{"_id":"@canvas-js/signed-cid","_rev":"81-e89b7353b7787140a03853e7d9bf7045","name":"@canvas-js/signed-cid","dist-tags":{"latest":"0.8.29","main":"0.8.26-main-488c798d"},"versions":{"0.6.0-alpha1":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.3","@ipld/dag-json":"^10.1.2","@noble/curves":"^1.1.0","@noble/hashes":"^1.3.1","multiformats":"^12.0.1"},"gitHead":"b3397b06e2e76066338116e14cc291fad5543d09","description":"This package implements a tiny signed data format for IPLD values. Any CID can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha1","_nodeVersion":"18.14.2","_npmVersion":"9.5.0","dist":{"integrity":"sha512-PzEFWJTLnvNdimYLV4x50CgVmdIS3Rly7I5C9+ww1gStYONedga+94p3o7BCdOH+wahzi7FiZFeT4zs/lACYpA==","shasum":"a7c0496bf6a6b27c86d5a2fe01ab1453118d1f58","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha1.tgz","fileCount":14,"unpackedSize":10219,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDeZOodbooX+GR/DnAUMyRlNCbRh/1UBZjKbkh26AKtIwIhAKRGs2rk1zT/DkNLAbnTp7856uZBDvq8VeRWqRfkSkCc"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha1_1694858670689_0.624825117189056"},"_hasShrinkwrap":false},"0.6.0-alpha2":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha2","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.5","@ipld/dag-json":"^10.1.4","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.1"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any CID can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\nexport type Signature = {\n\ttype: SignatureType\n\tpublicKey: Uint8Array // redundant for secp256k1 but still always included\n\tsignature: Uint8Array\n\tcid: CID\n}\n```\n\nThe signature signs the bytes of the CID, which carries metadata about the encoding format and hashing algorithm, plus the hash of the encoded value itself. This allows `Signature` values to be redistributed via different codecs without breaking signature validation.\n\n`ed25519` and `secp256k1` signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. `secp256k1` public keys are always compressed.\n\nOnly the `dag-json` and `dag-cbor` IPLD codecs are included by default, but others can be used by implementing the `Codec` interface. Similarly, only `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are included by default, but other can be used by implementing the `Digest` interface.\n\n## Usage\n\n```ts\nimport { createSignature, verifySignature } from \"@canvas-js/signed-cid\"\nimport { ed25519 } from \"@noble/curves\"\n\nconst privateKey = ed25519.utils.randomPrivateKey()\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = createSignature(\"ed25519\", privateKey, value)\nconsole.log(signature)\n// {\n//   type: 'ed25519',\n//   publicKey: Uint8Array(32) [ ... ],\n//   signature: Uint8Array(64) [ ... ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignature(signature, value) // throws an error if the signature is invalid\n```\n\n## API\n\n### Sign\n\n```ts\ndeclare function createSignature(\n\ttype: \"ed25519\" | \"secp256k1\",\n\tprivateKey: Uint8Array,\n\tvalue: any,\n\toptions: { codec?: string | Codec; digest?: string | Digest } = {}\n): Signature\n```\n\nDefaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Verify\n\n```ts\ndeclare function verifySignature(\n\t{ type, publicKey, signature, cid }: Signature,\n\tvalue: any,\n\toptions: { codecs?: Codec[]; digests?: Digest[] } = {}\n): void\n```\n\n### Utility types\n\n```ts\ntype Digest = { name: string; code: number; digest: (iter: Iterable<Uint8Array>) => Uint8Array }\ntype Codec = { name: string; code: number; encode: (value: any) => Iterable<Uint8Array> }\n```\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n","readmeFilename":"README.md","gitHead":"c22ac04418a7bbf4ac93187baceb01018037dda8","description":"This package implements a tiny signed data format for IPLD values. Any CID can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha2","_nodeVersion":"18.14.2","_npmVersion":"9.5.0","dist":{"integrity":"sha512-S0cBXmkYAjd1U2Ne7fUjgwEeEgBnyR/+TEFmqb2fUrGE+G6HiQMEmalXKEWzE6v63AG4eU+nZNDoSDOVJUkxfQ==","shasum":"e30e5cc26dd46dcafe00339a5c8608f1b72f17c0","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha2.tgz","fileCount":14,"unpackedSize":10219,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDK+LlQgzfrm+wU05XbMbboOcv6HJqynNizEWqnDrThCQIhANThLQI05eGDm8syZM5w13Hc3kxLOPh0wmpwvA4JocQz"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha2_1694859005063_0.47920549953896385"},"_hasShrinkwrap":false},"0.6.0-alpha3":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha3","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.5","@ipld/dag-json":"^10.1.4","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.1"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\nexport type Signature = {\n\ttype: SignatureType\n\tpublicKey: Uint8Array // redundant for secp256k1 but still always included\n\tsignature: Uint8Array\n\tcid: CID\n}\n```\n\nThe signature signs the **raw bytes of the CID**, which carries metadata about the encoding format and hashing algorithm, plus the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n`ed25519` and `secp256k1` signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. `secp256k1` public keys are always compressed.\n\nOnly the `dag-json` and `dag-cbor` IPLD codecs are included by default, but others can be used by implementing the [`Codec`](#codec) interface. Similarly, only `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are included by default, but other can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { createSignature, verifySignature } from \"@canvas-js/signed-cid\"\nimport { ed25519 } from \"@noble/curves\"\n\nconst privateKey = ed25519.utils.randomPrivateKey()\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = createSignature(\"ed25519\", privateKey, value)\nconsole.log(signature)\n// {\n//   type: 'ed25519',\n//   publicKey: Uint8Array(32) [ ... ],\n//   signature: Uint8Array(64) [ ... ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignature(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\n### Sign\n\n```ts\ndeclare function createSignature(\n\ttype: \"ed25519\" | \"secp256k1\",\n\tprivateKey: Uint8Array,\n\tvalue: any,\n\toptions: { codec?: string | Codec; digest?: string | Digest } = {}\n): Signature\n```\n\nDefaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Verify\n\n```ts\ndeclare function verifySignature(\n\tsignature: Signature,\n\tvalue: any,\n\toptions: { codecs?: Codec[]; digests?: Digest[] } = {}\n): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ntype Digest = { name: string; code: number; digest: (iter: Iterable<Uint8Array>) => Uint8Array }\n```\n\n#### Codec\n\n```ts\ntype Codec = { name: string; code: number; encode: (value: any) => Iterable<Uint8Array> }\n```\n","readmeFilename":"README.md","gitHead":"1a31b4407542b9ca9e6f993ef5b719c9434dc4f8","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha3","_nodeVersion":"20.4.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-I990SIOFbQAaLK2dMFVzwlgxPEp3phvjj3XUVXde/snxvkM2CmeDT0u3cqhCXyyLRTrHgzknJGQSItrzcVdqfg==","shasum":"2da519f36a38d92e2d4db77a81b59434cd57e352","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha3.tgz","fileCount":14,"unpackedSize":11325,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBVSe+mV05U+j4+5pbx5RlPUoHhvme4xX5iqKry8VSJhAiBmM0P8vnaEAv7tU442Oztn/cK3FNew45U0EkrqZWjtWw=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha3_1696307017510_0.5338671326709523"},"_hasShrinkwrap":false},"0.6.0-alpha4":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha4","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.5","@ipld/dag-json":"^10.1.4","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.1"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\nexport type Signature = {\n\ttype: SignatureType\n\tpublicKey: Uint8Array // redundant for secp256k1 but still always included\n\tsignature: Uint8Array\n\tcid: CID\n}\n```\n\nThe signature signs the **raw bytes of the CID**, which carries metadata about the encoding format and hashing algorithm, plus the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n`ed25519` and `secp256k1` signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. `secp256k1` public keys are always compressed.\n\nOnly the `dag-json` and `dag-cbor` IPLD codecs are included by default, but others can be used by implementing the [`Codec`](#codec) interface. Similarly, only `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are included by default, but other can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { createSignature, verifySignature } from \"@canvas-js/signed-cid\"\nimport { ed25519 } from \"@noble/curves\"\n\nconst privateKey = ed25519.utils.randomPrivateKey()\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = createSignature(\"ed25519\", privateKey, value)\nconsole.log(signature)\n// {\n//   type: 'ed25519',\n//   publicKey: Uint8Array(32) [ ... ],\n//   signature: Uint8Array(64) [ ... ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignature(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\n### Sign\n\n```ts\ndeclare function createSignature(\n\ttype: \"ed25519\" | \"secp256k1\",\n\tprivateKey: Uint8Array,\n\tvalue: any,\n\toptions: { codec?: string | Codec; digest?: string | Digest } = {}\n): Signature\n```\n\nDefaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Verify\n\n```ts\ndeclare function verifySignature(\n\tsignature: Signature,\n\tvalue: any,\n\toptions: { codecs?: Codec[]; digests?: Digest[] } = {}\n): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ntype Digest = { name: string; code: number; digest: (iter: Iterable<Uint8Array>) => Uint8Array }\n```\n\n#### Codec\n\n```ts\ntype Codec = { name: string; code: number; encode: (value: any) => Iterable<Uint8Array> }\n```\n","readmeFilename":"README.md","gitHead":"e142dcec0f778470fa8106f782d2fd0005acaff0","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha4","_nodeVersion":"18.14.2","_npmVersion":"9.5.0","dist":{"integrity":"sha512-211/KNVHMiF0R/WZg8ncv1KKFk+XOe030H1m0PbotIDQHvNcbXNbTOM+p7+df6tKw7OrAa6+deEV7iizUjNNgw==","shasum":"b36d4f8080248625a2bffc8484eafd20dde1a006","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha4.tgz","fileCount":14,"unpackedSize":11325,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCAkbSqWZrPmR595IZk5UHNniK0n6KGkzzYgGFL3L6l9gIhAM88RhQeMVJDXsW4qiC/iw40JL0IqdbEJtMILb+1IvIe"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha4_1696371136562_0.3474051802921698"},"_hasShrinkwrap":false},"0.6.0-alpha5":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha5","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.5","@ipld/dag-json":"^10.1.4","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.1"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\nexport type Signature = {\n\ttype: SignatureType\n\tpublicKey: Uint8Array // redundant for secp256k1 but still always included\n\tsignature: Uint8Array\n\tcid: CID\n}\n```\n\nThe signature signs the **raw bytes of the CID**, which carries metadata about the encoding format and hashing algorithm, plus the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n`ed25519` and `secp256k1` signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. `secp256k1` public keys are always compressed.\n\nOnly the `dag-json` and `dag-cbor` IPLD codecs are included by default, but others can be used by implementing the [`Codec`](#codec) interface. Similarly, only `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are included by default, but other can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { createSignature, verifySignature } from \"@canvas-js/signed-cid\"\nimport { ed25519 } from \"@noble/curves\"\n\nconst privateKey = ed25519.utils.randomPrivateKey()\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = createSignature(\"ed25519\", privateKey, value)\nconsole.log(signature)\n// {\n//   type: 'ed25519',\n//   publicKey: Uint8Array(32) [ ... ],\n//   signature: Uint8Array(64) [ ... ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignature(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\n### Sign\n\n```ts\ndeclare function createSignature(\n\ttype: \"ed25519\" | \"secp256k1\",\n\tprivateKey: Uint8Array,\n\tvalue: any,\n\toptions: { codec?: string | Codec; digest?: string | Digest } = {}\n): Signature\n```\n\nDefaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Verify\n\n```ts\ndeclare function verifySignature(\n\tsignature: Signature,\n\tvalue: any,\n\toptions: { codecs?: Codec[]; digests?: Digest[] } = {}\n): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ntype Digest = { name: string; code: number; digest: (iter: Iterable<Uint8Array>) => Uint8Array }\n```\n\n#### Codec\n\n```ts\ntype Codec = { name: string; code: number; encode: (value: any) => Iterable<Uint8Array> }\n```\n","readmeFilename":"README.md","gitHead":"7e9a66afa85467f1d23623335e726f485bad070a","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha5","_nodeVersion":"18.14.2","_npmVersion":"9.5.0","dist":{"integrity":"sha512-rFkO3IL0l68UixpLTkkzvJlQtJpYLqkp3kY5TtlR8yS2xkgLRK551fslZSfA49Own+AIpCKrPGRdzCxjtJixMQ==","shasum":"b75d37c10420e8a3fa924b2566fe3f3df9e6288c","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha5.tgz","fileCount":14,"unpackedSize":11325,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIB3L+xBfN0apHErhR7eiz5oX3fMIE3DFMEBpI1nnNWnDAiBEfB2pVVrXojjJiJk3m2J7tUbDzGn0ERf/n8nGvzUslw=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha5_1696415379749_0.6832089828861034"},"_hasShrinkwrap":false},"0.6.0-alpha6":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha6","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.5","@ipld/dag-json":"^10.1.4","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.1"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\nexport type Signature = {\n\ttype: SignatureType\n\tpublicKey: Uint8Array // redundant for secp256k1 but still always included\n\tsignature: Uint8Array\n\tcid: CID\n}\n```\n\nThe signature signs the **raw bytes of the CID**, which carries metadata about the encoding format and hashing algorithm, plus the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n`ed25519` and `secp256k1` signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. `secp256k1` public keys are always compressed.\n\nOnly the `dag-json` and `dag-cbor` IPLD codecs are included by default, but others can be used by implementing the [`Codec`](#codec) interface. Similarly, only `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are included by default, but other can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { createSignature, verifySignature } from \"@canvas-js/signed-cid\"\nimport { ed25519 } from \"@noble/curves\"\n\nconst privateKey = ed25519.utils.randomPrivateKey()\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = createSignature(\"ed25519\", privateKey, value)\nconsole.log(signature)\n// {\n//   type: 'ed25519',\n//   publicKey: Uint8Array(32) [ ... ],\n//   signature: Uint8Array(64) [ ... ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignature(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\n### Sign\n\n```ts\ndeclare function createSignature(\n\ttype: \"ed25519\" | \"secp256k1\",\n\tprivateKey: Uint8Array,\n\tvalue: any,\n\toptions: { codec?: string | Codec; digest?: string | Digest } = {}\n): Signature\n```\n\nDefaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Verify\n\n```ts\ndeclare function verifySignature(\n\tsignature: Signature,\n\tvalue: any,\n\toptions: { codecs?: Codec[]; digests?: Digest[] } = {}\n): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ntype Digest = { name: string; code: number; digest: (iter: Iterable<Uint8Array>) => Uint8Array }\n```\n\n#### Codec\n\n```ts\ntype Codec = { name: string; code: number; encode: (value: any) => Iterable<Uint8Array> }\n```\n","readmeFilename":"README.md","gitHead":"495a2432d499d3f06d1596cb981a0d0ebd33c7e1","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha6","_nodeVersion":"18.14.2","_npmVersion":"9.5.0","dist":{"integrity":"sha512-MzQL+ipE1vSR+D+CY32/mFTV8lVAeHFM0NkkvQmlr/EeL0AUwjYhTSLWnUbkIIj5/sry2eUhad+7Bo9cEN2X8w==","shasum":"94774de1b9e5514069805aada1632c236e87e5c3","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha6.tgz","fileCount":14,"unpackedSize":11325,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDJ9Xmfj7ASsu9alAY78Nez3t46P4ebaKmu1C3sh2eg3QIgNMn47d/RYZbK8Rk8Z+zlmmq8oHyUAAxDPQK9U98hyGM="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha6_1696460365269_0.5977533964540105"},"_hasShrinkwrap":false},"0.6.0-alpha7":{"name":"@canvas-js/signed-cid","version":"0.6.0-alpha7","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.2"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\nexport type Signature = {\n\ttype: SignatureType\n\tpublicKey: Uint8Array // redundant for secp256k1 but still always included\n\tsignature: Uint8Array\n\tcid: CID\n}\n```\n\nThe signature signs the **raw bytes of the CID**, which carries metadata about the encoding format and hashing algorithm, plus the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n`ed25519` and `secp256k1` signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. `secp256k1` public keys are always compressed.\n\nOnly the `dag-json` and `dag-cbor` IPLD codecs are included by default, but others can be used by implementing the [`Codec`](#codec) interface. Similarly, only `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are included by default, but other can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { createSignature, verifySignature } from \"@canvas-js/signed-cid\"\nimport { ed25519 } from \"@noble/curves\"\n\nconst privateKey = ed25519.utils.randomPrivateKey()\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = createSignature(\"ed25519\", privateKey, value)\nconsole.log(signature)\n// {\n//   type: 'ed25519',\n//   publicKey: Uint8Array(32) [ ... ],\n//   signature: Uint8Array(64) [ ... ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignature(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\n### Sign\n\n```ts\ndeclare function createSignature(\n\ttype: \"ed25519\" | \"secp256k1\",\n\tprivateKey: Uint8Array,\n\tvalue: any,\n\toptions: { codec?: string | Codec; digest?: string | Digest } = {}\n): Signature\n```\n\nDefaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Verify\n\n```ts\ndeclare function verifySignature(\n\tsignature: Signature,\n\tvalue: any,\n\toptions: { codecs?: Codec[]; digests?: Digest[] } = {}\n): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ntype Digest = { name: string; code: number; digest: (iter: Iterable<Uint8Array>) => Uint8Array }\n```\n\n#### Codec\n\n```ts\ntype Codec = { name: string; code: number; encode: (value: any) => Iterable<Uint8Array> }\n```\n","readmeFilename":"README.md","gitHead":"c6401aee7ef2f67a8bdaf3a6a915f05baf3748c0","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0-alpha7","_nodeVersion":"20.4.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-cl6lb7tGCRORMwGcgFkPTZN0yHmTlStxRfc7ffI3aSRKfI5/QA8PV9RzFjdu4RLr/Gf6or/VFJec5GQ3W/aWSQ==","shasum":"c8228147bbd9816855153b8d4023c32ea0dec4c3","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0-alpha7.tgz","fileCount":14,"unpackedSize":11325,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC+xQBUEocn/AD2goGraFyhcxQPDz0Wv8hvbvFgfWDL6QIgMtHyk9HwrPUsy5OQv3I5zejfYERlrukJEKzmLN07HyI="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0-alpha7_1697198404536_0.5649336857223974"},"_hasShrinkwrap":false},"0.5.0":{"name":"@canvas-js/signed-cid","version":"0.5.0","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.5.0","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"gitHead":"49fe03f81900c83f4366132d7594a9211e45a92d","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.5.0","_nodeVersion":"18.7.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-+hyixqCtPEERV5/g5i5EPEurjzH9HixOOsQ0PG7366k39nP0ZQ49F3O4JjNEuXCho+il1e2b4r0TfogGbYoYSA==","shasum":"c537007bf62c02b5526259a9fffe574872952602","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.5.0.tgz","fileCount":14,"unpackedSize":11302,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCEW8JWvZKkneyKsHBtXjGx35p61gAaRL3Hdd6dRkNGywIhALIb0Buofs2s29yuj5yNiwWFQso1gGkjW77Ng32sRzaF"}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.5.0_1698425560996_0.9587172690291701"},"_hasShrinkwrap":false},"0.5.1":{"name":"@canvas-js/signed-cid","version":"0.5.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.5.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"gitHead":"ff9bb86883166008528d0025765fa89241ca1dbd","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.5.1","_nodeVersion":"18.7.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-A0mwBh34aQKTnFfziPP33iZz9fsOd9xlWTYkk23zlgIcsaQebQYEfdsipoFhxjLvfbaMIXnUO6RB/Cb8XZ4Svw==","shasum":"8473e9d5556b106d4bfecafade666b7889297e19","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.5.1.tgz","fileCount":14,"unpackedSize":11424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFbAtKtOK3Sdt7Gp95/Yxa0+m/3cyHTdWgJjH6pflP8BAiEAyFOcKqrK/As4TKxmaU5naDLcL02g3Bi1jxJECoCwJAs="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.5.1_1698786762502_0.8553518192666736"},"_hasShrinkwrap":false},"0.6.0":{"name":"@canvas-js/signed-cid","version":"0.6.0","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.6.0","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"gitHead":"861ccf71276e0928901a3535717372c68cbb0a62","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.0","_nodeVersion":"18.7.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-gJECY5FM0CjzIHy8ef/AGKt+xYUhQINAiBkSqrDjk/ANPeTh6JCF/c4F+5M+OH3pJFMZq0l0eisqB+oAcGXUMQ==","shasum":"9336a25ff44e702848056b771ef88eb6f1f98d51","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.0.tgz","fileCount":18,"unpackedSize":20048,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAk6kPqcteLsOApJM5Ug7Y2dj5i4N6wr2ctR2oZqgPhhAiAE6sy/zSSOTBaUpBTAZHT2pV6fyF88BPldtUcbRWltAw=="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.0_1699581883843_0.7343499308535213"},"_hasShrinkwrap":false},"0.6.1":{"name":"@canvas-js/signed-cid","version":"0.6.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.6.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"gitHead":"190ba852ea0b44e39be65bca1924edca67c124f0","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.6.1","_nodeVersion":"18.7.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-s1OTIS5EiWy5R0iLkMg3D9fJZh4qj+zeRhCN5YsX0nGEty16jSOogRj3BapO5bA8vKTpvndv52/Pbq/7vNwowg==","shasum":"f2c2f4cef4e981e496f23737466ef2f409e184fe","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.6.1.tgz","fileCount":18,"unpackedSize":20048,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDdfv1JfBDooqcyBXtGik2jqRV5AA2j7fQdhPdD49/hIgIgXCPjDVhgPWYr9koIYiTnklQminFsL5REvJId9Dzl8O0="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.6.1_1699582514965_0.41868067664290143"},"_hasShrinkwrap":false},"0.7.0":{"name":"@canvas-js/signed-cid","version":"0.7.0","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.0","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"gitHead":"5c829eadb6ba896ea12e018dbe2e37621840f82d","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_id":"@canvas-js/signed-cid@0.7.0","_nodeVersion":"18.7.0","_npmVersion":"9.7.2","dist":{"integrity":"sha512-kqHdO0OiOjcNF7r5IoRmvP7EvPyPYcNt1jJ1OdJX0WBdKfrEPhW0AUSIYXgLQtyaUpDxzQRgBkfRMrgOHmYXvw==","shasum":"55719e68f2d55b5472a037f0fa17526d0b756ed5","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.0.tgz","fileCount":18,"unpackedSize":20048,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBI9Tiyc5dEnV0OM7fz6nNM0Qv/3RypOgAnkJsRGN9J+AiAPoLhYTO8BleoRiA6uUi0AvdzwO7F2Pm6Bk+zw68FwGw=="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.0_1701210937587_0.4856440286175234"},"_hasShrinkwrap":false},"0.7.1":{"name":"@canvas-js/signed-cid","version":"0.7.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.1","gitHead":"163efaebbf0061222cf814d231df55202ec7220d","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-0SuG5+0UytMWssBOJH3ZGK58FB6HTPgu8m/WOTdWbsbzhT/8YQ9U0eHXCz4YHU2m1oozFdUwX/qEurb7BWEeQA==","shasum":"811c7cbffd252f02dad83487dd11e05562d52e9d","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.1.tgz","fileCount":18,"unpackedSize":20048,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDiiS9DBJQG/0f/ET2I+EXgBFnujzhd9gHMXLZa4KFKmQIgHewlHfP1TVSE6rka6H9gZ62c5+O/ZqreOO3MiCRYh9k="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.1_1701458630745_0.11059992060398716"},"_hasShrinkwrap":false},"0.7.2-alpha.1":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.1","gitHead":"baf3c62bc1ba1cee8b9a54fd78923df0e057c28d","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-koQMas0de5LfWbqZXNyk4lbaukQttzayB/zVyUb7IlfQpOnoqPQW0h92jrzIF0m5Zc+y5p5T4NYVFiNq0g6HFg==","shasum":"9a1ffa4cdde93d2e958f7666e29aab40c7b05ddf","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.1.tgz","fileCount":18,"unpackedSize":20064,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHyBLckm8uGwCxdPCV3jVLo9LVhnqKmOdzU+a3JWsMJHAiAfHYAJGjOe+ZV95PiHjzuXFYHteMTccRGgruAqxP8K9Q=="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.1_1701547327547_0.4557306848988696"},"_hasShrinkwrap":false},"0.7.2-alpha.2":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.2","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.2","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.2","gitHead":"8b3e6353de94884674856d4eb494b477cbd83a0f","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-GDQEard5r1v59ekwZMlRWjuCNvaA2hGOp7/5IuiV4A5CM1bHOxl9tRBVTf6kjhfiUAAyCzoYZVOxRRzkOPB12w==","shasum":"bd271b3ae7992a3fce21647a631cbd82c2101b4a","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.2.tgz","fileCount":18,"unpackedSize":20064,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIH0Cm9FlEKh+ATfhbm0bL9TAi7OVeg7R7wyeSPRUusPnAiAFTMPtDeBE5RpTj2RNC5GED0LMPgVw7htjp38q/Rs6CQ=="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.2_1701547891585_0.15720320195145998"},"_hasShrinkwrap":false},"0.7.2-alpha.3":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.3","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.3","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.3","gitHead":"496e9f88219247fa46931555c21ffcf8efb730be","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-VWxLm4Me4iKJ3NeQ15V5hwVnIclQqhjDxWe7X4xgy9pJfChHx35xzuKPH1OpeBRQY14pBnxWZ9vZY6C4B/s4qQ==","shasum":"f26ed7bbebbea191e3d12d7f357653d39ccdc0db","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.3.tgz","fileCount":18,"unpackedSize":20064,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCeDjxxMbPvCl56NucjuBv13foBIIhCd3brEMK6aHqKzQIhAO3/5Z6jGnbE1RDhvLuvfdqXzc3X3Z3FUqQFm4E7vbF9"}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.3_1701548797785_0.7862002595460742"},"_hasShrinkwrap":false},"0.7.2-alpha.4":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.4","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.4","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.4","gitHead":"ee23b9276663cf2ecea5a285a6cac0a99117b000","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-PltKLXK2t1u6F8PTzxgptl80uA0xlHIGkwyaRg3oXzEleIKcVHLKNU58gjvODX/n3+CO/PqZcUKW7Zxw4jP02w==","shasum":"568863778917d304a02eed5df6e8d0393eb4226c","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.4.tgz","fileCount":18,"unpackedSize":20064,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGGT/k+eFbwV2NUWpht8ksWt++gSEG/VnYIhbgLgSZHAAiB5N9DO2l7Do8wEiGd3quMz9YBNv32NzG/FSynCXnjWAQ=="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.4_1701557430025_0.7571435953156336"},"_hasShrinkwrap":false},"0.7.2-alpha.5":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.5","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.5","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.5","gitHead":"2561abda8033cbbcda6b4327324305c2ad59952e","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-dfv3rSO1r9KjPOWF1+gIRwvd6pSgOAeSveApMenLn89zxQ4Oi5haPUska6FizIZP6Lp4PbJmY/Ys1WZAHtFZBg==","shasum":"99bce1abdb35a90f529b5113938affdb78a8741b","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.5.tgz","fileCount":18,"unpackedSize":20064,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCVIA10Fuh3b3p2wGaefw86Iv00mh5dtXel1nKdoMhccAIhAMX/AhkncFBux6GP3htgIpJULN0shbW8Q7POKUm5D2dq"}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.5_1701558226122_0.9632101644525359"},"_hasShrinkwrap":false},"0.7.2-alpha.6":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.6","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.6","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.6","gitHead":"36611d3f57b811a134bd0c33641983894ff0267f","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.19.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-EUfP/xvYYBJKp2lIsN6xnpwWhowfODuT7UpOCgKQZh6PQ3P2sNm28Wuj8AEmsB0LtEvzKdvpeQfgBajgB2nJXA==","shasum":"6e13d59819919626724948de53c5b15175231140","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.6.tgz","fileCount":18,"unpackedSize":20064,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCPra7XXUY/77yiFJk/HlZ4pXoaFhfyvJCOvIFfk6CnOQIgKN+JaGL1exkiUhaOWigtsTXKaUJ0I+wN2xOcpumvAzc="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.6_1701561421641_0.06925344757872964"},"_hasShrinkwrap":false},"0.7.2-alpha.7":{"name":"@canvas-js/signed-cid","version":"0.7.2-alpha.7","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2-alpha.7","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2-alpha.7","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"97e7169b77c903e33a736a1bdfb3cecff6ae97d6","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-R/JafCGFC+wuoONJxrvKY2ecAh/vma7XKfZT/oOWUMUkA8txESNtrK9mbwuFblpuLFTYgZcjuK6UQaiNgX4ZTw==","shasum":"f8fe11b64cad8e87f098d6d2571a0e19d8419987","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2-alpha.7.tgz","fileCount":20,"unpackedSize":22440,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGaMutG31uQrBYgcsWlH7plZHLJtXKHOr7BQpr7yUcw4AiEAhdDx0qRQ7janHMhn50ITOe129FAxXIQ5Ao4AtOv8ZYk="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2-alpha.7_1701568472463_0.4384148083506032"},"_hasShrinkwrap":false},"0.7.2":{"name":"@canvas-js/signed-cid","version":"0.7.2","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.2","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.2","gitHead":"0e03a9d5984fbbb999ef31e906ab5f15884d85f4","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-a/+uJFfMac4yazFa+d+sQvnOs06QpH5FSQPbW3eZKnRyf4d0vL7ROqEdTP0HAB5IcKYquhE9Gh428vdoZRJoKg==","shasum":"25c532ef187c3872822dc70c599fb8effde753bc","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.2.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDNw0/nvunrkV5heSjbkOqIRCQlFwgiOUfDIHlsPgZBWAIgUh8o7vqgzKISN34ZLbJ1UtrQgLG+vImIWSCQb5AFRbI="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.2_1701587810108_0.21524588546383083"},"_hasShrinkwrap":false},"0.7.3":{"name":"@canvas-js/signed-cid","version":"0.7.3","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.7.3","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.7.3","gitHead":"1a49d676c51ac8d43fb2103873d4c5147c2ee918","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-n0PAtJpNLoj+1oxbO+kHhIHbE1isp3G2PMRVM5WpPBHbsWrb2atsAytc84bUE7J/poEM2GautLBE1DUx9W13Og==","shasum":"9bd98ad14d2a6c613c6d32a45794579f0435fee1","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.7.3.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFAo17WkkdiB8bqWjUL2GsIQ+T60uP/v/3Sofc6uqA5EAiEAkBOeW+u4JyliINkwT8scq2b8e3YP8U4Yel+O/eWgCos="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.7.3_1701622202506_0.8159524703943473"},"_hasShrinkwrap":false},"0.8.0":{"name":"@canvas-js/signed-cid","version":"0.8.0","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.0","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.0","gitHead":"46bef2263d6e7ec9b746ced2c47da52cb7d8190b","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-YIN7Vvd2BUAP2xF1Jiw0ivj0F9lbgKzUQWy/74X4MTMyTUwkCoT7pKD9Y1rWfwlE+a9UpK5uNFl5TQFmQLZ8Xg==","shasum":"067264845a4fa7e736ee0f8169e594abdacd33f5","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.0.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFJkX6iH0cFggjdLfaj2WaLlsqN0E/7zTaDNS1mP6FHoAiApSgYCtfrbUYs63dl9w4yD6MMqvO0uz6kqPlLeKx0JUw=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.0_1701648426905_0.49899678386306867"},"_hasShrinkwrap":false},"0.8.1":{"name":"@canvas-js/signed-cid","version":"0.8.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.1","gitHead":"ee6eac58466e4770f053bfb8f7ce0dbc47f93ab7","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-cW6pI8qUTfRagADQXrx1zDuaKyQbMGT/cg5IrLV+PXC9n6WJOnZ10nQLVcLnjDPeF6gssXViu6VhmV06g+rJ8A==","shasum":"f76683dbf3e0259605b32f9c4c73e3bdf869b2ca","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.1.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDGVpNzMthggfaxBzNGGRWkYe8AR6B+zNrYdKreW3byYAiA9VW/1Ebho82wr+5DUWtc0817ukAINt5N5VbP1uYGN9Q=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.1_1701665677958_0.31439106691724183"},"_hasShrinkwrap":false},"0.8.2-alpha.1":{"name":"@canvas-js/signed-cid","version":"0.8.2-alpha.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.2-alpha.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.2-alpha.1","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"3eccfa06f54ee94c7f67d2414e62a9ac42d57785","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-z92omNMiQm8UKsa2zfLgW7dGEb3Qv5c6cFGpx1ozZXYqzSYXfF2Wf55yW7Iwam7C4Tfzr8sPhTCJDhwPbFwn2A==","shasum":"d0a31184cf22ebcd37698712cc08065261542802","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.2-alpha.1.tgz","fileCount":20,"unpackedSize":22440,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD13pzCsNyK8keerciFIBue5fZy1jE1Z1RQ6AM5/RSOAAIgdngAnwxt/03axlC4xbuyOexYmgpT3QDzGbXG4FMIvYc="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.2-alpha.1_1701720334323_0.6253549467622161"},"_hasShrinkwrap":false},"0.8.2-patch.1":{"name":"@canvas-js/signed-cid","version":"0.8.2-patch.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.2-patch.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.2-patch.1","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"25ee9cf2a9dcbbea1f1cd35e029bc40c7da2e809","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-lYUgEu1krUqVWi1BN23Ny/1PA8NlqK2VqrtWSiAsuYkms1Ao/EJl5lmQ5WbWm/wBGY9mpDll8oyG6kQ8b8KKhw==","shasum":"79a5883a0700b9c1f81548473308fbf7da7def28","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.2-patch.1.tgz","fileCount":20,"unpackedSize":22440,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICqO9HYCKC9E72gMkygCG3+NZyiWbvmu48V7S5iaT5J3AiBHzfn3SAHNyfXwPAK4P37SoEh/Dzlzncm4KOpF5vhOEw=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.2-patch.1_1701726666666_0.6326658659045081"},"_hasShrinkwrap":false},"0.8.2":{"name":"@canvas-js/signed-cid","version":"0.8.2","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.2","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.2","gitHead":"4e4cb0b166377ce2698e8a243d8cf5640f4f9c15","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-L5NDWvInin9KMQlpQmpTrpdDgUwR1yYXJjL9yEaLiVPaw9VdaodOaztvVECESdSQUwAUgDKIrtn83cyHQhKsAA==","shasum":"dfba72dfdd0481f17b4dccd60fd10dade3fe7dc2","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.2.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDa6GmDe2XRyNFYcFSAlUC9I4zRq+ExmDlBpEha9NErPQIgTPUkKMNLgJlAhtpJQogMz0qGb2sAfJklZGXWZu67dw0="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.2_1701726987791_0.4412408481353982"},"_hasShrinkwrap":false},"0.8.3":{"name":"@canvas-js/signed-cid","version":"0.8.3","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.3","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.3","gitHead":"67d3b585df47d98c10aead773bccd50b5c693b66","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-YLl1V6VyEbwd5DT3dtkwP9W22lbQ9z82WUBMXP+nkXwHo0s5uWz8aE+1zD/p+l21Kxfqjx+/pgjB8th7AUymSA==","shasum":"4f13afa5f95fcb8a2b764ca1c1f938ced23c67b0","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.3.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHNrQb+OEndJQvaQ6n++coI2jAFPcUFDJgBc9C1C2FqOAiEA3h+js8eC8IooqCcENLowtindamihiregAoqoXTBeeKE="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.3_1701733125154_0.6397665589831574"},"_hasShrinkwrap":false},"0.8.4":{"name":"@canvas-js/signed-cid","version":"0.8.4","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.4","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.4","gitHead":"15938e9189c92aaa31bde250c9409e8731911826","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-NNd9PBJzJvF5e8I3yP4amTqbUOydoO6ivDU3UPVrW17GpJbpn+Gn1HiWYCdM7I/7MMS08tN4f0nW9BAXmXdMjA==","shasum":"5fd141fd3dcf7aab9c34265d9ea8784869306452","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.4.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC8ES373InjxtXsfFUI9G6lYo3PsG2Hf4XN4ZvtAA0pagIgceiVcjZNCZfRtWCh0uoPvsVSyh/+HMMdjozTVLFbWvU="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.4_1701733910299_0.8230366793156398"},"_hasShrinkwrap":false},"0.8.5":{"name":"@canvas-js/signed-cid","version":"0.8.5","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.5","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.5","gitHead":"bcd5851457d39175316a9afac3f8a2f444cafe50","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-yqY9zDhd6myAxHSXK10YCMEdA2U9JbAW5U9VqrOvIOi84PcRVjByiJ/tQm0w4YHgKUezg8RdgcJ1iK2FkoBw5A==","shasum":"22d6b27974703c21c82de409e965fa7138f21c9d","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.5.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDl5XO0wQhKu5E6THtg7SD8+aZoi9kxOGJVw8Nydh0wiQIhAIDsk1SBzFQV6j5sSljlIzSDWuQo7gPxNxsaTglnUZ/A"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.5_1701735588663_0.768516257036312"},"_hasShrinkwrap":false},"0.8.6":{"name":"@canvas-js/signed-cid","version":"0.8.6","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.6","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.6","gitHead":"f5cdbeaa480dd4ec34fc38a41c6914f462bcb3b9","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-3VCCtCgi5hAt6RN0aWbOAC1OCq1sKELvl1foNmgaOBYjn2JOoqnw+Q331Yvui5GF6J0CZFuCuQ6z5J6KrF/x6Q==","shasum":"d7fc7404b3ee3f477c07fdd6a23f0b6979ce8220","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.6.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC960jTPZiX9vIvaL7D9hrRiDXu3E+bs2cRzU8gpq2HQwIgJHlUKUMXImqYdxWMQF3UddlmQo5P7yWk+E8Xg56yrUE="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.6_1701744339175_0.43502380442904065"},"_hasShrinkwrap":false},"0.8.7":{"name":"@canvas-js/signed-cid","version":"0.8.7","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.7","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.7","gitHead":"4231dd8bfeba96323cb15687c3c6f86c9129a1e7","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-ZRf72/vatokU4HDcjYFFOyvNRXJ1/aK43rSKlXcqtXhHtREGonnx7QAG3AjcfA/+BoJcZuoUKnl5wiEqXlmcrw==","shasum":"f9361c4e6631f3de181b07b6b0e7f55227b257eb","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.7.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCT4TD/ONC+pakIsUWjCPb4J1doVN41c6EbNueM+ezExAIhANcuBCUFJ+bk4KEAepAptm3JtZUJlB/DV+iZvFiN+Rl6"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.7_1701748359666_0.8420256931312442"},"_hasShrinkwrap":false},"0.8.8":{"name":"@canvas-js/signed-cid","version":"0.8.8","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.8","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.8","gitHead":"e88792cef8d92ff05c30f1358974a286d2ccc542","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-d01AszzxAdP2lz4C8p5bRgUfqb9TrUdHMxfeEL5h/f7zZ/hQlopbTbXPr3krY6rn997WN2rbhBM3o9sPBk8wgg==","shasum":"fa5c66e0c8d4c3d4b4e6c5c3fb6c4020a0a7f6c5","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.8.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDsWqyO5i0wdafupLbfS5zyp8cyptORmeKuO7O6pvX5ywIgJU1vhwsJRoVAY05MANpRYg0rZSum4nn5tEBZD1FLkbg="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.8_1701749584873_0.7964121661996537"},"_hasShrinkwrap":false},"0.8.9":{"name":"@canvas-js/signed-cid","version":"0.8.9","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.9","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.9","gitHead":"982949d51236261fd593a29f56b3af1e7364d71a","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-okSUi/yURGluVnEHh2/DsCTBUTyPVHqo+7E3l9Tu5gzncQuFmpWrbvxPuEul8TgpDKz+lAI0+s42mjpE2p2LvA==","shasum":"15d2cced424eddce0d4e32c108bd3d300242d818","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.9.tgz","fileCount":20,"unpackedSize":22424,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHiSfOio5x7cV050J4zUY3+8VcUmf0bwEIqXZcKqgzKkAiEApZLK9MuhQWXakBFBFasJSOLzIzSVhuNaD60OPpk95wM="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.9_1701758082946_0.6712024553346185"},"_hasShrinkwrap":false},"0.8.10":{"name":"@canvas-js/signed-cid","version":"0.8.10","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.10","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.10","gitHead":"cd2e6df9b8788edcbbdd59a0adc9aede863dbc26","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-rz1eFNLfXd3YGhFxfpxGKn4gYCQavxakts5NqKBnzsOqOwAmsJEcowhkUVtG2hP1QHHFLXSazQbyOv9mh0tnWQ==","shasum":"6fec38ae1cd9d08f5aba24e1519572fb60cc7830","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.10.tgz","fileCount":20,"unpackedSize":22426,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD9MdPAD8jns+zgVlFFtahJp2vZr7ggMJK7iOqwcbPz8AIhAOBsYiSDn0Kwgo/FDWCQv3CP9G4Q8R/HjBM3T4CbvT/j"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.10_1701798959371_0.4583416673848397"},"_hasShrinkwrap":false},"0.8.11":{"name":"@canvas-js/signed-cid","version":"0.8.11","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.11","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.11","gitHead":"b8fc3b9ce0e48352ffb31a984ad90b3159d5a311","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-HjNw2smzROSVZ1ie6nejnnXQq5+gGNb7Y2q3x1gYIJznpngwFS+fbv5PlH71rF9zc686qWmqE9jMmYBz6toJSw==","shasum":"6cdcf4d0aaeb6d94891f806f303c8d4f5493e6b5","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.11.tgz","fileCount":20,"unpackedSize":22426,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIErMUW8ytfdEYxIk/aRLyLBJx5SJY2LNiTCnn/SqLWk6AiAr+IuRG4PbIXlTKQoe30dh0Asg2Mv5ena6FXkgdsUl6w=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.11_1701805972556_0.3492476702023193"},"_hasShrinkwrap":false},"0.8.12":{"name":"@canvas-js/signed-cid","version":"0.8.12","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.12","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.12","gitHead":"f5232c0a68d96ac3526573395563a8785e66a147","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-T70Bwt8Wz2f8Dt17SsNLOeKGk6i6lTx5bvgGb/EsFRvNol5/apCWso9rRhUG6o62RfJnb0fEfQKm2fV/56jbSA==","shasum":"d01f21337497a72d8f33a79e0f83d45e03200e22","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.12.tgz","fileCount":20,"unpackedSize":22426,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD+xdhm+7XcwBHSUqZ+L50I1TlCuzxBEDpqfOSjdDcdYgIhAK63IkyvQ1fqyntj6E8xD8H6uSt+Govh1JBTBmur5HmG"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.12_1701807294959_0.8845494668731171"},"_hasShrinkwrap":false},"0.8.13":{"name":"@canvas-js/signed-cid","version":"0.8.13","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.13","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.13","gitHead":"fab0153b91e08810410e9a35488ba2064c0f4914","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-llLv7pt6I6gMgV72L5OVX+3nl0m/nmAognC/uUNdNf2LKOn6EbsbcbBJe1YMhT8BERW9gYNpX4++NVoYAd7SAQ==","shasum":"814d1c902ac7b8bc8f384e94644f23d61ae99a9c","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.13.tgz","fileCount":20,"unpackedSize":22426,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCIh5ID1lgm2DYI66+kvMy2d/N+24Zfmuu6wxFICeF1bwIgYb3ZklnYWJFNB1D4bNX6mWRyz20vQZSHBVlTt7AZ3G8="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.13_1702006313306_0.9103700235186529"},"_hasShrinkwrap":false},"0.8.14-alpha.1":{"name":"@canvas-js/signed-cid","version":"0.8.14-alpha.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.14-alpha.1","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.14-alpha.1","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"214749543b8d15f4e5c38c214f4d309817789e18","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-BfHyD2z5LbgA+zPQO78fvCTpcfY9l7gpantKQMFeOFtkXcgg9hhGiF+6YZIcI29Ny5keZRL9fdxPVdu9cwy68g==","shasum":"f79584b77411aaca7c11f641c566b714669dad87","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.14-alpha.1.tgz","fileCount":20,"unpackedSize":22442,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDuCpZF7jJhzKiWu184RhicK0BZ5OqvJPMNojwJ6JKh7QIhAJw3uAPj+yRQPam5EfLorzdHThJYVlJYD8ESF98J3lCA"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.14-alpha.1_1702070661042_0.3922002010358012"},"_hasShrinkwrap":false},"0.8.14":{"name":"@canvas-js/signed-cid","version":"0.8.14","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"ava":"^5.3.1"},"dependencies":{"@canvas-js/interfaces":"0.8.14","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.2.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.14","gitHead":"4a9070a7db0ec9a6a000fb1c9e1126e6ac142068","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-HmfgvoT7vG710q/Nkh3oiJyfRvt3A25A4hrMhQbz0BMa2n8gIhkJyWXPvFLCo7EBYbUv43t19lG36qwf/Bex9Q==","shasum":"789bad01249ca6f903761372f59fcfe6d3fe9136","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.14.tgz","fileCount":20,"unpackedSize":22426,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIH3VdyfVOyK81r47oWuaCU9H3Udun9SRncYQIeo2JmdyAiEAxSHsH7UFYloWAiwcsVMtgLBWv6eDRSUqxuN4nhV5bmY="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.14_1702073535361_0.7003220261679708"},"_hasShrinkwrap":false},"0.8.15":{"name":"@canvas-js/signed-cid","version":"0.8.15","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/signed-cid":"0.8.15"},"dependencies":{"@canvas-js/interfaces":"0.8.15","@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.15","gitHead":"7af360a7f3e308e2d441c87becd51f178ff05dc2","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"20.10.0","_npmVersion":"10.2.3","dist":{"integrity":"sha512-vuPwQ9Qlg6voOFh/o298BA1/31vNKraecEECiES7kQmbt7HtgiKbXSJfzS2v2zdXyWGIOwxxG9ZvRjdEnBiCqw==","shasum":"5b80f66614511539318c747470c5bdc86c0225ef","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.15.tgz","fileCount":18,"unpackedSize":20068,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAEJrZ0THGQA7SuiEeedqhDPys2CcxWtDc6aRhMiH/YZAiEA81BLCSZyeqtU+gINmNTnU8ABdlzRkqu7Hgek2gEOnTA="}]},"_npmUser":{"name":"joelg","email":"joelg@mit.edu"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.15_1702945696642_0.4063272586562794"},"_hasShrinkwrap":false},"0.8.16":{"name":"@canvas-js/signed-cid","version":"0.8.16","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.16","@canvas-js/signed-cid":"0.8.16"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.16","gitHead":"d9540dc8fa4c28d52e9087bcaa90899fe37149a7","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-pRGrgjOpfN4ZDE8224GUv7aFPAx1RIEUIof0SRZ0JLrR9qQjHnBuKKWBKafpcnUWIArrrEsZoEKozXZ/Y9BxlQ==","shasum":"1e0109ce1a95639ec8e9e0e8929e2d94d4ba1cd3","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.16.tgz","fileCount":22,"unpackedSize":25864,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDmRgYZum9SUhNL0xZXAB/PBWG0Vd+dV7E2nrvPMTHsgAIgfCPEjDlS2HTZP5lCF2UbflHU45TUPIgipgDm34aYoD8="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.16_1703626399903_0.5096151458515232"},"_hasShrinkwrap":false},"0.8.17":{"name":"@canvas-js/signed-cid","version":"0.8.17","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.17","@canvas-js/signed-cid":"0.8.17"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.17","gitHead":"66e9c4a2b1229c071c61cda085e5c9068e837945","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-Gvm3fZ6xA35RfIj4o78A4le5lpqKugZIOwo6TDtD1eTuj5aCrxpazF8ArAVCYak/MyIwBPYjX4vNkbB3pptPYQ==","shasum":"24790e9754910af8e23d1abdd05e31aa2bce33cc","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.17.tgz","fileCount":22,"unpackedSize":25864,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD2WNPiVtUIW+zx3pfMusmswev3pSfHT7ga+Fuiqkyc7QIgTqoi1TWWWLo/Mya07LuwH3prbPLFK/H5aSFvcUqMQ2g="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.17_1703713051069_0.04764747828116511"},"_hasShrinkwrap":false},"0.8.18":{"name":"@canvas-js/signed-cid","version":"0.8.18","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.18","@canvas-js/signed-cid":"0.8.18"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.18","gitHead":"e2d4dcaf5b82f421d43cf4ef90fca2a8170014da","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-g0toV67Qbdcul+8IPHlrMbe57jbQSHYliRYywix1wEoK4m7lOiZTi0/Iq2IHWJRV8Y/nFDkbRdTrCd21XQE5+g==","shasum":"5d283d76d02fcdc15c5ec8c8ac81ba251d2a1c22","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.18.tgz","fileCount":22,"unpackedSize":25864,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCLAduwFb7c0qteJZolsqW3++5oq2OLYgUAgk7AN/e4IwIhAIEVlnEepRHFMFNjQOP4LVhhmzk4nKcI7Bb9RQ2a8bPM"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.18_1704159999657_0.24829583397349042"},"_hasShrinkwrap":false},"0.8.19":{"name":"@canvas-js/signed-cid","version":"0.8.19","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.19","@canvas-js/signed-cid":"0.8.19"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.19","gitHead":"803cd527cb146ad02ca07b18455d342ac1cfb8be","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-lTz4r58lyggJpjuNprHJjYf77+S+rtrk7ml36m1guS5AkK97glI1LSEKaZAJjZgQBFYT+DaHPbBaypHqPXIxow==","shasum":"1638f00210af79177aae2e39e96cc8a1d19435d9","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.19.tgz","fileCount":22,"unpackedSize":25864,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC8jKAoNr28/ym/gzhIF66XE0uJIjxEtZQ4JMWpN247KAiBctL/JTmQ6AsT4qM35vsFqyvwLTDv6CLaCG97W6AnNPg=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.19_1704162154442_0.3676201638834591"},"_hasShrinkwrap":false},"0.8.20":{"name":"@canvas-js/signed-cid","version":"0.8.20","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.20","@canvas-js/signed-cid":"0.8.20"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.20","gitHead":"33f9acf7aae1fdb2dea6c7f55fbcfd9fcb219c7d","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-9rLhdiGiBDcg2Kd/vzQQeJk/TXG0aQMasyjgKeOeUALjId51sT2uPoN4c7d89/zPBW+/WUr+DwMBSgShoBTw8w==","shasum":"df0d207adfb31649c01347a6786aa32f54a91aa0","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.20.tgz","fileCount":22,"unpackedSize":25864,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDJssGDQQYjMwYoTVmqANEUZtviQdYR3V/URuyAPJJTHQIhANTZDHvvMRIIpqFko1YjucWsbSmmZeZwXbBbBxWuzqO5"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.20_1704498590348_0.7981897429433851"},"_hasShrinkwrap":false},"0.8.21":{"name":"@canvas-js/signed-cid","version":"0.8.21","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.21","@canvas-js/signed-cid":"0.8.21"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.21","gitHead":"65b2047a04b11952128596bfe060f7940b0cb96d","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-GvmD+zK8cpSId+12hDNce1ebE/Qkt89no+lByPhKccr0e3BwAanRb/3G2F8Z34CnzM7+DXHRb1WztMYADdDTxg==","shasum":"c18dcacb73f7ab3fdf97c0af424f16a98cf6e5b7","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.21.tgz","fileCount":22,"unpackedSize":25864,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCLTerIrpOFDwyGCkVYr1wBHTNf45NzBIWzBGBmg5m2jgIhAIT4ri2TRoh5WvYLPdTeQcjOe+k1ACXPZ5EruL3WfkaJ"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.21_1704505775823_0.23448557614501508"},"_hasShrinkwrap":false},"0.8.22":{"name":"@canvas-js/signed-cid","version":"0.8.22","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.22","@canvas-js/signed-cid":"0.8.22"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.22","gitHead":"9d2857d5aff34829f4391db88a60bc30207ffa00","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-UgktLh97NcnNvptpFm9vPWMCatqIHvmV7hzjMne+OPFHVbIMiB8S5TP59eqcfEZRYRwTX9gd8FVX23FRIrSlnw==","shasum":"24c51c5f897347d1a994ff720784080ad4b0420d","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.22.tgz","fileCount":22,"unpackedSize":26839,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICIgCz1RO45ATTOltWbSTj/T2H0sbN6Yq4LjF+QkKN8oAiAQuV6sC+epTvckUo9xMWEmYDSkYOU3j6XlFJZ6ygY92A=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.22_1705564365149_0.20377648579479501"},"_hasShrinkwrap":false},"0.8.23":{"name":"@canvas-js/signed-cid","version":"0.8.23","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.23","@canvas-js/signed-cid":"0.8.23"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.23","gitHead":"c747cbaf6f94ef73558dfc54cf6943f977dfe783","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-ePnXhw6vi5KJpkuJJrfgQfr+gqn/3ORotODOphx0Ofqst6JHgVZbxiJ6g1WjC2dp8dmbFM6D3lqWdqi2O++/oA==","shasum":"d5c21cb25f3a9504aa750247821b688bbc53896d","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.23.tgz","fileCount":22,"unpackedSize":26839,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDYaQJChvQDTsW3D2SdV9WmHvMHoVu2d9cZX0G/CvEowAIhAJZgCNXd5JxjOOCVb9HARC7BczXqqlBqx3+UzJtVcShi"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.23_1705565966200_0.8732213430401539"},"_hasShrinkwrap":false},"0.8.24":{"name":"@canvas-js/signed-cid","version":"0.8.24","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.24","@canvas-js/signed-cid":"0.8.24"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^12.1.3"},"_id":"@canvas-js/signed-cid@0.8.24","gitHead":"1dcec7ff0fdf12bc2b213c0c65bdabfd01297ca6","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-Y+uVx9hC8eQ+ZoJw/kbQH/MvhhUO6RBpYI8YO9Z7pYvTjy9CznAUiqoRANTpz1ALHgsRkEPNe+tu5j8h9Z1cPQ==","shasum":"b4735022a32a15b5dc586543365b7eecd0a5e6d5","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.24.tgz","fileCount":22,"unpackedSize":26839,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC4MzDcHLEuEJlqyZI+KcbnMLRxZp/0uCduQU8bkLrw9wIgePdZ0g4fhgGk8eGxlmCpei/2CaBnmfpljlZYy05oJoY="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.24_1705605462280_0.38698734025128534"},"_hasShrinkwrap":false},"0.8.25":{"name":"@canvas-js/signed-cid","version":"0.8.25","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.25","@canvas-js/signed-cid":"0.8.25"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.25","gitHead":"e088aafe5b2aafe2f046b7a8b4e121d7ba148c4e","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-+E1VPqTUtYbM6NV5jY5mhfCq3ikihSEw7XJmuwoLd1krXJw0R/OdypAa+fu05SK549S/pInEQGEJx7OIhz5aCA==","shasum":"045d8e7fe5d7946d2db56c779230987027960d33","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.25.tgz","fileCount":22,"unpackedSize":26839,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCKKUtl7iUnX9U52FFMz1gJoVZrUK9sS6yAisSzidFRwQIgdV2SmKoHPUb99bSW/sq3OsKVVQItpIbi+30UkMAcFc4="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.25_1705623771124_0.6024605894432087"},"_hasShrinkwrap":false},"0.8.26-alpha.1":{"name":"@canvas-js/signed-cid","version":"0.8.26-alpha.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.26-alpha.1","@canvas-js/signed-cid":"0.8.26-alpha.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.26-alpha.1","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"62a1933ddcbbcfc1bd06a9a386e85cedf391e2fd","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-Fuo9RcwjEWrrcAVR7A6wKFSg++NV+UE4ltgglS1YYiCLMIUAQGTiFkqffW73wl15Usv0TL0GcOwLDzhJ4oHXqg==","shasum":"a77f2949f6b84fedd901e854c2011ee8cbe5c400","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.26-alpha.1.tgz","fileCount":22,"unpackedSize":26863,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC/3c9Wx2VlaAZFy6r3YFZnfk/GaNz3al/0S3j2+jTphwIgLYyE8OnknUl/vZpmRZawF3Fn7qOpRZ/75X1pLcIQnP4="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.26-alpha.1_1705688027648_0.40465698478632617"},"_hasShrinkwrap":false},"0.8.26-alpha.2":{"name":"@canvas-js/signed-cid","version":"0.8.26-alpha.2","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.26-alpha.2","@canvas-js/signed-cid":"0.8.26-alpha.2"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.26-alpha.2","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"05587335aadd9dc1b47f26b9d588e249dd57d0e3","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-xcLFlKK24P7DoD4EQMgdGSm5+8SRbRivLZVkGzTbt+RW5j9p7pfhyd4Y4wjL7tW7mNIDcMaO4ZKubEwK+cNOfg==","shasum":"7e54704b0e3a180d81924a5340e747fb2fb39c1c","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.26-alpha.2.tgz","fileCount":22,"unpackedSize":26863,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCeVygqb5sKD54irOmKzL41CLVUEo+4DvjkeJr0isb3+QIgVu28W9rggQcAjlPZcovtIDjGuP/tOOu/b2IqiFNZob4="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.26-alpha.2_1705708779340_0.5128005281036814"},"_hasShrinkwrap":false},"0.8.26-alpha.3":{"name":"@canvas-js/signed-cid","version":"0.8.26-alpha.3","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.26-alpha.3","@canvas-js/signed-cid":"0.8.26-alpha.3"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.26-alpha.3","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"4e873f7ad3944e1b65202fe28ab516f94e0db0a1","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-DQCgjsr2l2Hzx9XDkdWwOFQRtwDA3VC6k1UVvSuqhIIm0GwOVXK5UrISkR3g2vzKF6NqMBtTs+kaTv/LPVp0Yw==","shasum":"7abb0ec94ad6fd84c5adbe64a7c529b25641cdca","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.26-alpha.3.tgz","fileCount":22,"unpackedSize":26863,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCQQ0Eh/zIwWUlBw1SPKQFq0ofJOkh6xx+qcs2eYfp7SAIhAI3VYYGUY3gtG9EalJwrvRygxJUY1lwyHf+2GCeObT5C"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.26-alpha.3_1705717870290_0.4344824322063665"},"_hasShrinkwrap":false},"0.8.26-alpha.4":{"name":"@canvas-js/signed-cid","version":"0.8.26-alpha.4","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.26-alpha.4","@canvas-js/signed-cid":"0.8.26-alpha.4"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.26-alpha.4","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"0a0855cadfca0afd3afca87c6c51527896f97217","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-7yyp2vuJSUzYZW5O3Drw4nE7GxxR74gPQFTCm1MmTu7RW3i5R9Sw9xQ9Z3yf3/Le7F9pfK6C7KOsYT2DUKjsYQ==","shasum":"41b1b011694ad15c6f5d5ef204503a00d97345f8","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.26-alpha.4.tgz","fileCount":22,"unpackedSize":26863,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBXYwjDUve8oRh/HsHouFFQ/d85oQBJsYQdER7BbFmglAiARdosZLFc1a55TdBoP1TZLe/gWWTvnK97LzI60F5mXqw=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.26-alpha.4_1705780437487_0.8272551854403674"},"_hasShrinkwrap":false},"0.8.26":{"name":"@canvas-js/signed-cid","version":"0.8.26","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.26","@canvas-js/signed-cid":"0.8.26"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.26","gitHead":"a08d11268634a47cfb42ce825ace624a592d9c71","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-vh4AGM9ah5YprQ5i/EzZ4eKpZG9hh9LNQc+pU8CLXe0L2ofasCsTvI29BmP9DkYxaE67kqnvujhuJTL6Aqzz7A==","shasum":"3ff9cdcab5c42c955fd1470d73a65148dc7c9c80","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.26.tgz","fileCount":22,"unpackedSize":26839,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGEGOK9ZCq4QmibXDf+Suxc4F4aezOAYSJ+y7hTWNG/PAiAxhRX3xXlvUAXLSuIOpqe5AgqW3RxjhfSsAs1X+RQncQ=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.26_1705782307057_0.4328538049565196"},"_hasShrinkwrap":false},"0.8.26-main-488c798d":{"name":"@canvas-js/signed-cid","version":"0.8.26-main-488c798d","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.26-main-488c798d","@canvas-js/signed-cid":"0.8.26-main-488c798d"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","ethers":"^6.9.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.26-main-488c798d","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"f5fa3238e08245c9c3d21c4c24dc99dedd46cb21","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-r+2VbSD9VByr9XJGD3344SBa65w7xVSwITUJaSxOLvHuDREDqg8lOpk2OGkzKo3bTDlw8AuTmhmj5uR1bU/gfA==","shasum":"3f86509f100c029a41856bfd3f28efedfe8d4612","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.26-main-488c798d.tgz","fileCount":24,"unpackedSize":35902,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDQxhvQKd8vSqJOLh6CGM8qH1lK0OA1wFgddONX4JrpHwIgDiTAscSoaPFP21m9KSl3aHa83OmH+dqQ6D+f9PF4pQI="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.26-main-488c798d_1708039941738_0.09705909367876453"},"_hasShrinkwrap":false},"0.8.27-patch.1":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.1","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.1","@canvas-js/signed-cid":"0.8.27-patch.1"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.1","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"2d884ef0881fd52445d31e9e27a025eac42208da","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-LlJ87LZoqjwCQrXba0X2P85T+xrXVR0fuUCFqSlabOVi3G6/yIAf4fNLprlVcG8FA0Gj5vBs47KvLdz8FM960g==","shasum":"0d00354b8cd654970ae455a63f8eb952f9a8ed9e","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.1.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCyr2XPjf8L0do1iuVkpOo7fXHbu4NTAy2VA4eXENg1aQIgTry43iOiZNpj3L1PEWCouQz6ENOV9xrnxH/5Z2yiUf0="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.1_1714305480074_0.7438946757299754"},"_hasShrinkwrap":false},"0.8.27-patch.2":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.2","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.2","@canvas-js/signed-cid":"0.8.27-patch.2"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.2","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"413abd6c57044eb19ce772e87851a7635463ca61","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-ttciKydCkC44eXwumC+PvoC88V3s7crcDZM3omJE79d6XqtOcPDekKxEgOpulwl71XhT9AVpyG2sqCO3ly8WBg==","shasum":"e447827b60407b054a1f574815a13dc8f4e9e6bd","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.2.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD66JC1yc7QEMiOJRyAa2JlPLVT2iQ/7+g76Hiy0IqvwwIhANN6sY/mezjWZ5OjQzLg4OxP3oP674J9hXpR8FsnJVcZ"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.2_1714339220719_0.5285590377668561"},"_hasShrinkwrap":false},"0.8.27-patch.3":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.3","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.3","@canvas-js/signed-cid":"0.8.27-patch.3"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.3","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"6a48d6b22d281b96fe8921290d6589c2ec3d87a3","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-KvwzHc/Hpm+VTBNwd9SDk0MvTH0ldTvZl703lcA5Q2cagyr8C5X/ppZLWks5mNZWVvECDZEziWLrp88IK56KrQ==","shasum":"9dfeaf10fcf20fb1290eb747fadb92cbad439a0e","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.3.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCeO0nZcyrOpQOTlAyBpgvySBlqqLwLgSl0d/VMjM0r6AIhAIFFFnLjWiRXBwCehIGrRvfRb35WDFU7r1040KltYnA8"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.3_1714340796234_0.9692683266378455"},"_hasShrinkwrap":false},"0.8.27-patch.4":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.4","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.4","@canvas-js/signed-cid":"0.8.27-patch.4"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.4","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"76d7f9f4d9adc4f9a9d5e2c8045f7cc7f072d2d6","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-kMZlkF12B0vZpoFDaj3QmZHwEq+G+zbxEHgkeyoPmNR3qeUBgPajfPQuxRrfCSH8LzPbb6yUyr86Xh0sMAtrKg==","shasum":"ffb89c5567895d6ffcfc8e74fc13c91f3be11b48","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.4.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDtiSFlQRvfRGWmxn53YkNCShW64zUdndZhDA+VZwIZLAIhALzIfF2nWvagdizRT7E7TfDe0G+V0e/ZBdFk+D+B6D4C"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.4_1714342647113_0.5859973047041671"},"_hasShrinkwrap":false},"0.8.27-patch.5":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.5","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.5","@canvas-js/signed-cid":"0.8.27-patch.5"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.5","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"5ce9a133ac299f1210c046ec1f43742cc06faed0","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-fbsS9PyZtTRMLryxJ1PgXvhszdT3qY+oQC8BGvpVcYEwak5FY86Ek/ps5mpklIr8/TQ57QeGycVdhYgSoSNtpA==","shasum":"47f610a50e734b4d6f3c64ee86b1993f24adb4c7","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.5.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBeycGWbtBMjGIshSzYSGVzBGcrHqwgkhuMy3JJiSFDJAiEArnS3x58kT2ku3qghQ3nQn8JD4Pc1m2a1zAHm9bj5xqw="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.5_1714344936852_0.3706865763630087"},"_hasShrinkwrap":false},"0.8.27-patch.6":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.6","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.6","@canvas-js/signed-cid":"0.8.27-patch.6"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.6","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"e404c399f6d68df6bc6905e6372fa2f815c34cd6","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-5RTkbfIynKvNQgsszM669IfODNj2z9H7q8tyo45iA/PC0L5lwjd4c5ajbOndt+Ac6AZXRUIAXEvZDHhH8qRkHw==","shasum":"ed10f2d59154f751772f61776671a24a40c81649","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.6.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDTDW5DsuqZ29s4Fe8uVIgGORv7yuAjOlzmOVS8sMHTWgIhAL8KxSFnWDmxQ+IYpsMthlfNRPxTf1nj0sgZse8EE5OV"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.6_1714602433673_0.19065813507949736"},"_hasShrinkwrap":false},"0.8.27-patch.7":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.7","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.7","@canvas-js/signed-cid":"0.8.27-patch.7"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.7","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"532432cc5d6ac0de3eeaca17f64d42c7f1594720","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-dxSLeMmB2JHycwqOWxxIA3CPKwLd3kPHfF0eXW+fqcd9f17LUtltdOziI7BCYD8KJ1b+8vV0mLeLW/+5mhyfIw==","shasum":"c89f4a8388426f790bb2ce43c437a032be6ff120","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.7.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFhJKyepq1LCeFiftxeD3+/UH/FSlMndz+VGJKN8796lAiB+POraNem68goW3GZpmaTpSAv10bkwecffsqi1sraymg=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.7_1714605756065_0.17955598352760926"},"_hasShrinkwrap":false},"0.8.27-patch.8":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.8","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.8","@canvas-js/signed-cid":"0.8.27-patch.8"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.8","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"7edcb65ccff60eedb3e60c721ada31168a2d92b6","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-WLe22o2nnnMpSmvFs64nar9xdAC5jCbOOv67N1o4Yyoforo6HyYJvr+O73XGa+1glPrmX0+oVsxvmftbkLzoHw==","shasum":"a3fc1977a6a0e5893e63ea5d459b6b3c870348ff","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.8.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC948gI9tYiMxHx/PfusSDVYBfnaT8hAZmviVkk1yERDAIhAM/yZDDSXc58AU5G+xxpXGOwpYevqcC0H8tI0GVL0F9/"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.8_1714619374525_0.48659028398674"},"_hasShrinkwrap":false},"0.8.27-patch.9":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.9","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.9","@canvas-js/signed-cid":"0.8.27-patch.9"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.9","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"032aa18effc24529acba641e9f28727a6c4463d3","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-zajru9KUGoaEYw59KWUGWYkpuft2QAYsM7uM9LV/r5b5yFz2ruA84MasKum+ZIHH0mvvIkNG2ECSrJjnFVEUAg==","shasum":"f9662b2b7f00cbb06f0f29ac0fae334bde93c96b","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.9.tgz","fileCount":18,"unpackedSize":20092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHhRqkHExL8AAPDWfq+KFFs4vnNSHIyABOGuCaXidqxCAiEApb13ZPnf48LQwDzmXGLR8YI52INnFDeylZhXk34msAw="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.9_1714622556758_0.6788332578626635"},"_hasShrinkwrap":false},"0.8.27-patch.10":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.10","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.10","@canvas-js/signed-cid":"0.8.27-patch.10"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.10","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"e8848160dd7f2097788e3fb6c05ac0813704acc8","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-ENm6U5M3yXqO6DWzn2DoKo2JcjyrldQcLUnoFG1ozS3+C+w37wo5bRWhCVjPrRrBEk0/BDfvfbk1NrUobZRtdA==","shasum":"3e2a970dff9b401f3e460f7747d2d4d3310e6a39","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.10.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDjCL/wkA8fzFwr5XThdlqMmO4bwhhjKxQPfBhETkRgfQIhAPDHxpz8StwG+e5diFUVIO2D6q40fYDSOhWLJj4TU5ye"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.10_1714632722319_0.4849404881674655"},"_hasShrinkwrap":false},"0.8.27-patch.11":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.11","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.11","@canvas-js/signed-cid":"0.8.27-patch.11"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.11","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"f8078bf48754086e1f1fdb8a6506a7cc37c04a1c","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-5WkqBBvkveVQeV3/6YsLosrygpOl9rYeicnCck0ZqjhGpqjtIdH/r7BQV0YGsWNzLKOM9Bgscj4zBQHQfMiu4w==","shasum":"99f9097f50ef9ddf28a0fb9f2406cc1ee51d3225","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.11.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC3ous6bc2puKc1havGAqmEcWq1Eu2xjCrrAYDspKiOdAIhAIuFUeE2Us+eoVaV1o4LKN0ELyic8FyPsQzWgn2im9R5"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.11_1714633574294_0.6211869800574152"},"_hasShrinkwrap":false},"0.8.27-patch.12":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.12","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.12","@canvas-js/signed-cid":"0.8.27-patch.12"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.12","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"78a71cd5b05cead5b50e7810eb25a430e2a1eef5","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-LpOoY2t2YthJwurSU7oqt/wyudBd/IGtkLU9JDOapf4C/OONmn0I4RQyvzKfQLVdxq3rxWVA9CIqhwmpkfYRTQ==","shasum":"18bed345889d813209c3944cbf468892d1e1baa9","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.12.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIF+Lwfy+k23eXaVnF1qMtlGlXzPft3+FXY2AInxYBRbXAiAJucCv8gForAFozlkIAoizCXaaBjEC8vK4wr3zSOHO9Q=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.12_1714641208368_0.029170004699137664"},"_hasShrinkwrap":false},"0.8.27-patch.13":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.13","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.13","@canvas-js/signed-cid":"0.8.27-patch.13"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.13","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"01344233db17392277863b5d0eaa21c861799ffa","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-YIiavd85EMSBsXW+9u8gp64WYKGsCyaX71zqfUuH5CpC+2dpOOBeRP44JfZUKIOc9ZaiBzAsVyDJ+GMYueIoHw==","shasum":"80d3ad2c0a93cdb0fe98e7baf9f3a26560fdddef","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.13.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICf+NMMChriYEYZLaBq/UL8tY9+fRl45ed/pToixB3seAiEAopS65shy3oyAEtsoBdDQHg8wZMv0EbTPRf5V7+OokXo="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.13_1714644462975_0.24387035237119115"},"_hasShrinkwrap":false},"0.8.27-patch.14":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.14","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.14","@canvas-js/signed-cid":"0.8.27-patch.14"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.14","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"ce91e4856f95bb4bd5a58d65195e9891d8a7cfd8","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-DmTjKOiJGgT5m8hpOmq7NSyvNC5uFA7fFs8Uicw7B9e/YEHu1gg+2xmlGN3hXWG9jGdoD6FSnflY9o2viGyYuQ==","shasum":"f02f57e11a0fe05a0c97cd3b375a709807c1e1f5","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.14.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQD6SIXAj7WZILZeGNUcLmYIdmH+VXbLYiB2Ag1FMD/ssQIhAKrAgSKUg+EhPp8RIrX+7NbjQEYcJneXMEh5sQ7qHfK+"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.14_1714679590075_0.14799905361664178"},"_hasShrinkwrap":false},"0.8.27-patch.15":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.15","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.15","@canvas-js/signed-cid":"0.8.27-patch.15"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.15","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"99498d66fe187fcfbfe22170d02b60a494e86510","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-Xi8Jwi7vt3Vn6SaTwbbyMm55xO8ySsfAw83xdcqQ3AfDiC2AdlM4389He1JfPeq3ydh7T3hLajMEJVamqwtElw==","shasum":"10fc5463c962b104e43e26b96289b6c6079f9715","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.15.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDELEF/KaT1lGq4RqBATTVCq2VWtJJeOfSPNNh8HD9CxgIhAO8msbnw+6cgd4JD5Q7ycJtys0mDfHCaGlZt0JJwPcyD"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.15_1714687502873_0.22460410766625505"},"_hasShrinkwrap":false},"0.8.27-patch.16":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.16","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.16","@canvas-js/signed-cid":"0.8.27-patch.16"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.16","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"4137f6f086aaf82269cf344656a4c8a5dc8ecacb","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-RsX84dvlfU7QziPHCj+JNFTahFA1UJpsvtXL8mUAEEKOIxHSoqAdGtVIlF4nQYIEbuEe6O33MKLY9Zkm2ILR6Q==","shasum":"fe1fe9c7ae69de3b4b4162f36b9874c764185523","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.16.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDMuFcpL/o4AcZF9UhwsVyfM3/dedLvwv8b8z+RC5TH3QIhALCqxPOKrDSlmM3l15aBCvf/w6ybLk6ApocH798Drpua"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.16_1714688238448_0.07071630566135267"},"_hasShrinkwrap":false},"0.8.27-patch.17":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.17","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.17","@canvas-js/signed-cid":"0.8.27-patch.17"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.17","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"38c3e62f0b4c8cc3a550994c373e76a8ff1bc516","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-8TWhODZV6Elp1EdpCzAKa4q5LLKKP4jWJT7xkXFme4N2MAi+zFK8WkBYmLYQhcuZtnzEeRrW+0aq7opBkE8jCw==","shasum":"48ba65e552e21f5416b5edb91d5d02d66c4d594e","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.17.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGb2XrNdLFQv9SGufoS9yc55svJPDmu0d96C5yWMX/dGAiBRafp9effjGk7f8gRIZH9FGznzg/ckh8UYByM95pncKQ=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.17_1714760977595_0.6270117996718152"},"_hasShrinkwrap":false},"0.8.27-patch.18":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.18","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.18","@canvas-js/signed-cid":"0.8.27-patch.18"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.18","gitHead":"762fa73a447ea97c5379681b3d3cfe58ad51fc9f","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-2cmv2WXKG82Jm+uVmprEtb4GynRw68ExPXo6OUf3Qcp3RET0Fkn2L5P9LC2E6ZoLS+OgI/aoCOv6GJ3uyUspMg==","shasum":"12f24bb9b72a0f2dca100081ae6f56568d262d34","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.18.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICclm30tkJZQnC5pm+fseZ/pcU3tCCOupgnrR8TUbIK3AiBYjojL39UHyihi0R5BgDukfRWjFnCretwlExTa11OKuw=="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.18_1714763126839_0.05057514761046389"},"_hasShrinkwrap":false},"0.8.27-patch.19":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.19","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.19","@canvas-js/signed-cid":"0.8.27-patch.19"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.19","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"ec827388c1e44b133868b56293f6e4f91af6c924","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-uOjuaPOdRSUCH4S9xc02BLhvDOpXwT1l3yWcsgkN1NtmjI6bWBb+xujiyiMlXAFOC6KIGFcwDMvDuoGlhy1lbQ==","shasum":"a645034eaf3fe1cac0e22ca6c4b85cf6b29cbf75","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.19.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAISvKGkoD1o8uQEFqfWa8C5TbFuC6bNgvNlbcG7JO0GAiEA6AOJfUlcf749ALn9KTjNJpLd7bkMyI4STvyETo6mV0w="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.19_1714764032181_0.8652843668796038"},"_hasShrinkwrap":false},"0.8.27-patch.20":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.20","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.20","@canvas-js/signed-cid":"0.8.27-patch.20"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.20","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"f1fdcdc097c527e805c590fab8cb80e727e87cf5","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-d/GPBYO74r34Z3rZwXpC0/eYLYDX9fhb/jd+1sdBk3QLhH66RSaq84J8MoHt67/s2rbdK96zqF61sAHkwmYShA==","shasum":"fca60401b76f0abbbfe3dabb648c6bb9c127c02e","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.20.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCWSY4ix1U2KYxz6dblMXJB2J1Sm1sXA5SwjV4EGq4AOAIhAIuBMdqragHiVvIjcURaMbiEZnwJxaZX0DGDdV1XzY+v"}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.20_1714764764796_0.7779271991837553"},"_hasShrinkwrap":false},"0.8.27-patch.21":{"name":"@canvas-js/signed-cid","version":"0.8.27-patch.21","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.27-patch.21","@canvas-js/signed-cid":"0.8.27-patch.21"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.27-patch.21","readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md","gitHead":"9bf65b1489a2352438d41988cf4b77c21672671f","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-+ZlQG8CgOfzbotzWiD16mpNeeuXuTRd369O2wNi0T6dXzEfdIYd/yYBvcr0ye/ozQW474ZL/GKifWFNLGpW3Ng==","shasum":"502ba5a54df4c2ff8d546c001aca7fefeca3f0d4","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.27-patch.21.tgz","fileCount":18,"unpackedSize":20095,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHhCFcwD0doaoQgma3sc0M8qOacHkOGbJTHr64OO8UdTAiEAoxQYiHHCG2rhDwwfZB0UTtmjVasU+Qx2oTsA9Swua4s="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.27-patch.21_1715656125940_0.9786935271882695"},"_hasShrinkwrap":false},"0.8.28":{"name":"@canvas-js/signed-cid","version":"0.8.28","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.28","@canvas-js/signed-cid":"0.8.28"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.28","gitHead":"dd7d9696f09f728e950872f31d89dfc3f82cb0ac","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-2iaIUd7ki3MW+SSI3u0j0ePx+KvR4jK6Taie3OHIPxav5hdSnSO/ZBFMcXdWNiHGtQU9+uT7HfoAhOoTiMKaGQ==","shasum":"681849ab57c46ad079678569c854eec2dbb14852","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.28.tgz","fileCount":18,"unpackedSize":20068,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFGESqBr4/8ThNvHcDfzQlxgOiYMB+U9bGNFpDv/Raj0AiEAtj5NPpdOOEdwskYArBci1EVJJEiSy4cwg0o23IL4Dag="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.28_1715819037408_0.5061281485286566"},"_hasShrinkwrap":false},"0.8.29":{"name":"@canvas-js/signed-cid","version":"0.8.29","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"type":"module","engines":{"node":">=18.0.0"},"main":"./lib/index.js","types":"./lib/index.d.ts","sideEffects":false,"scripts":{"test":"ava"},"devDependencies":{"@canvas-js/interfaces":"0.8.29","@canvas-js/signed-cid":"0.8.29"},"dependencies":{"@ipld/dag-cbor":"^9.0.6","@ipld/dag-json":"^10.1.5","@noble/curves":"^1.3.0","@noble/hashes":"^1.3.1","multiformats":"^13.0.1"},"_id":"@canvas-js/signed-cid@0.8.29","gitHead":"0fc5332fe2fecb5b76b20d8baea513f24c3ab045","description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","_nodeVersion":"18.18.2","_npmVersion":"9.8.1","dist":{"integrity":"sha512-+mldPkS62LmSrFocPtOxMID20W3upZ7jh6W/t8BPdqS2R/cJBVx1wzrMUKGsyT1qZii6zwVvWz07vYWC7LPppw==","shasum":"d38935a79bb2814d1ecac13bc86e040f428e2869","tarball":"https://registry.npmjs.org/@canvas-js/signed-cid/-/signed-cid-0.8.29.tgz","fileCount":18,"unpackedSize":20068,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICBrfxsIux91PTiNq4hvR/1QIzJgB8ykreH4UpCc+7eoAiEAvBEFgENjNjAAFODAoONkUvlrRTmgXTEZxkl1ZmYEO6c="}]},"_npmUser":{"name":"raykyri","email":"raykyri@gmail.com"},"directories":{},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/signed-cid_0.8.29_1716308653454_0.16509370079510055"},"_hasShrinkwrap":false}},"time":{"created":"2023-09-16T10:04:30.595Z","0.6.0-alpha1":"2023-09-16T10:04:30.850Z","modified":"2024-05-21T16:24:13.793Z","0.6.0-alpha2":"2023-09-16T10:10:05.299Z","0.6.0-alpha3":"2023-10-03T04:23:37.692Z","0.6.0-alpha4":"2023-10-03T22:12:16.773Z","0.6.0-alpha5":"2023-10-04T10:29:39.941Z","0.6.0-alpha6":"2023-10-04T22:59:25.493Z","0.6.0-alpha7":"2023-10-13T12:00:04.702Z","0.5.0":"2023-10-27T16:52:41.244Z","0.5.1":"2023-10-31T21:12:42.735Z","0.6.0":"2023-11-10T02:04:44.089Z","0.6.1":"2023-11-10T02:15:15.227Z","0.7.0":"2023-11-28T22:35:37.731Z","0.7.1":"2023-12-01T19:23:50.915Z","0.7.2-alpha.1":"2023-12-02T20:02:07.753Z","0.7.2-alpha.2":"2023-12-02T20:11:31.785Z","0.7.2-alpha.3":"2023-12-02T20:26:37.967Z","0.7.2-alpha.4":"2023-12-02T22:50:30.230Z","0.7.2-alpha.5":"2023-12-02T23:03:46.299Z","0.7.2-alpha.6":"2023-12-02T23:57:01.816Z","0.7.2-alpha.7":"2023-12-03T01:54:32.709Z","0.7.2":"2023-12-03T07:16:50.399Z","0.7.3":"2023-12-03T16:50:02.689Z","0.8.0":"2023-12-04T00:07:07.149Z","0.8.1":"2023-12-04T04:54:38.140Z","0.8.2-alpha.1":"2023-12-04T20:05:34.508Z","0.8.2-patch.1":"2023-12-04T21:51:06.890Z","0.8.2":"2023-12-04T21:56:27.951Z","0.8.3":"2023-12-04T23:38:45.349Z","0.8.4":"2023-12-04T23:51:50.447Z","0.8.5":"2023-12-05T00:19:48.924Z","0.8.6":"2023-12-05T02:45:39.345Z","0.8.7":"2023-12-05T03:52:39.878Z","0.8.8":"2023-12-05T04:13:05.068Z","0.8.9":"2023-12-05T06:34:43.228Z","0.8.10":"2023-12-05T17:55:59.622Z","0.8.11":"2023-12-05T19:52:52.773Z","0.8.12":"2023-12-05T20:14:55.174Z","0.8.13":"2023-12-08T03:31:53.549Z","0.8.14-alpha.1":"2023-12-08T21:24:21.338Z","0.8.14":"2023-12-08T22:12:15.563Z","0.8.15":"2023-12-19T00:28:16.837Z","0.8.16":"2023-12-26T21:33:20.066Z","0.8.17":"2023-12-27T21:37:31.246Z","0.8.18":"2024-01-02T01:46:39.826Z","0.8.19":"2024-01-02T02:22:34.613Z","0.8.20":"2024-01-05T23:49:50.521Z","0.8.21":"2024-01-06T01:49:36.007Z","0.8.22":"2024-01-18T07:52:45.376Z","0.8.23":"2024-01-18T08:19:26.351Z","0.8.24":"2024-01-18T19:17:42.429Z","0.8.25":"2024-01-19T00:22:51.402Z","0.8.26-alpha.1":"2024-01-19T18:13:47.812Z","0.8.26-alpha.2":"2024-01-19T23:59:39.506Z","0.8.26-alpha.3":"2024-01-20T02:31:10.504Z","0.8.26-alpha.4":"2024-01-20T19:53:57.687Z","0.8.26":"2024-01-20T20:25:07.369Z","0.8.26-main-488c798d":"2024-02-15T23:32:21.943Z","0.8.27-patch.1":"2024-04-28T11:58:00.233Z","0.8.27-patch.2":"2024-04-28T21:20:20.868Z","0.8.27-patch.3":"2024-04-28T21:46:36.436Z","0.8.27-patch.4":"2024-04-28T22:17:27.287Z","0.8.27-patch.5":"2024-04-28T22:55:37.002Z","0.8.27-patch.6":"2024-05-01T22:27:13.801Z","0.8.27-patch.7":"2024-05-01T23:22:36.235Z","0.8.27-patch.8":"2024-05-02T03:09:34.681Z","0.8.27-patch.9":"2024-05-02T04:02:36.960Z","0.8.27-patch.10":"2024-05-02T06:52:02.474Z","0.8.27-patch.11":"2024-05-02T07:06:14.468Z","0.8.27-patch.12":"2024-05-02T09:13:28.537Z","0.8.27-patch.13":"2024-05-02T10:07:43.128Z","0.8.27-patch.14":"2024-05-02T19:53:10.223Z","0.8.27-patch.15":"2024-05-02T22:05:03.090Z","0.8.27-patch.16":"2024-05-02T22:17:18.655Z","0.8.27-patch.17":"2024-05-03T18:29:37.735Z","0.8.27-patch.18":"2024-05-03T19:05:27.066Z","0.8.27-patch.19":"2024-05-03T19:20:32.361Z","0.8.27-patch.20":"2024-05-03T19:32:44.991Z","0.8.27-patch.21":"2024-05-14T03:08:46.104Z","0.8.28":"2024-05-16T00:23:57.620Z","0.8.29":"2024-05-21T16:24:13.599Z"},"maintainers":[{"name":"rjwebb","email":"bob.wbb@gmail.com"},{"name":"joelg","email":"joelg@mit.edu"},{"name":"raykyri","email":"raykyri@gmail.com"}],"description":"This package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.","author":{"name":"Canvas Technologies, Inc.","url":"https://canvas.xyz"},"readme":"# @canvas-js/signed-cid\n\nThis package implements a tiny signed data format for IPLD values. Any [CID](https://docs.ipfs.tech/concepts/content-addressing/) can be signed, and the resulting `Signature` can be passed around as an independent value on its own.\n\n## Table of Contents\n\n- [Overview](#overview)\n- [Usage](#usage)\n- [API](#api)\n  - [Ed25519Signer](#ed25519signer)\n  - [Secp256k1Signer](#secp256k1signer)\n  - [Verify a signed value](#verify-a-signed-value)\n  - [Verify a standalone signature](#verify-a-standalone-signature)\n  - [Utility types](#utility-types)\n\n## Overview\n\n```ts\nimport type { CID } from \"multiformats/cid\"\n\nexport type Signature = {\n  publicKey: string /** did:key URI */\n  signature: Uint8Array\n  cid: CID\n}\n```\n\nSignatures sign the **bytes of the CID**, which carries metadata about the encoding format and hashing algorithm in addition to the hash of the encoded value itself. This allows values and their signatures to be re-encoded with different codecs without breaking validation.\n\n[`did:key` URIs](https://w3c-ccg.github.io/did-method-key/) are used to encode public keys.\n\nEd25519 and Secp256k1 signatures are supported, using the audited [`@noble/curves`](https://github.com/paulmillr/noble-curves) library. Secp256k1 public keys are always compressed.\n\nThe `dag-json`, `dag-cbor`, and `raw` IPLD codecs are supported by default, and others can be used by implementing the [`Codec`](#codec) interface. Similarly, `sha2-256`, `blake3-256`, and `blake3-128` multihash digests are supported by default, and others can be used by implementing the [`Digest`](#digest) interface.\n\n## Usage\n\n```ts\nimport { Ed25519Signer, verifySignedValue } from \"@canvas-js/signed-cid\"\n\nconst signer = new Ed25519Signer() // export the private key using `signer.export()`\n\nconst value = { foo: \"hello world\", bar: [1, 2, 3] }\nconst signature = signer.sign(value)\nconsole.log(signature)\n// {\n//   publicKey: 'did:key:z6MkoTVvGXtN1Bjjd2dBMnaMNs2HFVzYkDZKNsMvVZCtaBep',\n//   signature: Uint8Array(64) [\n//     123,  77, 189, 225, 151, 159, 181,   5, 144, 130, 130,\n//      58,  36, 189, 147, 133, 197, 194, 119, 116, 167, 215,\n//     156,  18, 189,   6, 203, 156,  45,  40,  29, 215,  91,\n//      47,  21,  44,  91,   9,  76,  79, 105,  75,  89, 144,\n//      63, 198, 222, 175,  61, 131,  94,  20, 124,  91, 230,\n//     149, 141,  43,   0, 207, 205,  76,   7,   9\n//   ],\n//   cid: CID(bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a)\n// }\n\nverifySignedValue(signature, value) // throws an error if the signature is invalid\n```\n\nWe can see a detailed breakdown of the CID in the signature with the CID explorer tool [here](https://cid.ipfs.tech/#bafyreibqke43yd2rqll4nwlrbfjfqferamxp3sdia36a6awqvcae3cmm7a). The prefix bytes of the CID tell us that it carries the sha2-256 hash of a dag-cbor value, and that the hash digest is `0x305139BC0F5182D7C6D9710952581491032EFDC86806FC0F02D0A8804D898CF8`.\n\nWe can check this by encoding and hashing the value ourselves:\n\n```ts\nimport { encode } from \"@ipld/dag-cbor\"\n\nconst value = encode({ foo: \"hello world\", bar: [1, 2, 3] })\nconsole.log(value)\n// Uint8Array(25) [\n//   162,  99,  98,  97, 114, 131,   1,\n//     2,   3,  99, 102, 111, 111, 107,\n//   104, 101, 108, 108, 111,  32, 119,\n//   111, 114, 108, 100\n// ]\n\nconst hash = crypto.createHash(\"sha256\").update(value).digest()\nconsole.log(hash)\n// <Buffer 30 51 39 bc 0f 51 82 d7 c6 d9 71 09 52 58 14 91 03 2e fd c8 68 06 fc 0f 02 d0 a8 80 4d 89 8c f8>\n```\n\nAgain, signatures always sign the raw bytes of the entire CID, not just the hash digest.\n\n## API\n\nSigning defaults to `dag-cbor` and `sha2-256` if `options.codec` or `options.digest` are not provided, respectively.\n\n### Ed25519Signer\n\n```ts\nexport declare class Ed25519Signer<T = any> {\n  public static type: \"ed25519\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 32-byte ed25519 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"ed25519\"; privateKey: Uint8Array }\n}\n```\n\n### Secp256k1Signer\n\n```ts\nexport declare class Secp256k1Signer<T = any> {\n  public static type: \"secp256k1\"\n  public static code: number\n\n  public readonly uri: string\n\n  /**\n   * @param privateKey 33-byte secp256k1 private key\n   */\n  public constructor(privateKey?: Uint8Array)\n\n  public sign(value: T, options?: { codec?: string | Codec; digest?: string | Digest }): Signature\n\n  public export(): { type: \"secp256k1\"; privateKey: Uint8Array }\n}\n```\n\n### Verify a signed value\n\n```ts\nexport type SignatureType = \"ed25519\" | \"secp256k1\"\n\n/**\n * Verify that the signature is valid, and that signature.cid matches the given value\n */\nexport declare function verifySignedValue(\n  signature: Signature,\n  value: any,\n  options?: { types: SignatureType[]; codecs?: Codec[]; digests?: Digest[] }\n): void\n```\n\n### Verify a standalone signature\n\n```ts\n/**\n * Verify that the signature is valid\n */\nexport declare function verifySignature(signature: Signature, options?: { types: SignatureType[] }): void\n```\n\n### Utility types\n\n`Codec` and `Digest` are similar to some existing interfaces in the JavaScript IPLD ecosystem, but are defined the way they are here to support synchronous zero-copy streaming encoders.\n\n#### Digest\n\n```ts\ninterface Digest {\n  name: string\n  code: number\n  digest: (iter: Iterable<Uint8Array>) => Uint8Array\n}\n```\n\n#### Codec\n\n```ts\ninterface Codec {\n  name: string\n  code: number\n  encode: (value: any) => Iterable<Uint8Array>\n}\n```\n","readmeFilename":"README.md"}