{"_id":"@cardano-slips/server","_rev":"6-0041a7954412f3836a221318a768b6f4","name":"@cardano-slips/server","dist-tags":{"latest":"0.2.1"},"versions":{"0.0.0":{"name":"@cardano-slips/server","version":"0.0.0","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"license":"MIT","_id":"@cardano-slips/server@0.0.0","maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","dist":{"shasum":"9f89515bcfcf155e6b90191a55437c5f9baf9160","tarball":"https://registry.npmjs.org/@cardano-slips/server/-/server-0.0.0.tgz","fileCount":8,"integrity":"sha512-XemWqcaGcnpmUitVDmlMU5H+shDHO2Xai71OYMSsKFVchFs8SpbrWg01AksldnvtJkhyRX4uKQIcWjPmnCQKNA==","signatures":[{"sig":"MEUCIHovhjvz1FAdLiHyekh4dHHmGRx78Bv7nIJ0qYKVEaTfAiEAl2imTmYhLqzkjuiVv+tlZrWc/fP9W8YV4oxQe6NBdIs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":7286},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -b tsconfig.build.json","clean":"rm -rf dist build coverage .tsbuildinfo .turbo","typecheck":"tsc -b tsconfig.src.json && tsc -p tsconfig.test.json"},"_npmUser":{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"},"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","directories":{},"sideEffects":false,"_nodeVersion":"22.22.0","dependencies":{"@cardano-slips/core":"^0.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/server_0.0.0_1787693173125_0.9736824499746275","host":"s3://npm-registry-packages-npm-production"}},"0.0.1":{"name":"@cardano-slips/server","version":"0.0.1","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"license":"MIT","_id":"@cardano-slips/server@0.0.1","maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","dist":{"shasum":"af8e092956f7a87792ed764474ec4d857031dea7","tarball":"https://registry.npmjs.org/@cardano-slips/server/-/server-0.0.1.tgz","fileCount":8,"integrity":"sha512-qGaucyA1TxFUmT1HSDLSRWNoqNeYyRbYhhytggixcCz3tkzYRrOW8m43tGbaM9xz2RupbQP8Z/djsHi2CmxiHw==","signatures":[{"sig":"MEUCIQCD/3DfbZR0YSc/DhKWFHW4fDEpri11KB/RC+84L1snxwIgc8yzD7r0c/R4Ua/Ma4wZvkgreoeY2n8YJ9wJ03Zb51Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cardano-slips%2fserver@0.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7286},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -b tsconfig.build.json","clean":"rm -rf dist build coverage .tsbuildinfo .turbo","typecheck":"tsc -b tsconfig.src.json && tsc -p tsconfig.test.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c15a2e97-c8e0-413f-9284-937e1df43a44"}},"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","dependencies":{"@cardano-slips/core":"^0.0.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/server_0.0.1_1787695176684_0.5850447821923226","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@cardano-slips/server","version":"0.0.2","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"license":"MIT","_id":"@cardano-slips/server@0.0.2","maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","dist":{"shasum":"c88d14cb5b6f555af6cc19809e329d73862ab6ed","tarball":"https://registry.npmjs.org/@cardano-slips/server/-/server-0.0.2.tgz","fileCount":8,"integrity":"sha512-znIG6wkzzwYMlczZKMqv16uKJrZDvtPMykKqjyf0wOp4M1kJvvKI6uj6GkY67mq41QVuuLia/Np+pAJDRKWmOg==","signatures":[{"sig":"MEYCIQC2yur+B73E//miLvoJ9+gWWb1cqz8Omi3Gr3zHprAK8AIhAOTMfqDP+cUZEITsZ8kBJuP/FZeZOnDJl0iQhxu/eAiT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cardano-slips%2fserver@0.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":5973},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -b tsconfig.build.json","clean":"rm -rf dist build coverage .tsbuildinfo .turbo","typecheck":"tsc -b tsconfig.src.json && tsc -p tsconfig.test.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c15a2e97-c8e0-413f-9284-937e1df43a44"}},"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","dependencies":{"@cardano-slips/core":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/server_0.0.2_1787700597206_0.7795764956768456","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@cardano-slips/server","version":"0.1.0","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"license":"MIT","_id":"@cardano-slips/server@0.1.0","maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","dist":{"shasum":"47de7d09e48e4ed60ef54e311ea01841a8136df6","tarball":"https://registry.npmjs.org/@cardano-slips/server/-/server-0.1.0.tgz","fileCount":13,"integrity":"sha512-wARpYEuaSGwwcw/EIv6MM9DNClRvDenZOqyWUNuoabUaW//ATP+Isnc4uFHAOoab76EyH8nOlmMqOinyGR6MZA==","signatures":[{"sig":"MEUCICfLPOBmRSYzcfq8e4jev80Q+FZIhVWa9FE9skFW9YdlAiEA/UXfeQTHXTLPfDrZOiQ6tOHR2Afk1vSyS6pGZyD1A4I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cardano-slips%2fserver@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":37820},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -b tsconfig.build.json","clean":"rm -rf dist build coverage .tsbuildinfo .turbo","typecheck":"tsc -b tsconfig.src.json && tsc -p tsconfig.test.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c15a2e97-c8e0-413f-9284-937e1df43a44"}},"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","dependencies":{"effect":"^3.22.1","@cardano-slips/core":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/server_0.1.0_1787903845036_0.6555725956070484","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@cardano-slips/server","version":"0.2.0","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"license":"MIT","_id":"@cardano-slips/server@0.2.0","maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","dist":{"shasum":"0ba8fb105394dc73d474df3afe3bac328d1b9f14","tarball":"https://registry.npmjs.org/@cardano-slips/server/-/server-0.2.0.tgz","fileCount":28,"integrity":"sha512-79AzPxiw6z0Ahyo4O2vbMb4mBImHRgpm4apHXsuk4QtD5RU9dJ0Iac/nvM70aHWGOldjIN4FgaIiww5gcZJb/g==","signatures":[{"sig":"MEYCIQDsGIidkHwYE7MQSA0IyFZsF+43EuQ8OgnOJqHMSsn11gIhAI6IQYdcMJH/0U5jaOhn8wIvv+mMpcne0UbZFwjU/Pfy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cardano-slips%2fserver@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":80869},"type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json","./adapters/node":{"types":"./dist/adapters/node.d.ts","default":"./dist/adapters/node.js"}},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -b tsconfig.build.json","clean":"rm -rf dist build coverage .tsbuildinfo .turbo","typecheck":"tsc -b tsconfig.src.json && tsc -p tsconfig.test.json"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c15a2e97-c8e0-413f-9284-937e1df43a44"}},"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","dependencies":{"effect":"^3.22.1","@cardano-slips/core":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^6.0.3","@types/node":"^26.2.0"},"_npmOperationalInternal":{"tmp":"tmp/server_0.2.0_1788172213878_0.21623898218860793","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"_id":"@cardano-slips/server@0.2.1","bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","dist":{"shasum":"1639429140c079636007fb2f79fcc80374132fd9","tarball":"https://registry.npmjs.org/@cardano-slips/server/-/server-0.2.1.tgz","fileCount":28,"integrity":"sha512-Apk/rw4wnnYa/3N6yuB7AwWXUGoL2Gnq6czxxY24t+WGe5hP1S7zFfLSLuSI/wqgZmLE5fsGcQJ2IqWjRi5CPw==","signatures":[{"sig":"MEUCIQDwtUIhS6/p8cQh26muShsNogSbv4pQpMSlwwlNPP02/wIgE5nWgguMT8TSdToNZdYKvv/7bJpNGRtKxK3IZzhYnIc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCQGpQ5som9xgiBbS35CvLU5hFrYnmHHDPKfIut38/veAIhAIeMl296Z0/nilPr23Tn6Gdg20u0Lr+rvilPFVCpmylD"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cardano-slips%2fserver@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":80869},"name":"@cardano-slips/server","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./package.json":"./package.json","./adapters/node":{"types":"./dist/adapters/node.d.ts","default":"./dist/adapters/node.js"}},"license":"MIT","scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -b tsconfig.build.json","clean":"rm -rf dist build coverage .tsbuildinfo .turbo","typecheck":"tsc -b tsconfig.src.json && tsc -p tsconfig.test.json"},"version":"0.2.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"c15a2e97-c8e0-413f-9284-937e1df43a44"}},"homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","directories":{},"maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"sideEffects":false,"_nodeVersion":"26.0.0","dependencies":{"effect":"^3.22.1","@cardano-slips/core":"^0.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^6.0.3","@types/node":"^26.2.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/server_0.2.1_1790762414296_0.7931542582134115"}}},"time":{"created":"2026-08-25T21:26:12.834Z","modified":"2026-09-30T10:00:14.776Z","0.0.0":"2026-08-25T21:26:13.268Z","0.0.1":"2026-08-25T21:59:36.810Z","0.0.2":"2026-08-25T23:29:57.399Z","0.1.0":"2026-08-28T07:57:25.231Z","0.2.0":"2026-08-31T10:30:13.996Z","0.2.1":"2026-09-30T10:00:14.396Z"},"bugs":"https://github.com/emmanuel-musau/cardano-slips/issues","license":"MIT","homepage":"https://github.com/emmanuel-musau/cardano-slips/tree/main/packages/server#readme","keywords":["cardano","cardano-slips","endpoint","nextjs","transaction"],"repository":{"url":"git+https://github.com/emmanuel-musau/cardano-slips.git","type":"git","directory":"packages/server"},"description":"The publisher side of Cardano Slips: defineSlip handlers validated against the core schemas before a response leaves the server, plus one framework adapter","maintainers":[{"name":"emmanuel-musau","email":"emmanuelmutisya254@gmail.com"}],"readme":"# @cardano-slips/server\n\nThe publisher side. You write the two handlers a Slip endpoint needs; this validates what they return against the spec's own schemas before it goes on the wire, sets the headers a browser client cannot work without, and maps a failure to the status the spec pairs with it.\n\n```\npnpm add @cardano-slips/server\n```\n\n## What it is for\n\nA Slip endpoint is `GET` describing an intent and `POST` returning the publisher's side of a transaction. Both shapes are normative and both are easy to get subtly wrong — a missing `Access-Control-Allow-Origin`, an amount sent as a JSON number, a sold-out option reported as a `409` when the spec says answer `200` with `disabled`.\n\n```ts\n// app/api/slips/pay/route.ts\nexport const { GET, POST, OPTIONS } = defineSlip({\n  network: \"mainnet\",\n\n  get: () => ({\n    title: \"Pay 12.00 USDM to Corner Store\",\n    description: \"One payment to the shop's address. Nothing is stored, no account is created.\",\n    icon: \"https://linktap.example/i/corner-store.png\",\n    label: \"Pay 12.00 USDM\"\n  }),\n\n  post: ({ changeAddress }) => ({\n    intent: {\n      outputs: [{ address: shop, lovelace: \"0\", assets: [usdm(\"12000000\")] }],\n      validUntil: inTenMinutes()\n    }\n  })\n})\n```\n\n`type`, `version` and `network` are filled in, and a handler cannot restate them: one URL speaks one major version and serves one network, so there is nothing for a response to disagree with. A handler returns `fail(\"UNAVAILABLE\", \"Sold out for today.\")` where a request cannot be answered, and a `disabled` Slip with its `reason` where the endpoint answers fine and there is currently nothing to sign — the spec keeps those apart, and so does this.\n\nEvery response the handlers produce is checked against the `core` schemas on the way out — the failure bodies included. A publisher who declares a shape version 1 does not define fails at their own boundary, at their own deploy — not at a stranger's wallet, where the same mistake arrives as a Slip that will not load and a person with nothing to act on.\n\n## What ships in v1\n\nRoute handlers for `GET`, `POST` and the `OPTIONS` preflight a JSON body makes mandatory, `slips.json` serving from the origin root, and the spec's failure codes mapped to their HTTP status.\n\nAn endpoint written in something other than TypeScript does not need this package. The payload shapes are normative and published as JSON Schemas in [`spec/CIP-XXXX/schemas/`](../../spec/CIP-XXXX/schemas); a Laravel or Go endpoint validating against those conforms exactly as well as one built here. That is the protocol working, not a gap in it.\n\n## Mounting it on Next.js\n\nThe App Router asks for exactly what `defineSlip` returns, so a route file is the destructure and nothing else:\n\n```ts\n// app/api/slips/pay/route.ts\nexport const { GET, POST, OPTIONS } = defineSlip({ ... })\n```\n\n**A route with dynamic segments** gets them as `params`, already resolved — Next 15 and 16 hand them over as a promise, 13 and 14 as a plain object, and both arrive here the same way:\n\n```ts\n// app/api/slips/pay/[handle]/route.ts\nexport const { GET, POST, OPTIONS } = defineSlip({\n  network: \"mainnet\",\n  get: ({ params }) => shopCard(params.handle as string),\n  post: ({ params, changeAddress }) => payment(params.handle as string, changeAddress)\n})\n```\n\nA catch-all segment matches more than one, so a value is `string | readonly string[]` and a route that uses one has to say which it expects. On a route with no dynamic segment `params` is `{}`.\n\n**`slips.json` goes at the origin root**, which is a route segment named for the file:\n\n```ts\n// app/slips.json/route.ts\nexport const { GET } = defineDomainMapping({\n  rules: [{ pathPattern: \"/pay/*\", apiPath: \"/api/slips/pay/*\" }]\n})\n```\n\nThe rules are fixed at deploy, so they are decoded when the module loads: a mapping the spec rejects throws where the publisher can see it rather than serving a file no client will accept. `Cache-Control: public, max-age=300` is the default, matching the spec's own example; pass `{ maxAge }` to change it. There is no `OPTIONS` here on purpose — a `GET` carrying only `Accept` is a simple request, so a browser never preflights it.\n\nBoth route shapes and the `params` typing are verified against Next 16.3.3. Serving the mapping from `public/slips.json` instead works too, but then the CORS header is yours to add in `next.config`, and a mapping the spec rejects ships silently.\n\n## Mounting it anywhere else\n\n`defineSlip` returns `(Request) => Promise<Response>`, so any runtime built on those needs no adapter — Hono, SvelteKit, Remix, Bun, Deno and Cloudflare Workers all take these handlers directly.\n\n## Mounting it on NestJS or Express\n\nThese serve Node's `IncomingMessage`/`ServerResponse` rather than the Web pair, so they get a bridge. It is a second entry point, not part of the root — a Workers or Deno consumer should never have to install Node's types to build against this package:\n\n```ts\nimport { toNodeHandler } from \"@cardano-slips/server/adapters/node\"\n```\n\n`toNodeHandler` returns one function, and both frameworks mount it the same way:\n\n```ts\n// Express\nconst handler = toNodeHandler(endpoint, { origin: \"https://linktap.example\" })\n\napp.use(express.json())\napp.all(\"/api/slips/pay/:handle\", handler)\n```\n\n```ts\n// NestJS\nconst app = await NestFactory.create(AppModule)\napp.use(\"/api/slips/pay\", toNodeHandler(endpoint, { origin: \"https://linktap.example\" }))\n```\n\nIt handles the three things that break a naive bridge. A body parser that already ran — `express.json()`, and Nest's, which is on by default — leaves the stream drained and the parsed value on `req.body`, and reading the stream again would hang forever; this takes the body from wherever it actually is. Route parameters a framework matched (`req.params`) arrive in the handlers as `params`, the same way a Next dynamic segment does. And Express rewrites `req.url` for a handler mounted under a prefix, so the path is read from `req.originalUrl` where there is one — otherwise the `app.use` form above would hand your handlers `/` and every relative `href` would resolve against the wrong base.\n\n**The origin is yours to state, and that is deliberate.** `toNodeHandler` refuses to be built without either an `origin` or `originFromHeaders: true`. `Host` and `X-Forwarded-Host` are the client's to set: the origin reaches your own handlers as `context.url`, and it fixes what counts as same-origin when a linked action's `href` is checked. Behind a proxy that overwrites those headers, `originFromHeaders` is fine. Exposed to whatever a request claims, it is a header away from your endpoint describing itself as somewhere else. Naming the origin costs one line and removes the question — and whichever way it is settled, only the path and query ever come from the request, so a protocol-relative target cannot move it.\n\nRequest headers reach the handlers, less the hop-by-hop ones, so an endpoint that rate-limits or authenticates on a header behaves the same here as on a Web-standard runtime. A `POST` body is bounded at 64 KiB whether or not a parser read it first, since a conforming one is two short strings — pass `maxBytes` to change it. `HEAD` answers as the `GET` does without the body; anything else is `405` with an `Allow` header.\n\nVerified against Express 5 and NestJS 11 on Node 22. Fastify is not covered: it parses the body onto its own `request.body` rather than `request.raw`, so it needs a mount of its own and has not been written or tested yet.\n\n## What it will never import\n\n`flow` or `verifier`. A dApp shipping an endpoint should get a request handler, not a React tree and not a CBOR decoder, and the dependency rule that says so is in [ARCHITECTURE](../../docs/ARCHITECTURE.md#dependency-rules). `test/dependencies.test.ts` is what keeps it true rather than intended.\n\nIt also holds no keys and signs nothing. An endpoint returns an unsigned partial intent; the person's own wallet is the only thing in this protocol that signs.\n\n## Entry point\n\nTwo entries, and no third. The root is everything a Slip endpoint needs; `@cardano-slips/server/adapters/node` is the Node bridge, kept separate so the root surface stays runtime-agnostic. Deep imports into `dist/` are not a supported surface, so moving a file is never a breaking change:\n\n```ts\nimport { ... } from \"@cardano-slips/server\"\n```\n\nMIT licensed. Issues and contribution guide: [cardano-slips](https://github.com/emmanuel-musau/cardano-slips).\n","readmeFilename":""}