{"_id":"@capdaddy/carta-archive","_rev":"16-ecff415ff06b29f9b2d4d2fa632ecc57","name":"@capdaddy/carta-archive","dist-tags":{"latest":"1.14.0"},"versions":{"1.0.0":{"name":"@capdaddy/carta-archive","version":"1.0.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.0.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"a359c7d33ebf285ba874617693ebc5ae61189231","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.0.0.tgz","fileCount":29,"integrity":"sha512-BwvoV2vQ87uVaJ+GA5P/4lUXcOalHyVSq80LYBEnrabkNMtnHkPJ0CDaQsNai1pExhk4ZUT3r7StVwwpG4t5sA==","signatures":[{"sig":"MEYCIQC6CwGtpoi6e7sYbW5iz7X2PJSW8jpI/btnahkdLtfBYQIhAN6OCSaX7RP84cPX7BMDYHfI85ZXUCV7ccuFfhhtii3t","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":306344},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"b9edefac6bd80f2e817b89edb03effe2684d22e5","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.0.0_1786397103414_0.3492902324340912","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@capdaddy/carta-archive","version":"1.1.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.1.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"3dad4d66d50e75c73641e1bfd461b375e235d040","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.1.0.tgz","fileCount":31,"integrity":"sha512-b3a288JpDBEPpy0G+qSyORBgoX+/EdHlMIxhKdZSl4QooowrafX6+u7NFlJxtZwga3lyu2+bsjgSNM3DPgSddg==","signatures":[{"sig":"MEQCIDHsdN5otDGoR/WeI3uNv0Ljb6xsksqqcOJEflOw6IQIAiBxJJKZrqgRXkba8W1bTU1MSn4FRKEOy6huJbxKmCL2wg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":331851},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"5422e86f9e77698e2742cdcf413a34d8975254d2","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.1.0_1786406489002_0.8324100317432492","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@capdaddy/carta-archive","version":"1.2.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.2.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"4c519e7f5b02749ed2e280d697e5daa34a241fac","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.2.0.tgz","fileCount":31,"integrity":"sha512-/xvO4xuGvBx0uEDXCAaef7eZ/Ykq07a/aGwmrPBIGNOiMvKY1YsiZd5D8ofmfcNqz04KqBk3tArSgqOxvpw7QQ==","signatures":[{"sig":"MEQCIA8hOAwNe6P9HCPz9c2wUbqZMTbv22t1YwMKGY0gleLLAiAiKDYb/i3tViU8IZgOLSh/hO6YKH7hzHhBu5arGjMFKw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":351112},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"00c25e07c611ed3fc47f74d3fdd3b49b31c14002","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.2.0_1786455918499_0.18927684978936798","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@capdaddy/carta-archive","version":"1.3.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.3.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"8dead6de78eca5a084dc58cf181a3be099e178f5","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.3.0.tgz","fileCount":31,"integrity":"sha512-jywsxk9IToOoEuH0Etn0EmCgkdW2GXtIxzdqK+go8O7ZTxDRACKi+IbxMmUDX7VJ7CcGUIaUM/hchkkRQLiABw==","signatures":[{"sig":"MEQCIGeY6MaCtQVDI36ans84BqbzpTGCvdgFHt1C7Rw5sXF1AiBk6TCS8Epm88WDBU4Z+ci4gdHCZp12W7uspTQy+cjGdw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":371581},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"94d62bdb662899e74a05f880803137e52d8114ac","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.3.0_1786460827503_0.30748561500460925","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@capdaddy/carta-archive","version":"1.4.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.4.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"97546a41fce3b224c020fa84d55c2f86543b1622","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.4.0.tgz","fileCount":31,"integrity":"sha512-wLYcpSqWCXUMXOAmbbX9jVOpj60QUXywsbzoKGy11hrAvOD4HVtjb7H0BI2kWEq/UzvDEsry3hOUihbHtOx7gA==","signatures":[{"sig":"MEYCIQCtkzzrb97414Rl12bQjmSockhai29JYzkVRiQqf1lkngIhALpaBGEIShflmBbK+sq2SDAxywrzh6w3iNtYnvaT1ugM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":377951},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"f9e502947faad3362e1f46d7637189e7c20366df","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.4.0_1786477441892_0.27695058281720764","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@capdaddy/carta-archive","version":"1.5.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.5.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"8798d92268885de139b746e4550acdfdce36508a","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.5.0.tgz","fileCount":33,"integrity":"sha512-+BNGYMoF+FIib46Nmfci6BKoLm40YQLoX7crTlzarI2/dIrpPoShD5KarhY/8F0JCuniRJi8bZ2zwYXAWgEUFw==","signatures":[{"sig":"MEQCIAef4xGc/GrSPg/c5ggsi7FO2SH8gW8HYM5qfu0OKmZ7AiBj8zw6g0JyTJKm7ugHPLSzWLQp2Gx1DAvuEb3UbYQZZQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":400468},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"e6bea15c59dd0db20fda1520dabed002414c4cc3","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.5.0_1786485199185_0.08192909775996537","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@capdaddy/carta-archive","version":"1.6.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.6.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"9caa10e4443250c74a31a9d1b71999bb9c8faa34","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.6.0.tgz","fileCount":35,"integrity":"sha512-5iPCBgZMeGf28IVmxOKw9p8WzQzSguszlMIrtr4ElT8y/QIusRMn6AeD+kqrWXUI+fnrAp3L9fovuN67eHzO1g==","signatures":[{"sig":"MEUCIHchcuKIFhnaHacsGnUj/2bTzWKZJ63r8dQ64I5FH5kwAiEA9Hs+OqredUsX0cR1avxx2VQ+L0kYOgEDAyHF804b59o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":435950},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"c75d1da5f2211fa742f4e74b874939fb5d1f2084","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.6.0_1786491108502_0.23956891293955573","host":"s3://npm-registry-packages-npm-production"}},"1.7.0":{"name":"@capdaddy/carta-archive","version":"1.7.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.7.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"e37f9dd2f4cea7d890514b9d9425504a2866a319","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.7.0.tgz","fileCount":37,"integrity":"sha512-nNXGGPEbM2FY6ZBVrXKzS0p2S8AO9p2IZuAVdz4GEv9Xat+1StG2WoX0LyI1JWGQp8snmqDb1bBPRHbI1voPcA==","signatures":[{"sig":"MEUCIHNSdu4wJsZGb6R9UrGfclFG+kNBO6DdgZWEWi/1uZbSAiEAodPD0spe3vAH0CM0YUWBXLLjivcUZEZyu8ikD+2joM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":447538},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"35920a93161e1851ce021ba3392c5c12fdfe62a3","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","dependencies":{"archiver":"^8.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.7.0_1787268055506_0.10155643662688307","host":"s3://npm-registry-packages-npm-production"}},"1.8.0":{"name":"@capdaddy/carta-archive","version":"1.8.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.8.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"d42ed8c37d797e871b9f3c566147355e827e8c54","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.8.0.tgz","fileCount":39,"integrity":"sha512-VEi5LE8xT2CMBK4PN8TtJHutqi3vfHfsyiBnIbmGS9Ysk3kMNxZLxLqGFpjgMq6CjduuOb35HAc3pFeNtQzGeg==","signatures":[{"sig":"MEUCIEKcc2L3qIreZZ5ttMG8MzN3kyUdUIlDkSbKKy/30AapAiEAqUkTAw5PP1ySjw1JuW1xo5EUg4C4h1VCfm+BgZhjH78=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":456454},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"03ab71c2fc648741c8f85e1a58ef4828634016de","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","dependencies":{"archiver":"^8.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.8.0_1787317475523_0.5849822337717367","host":"s3://npm-registry-packages-npm-production"}},"1.9.0":{"name":"@capdaddy/carta-archive","version":"1.9.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.9.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"d7e2a63e81a18fafb6099e3138db9894e9020292","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.9.0.tgz","fileCount":39,"integrity":"sha512-vCr/mn+7WbnkOoqb7T/bCMBuADiKxDyWpPgMHf2f7K5KkHNzDObXdBlyr0M2Yab52u5ERRGHJMKRW4d1BOKFxA==","signatures":[{"sig":"MEQCIGN+suA83RgMBvnKaikEdWZznslRtfnFaVXm4mSzIaYuAiAwtiLRBbn3M7H6vO8rAne7zQ4BgG+9J19N4upCtZ9qpg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":469504},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"037118fb55acb9b93a233f31f68bfcf3a14d1891","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","dependencies":{"archiver":"^8.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.9.0_1787494330862_0.8507726953744448","host":"s3://npm-registry-packages-npm-production"}},"1.10.0":{"name":"@capdaddy/carta-archive","version":"1.10.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.10.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"9b223ced32dbc3df6f95e3ada3581234ebb61753","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.10.0.tgz","fileCount":39,"integrity":"sha512-RdPtHbXsLzcdNRSpYp/9oj/6wOUqX61EzP7QJDKjP3IuvaRZknlIf8DK8qVIw7VQFsAe6XNrJWlZbokZgY0yag==","signatures":[{"sig":"MEUCIBQ50sP5iujS2gUMBRncG0E2g5m13D5oKGMiM0DDHjEdAiEA3WdW/LcWF73DvQVCVLI//NroQZ/kU3Vz3b2hrmzS9L8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":496084},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"86c09c9461f1ece13c74a991208303288d4a1a65","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.13.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"24.17.0","dependencies":{"archiver":"^8.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.10.0_1788296187513_0.28158535183637623","host":"s3://npm-registry-packages-npm-production"}},"1.11.0":{"name":"@capdaddy/carta-archive","version":"1.11.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.11.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"e5ff14c66a10a01094a98430538478f66785bc42","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.11.0.tgz","fileCount":39,"integrity":"sha512-+kWhWC3DfxiXOdCyKIoZntDfmeR6AtlOHHaAdFa30rUD3nMWl/Ckiw25gcBG7cRrq8tbe9nUawwLpnjF0M6RMQ==","signatures":[{"sig":"MEUCIQDVIPcamFM0/xndV5YxLJzO/2BUp1sEavNYwx+suZEDOAIgT0mPAihRiJ0zlZrDKBTDl7Kx1bzOzmKE6ECrbKTuceI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":523459},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"650119a958e2c094bb2d9e4f7008dfd99df2a4da","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.13.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"24.17.0","dependencies":{"archiver":"^8.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.11.0_1788307579503_0.9922047238408163","host":"s3://npm-registry-packages-npm-production"}},"1.12.0":{"name":"@capdaddy/carta-archive","version":"1.12.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.12.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"5c4f88489b48abd7f9b05556e9984b7d0312d1c5","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.12.0.tgz","fileCount":97,"integrity":"sha512-qh7anSSsvahlbaHx6JYiNjOTMat3qK1De1wuno8RJxxv72YTRU6vkj9ZMbnYHVVKtLGKXLSu+B3T1rnPI5v3OA==","signatures":[{"sig":"MEUCIQDTnhOYMouRPeDanJGOS5Rn8h1Ys7uBou+jutmHuuaosgIgIeml8GUMGhdx9qnhsq0v/V/+J1n3uePiZpZ6MY0ioUU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1324162},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"d540872ce2bf8f14f1191dd2d337a568c1374bc9","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","dependencies":{"archiver":"^8.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.12.0_1788398310178_0.5543942306097231","host":"s3://npm-registry-packages-npm-production"}},"1.13.0":{"name":"@capdaddy/carta-archive","version":"1.13.0","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.13.0","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"8c45c5da8a80ce61249f04dc104999947f6e65f7","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.13.0.tgz","fileCount":99,"integrity":"sha512-Moavfv3wO3sPGp3Y3ngfWsTY2EzPTnOqXXiYJeQsqK7LtIPjGQoa3bigRCMuWJhf9KRvmRYDtumCEhP8q0UnJA==","signatures":[{"sig":"MEYCIQCC7lmQQbCRR9pU8RbsjhuVpFdfRJZiwoUHHErd1resXwIhAO/sXJuZJul9kNYb8hNv7aywoXrdZl8+IQeb2ArQv0WW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1453210},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"ee28284082b7d62df5856bb40dda1e536d0b7303","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","dependencies":{"archiver":"^8.0.0","puppeteer-core":"25.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.13.0_1788550895620_0.5750216083555328","host":"s3://npm-registry-packages-npm-production"}},"1.13.1":{"name":"@capdaddy/carta-archive","version":"1.13.1","keywords":["carta","cap-table","export","migration","data-portability"],"license":"MIT","_id":"@capdaddy/carta-archive@1.13.1","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"homepage":"https://capdaddy.cc/import/from-carta","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"dist":{"shasum":"f17e30ba9a3e6efce16852215b1325972cb1b521","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.13.1.tgz","fileCount":99,"integrity":"sha512-hZNnmFL63afLGQNpKXo8M/VdOMb+6lbvcW470MV5nxlIFx9lZkWklTDaUF2E7ECy6f4mjKDIBQgDFDtfW96P+g==","signatures":[{"sig":"MEUCIGqxbhUI7MOjV7mf9B/i/JQ+I3hCza1iXE9pV/DCu+wDAiEAxMdcnM2It0xPeQ7SccZAwm4gWPO1Xwqc/u1Hisc33Fo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1453332},"type":"module","engines":{"node":">=20"},"exports":{".":"./dist/index.js","./manifest":"./dist/manifest.js","./endpoints":"./dist/endpoints.js"},"gitHead":"dd77dca8877aefc31f0b1f7d45614897ad8614c0","scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"repository":{"url":"git+https://github.com/jackneil/hank-captable.git","type":"git","directory":"scripts/carta-archive"},"_npmVersion":"11.16.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","directories":{},"_nodeVersion":"26.3.0","dependencies":{"archiver":"^8.0.0","puppeteer-core":"25.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/carta-archive_1.13.1_1788612404148_0.3144875983704065","host":"s3://npm-registry-packages-npm-production"}},"1.14.0":{"name":"@capdaddy/carta-archive","version":"1.14.0","description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","type":"module","license":"MIT","engines":{"node":">=20"},"dependencies":{"archiver":"^8.0.0","puppeteer-core":"25.9.0"},"bin":{"carta-archive":"bin/carta-archive.mjs"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/jackneil/hank-captable.git","directory":"scripts/carta-archive"},"homepage":"https://capdaddy.cc/import/from-carta","exports":{".":"./dist/index.js","./endpoints":"./dist/endpoints.js","./manifest":"./dist/manifest.js"},"keywords":["carta","cap-table","export","migration","data-portability"],"scripts":{"build":"tsc -p tsconfig.build.json","prepack":"node prepack.mjs"},"gitHead":"ecb027c44fc06ae026fe0e19b281f53d76944996","_id":"@capdaddy/carta-archive@1.14.0","bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"_nodeVersion":"26.3.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-ZkSiJmgfcUs32mZVR7tbhUERx1QGMwAlGp/u7dx4Vu0VSmdyRZ4DaBGHaFLmUd2KbxVndIfkOtpJn1M2Yr1W5w==","shasum":"7480e2e942c789a1d45c8bf6a306f0a2472c6700","tarball":"https://registry.npmjs.org/@capdaddy/carta-archive/-/carta-archive-1.14.0.tgz","fileCount":101,"unpackedSize":1547242,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCfgt8IZSP15MDEhHnd9w3edaZqkoVeEjXbFVA5h7f6/AIgKDcwkoAsABrXDSmn7mT/aWp3xSFgq54JHytsh+rr0To="}]},"_npmUser":{"name":"jackmd","email":"jack@jackmd.com"},"directories":{},"maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/carta-archive_1.14.0_1788625138906_0.5895435165170615"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-10T21:25:03.256Z","modified":"2026-09-05T16:18:59.233Z","1.0.0":"2026-08-10T21:25:03.584Z","1.1.0":"2026-08-11T00:01:29.136Z","1.2.0":"2026-08-11T13:45:18.657Z","1.3.0":"2026-08-11T15:07:07.671Z","1.4.0":"2026-08-11T19:44:02.041Z","1.5.0":"2026-08-11T21:53:19.334Z","1.6.0":"2026-08-11T23:31:48.660Z","1.7.0":"2026-08-20T23:20:55.669Z","1.8.0":"2026-08-21T13:04:35.702Z","1.9.0":"2026-08-23T14:12:11.007Z","1.10.0":"2026-09-01T20:56:27.657Z","1.11.0":"2026-09-02T00:06:19.655Z","1.12.0":"2026-09-03T01:18:30.337Z","1.13.0":"2026-09-04T19:41:35.812Z","1.13.1":"2026-09-05T12:46:44.301Z","1.14.0":"2026-09-05T16:18:59.048Z"},"bugs":{"url":"https://github.com/jackneil/hank-captable/issues"},"license":"MIT","homepage":"https://capdaddy.cc/import/from-carta","keywords":["carta","cap-table","export","migration","data-portability"],"repository":{"type":"git","url":"git+https://github.com/jackneil/hank-captable.git","directory":"scripts/carta-archive"},"description":"Get a complete copy of your own company's records out of Carta. Runs on your machine, against your own logged-in session.","maintainers":[{"name":"jackmd","email":"jack@jackmd.com"}],"readme":"# carta-archive\n\nRetrieve a complete, structured copy of your own organisation's Carta records.\n\n## Warnings\n\n**Run this tool BEFORE you cancel your Carta subscription.** Carta destroys\naccount access permanently after offboarding. You get one window. Do not wait.\n\n**Check REPORT.md before you cancel anything.** Exit code 1 means some items are\nstill in Carta for you to copy by hand. Exit code 2 means the archive is not a\ncomplete copy: read the report, fix the failures, and run again.\n\n**These endpoints are private and undocumented.** Carta can change them at any\ntime. The tool verifies the shape of every response. It records a structured\nfailure when a shape changes. It never guesses.\n\n## Start here\n\nRun it, sign in to Carta in the window that opens, done.\n\nYou need Node 20 or newer and Google Chrome. `npx` fetches the tool and the two\nlibraries it uses; there is nothing for you to install by hand. The tool drives\nthe Chrome you already have. It downloads no browser.\n\n**1. Find your corporation id.** Open Carta and look at the address bar:\n\n```\nhttps://app.carta.com/corporations/3005703/securities/\n                                   ^^^^^^^ this number\n```\n\n**2. Run it.**\n\n```\nnpx @capdaddy/carta-archive --corp 3005703\n```\n\n**3. Sign in to Carta in the window that opens.** The tool opens Chrome on your\nown Carta page and waits, for up to fifteen minutes. Sign in there and leave the\nwindow open. The run starts by itself.\n\nYou type your password into Carta, never into this tool. There is no cookie to\ncopy and no developer tools to open. Chrome keeps its own profile beside your\narchive, so a second run is already signed in.\n\nIf Carta asks for a quick security check while the run works, the tool opens\nthat page in the window and tells you. Complete the check and the run continues\nby itself.\n\n**4. Read REPORT.md** in the archive directory. Exit code 0 means the copy is\ncomplete and there is nothing for you to fetch. Anything else means there is,\nand the report says what.\n\n**5. Upload the zip.** A complete run packs your archive into a single\nready-to-upload file beside the archive directory, and prints its name. Open\n[capdaddy.cc/import/carta-archive](https://capdaddy.cc/import/carta-archive),\ndrop that file in, select \"Check it first\", then \"Load it\". You do not have to\ncompress anything yourself.\n\nSize is not a limit. A large archive is sent in parts of 8 MB, both by this tool\nand by the import page. Each part carries its own checksum. A small part is\ndeliberate. On a home connection of about 1 MB/s, a 48 MB part held one request\nopen for more than two minutes, and the connection dropped before the part\narrived.\n\nIf an upload stops part way, start it again. The tool asks CapDaddy which parts\nit holds, and it compares the checksum of each one against the file on disk. It\nsends only the parts that do not match. A repacked archive is a different file,\nso the tool sends it again in full.\n\nIf your connection refuses a request of 8 MB, use `--part-bytes` with a smaller\nnumber. The tool also lowers the size by itself when a request is refused\nbecause it is too large.\n\nLoading the same archive twice is safe. Documents are matched on their content\nhash, board consents on their Carta id, and a security whose real agreement is\nalready in place is left alone. A second load reports what was already there and\nchanges nothing.\n\n### Let the run deliver it for you\n\nOn CapDaddy's Move-from-Carta page, create a one-time upload code and pass it:\n\n```bash\nnpx @capdaddy/carta-archive --corp 3005703 --upload-code <code>\n```\n\nA complete run then packs the archive, uploads it, and prints where to read the\nreport. The code works once, expires in 24 hours, and can only add records to\nthe company it was created for. A large archive travels in parts, so there is no\nsize at which this stops working, and the archive stays on disk either way.\n\nThe run checks the code when it starts. The check also holds the code for this\nrun. If the code has less than six hours left, CapDaddy gives it six hours. A\ncode that works when the run starts can then deliver when the run ends.\n\nIf the code is dead, the run tells you at once. In a terminal, the run asks you\nfor a new one. Create a new code on the Move off Carta page and paste it. The\nrun does not show the code on the screen, and it does not write it to the log.\nPress Enter to continue without a code. The run then collects your archive, but\nit does not upload it.\n\nThe run asks again at the end, after it packs the archive. It asks when the code\nis dead, and it asks when you gave no code at all. Paste a code to deliver the\narchive immediately. The run collects nothing again.\n\nA scheduled job or a script has no terminal and cannot answer. Such a run\ncontinues and writes your archive to disk. The last screen tells you to create a\nnew code on the Move off Carta page. A code that you already used cannot be used\nagain, so you always need a new one.\n\nYou then have two ways to finish:\n\n- Upload the packed file by hand on the import page. This needs nothing from\n  Carta.\n- Run the same command again with the new code. The second run reuses what is on\n  disk, the reports it already built included, so it is much shorter. It still\n  reads Carta to take whatever the first run did not. Chrome keeps its profile,\n  so it usually opens already signed in.\n\nUse `--no-zip` to skip the packing step and keep only the directory. An upload\ncode cannot deliver anything if you also pass `--no-zip`, because there is no\npacked file to send.\n\nA dry run collects nothing. It never checks the code, and it delivers nothing.\nThe run says so when you pass `--upload-code` and `--dry-run` together.\n\n#### One code loads one archive\n\nA code is good for one load. A load that finishes spends it.\n\nRead this before you run `--only`. A run with `--only` collects the families you\nname. If that run delivers the archive, it spends the code. Create a new code\nbefore you run the full collection. If you do not, the full archive is not\ndelivered, and you must upload the file by hand. The last screen tells you this\nafter a delivered `--only` run.\n\n#### If CapDaddy does not answer the last request\n\nThe last request starts the load. If CapDaddy takes the archive and does not\nanswer, the tool cannot know whether the load ran. So it asks the code, because\na load that finishes spends the code.\n\n- If the code no longer works, the load probably ran. The tool tells you to open\n  the import page and to look at the most recent run. Look first. If you upload\n  the archive again, you load the same records twice.\n- If the code still works, nothing was loaded. The tool tells you to upload the\n  file yourself, and your archive is safe on disk.\n\n### Would you rather not do any of that?\n\nGive the whole job to an agent. This package ships a skill, so Claude Code and\nCodex can read it and drive the migration for you, including your logged-in\nbrowser. Ask your agent:\n\n```\nMigrate my company off Carta.\n```\n\nPrefer the agent if your Carta holds SAFEs, convertible notes, RSUs, RSAs, SARs,\nmore than one equity plan, or more than one currency. This tool was proven\nagainst one organisation that had none of those, and it stops rather than guess.\nAn agent can read a record it does not recognise and carry on.\n\n### If Chrome is not installed\n\nWithout Chrome the tool cannot open a browser for you, so you supply your Carta\nsession yourself. Read \"Advanced fallback: supply the session cookie yourself\"\nbelow. Everything else about the run is the same.\n\n### Your password\n\nThis tool never asks for your Carta password, never sends it, and never stores\nit. You type it into Carta itself, in the browser window on your own computer.\nThis tool never reads your Carta session either: the browser attaches it, and\nthe tool only reads the answers.\n\n## What this tool does\n\nThis tool retrieves the account owner's own organisation data using the owner's\nown session. It does what you can already do by hand in the browser. It cannot\nsee anything that you cannot already see on screen.\n\nIt collects sixteen families of records, in this order:\n\n| Family | Contents |\n| --- | --- |\n| `securities` | Certificates, option grants, warrants, stakeholders, and the document to security join. Also the paper Carta generates for each one: the detail panel, the print view, the vesting schedule, the exercise ledger with its documents, and the ISO 100,000 dollar limit screen |\n| `stakeholders` | The roster, every person's profile and relationship history, the employee equity view, the HRIS reconciliation, and who may see what |\n| `captable` | Share class and stakeholder cap tables, one snapshot per milestone date plus today |\n| `reports` | Every report the Carta Run Reports hub offers, except the two named in \"The reports\" below. The two reports the CapDaddy import reads are included |\n| `boardroom` | Board consents, consent detail, exhibits, consent archives, the board document tree, board members, meetings, and the approved draft securities |\n| `plans` | Equity plans, the pool ledger, legends, vesting schedules, document sets, performance conditions, and acceleration terms |\n| `charter` | Share classes, the authorized shares history, the charter versions, and every certificate of incorporation |\n| `compliance` | The Carta health checks, 409A status, beneficial ownership (CTA), QSBS, Form 3921, the tax administration, and the jurisdiction rates export |\n| `fundraising` | Financing history, outstanding convertibles, saved models, and tender offers |\n| `drafts` | Draft securities of all nine types, with their full terms |\n| `dataRooms` | Every data room, its directory tree, its files, the people invited to it, the record of who read which document, and the rooms other companies shared with you |\n| `library` | The company documents library, with the category, group and date of each document |\n| `documents` | The company balance sheet and income statement, and the document delivery queue |\n| `communications` | The messages the company sent, your inbox, investor relations, audit confirmations, and the employee hub |\n| `company` | Board members, signatories, roles and permissions, the corporation record, the Carta contract, every settings screen, the payment activity, and the dashboard |\n| `valuations` | The 409A history, every completed 409A report PDF, share class terms, the valuation ledger, and the reports in flight |\n\nRun one family on its own with `--only <family>`.\n\nMoney and share counts stay as text. Carta sends full precision decimal strings,\nfor example `\"0.180000000000\"` and `\"625\"`. The tool copies them into the\nmanifest without change. It never converts one to a number.\n\n## Three ways to run it\n\n### Primary: the tool opens Chrome for you\n\nThis is what `--transport chrome` does, and what `auto` picks when you give no\ncookie. You never touch a credential.\n\nCarta's session cookie is HttpOnly. JavaScript on the page cannot read it. Only\nthe browser can send it. So the tool opens your own Google Chrome, waits while\nyou sign in to Carta, and then runs each request inside that signed-in page with\n`fetch(..., {credentials: 'include'})`. The browser attaches the session cookie\nitself. This tool never reads it, never stores it, and never sends it anywhere.\n\n```bash\nnpx @capdaddy/carta-archive --corp 3005703\n```\n\nWhat you see:\n\n1. A Chrome window opens on your Carta securities page.\n2. The tool prints \"Sign in to Carta in the window that opened\" and waits, for\n   up to fifteen minutes.\n3. You sign in. The run starts by itself and prints its progress.\n4. If Carta asks for a security check, the tool opens that page in the window\n   and asks you to complete it. The run continues by itself afterwards.\n\nThree details that matter:\n\n- **Chrome keeps its own profile** in `<out>/chrome-profile`. A second run is\n  already signed in. The profile holds your live Carta session, so the tool\n  never puts it in the upload file. Use `--browser-profile <dir>` to keep it\n  somewhere else. Keep that directory on a local disk. Do not put it in a folder\n  that syncs to a cloud service, and do not put it on a shared drive. The tool\n  makes the directory readable by you only, but a folder that syncs copies the\n  session to every device on the account. The tool refuses a directory that\n  overlaps the archive directory, because the archive is what goes into the\n  upload file.\n- **The window is never hidden.** A hidden browser cannot be signed into, and\n  Carta's bot check refuses one. There is no flag to turn the window off.\n- **This path reads two things the others cannot.** Cloudflare refuses some\n  Carta pages to any cookie, one route at a time, and it does not refuse a real\n  browser. The beneficial ownership record (CTA) lives on `kyc.app.carta.com`,\n  and a browser can navigate to it.\n\nIf no Chrome is on the machine, the tool says so, names what to install, and\npoints at the cookie path below. It never falls back to a credential by itself.\n\n### An agent drives a browser you are already signed in to\n\nUse this when your Carta holds a record this tool has never seen: an agent can\nread it and carry on. It is the same in-page fetch, with the agent supplying the\nbrowser instead of the tool.\n\nThe agent supplies a capability object and calls `runArchive` directly:\n\n```ts\nimport { runArchive } from './scripts/carta-archive/index'\n\nconst code = await runArchive(['--corp', '3005703', '--out', './carta-archive'], {\n  browser: {\n    // Run a JavaScript function expression in the logged-in Carta tab.\n    // Return its JSON result. Use chrome-devtools MCP, Playwright MCP, or the\n    // Codex equivalent.\n    evaluate: (source) => driveTheBrowser(source),\n\n    // Optional. Write a document straight to disk with the browser's own\n    // download machinery. Use CDP Page.setDownloadBehavior, or click a\n    // download-attributed anchor. Return the path the browser wrote.\n    download: (url, target) => downloadInBrowser(url, target),\n  },\n})\n```\n\nEach capability serves a different part of the run:\n\n| Capability | What it enables |\n| --- | --- |\n| `evaluate` | Every JSON endpoint, every HTML page, and all enumeration |\n| `download` | Document retrieval only |\n\nDocument bytes never travel through the agent. An organisation can hold four\nhundred documents. Routing those bytes through a language model context would\ncost far too much. The browser writes each file to disk. The tool then verifies\nthe file on disk: size, content type, and SHA-256.\n\nIf you supply `evaluate` but not `download`, the run still works. It enumerates\neverything and collects every JSON record. Each document then records a failure\nthat names the missing capability. Add the download hook, then run again.\n\nTwo more capabilities are optional, and a capability that offers them does more:\n\n| Capability | What it enables |\n| --- | --- |\n| `clearChallenge` | Show a challenged page to the person at the keyboard, wait for them to pass the check, then retry the page once |\n| `readJson` | Read an allow-listed session host an in-page fetch cannot reach, by navigating a tab to it |\n\nThe Chrome path implements both. Without them the run still lands, and it says\nwhat it could not take.\n\nOne record needs `readJson`. Carta serves the beneficial ownership record (CTA)\nfrom `kyc.app.carta.com`, which is a different host from `app.carta.com`. From\ninside a Carta page this tool sends same-origin requests only. A capability that\ncannot navigate therefore gets a refusal that names the Carta screen. The Chrome\npath reads the record, and so does the cookie path, because both treat\n`app.carta.com` and `kyc.app.carta.com` as the two session hosts. You can also\nopen Compliance and Tax, Beneficial ownership (CTA) in Carta and copy the record\nby hand.\n\n### Advanced fallback: supply the session cookie yourself\n\nUse this path when Chrome is not installed on the machine, or in CI, where there\nis no window for anybody to sign in to.\n\nTo copy the cookie header:\n\n1. Open Carta in a browser. Sign in.\n2. Open the developer tools. Select the Network tab.\n3. Reload the page. Right-click any request to `app.carta.com`.\n4. Choose Copy, then Copy as cURL.\n5. Save the command to a file, or export the cookie as `CARTA_COOKIE`.\n\nThe cookie file accepts the whole cURL command. The tool reads the cookie and\nthe browser user agent out of it. The user agent matters: Cloudflare binds its\n`cf_clearance` cookie to the browser that earned it.\n\nCloudflare decides its bot check one route at a time. One run can therefore take\nhundreds of pages and still be challenged on one kind of page. If REPORT.md\nnames a challenged route, your session is not the problem. Run the tool again\nwith `--transport chrome`, which opens your own Chrome and needs no cookie. The\nbot check does not challenge it.\n\nA cookie that carries no Carta session is refused before the first request. Read\nthe exact quoting rules, and the failure that produced them, in `cookie.ts`.\n\nNever pass the cookie as a command-line value. Shell history keeps it forever.\nThe tool refuses a `--cookie` flag for this reason.\n\n```bash\nCARTA_COOKIE=\"<the cookie header value>\" \\\n  npx tsx scripts/carta-archive/index.ts --corp 3005703\n\n# Or read it from a file.\nnpx tsx scripts/carta-archive/index.ts --corp 3005703 --cookie-file ./cookie.txt\n```\n\nThe cookie never appears in the manifest, the report, the raw dumps, or a log\nline. The tool sends it to two hosts and to no others: `app.carta.com`, and\n`kyc.app.carta.com`, which serves the beneficial ownership record that the Carta\napplication itself reads from there. It checks every redirect hop again, so a\nhop to `documents.carta.com`, to a content delivery network, or to presigned\nAmazon S3 drops the cookie. Those hosts authenticate the signature on the link,\nnot the session, so they need no cookie. A hop to plain `http://` drops the\ncookie too, whatever the host. The session travels over https or not at all.\n\n## How to run it\n\n```bash\n# See what a full run would retrieve. Retrieve nothing.\nnpx tsx scripts/carta-archive/index.ts --corp 3005703 --dry-run\n\n# Run the whole archive.\nnpx tsx scripts/carta-archive/index.ts --corp 3005703 --out ./carta-archive\n\n# Run one family, inspect the result, then run it again.\nnpx tsx scripts/carta-archive/index.ts --corp 3005703 --only boardroom\n\n# Print the endpoint map and exit. This contacts nothing.\nnpx tsx scripts/carta-archive/index.ts --emit-endpoint-map\n```\n\n### Options\n\n| Option | Effect |\n| --- | --- |\n| `--corp <id>` | The Carta corporation id. Read it from a Carta URL. Required. |\n| `--out <dir>` | The archive directory. The default is `./carta-archive-<corp>`. |\n| `--cookie-file <path>` | A file that holds the cookie. It can hold the whole command from Copy as cURL, a `Cookie:` header, or the bare value. |\n| `--base-url <url>` | The default is `https://app.carta.com`. The URL must be https. The tool refuses a plain http base before the run starts. |\n| `--delay <ms>` | The smallest gap between two requests. The default is 900, and the run adds up to another 78 per cent of it at random. `--delay 0` turns the pacing off; use that only against a test server. |\n| `--gentle` | Double every pause: the gap between requests, the breath every 30 to 50 requests, and the wait between families. Use it if Carta asks you for a bot check part way through a run. |\n| `--concurrency <n>` | 1 or 2. The default is 1. |\n| `--only <a,b>` | Run only these families. |\n| `--data-room-root <room=dir>` | Give a start directory id for a data room. Use this only if the room page stops carrying its `root_documents` key. Repeat as needed. |\n| `--transport <auto\\|chrome\\|browser\\|cookie>` | The default is `auto`: it opens Chrome when you gave no cookie and Chrome is installed, and otherwise reads the cookie you supplied. |\n| `--browser-profile <dir>` | Where Chrome keeps the profile it signs in with. The default is `<out>/chrome-profile`. It is never packed into the upload. Keep it on a local disk, never in a synced or shared folder. |\n| `--dry-run` | Enumerate and measure. Retrieve nothing. |\n| `--skip-head` | With `--dry-run`, do not probe file sizes. |\n| `--fresh` | Ignore the checkpoint. Start again. |\n| `--upload-code <code>` | A single-use code from the Move-from-Carta page. A complete run then delivers the archive for you. In a terminal, the run asks for a new code if this one is dead. |\n| `--report-years <years>` | Tax years for the reports Carta generates one year at a time. Give them as `2024,2025,2026`. The default is this year, which is what Carta's own report defaults to. |\n| `--part-bytes <MB>` | How much archive one upload request carries. Use 1 to 64. The default is 8. Use a smaller number if your uploads keep stopping. |\n| `--import-url <url>` | The CapDaddy import page. The default is `https://capdaddy.cc/import/carta-archive`. |\n| `--no-zip` | Do not pack the upload file. The archive directory is written either way. |\n| `--no-color` | Never colour the output. `NO_COLOR` does the same. |\n| `--ascii` | Draw with plain ASCII characters. |\n| `--emit-endpoint-map` | Print the endpoint map as JSON. Exit. |\n\n### Exit codes\n\n| Code | Meaning |\n| --- | --- |\n| 0 | Complete. Carta offered nothing this tool left behind. Items the archive holds another way do not change this code. |\n| 1 | Complete, with items to copy by hand, or with records this tool did not recognise. Read REPORT.md. |\n| 2 | At least one failure, or one count mismatch. The archive is not complete. |\n| 3 | The run could not start. |\n\nA skip has two meanings, and only one of them is work:\n\n- **Items to copy by hand.** Carta still holds the item and this run did not\n  take it. Each one is in REPORT.md, under \"Items to copy by hand\", with the\n  Carta screen that serves it. These give exit code 1.\n- **Carta offers, this tool leaves in place.** Nothing is missing. The archive\n  holds the same records another way, or Carta holds nothing to take: a ledger\n  print view whose rows are in the manifest and in the ledger report, a draft\n  nobody wrote, the monthly and annual views of figures the quarterly series\n  already carries, a report whose other generation landed, a report Carta\n  refuses this organisation, a report the application itself cannot request.\n  REPORT.md lists every one with its reason. These do not change the exit\n  code.\n\n## What lands where\n\n```\n<outdir>/\n  manifest.json        Every object, at full precision, plus the run metadata\n  checkpoint.json      Resume state\n  endpoint-map.json    The endpoints this run used\n  REPORT.md            The human summary: counts, failures, skips\n  files/<family>/      Every retrieved document\n  raw/                 Each response as Carta returned it, with every signed link cut to `<presigned-query-redacted>`\n  raw/unrecognized/    Every record the tool could not interpret\n```\n\nThe families are the sixteen in the table above, and `files/` holds one\ndirectory per family that retrieved a document.\n\n`valuations` reads two pages that have no JSON endpoint behind them: the 409A\nand FMV history at `/corporations/{corp}/409A/reports/`, and the share-class\nterms at `/corporations/{corp}/share-classes/manage/`. Those terms (par value,\nseniority, pari-passu, dividend type) appear in no Carta export.\n\nThe path and the column names of both pages were observed live. The markup was\nnot. So the parser matches a table by its HEADER NAMES, and a page it cannot\nread raises a failure. It never reports zero rows as \"this company has none\".\nConfirm the parse against the live page on the first run of a new organisation.\n\n`securities` archives pages as well as documents. Carta keeps the detail panel\nand the print view of a security as HTML only. There is no file to download, and\nneither page is in Carta's own offboarding export. The tool saves each one under\n`files/securities/`:\n\n| File | What it is |\n| --- | --- |\n| `<label>-modal.html` | The detail panel, with every tab in it: the approvals and their signature ids, the documents, the exercise history, the compliance fields, and the legend |\n| `<label>-print.html` | The document Carta renders for that security. For a certificate this is the certificate itself, front and back |\n\nA signed link inside a saved page is cut to `<presigned-query-redacted>` before\nthe page is written, the same as in `raw/`. The page is the record. The link\nwould have expired within the hour in any case.\n| `ledger-print-<kind>.html` | The whole ledger of one instrument, from the print link the screen supplies |\n\nCarta builds the whole-ledger print link with the filter query of the list you\nare looking at. The link on its own answers HTTP 404. The run records that\nanswer as a skip and not as a failure, because every row of that ledger is\nalready in `manifest.json` and in the Securities Ledger report. To keep the\nprinted page as well, open Securities in Carta, select the instrument tab, and\nuse Print.\n\nThe tool also reads the same panel into records, under `securities.details`. Two\nrules govern that reading. It keeps every date and every money amount as the\nexact text Carta printed. And it fails closed: a shape it cannot read yields no\nrecord at all, the markup stays on disk, and the run says which security it\ncould not read. A half read exercise row would be worse than no row.\n\n`manifest.json` holds the archive. Each file entry records the byte count, the\nSHA-256 hash, the content type, and the join back to its security, consent, or\ndata room. `REPORT.md` prints the expected count against the retrieved count for\nevery family.\n\n## The reports\n\nCarta keeps some of your records in its Run Reports hub only. The hub builds a\nspreadsheet on request; no endpoint returns the same data. The tool therefore\ngenerates every report the hub offers, except the two named at the end of this\nsection. It waits for each report, and it downloads the report into\n`files/reports/`.\n\nThe tool records each report under a fixed name: `cap-table.xlsx` and `ocx.xlsx`\nfor the two reports the CapDaddy import is built on, and the Carta report type\nfor every other one, for example `stakeholder_contact_report.xlsx`.\n\nThose are the names in `manifest.json`, not the names on disk. Each file lands as\n`files/reports/<report id>-<filename>`. The report id is the id Carta gave the\ngeneration. The filename is the name Carta sent with the download, or the fixed\nname above when Carta sent none. So a real run writes\n`files/reports/11082423-HANK.ai-s-Cap-Table.xlsx`, or\n`files/reports/11082423-cap-table.xlsx`. Do not look for\n`files/reports/cap-table.xlsx`. No run writes that path.\n\nRead `manifest.json` to find a report. Each entry under `files` records `name`\n(the fixed name above), `path` (where the file really is), and a `join` that\nnames the report type and the parameters the run sent. The CapDaddy import reads\nthose entries, never the directory listing.\n\n| Report | Hub folder | What it carries |\n| --- | --- | --- |\n| Cap Table | Capitalization | The capitalization table, with the Detailed worksheet and the securities ledgers by type and class. The CapDaddy import reads this file first. |\n| OCX | Capitalization | Equity data in the Open Cap Table Data Format. The CapDaddy import reconciles it against the cap table report at the same as of date. |\n| Stakeholder Ownership Details | Capitalization | Ownership for each stakeholder, at the as of date. |\n| Canceled and Returned Report | Securities | Securities that were canceled, and the shares that returned to the pool. |\n| Certificates Ledger | Securities | The ledger of certificates. |\n| Equity Plan Granted | Securities | Everything granted under the equity plans. |\n| Mass Issuance Report | Securities | Securities issued in bulk, at the as of date. |\n| Options Outstanding Report | Securities | Every option that is still outstanding. |\n| Securities Ledger | Securities | The ledger of every security. |\n| Share Registry | Securities | The share registry. |\n| All Stakeholders Ledger | Stakeholder | The ledger of every stakeholder. |\n| Stakeholder Details | Stakeholder | The full detail Carta holds for each stakeholder. |\n| Equity Awards Outstanding | Equity Plan | Every equity award that is still outstanding, across the plans. |\n| Equity Plan | Equity Plan | Equity plan activity at the as of date, the summary worksheet only. Carta leaves the transactions ledger, the rollforward, and the stakeholder sums worksheets unticked, and this run sends those defaults. Generate the report from the Carta hub with those boxes ticked if you need them. |\n| Equity Pool Transaction Ledger | Equity Plan | The equity pool values with every transaction that moved them, in summary and in detail. |\n| Form 1099b Cost Basis Report | Equity Plan | The cost basis and the acquisition dates behind the Form 1099-B for a tender offer, for one tax year. |\n| Revenue Procedure Disclosure Statements Report | Equity Plan | The revenue procedure disclosure statements for one tax year. |\n| Tax Withholding Report | Equity Plan | The tax withholding events Carta processed, over a period. |\n| 83(b) Elections | Compliance | The 83(b) election filing status of every eligible security. |\n| Disqualifying Dispositions Report (ISO) | Compliance | Disqualifying dispositions on certificates that came from an incentive stock option, between the earliest and the latest transaction date. |\n| Documents Report | Compliance | Every security with its id, its holder, and the documents attached to it. |\n| Rule 701 Analysis | Compliance | The Rule 701 exemption analysis over a period. An empty from date means one year. |\n| Security Acceptance Status Report | Compliance | Every security and whether its holder has accepted it. |\n| Stakeholder Contact Spreadsheet | Compliance | Every stakeholder with their name, email address, and postal address. |\n| Transactions Audit Report | Compliance | Every action taken in the Carta account, over a period. |\n| YTD Payroll Records Report | Compliance | The compensation values uploaded for tax withholding, over a period. |\n| Certificate Transaction Report | Transactions | Every transaction against a certificate, up to the as of date. |\n| Exercised and Settled | Transactions | Every option exercise and every settlement. |\n| ISO/NSO Vesting Report | Vesting | Vesting tranche by tranche, with the incentive and non qualified split. |\n| Vesting Details | Vesting | Vesting tranche by tranche. |\n| Forfeiture Report | Terminations | An estimate of the forfeiture rate, from the terminations already recorded. |\n| Historical Terminations | Terminations | What each recorded termination did to the equity plan. |\n| Tender Offer Seller Model | Modeling | Eligibility and transaction parameters for each stakeholder in a Carta Liquidity transaction. |\n| Voting Rights Report | Modeling | Outstanding ownership and votes for every stakeholder. |\n\nThe run also asks for the reports Carta keeps for a public company, for an\nemployee stock purchase plan, and for the older version of a report it now\nserves a newer one of. Your organisation probably has none of these. Carta\nanswers each one with a refusal, and the run records that refusal as a skip,\nbecause nothing is missing from your archive. An organisation that does hold\nthose products gets the reports.\n\nCarta refuses such a report in more than one way. It answers with an error\nstatus, or it accepts the request and then marks the finished report with an\nerror. Both are refusals, and the run records a skip for both. The one answer\nthe run never reads as a refusal is HTTP 401, because that means your session\nhas ended.\n\nCarta serves some reports by two paths at once: an older path and a newer one.\nThe two produce the same report, and the hub shows one row. The run asks for\nboth. If one of them produces the file and Carta refuses the other, the run\nrecords a skip that names the report it does hold. Your archive has the report.\n\nTwo reports the hub offers are NOT generated:\n\n- The Carta SOC report. The download signs a non disclosure agreement, which is\n  a legal act by a person and not a copy of your records. Sign it and download\n  the report from the hub if you need it.\n- Termination modeling. The report models a termination that has not happened,\n  so it needs a stakeholder, a date, and a reason that you choose. It holds no\n  record of its own.\n\n`manifest.json` carries the whole catalogue under `reports.catalogue`, with the\nreason beside every report the run did not generate, and one row per request\nunder `reports.generated`.\n\nTwo reports are built one tax year at a time: the Form 1099b cost basis report\nand the revenue procedure disclosure statements report. Carta draws that year\nlist in your browser and serves it from no endpoint, so the run takes the year\nCarta itself selects, which is this one, and names the earlier years as a skip.\nRead the Year list on the report and pass `--report-years 2024,2025,2026` to\ntake them.\n\n## The tool is polite\n\nRequests run one at a time by default. The limit is two at a time. There is no\nburst mode. The run is paced like a person reading their own records, not like a\nscript:\n\n| What | How long |\n| --- | --- |\n| The gap between two requests | 900 to 1600 ms, drawn at random for each one |\n| A breath, every 30 to 50 requests | 3 to 6 seconds |\n| Between two families | 5 to 10 seconds |\n| The rate, at most | 40 requests a minute, whatever the gaps come out at |\n\nThe gap is drawn at random on purpose. A fixed gap is its own signature: nothing\na person does arrives every 750 ms to the millisecond. The rate ceiling is\nseparate from the gap, because a floor on the spacing is not a ceiling on the\nrate. The run prints the ceiling once for each family, as\n`pacing: human, 40 requests per minute at most`.\n\nThe run slows itself down when Carta asks it to. A 429, a 5xx, or a Cloudflare\ncheck doubles the gap for the rest of the run, up to 8 seconds. The run says so\nonce. `Retry-After` is honoured as it always was.\n\n`--gentle` doubles every pause above: the gap, the breath, and the wait between\nfamilies. Use it if Carta asks you for a bot check part way through a run.\n`--delay <ms>` sets the smallest gap, and the run still adds up to another 78 per\ncent of it at random. `--delay 0` turns the pacing off; use that only against a\ntest server.\n\nThe tool retries a network fault, a 408, a 425, a 429, and a 5xx. It honours\n`Retry-After`. It does not retry a 401, a 403, or a 404, because those are\nanswers and not faults.\n\n### What the tool does NOT do\n\nThis is the whole posture, and it is short on purpose:\n\n- It does not spoof a fingerprint. It does not pretend to be a browser it is\n  not, and it does not forge a device, a screen, a font list, or a canvas.\n- It hides nothing beyond the two launch flags it already uses, which suppress\n  Chrome's automation banner over the window you type your password into.\n- It uses no proxy, no address rotation, and no third party network.\n- It solves no bot check. When Carta or Cloudflare asks for a human check, the\n  window comes forward and you answer it yourself.\n\nThe tool is your own installed Chrome, with your own session, reading your own\nrecords at a human pace. Nothing about it is designed to look like anything\nelse.\n\n## The run survives what happens on a laptop\n\nA migration runs for the better part of an hour on a machine you are also using.\nThree things go wrong in that hour, and the run handles all three.\n\n**Carta signs you out.** The run notices, checks the session from inside the\npage, and pauses. The window comes forward with Carta's sign-in page on it and\nprints `Carta signed you out. Sign in again in the window; the run continues by\nitself.` Sign in, and the run continues with the record it stopped on. Nothing is\nrecorded as a failure because of it. If nobody signs in within 15 minutes, the\nrun stops early with one reason, keeps everything it has, and tells you the\ncommand to run again.\n\n**You close the window, or Chrome stops.** The run finishes the record it is on,\nwrites the checkpoint, and prints `The browser window was closed. Run the same\ncommand again to continue where this stopped.` It exits with code 2, because the\narchive is genuinely short.\n\n**The network drops.** One lost request is a blip and is recorded as any other\nfailure. Five in a row is an outage: the run pauses, re-checks the connection\nevery 30 seconds for up to 10 minutes, prints `waiting for the network`, and then\ncarries on with the record it stopped on. If the connection never comes back,\nthe run stops early with one reason.\n\nA laptop that slept in the middle of a run wakes up in one of those states, so\nthe cases above cover it. In every case the run stops with ONE reason rather than\nturning every remaining record into its own failure, and everything already\nretrieved is kept.\n\n## The run is safe to interrupt\n\nThe tool writes a checkpoint after every completed unit of work. Stop the run at\nany time. Start it again with the same `--out` directory. It continues from the\ncheckpoint. It reads each earlier response from `raw/` instead of asking Carta\nagain, with three exceptions.\n\nA response that carried a signed link is read from Carta again. The copy in\n`raw/` has the signature cut out, so it cannot serve a download. The tool sees\nthe cut and asks Carta for the response again, follows the fresh link at once,\nand never stores or reuses a signed link. Board consent documents, charter\nfilings, plan documents, 409A reports, warrant documents and the security detail\npanels all work this way. A response that still holds a signature is read again\ntoo. A stored signature has been expiring since the moment it landed, so the\ntool never follows one.\n\nA file the manifest records is trusted only when its bytes are still on disk.\nIf a file went missing between two runs, the tool retrieves it again rather than\nreport a complete archive over a hole.\n\n## A checkpoint speaks only for the version that wrote it\n\nThe checkpoint records the version of this tool that made it. A run that finds a\ncheckpoint from a different version does not continue from it. It starts again\nand asks Carta for every list, because a saved answer from an older build can be\nweeks out of date, and a security issued since then would be missing from your\narchive with nothing to tell you. The run prints one line that names the version\nthat wrote the checkpoint and the date.\n\nThe run keeps every document already in the archive. It matches a document by\nits SHA-256 hash, so it stores identical bytes once and never writes a second\ncopy. It moves the earlier `raw/` directory to `raw.<version>/` so the new run\ncannot mix its answers with the old ones. Nothing is deleted.\n\n## Nothing is dropped\n\nSome record shapes are not validated, because our own organisation does not have\nthem. We have no SAFEs. We have no convertible notes with balances. We have no\nRSUs, RSAs, or SARs. We have one equity plan, one currency, and one jurisdiction.\n\nWhen the tool meets a record it cannot interpret, it does three things:\n\n1. It writes the record to `raw/unrecognized/`, exactly as Carta sent it.\n2. It lists the record in `manifest.json`, under `unrecognized`.\n3. It continues with the rest of the run.\n\nLosing a record is the one unacceptable outcome. An unrecognised record forces\nexit code 1, so you cannot miss it.\n\nThe tool also records every item it did NOT take, and it says which of the two\nmeanings applies. An item you must copy by hand forces exit code 1 and is named\non the closing screen. An item the archive already holds another way does not\nchange the exit code. REPORT.md lists both, in two sections, so you can see\nevery decision this tool made for you.\n\n## Failures are machine readable\n\nEach failure in `manifest.json` carries these fields:\n\n| Field | Contents |\n| --- | --- |\n| `family`, `unit` | Which collector failed, and on which unit of work |\n| `httpStatus` | The status Carta returned, or null for a transport fault |\n| `endpointId`, `endpoint` | The endpoint map entry, and the path that failed |\n| `expectedKeys`, `receivedKeys` | The keys required, and the keys received |\n| `excerpt`, `rawPath` | A short body excerpt, and the full body on disk |\n| `remediation` | The Carta page or report that supplies the same data |\n\n`REPORT.md` prints the same object in a readable form. Only the session cookie\nis removed from a failure body. Presigned signatures are also removed, because a\nsignature is a credential and it stops working within an hour.\n\n## How to re-discover a changed endpoint\n\nCarta can change a private endpoint at any time. Use this method, and only this\nmethod:\n\n1. Open the real Carta page in a browser. Sign in.\n2. Open the developer tools. Select the Network tab.\n3. Filter the requests to XHR and fetch.\n4. Use the page as normal. Watch the calls that the application itself makes.\n5. Record the path, the query parameters, and the response keys.\n6. Update the entry in `scripts/carta-archive/endpoints.ts`. Set `verifiedOn` to\n   today.\n\nRun `--emit-endpoint-map` first. It gives you the old path, the expected\nresponse keys, and the date somebody last verified the call.\n\nDo not guess a URL. Do not bulk-probe URLs. Guessing is unreliable, it produces\nwrong data quietly, and it looks like scanning. Record the call that the\napplication makes instead.\n\n## What this tool cannot reach\n\nThe tool does not collect the records below. Retrieve each one by hand before\nyou cancel.\n\n| Record | Why | Manual fallback |\n| --- | --- | --- |\n| The equity totals of a stakeholder who is not an employee | Carta serves the employee view filtered to its own six employment relationships. This tool does not guess an unfiltered request. The person is still in the roster and in the full stakeholder records. | Stakeholders. Open the person. Read the Holdings tab. |\n| The Carta invoice history | The invoices are held by YayPay, outside Carta. The tool records the link and does not follow it. | Company settings, Subscription details. Open the statement link. |\n| The administrator's own account record in the manifest, beyond the identifying fields | The account belongs to the person, not to the company, so the manifest keeps the name and email only. The full response is still in `raw/company.me.json`. | The account menu, User settings. |\n| The company account users who can reach a data room | A room's Access tab counts them beside the invited people, but the endpoint answers with the invited people only. The account users come from the company permissions screens, which the `company` family reads. | Documents, Data rooms. Open the room, Access tab, and select View account users. |\n| A file attached to a message in the communication centre | No message on the validated organisation carried one, so the shape of an attachment link was never observed, and this tool never builds a document URL. A message that says it has attachments is reported, never dropped. | Communications. Open the message and download each attachment. |\n| The second and later pages of your inbox | The inbox lists send their page number in a parameter that was never observed. One page is read, and a run that finds more pages says so. | The account menu, Inbox. Read the remaining pages there. |\n| The detail of a saved round model, a pro forma model, or a tender offer | The list is collected. The detail view was never observed live, and this tool does not guess an endpoint. | Scenario modeling. Liquidity, Tender offers. Open each one. |\n| A document attachment with no link in the payload | The tool never builds a document URL. | Open the security. Use its Documents tab. Or run the Documents report. |\n| The detail panel of a convertible note or a SAFE | The organisation this tool was proved against holds none, so the panel was never opened. The tool asks for it on the path the application's own code builds, and it keeps whatever comes back as an unrecognised record if the answer differs. | Securities, SAFEs and convertibles. Open each one and copy its tabs. |\n| The Carta SOC report | The download signs a non disclosure agreement. That is a legal act by a person, not a copy of your records. | Run reports, Carta SOC Report. Sign the agreement and download it. |\n| The termination modeling report | It models a termination that has not happened, so it needs a stakeholder, a date, and a reason that you choose. | Run reports, Termination Modeling. Choose the stakeholder and the date. |\n| Earlier tax years of the Form 1099b and the revenue procedure reports | Carta draws the year list in your browser and serves it from no endpoint, so the run takes the year Carta selects. | Read the Year list on the report, then run again with `--report-years`. |\n\n`REPORT.md` does not name every row of this table. Read the three groups below\nbefore you trust the exit code.\n\n**The run records a skip.** It names these rows on every run that reaches the\nscreen behind them: the equity totals of a stakeholder who is not an employee,\nthe administrator's own account settings, the detail of a saved round model, a\npro forma model or a tender offer, a document attachment that carries no link,\nthe Carta SOC report, the termination modeling report, and the earlier tax years\nof the two reports Carta builds one year at a time. A skip holds the archive\nshort of complete, and the run then exits non-zero.\n\n**The run records a failure or an unrecognised record, and only when your\narchive holds the case.** A file attached to a message in the communication\ncentre is a failure. The second and later pages of your inbox are a failure. The\ndetail panel of a convertible note or a SAFE is an unrecognised record, when the\nanswer differs from the shape the walk observed. A company with no message\nattachment, a one page inbox and no convertible note gets none of these records,\nbecause there is nothing to record.\n\n**The run names nothing at all.** Two rows live in this table only: the Carta\ninvoice history, and the company account users who can reach a data room. A run\nthat retrieves everything else reports the archive complete and exits zero\nwhile these two rows are uncopied. Copy these two by hand from this table.\n\nThe tool now DOES collect the records this table used to list. It collects every\nstakeholder profile, with the date of birth, the obfuscated tax id, the payroll\nid, and the dated history of every relationship change. It collects every\ncompany settings screen, including the two that Carta serves as forms with no\ndata endpoint: it saves each page and reads the current value of every field\nout of it. It also collects the 409A and FMV\nhistory, the share class terms, the authorized shares history, every certificate\nof incorporation, the vesting schedules, the legends, the document sets, the\nperformance conditions, the financing history, and the draft securities.\n\nIt also collects the whole approval trail of every security, with the date and\nthe signature id of each approval, plus the exercise ledger, the 83(b) filing\nstate and the withholding record behind each exercise, the four documents Carta\nkeeps for each exercise, and the ISO 100,000 dollar limit screen.\n\nFour links on an exercise request are NEVER called. One sends a reminder email\nto a stakeholder. The other three approve, reject, or adjust the exercise. This\ntool reads a ledger. It changes nothing.\n\nIt now also collects the data room access lists and read histories, the company\ndocument library categories, the company financials, the document delivery\nqueue, the communication centre messages with their bodies, your inbox, investor\nrelations, the audit confirmations, and the employee hub.\n\nThe tool does collect board consent documents. Carta keeps the download link out\nof the consent record. A second endpoint mints a presigned link for the consent\nfile, and the tool uses that link immediately. If the mint call fails, the tool\nrecords a failure for that consent. Then open Board, Consents in Carta and save\nthe PDF. Or download the Consents folder as a zip.\n\nThese conditions apply to the data rooms:\n\n- A data room has no single root directory. The room page is client rendered, so\n  the served page holds no table. It carries the top level listing as HTML\n  entity encoded JSON, under the key `root_documents`. The tool reads that key\n  and decodes it. Each entry is a complete node, so the tool knows which entries\n  are directories and which are files. A top level entry that is a file is\n  downloaded directly.\n- If Carta removes the `root_documents` key, the tool can find no start point.\n  It then fails that room and tells you what to do. Open the room. Open the\n  developer tools. Read a directory id from the `/api/dirs/<roomId>/<dirId>`\n  request. Run again with `--only dataRooms --data-room-root <roomId>=<dirId>`.\n- The completeness check for a room is the number of files the tool enumerated\n  against the `document_count` Carta publishes for that room. `REPORT.md` prints\n  both numbers for every room. A difference is a failure, and it sets exit\n  code 2. The number of top level entries is never a completeness signal: one\n  room holds 144 files under a single top level folder.\n- Carta stamps some data room files with a watermark. The archived bytes then\n  differ from the original upload. The manifest records `watermarked` for each\n  such file.\n\nThese conditions apply to the security attachments:\n\n- Each attachment is `{id, url, name}`. The field is `url`. The value is an\n  absolute URL on `documents.carta.com`. That host is not `app.carta.com`, and\n  the URL carries its own access token in the path.\n- The tool never sends the Carta session cookie to that host.\n- The tool never fetches those bytes from inside the Carta page. The browser\n  blocks a cross origin fetch. The bytes go through the browser download path.\n  If the agent supplies no download capability, the tool records a failure for\n  that attachment and names the manual fallback.\n- Several securities can share one attachment, with the same URL and the same\n  filename. The tool keys each stored file by the attachment id, and it\n  de-duplicates identical content by SHA-256 hash. Two documents with different\n  content never share a path, and one file never overwrites another.\n\n## Tests\n\n```bash\nnpx vitest run tests/carta-archive/\n```\n\nThe tests use fixtures and a stubbed fetch. They never touch the network.\n\n## After the archive: load it\n\nAn archive is not a migration. `scripts/carta-load/` moves it into CapDaddy and\ntells you what is still missing.\n\n```\nnpm run carta:plan   -- --archive <dir>\nnpm run carta:load   -- --archive <dir> --org <slug>\nnpm run carta:verify -- --org <slug> --archive <dir>\n```\n\nA migration is finished when `carta:verify` prints `placeholders: 0`. See\n`scripts/carta-load/README.md`.\n","readmeFilename":"README.md"}