Types, zod schemas and JSON Schema for the Burnt provider registry artifact served at api.provider-registry.burnt.com.","directories":{},"sideEffects":false,"_nodeVersion":"24.18.1","allowScripts":{"esbuild@0.28.1":true,"fsevents@2.3.3":true},"dependencies":{"redos-detector":"6.1.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"tsx":"^4.19.2","zod":"3.25.76","typescript":"^5.7.2"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/provider-registry-types_0.5.1-rc.10_1787333186170_0.7189564276892404","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@burnt-labs/provider-registry-types","version":"0.6.0","description":"Types, zod schemas and JSON Schema for the Burnt provider registry artifact served at api.provider-registry.burnt.com.","license":"MIT","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./schema.json":"./dist/schema.json"},"sideEffects":false,"scripts":{"build":"tsc -p tsconfig.json && npm run generate:json-schema","generate:json-schema":"tsx scripts/generate-json-schema.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"devDependencies":{"tsx":"^4.19.2","typescript":"^5.7.2","zod":"3.25.76"},"publishConfig":{"access":"public"},"allowScripts":{"esbuild@0.28.1":true,"fsevents@2.3.3":true},"repository":{"type":"git","url":"git+https://github.com/burnt-labs/provider-devtool.git","directory":"packages/provider-registry-types"},"dependencies":{"redos-detector":"6.1.4"},"gitHead":"03f958e8e762df9767b86f2a43024741b679af73","_id":"@burnt-labs/provider-registry-types@0.6.0","bugs":{"url":"https://github.com/burnt-labs/provider-devtool/issues"},"homepage":"https://github.com/burnt-labs/provider-devtool#readme","_nodeVersion":"24.20.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-2BNp1X+IEMCLsbY7uId3F0XLZmLpIQEa3OpUSCrUIYuC2wyfz2/og7zYjo1M6y997Tz1xzJTzqTPDG2l0aOkmg==","shasum":"ad9814164b582ec8a2f206c3e5d1787dc8b29dcf","tarball":"https://registry.npmjs.org/@burnt-labs/provider-registry-types/-/provider-registry-types-0.6.0.tgz","fileCount":14,"unpackedSize":831523,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCCmTWfzsSPv25H9wu14pIoijtnc3jlJqUfiDvLhAPffQIgUnzCe57W0H3M300nE4pBPqAzHR0AolMiRpy8+jldqjQ="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:00384bed-c191-44af-9ac3-02e36305be16"}},"directories":{},"maintainers":[{"name":"burntfilament","email":"filament@burnt.com"},{"name":"burnt_val","email":"val@burnt.com"},{"name":"ertemann","email":"ertemann@burnt.com"},{"name":"zaphodthebeebs","email":"zaphod@burnt.com"},{"name":"devops.burnt.com","email":"devops@burnt.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/provider-registry-types_0.6.0_1788528032049_0.18540899805410582"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-21T13:07:38.378Z","modified":"2026-09-04T13:20:32.341Z","0.0.0":"2026-08-21T13:07:39.016Z","0.0.1":"2026-08-21T13:12:05.979Z","0.5.0":"2026-08-21T16:57:44.973Z","0.5.1-rc.10":"2026-08-21T17:26:26.320Z","0.6.0":"2026-09-04T13:20:32.187Z"},"bugs":{"url":"https://github.com/burnt-labs/provider-devtool/issues"},"license":"MIT","homepage":"https://github.com/burnt-labs/provider-devtool#readme","repository":{"type":"git","url":"git+https://github.com/burnt-labs/provider-devtool.git","directory":"packages/provider-registry-types"},"description":"Types, zod schemas and JSON Schema for the Burnt provider registry artifact served at api.provider-registry.burnt.com.","maintainers":[{"name":"burntfilament","email":"filament@burnt.com"},{"name":"burnt_val","email":"val@burnt.com"},{"name":"ertemann","email":"ertemann@burnt.com"},{"name":"zaphodthebeebs","email":"zaphod@burnt.com"},{"name":"devops.burnt.com","email":"devops@burnt.com"}],"readme":"# `@burnt-labs/provider-registry-types`\n\nTypes, zod schemas and JSON Schema for the provider registry artifact served at\n`https://api.provider-registry.burnt.com`.\n\n```bash\nnpm install @burnt-labs/provider-registry-types zod\n```\n\n```ts\nimport {\n  RegistryArtifactSchema,\n  SUPPORTED_ARTIFACT_SCHEMA_VERSION,\n  type RawProvider,\n  type ProofPlan,\n  type ProviderHostGroup,\n  type EndpointHostBinding,\n} from '@burnt-labs/provider-registry-types';\n\nconst artifact = RegistryArtifactSchema.parse(await res.json());\n```\n\nThe generated JSON Schema is available at\n`@burnt-labs/provider-registry-types/schema.json` for consumers that do not use\nzod (the Rust verifier, CI conformance jobs).\n\n## zod compatibility\n\n`zod` is a **peer** dependency, and the supported range is\n`^3.25.0 || ^4.0.0`.\n\nzod 3.25 ships the whole of zod 4 at the `zod/v4` subpath, which is what this\npackage imports — so a consumer pinned to zod 3.25 gets the same types and the\nsame runtime behaviour as one on zod 4, without migrating. That matters because\nthe largest consumer, EarnOS's `data-ops`, exports zod schemas to ~20 workers\nand cannot move versions for this package alone.\n\nDeclarations are emitted against the **floor** of that range rather than the\nnewest zod, and this is load-bearing rather than incidental: zod 4.4.3 gave\n`ZodDiscriminatedUnion` a second type parameter that zod 3.25's bundled v4 does\nnot have, so declarations built against 4.4.3 fail on 3.25 with `TS2707`. The\nolder, narrower generic satisfies both. `npm run check:consumer-compat` in the\nsource repo packs this tarball and compiles a consumer against every version in\nthe range, so the constraint is checked rather than remembered.\n\nIts root validates a **registry artifact** — the bytes at\n`/.well-known/provider-registry/providers.json` — so compiling the document and\nhanding it an artifact is the whole job. The other shapes are `$ref` targets\nrather than alternative roots:\n\n```json\n{ \"$ref\": \"https://burnt.com/schemas/provider-registry.schema.json#/$defs/ClaimOutputArtifact\" }\n```\n\nThe root deliberately asserts something. A schema document carrying only\n`$defs` has no root assertions, and an empty schema accepts every instance —\n`{}` and `null` included — while looking exactly like a validation step that\npassed. The generator refuses to emit one.\n\n## Why this exists\n\nConsumers live in separate repositories with no shared build — EarnOS, the\nSatya verifier, the Expo SDK. Before this package their only options were\nhand-written types or a vendored copy of a schema from another repo, and both\nrot silently. A vendored schema validated against a vendored fixture detects\nnothing: both sides of the comparison are frozen.\n\nTwo partial descriptions existed and neither was both authoritative and\naccurate:\n\n- the service's own OpenAPI typed the envelope but declared\n  `endpoints: unknown[]` and omitted `proofPlans` entirely;\n- `tls-app-attest/contracts/provider_template.schema.json` typed the body but\n  set `additionalProperties: false` while the service served three keys it\n  never declared, so it rejected 16 of 51 live providers.\n\nThis package is generated from the zod the service validates with, so the types\nand the served bytes cannot disagree.\n\n## Contract rules\n\n- **Objects are additive-safe.** Unknown keys pass through, so a new upstream\n  field never breaks a consumer. Verified live: the registry went from 51 to 52\n  providers during development and the schema accepted the new one unchanged.\n- **Every field a consumer reads is declared.** The catchall is for fields we\n  do not interpret, never a hiding place for ones we do.\n- **SDK-interpreted nested fields are strict.** `auth` remains additive-safe,\n  while `auth.submitSignal[]` entries and their request/response rules reject unknown\n  keys, enforce the Expo SDK vocabulary, require unique IDs and canonical HTTPS URLs,\n  cap every trimmed matcher string at 2048 characters, validate JSON-path grammar, and cap the\n  provider at 32 login-cover regexes totaling 8192 characters before publication.\n- **Fail closed on the rollback floor.** Reject an artifact whose\n  `registryVersion` is below `minimumAllowedRegistryVersion`; the floor moves\n  when a provider is disabled, so an older cached artifact can present a revoked\n  provider as active.\n- **Publication is not readiness.** `metadata.isSatyaReady` is a curated devtool\n  tag, not a verdict, and `templateGovernance.providerActivationState` is a\n  separate axis again. A disabled provider **remains in the artifact** — filter\n  on the field, never on absence.\n\n## Contract additions\n\n### Next — dynamic host binding\n\nDeclares `tlsIdentityPolicy.hostGroups`, endpoint `hostBinding`, and\n`replayCapturedUrl`. A pinned-set binding references a named exact-host group; the\nDevtool semantic validator (not JSON Schema alone) enforces per-host pins, path and regex\nconstraints, group limits, and proof-plan host intersection. Consumers must continue to fail\nclosed on unknown host-binding modes.\n\n### 0.3.0 — typed `auth.submitSignal`\n\nIntroduced the typed singleton login-submit signal contract. It was superseded by the\n0.4.0 array contract before the feature was enabled in the production registry.\n\n## Breaking changes\n\n### 0.4.0 — multiple login submit signals\n\n`RawProvider.auth` and its presentation-only login submit signals are now typed in\nthe Zod and JSON Schema contracts. `submitSignal` is an ordered array of 1–16 entries;\neach requires a unique stable ID and canonical HTTPS URL, and supports URL-bound request\nrules, request `bodyContains`/`bodyRegex`, response `bodyContains`/`bodyRegex`, an optional\nnavigation regex, a 1000–15000 ms timeout, and response-status handling. Unknown direct\n`auth` siblings still pass through for forward compatibility; the SDK-interpreted entries\nare strict. Regexes must compile, contain no backreferences, and pass bounded static\nbacktracking analysis; anchor body regexes and use `bodyContains` for substring checks.\nAdding, editing, or reordering `auth` changes `policyHash` because the policy projection\ncopies it verbatim.\n\nThis replaces the 0.3.0 singleton `submitSignal` object with an array whose entries\nrequire `id` and `url`.\n\n### 0.2.0 — `session_stored` → `sessionStored`\n\nThe registry served this key snake_case while every other key was camelCase, and\nwhile `provider-policy`'s validation rule declared the camelCase spelling — so\nthe rule matched nothing and the field was unvalidated on write for as long as\nit existed. The wire format was renamed to the spelling the rule, this schema's\ndocs, and the verifier's policy-hash projection all already used.\n\nConsumers reading `provider.session_stored` must read `provider.sessionStored`.\nIt is not dual-served: the old spelling is rejected on write, so an artifact\npublished after the migration carries only the new one.\n\nThe field is part of `policyHash`, so affected providers' hashes changed with\nthe rename. Verify against a freshly fetched artifact rather than a cached one.\n\n## Do not edit `src/schema.ts`\n\nIt is generated. Edit\n`backend/src/schemas/provider-registry.schema.ts` in this repo and run:\n\n```bash\nnpm run generate:types-package\n```\n\nCI regenerates and fails on a dirty tree, and a scheduled job validates the\n**live** artifact against this schema.\n\nThe generated `dist/schema.json` is a structural interchange schema. Publishing must use\n`RawProviderSchema` and the Devtool policy validator as the authoritative semantic gate for\nrefinements JSON Schema cannot preserve or express fully, including canonical login-submit\nURLs, URL-rule binding, unique signal IDs, safe regular expressions, and well-formed Unicode.\n","readmeFilename":"README.md"}