{"_id":"@clawdreyhepburn/ovid","_rev":"9-b4c128f1132fb24c5611838a937e99f3","name":"@clawdreyhepburn/ovid","dist-tags":{"latest":"0.5.0"},"versions":{"0.2.0":{"name":"@clawdreyhepburn/ovid","version":"0.2.0","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.2.0","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"52a875924369b8c603c97078e84d829137810015","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.2.0.tgz","fileCount":30,"integrity":"sha512-sBarpjldApaChfdiQh4UU0GcU1sziPnSxFLmRwcUDMVDB5Riss7BbrEBdZWC0ykDqq30Dpsy9UxJ2DN+/tL+Bg==","signatures":[{"sig":"MEUCIFweTBUDmT6xJzB6Og+zD3RU5CnNLbNLQhjas8/B4JCdAiEAmQNs40JcAD0AwE4ehvvWkc7PWb+y8N1ADbmoJw5cVQc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":109773},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"660db7ff8de53fd5769d420f114b4e679aba4d93","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.2.0_1774309273725_0.18057083652924044","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@clawdreyhepburn/ovid","version":"0.2.1","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.2.1","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"eec231fb49bfebec6b70dab8dcd2e155b897d15d","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.2.1.tgz","fileCount":16,"integrity":"sha512-YfEosxgBigIf4KMVH8Cxt1nynOTcU+CsP0ASRy3f+tuR3S84N94NzjmMmXbq/XEvDoig/Kd8Qyi6icITEbxpxA==","signatures":[{"sig":"MEQCIFEjghUKua1N78nn20hpnbrY4WVULiMTLfBcLWVjhN55AiAsHeFEOwgEJtQhLImUYT6ONKsQf4N5AB5RJfRVnfwO1w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30118},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"576f3d00ab1c0981035ffa641ba8a0c2597cf760","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.2.1_1774309301568_0.8294226810004706","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@clawdreyhepburn/ovid","version":"0.2.2","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.2.2","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"5e9eb02715a89f469a9df4adbed6f3dcde61ca2c","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.2.2.tgz","fileCount":16,"integrity":"sha512-+K7ofQ9X+LQo8mjjWeR0PrCYJWgHE5jzAxbERnlViAQ5K+cNTCAzeuakGxfdaqI6BTzCeUX4Ak3VbnmmGBaFCA==","signatures":[{"sig":"MEQCIGh0BgGmNCxAUnjX9avKg6IFC5giwYKbbGZuvBBZXlpZAiAKi3FvPNOOnd/c8Alkvqibjo8HIt785Nz1OM5sTTanmg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31309},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7a50049995d0e0efc726741793a8edf3c607c020","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.2.2_1774311943493_0.6191823503345921","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@clawdreyhepburn/ovid","version":"0.3.1","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.3.1","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"e524f3ee570f4944b69b4320f840481728385d7a","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.3.1.tgz","fileCount":16,"integrity":"sha512-RwaJIoQo0FILFHczQWgZz4xUOaK/dWDnIX2v+3GsXs6N1tqx3nIqarNdv52yywc3pmmTZ4CDqBtZoFLKOQBTZw==","signatures":[{"sig":"MEUCIQDVe80Ik2sFyvD8uu/srtHguE/6ImziUdOh2rFcJZAscgIgVdDfDOs0Ikqfw5qA8ZyEiB/PFA1tUWMp48gDzWkmQi0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35903},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"9a623095a2c869f3359b7a9f8946aea4e3274943","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.3.1_1774382252652_0.7200068065442344","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@clawdreyhepburn/ovid","version":"0.4.0","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.4.0","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"d7f67ff742a40378706383f8aed3e4997585b36f","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.4.0.tgz","fileCount":18,"integrity":"sha512-yPs2LIXONjXplUGv7wfYj8iuXO4Qb/27EMgZIk1EamXLj0LhA4F8xMQD5GSgphwFMvQFDXTExCAyjJYpEFHz7A==","signatures":[{"sig":"MEUCIQDC7UbdbmIDuS/DSjM4tQk4eiWrE90AGZJrYUvtZvgXBwIgSD7t2phMufpGeqzgP4fLagLNM937MHWFo1uWBRGZfN0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61856},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ce33a23f9c32bfdb7898102b52bdec9edefc871a","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.4.0_1776627369517_0.8699449139200608","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@clawdreyhepburn/ovid","version":"0.4.1","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.4.1","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"ebab3973963dc9c385bcf3310b0a4877b00de4d2","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.4.1.tgz","fileCount":18,"integrity":"sha512-qGOlUHPjkgcz8VyFEjM1pbCvP482XFNTJivqWccvuZzVFvvF82Mpeqk0bF3tDOLwQYZBktINhb/xds4TXWdkYA==","signatures":[{"sig":"MEQCIHPYpnp+2b7anSTtKVsgApq5NLa0pLsWOkynk5DzLZ5mAiBjRmphkzFvIFCWp4iGYnMkx7flZnjNJ0BlapP0kcBZ4g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67995},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"0acf72d60b495272e71ba4986cb0ac0594f6d47b","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.4.1_1783958556884_0.8424501340879671","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@clawdreyhepburn/ovid","version":"0.4.2","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.4.2","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"d41dbf1ca545b07783bed09bef09046c015ab898","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.4.2.tgz","fileCount":18,"integrity":"sha512-gTk65OpnBKuVzDNZ/1L9FvlW3hmSSJyaLIZ/XXUOdCRf1vox3dPCFPh6xugKWLRCi8EOzifDVKsvA8MMDXo5iA==","signatures":[{"sig":"MEQCIFdOdk7WLeqybs1/u+4LLrqOewatSxMGNed5bhUc1/hBAiB7su4NNPywhSd7ikIath8ZALoCFyNt8IOa18/ydSly9Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71551},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c7913a3d19ae9dc4a047130116fbb75e15102381","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.4.2_1783964700352_0.5087705910759781","host":"s3://npm-registry-packages-npm-production"}},"0.4.3":{"name":"@clawdreyhepburn/ovid","version":"0.4.3","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"license":"Apache-2.0","_id":"@clawdreyhepburn/ovid@0.4.3","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"dist":{"shasum":"5a36c1fb3332d5b7d5574829e1b343709f91c845","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.4.3.tgz","fileCount":20,"integrity":"sha512-qkttUGtyTsreYVAl+hsUT/OxDIqDfArrwn7tNM0WCBSd66AW4DCdhZ1q7vXY3Muh9z1xqMdaIMe7VVaL61mUJQ==","signatures":[{"sig":"MEUCIQDYaZtsrSkP+CyS5nVuDt2HknajlaLQVzcZPLzfnDFNAwIgDhK04dqQoK9aBS2NceT9C2SfoQAWEFourDn3PNPD40o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":76148},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"152a2074d5fe9418c521e8ff7fb8ed43b73d5446","scripts":{"test":"vitest run","build":"tsc","test:watch":"vitest"},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"repository":{"url":"git+https://github.com/clawdreyhepburn/ovid.git","type":"git"},"_npmVersion":"10.9.4","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","directories":{},"_nodeVersion":"22.22.0","dependencies":{"jose":"^6.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.0.0","typescript":"^5.7.0","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/ovid_0.4.3_1784571271921_0.5946675792032443","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@clawdreyhepburn/ovid","version":"0.5.0","description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/clawdreyhepburn/ovid.git"},"homepage":"https://github.com/clawdreyhepburn/ovid","bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","test":"vitest run","test:watch":"vitest"},"dependencies":{"jose":"^6.0.0"},"devDependencies":{"@types/node":"^25.5.0","typescript":"^5.7.0","vitest":"^3.0.0"},"gitHead":"152a2074d5fe9418c521e8ff7fb8ed43b73d5446","_id":"@clawdreyhepburn/ovid@0.5.0","_nodeVersion":"26.5.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-HIr1ufjggKcBl//hBYePJDLaXA8ai7JZZ0MJpUyUqzGY0IpmVH5V1Ib4c/4QQvDlO06mS9g8NyLmqNazC+vIoQ==","shasum":"044f0380dbf182fb8afe9071449644a6d94fbd87","tarball":"https://registry.npmjs.org/@clawdreyhepburn/ovid/-/ovid-0.5.0.tgz","fileCount":24,"unpackedSize":95488,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFcOVci4sO/9vlV+yLoCTxFmHlcWgPmEYNt1ZM4s1MkvAiBu43rKApfJpFZ+dR85ipj2nemxY0lSsIsnl4RaSpNhPw=="}]},"_npmUser":{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"},"directories":{},"maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ovid_0.5.0_1784728698633_0.1535716486425276"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-23T23:41:13.617Z","modified":"2026-07-22T13:58:18.962Z","0.2.0":"2026-03-23T23:41:13.876Z","0.2.1":"2026-03-23T23:41:41.713Z","0.2.2":"2026-03-24T00:25:43.630Z","0.3.1":"2026-03-24T19:57:32.808Z","0.4.0":"2026-04-19T19:36:09.675Z","0.4.1":"2026-07-13T16:02:37.103Z","0.4.2":"2026-07-13T17:45:00.504Z","0.4.3":"2026-07-20T18:14:32.054Z","0.5.0":"2026-07-22T13:58:18.809Z"},"bugs":{"url":"https://github.com/clawdreyhepburn/ovid/issues"},"license":"Apache-2.0","homepage":"https://github.com/clawdreyhepburn/ovid","keywords":["agent-identity","ai-agent","jwt","ed25519","sub-agent","credential","attestation","delegation","cedar","openclaw","mcp","non-human-identity"],"repository":{"type":"git","url":"git+https://github.com/clawdreyhepburn/ovid.git"},"description":"Cryptographic identity documents for AI agents — Ed25519 signed JWTs with delegation chains","maintainers":[{"name":"clawdreyhepburn","email":"clawdrey.hepburn@engageidentity.com"}],"readme":"<p align=\"center\">\n  <h1 align=\"center\">🪪 OVID</h1>\n  <p align=\"center\"><strong>Cryptographic identity for AI agents.</strong></p>\n  <p align=\"center\">\n    Ed25519 signed JWTs with delegation chains — tells you exactly who a sub-agent is, who created it, and when it expires.\n  </p>\n  <p align=\"center\">\n    <a href=\"#the-problem\">The Problem</a> •\n    <a href=\"#how-it-works\">How It Works</a> •\n    <a href=\"#quick-start\">Quick Start</a> •\n    <a href=\"#api\">API</a> •\n    <a href=\"#mandate-evaluation\">Mandate Evaluation</a> •\n    <a href=\"docs/SECURITY.md\">Security Guide</a> •\n    <a href=\"#faq\">FAQ</a>\n  </p>\n</p>\n\n---\n\n## New here? Read this first (no background assumed)\n\n**What is this, in one sentence?** OVID is a small software library that gives each automated AI helper its own tamper-proof **ID badge**, so you always know who a helper is, who created it, what it's allowed to do, and when its access expires.\n\n**Why does that matter?** When an AI assistant is given a big job, it often spawns smaller **helper programs** (\"sub-agents\") to handle pieces of it. By default, each helper inherits *all* the power of the thing that created it — like handing a house-painter the keys to your house, car, and bank account when they only needed one room. OVID replaces that with a specific, limited, unforgeable badge for each helper.\n\n**A few terms you'll see, in plain English:**\n\n- **Agent / sub-agent** — an automated AI worker. A \"sub-agent\" is a helper spawned by another agent.\n- **Badge / identity document / \"OVID\"** — a small signed file that proves who a helper is and what it may do. (OVID = **O**penClaw **V**erifiable **I**dentity **D**ocument.)\n- **Mandate** — the list of allowed actions printed on the badge.\n- **Signing / cryptographic signature** — unforgeable digital math (the same kind that secures websites) that makes a badge impossible to fake or alter.\n- **Chain** — because a helper can spawn its own helper, badges link together in a traceable chain leading back to you, the human.\n- **JWT** — a common, standard file format for signed digital tokens. An OVID badge *is* a JWT with some extra fields. You don't need to know the format to use the library.\n\n**What OVID does and doesn't do:** OVID *issues and verifies* badges (identity + expiry + traceability). It does **not** by itself stop a helper from misbehaving — that enforcement is a separate, companion job. See [How OVID Fits the Stack](#how-ovid-fits-the-stack). Think: OVID prints and validates the ID card; a separate security desk checks it at every door.\n\nThe rest of this README goes deeper and is aimed at developers integrating the library. If you just want the OpenClaw plugin that does all of this automatically, see **[@clawdreyhepburn/openclaw-ovid](https://github.com/clawdreyhepburn/openclaw-ovid)**.\n\n---\n\n## The Problem\n\nWhen an AI agent spawns a sub-agent, the sub-agent inherits everything — API keys, credentials, tool access, filesystem. The code reviewer has a credit card. The browser worker can send tweets. The research agent can read every file on the machine.\n\nThis is [ambient authority](https://en.wikipedia.org/wiki/Ambient_authority), and it's the same mistake we made with Unix root shells, shared browser cookies, and unsandboxed containers. The fix has always been the same: **explicit, attenuated credentials.**\n\nOVID gives every sub-agent its own identity document — a signed JWT that says who it is, what mandate it carries, who created it, and when it expires. The spawning agent signs it. The chain is verifiable back to the human.\n\nRead more: [Your Sub-Agents Are Running With Scissors](https://clawdrey.com/blog/your-sub-agents-are-running-with-scissors.html)\n\n## How It Works\n\n```\nHuman (root of trust)\n  │\n  │ delegates authority to\n  ▼\nPrimary Agent (long-lived, has keypair)\n  │\n  │ issues OVID to\n  ▼\nSub-Agent (ephemeral, carries OVID JWT with Cedar mandate)\n  │\n  │ can issue derived OVID to\n  ▼\nSub-Sub-Agent (shorter lifetime, auditable chain)\n```\n\n**Four principles:**\n\n1. **The spawner is the attestor.** You trust a sub-agent because you trust the thing that created it — and that trust is cryptographically verifiable.\n2. **Lifetime can only shorten.** A child's OVID can't outlive its parent's. When the parent expires, everything downstream expires.\n3. **Identity is self-contained.** An OVID carries everything needed for verification. No database. No central server. No network calls.\n4. **The chain is the proof.** Each OVID embeds its full parent chain of cryptographic attestations. Walk it back to the root and verify every signature against a trusted root public key. No intermediate JWTs required.\n\n### What OVID verifies — and what it doesn't\n\nOVID is an **identity and lifetime** layer. A successful `verifyOvid` proves:\n\n- The leaf agent's keypair was attested by the chain of parents back to a\n  trusted root.\n- Every `iat`/`exp` along the chain is internally consistent (lifetimes can\n  only shorten, and the JWT's `iat` cannot predate the parent's attestation).\n- The JWT was authored by the leaf's own keypair (not forged by a sibling).\n- The token has not yet expired.\n\nOVID does **not** verify:\n\n- **Mandate attenuation.** OVID will happily sign a chain where a child's\n  `policySet` is broader than its parent's. A rogue parent can mint a\n  wide-open child token if it wants to. Enforcing that children only receive\n  a subset of their parent's authority is the job of\n  [`@clawdreyhepburn/ovid-me`](https://github.com/clawdreyhepburn/ovid-me)\n  (or any policy engine that consumes the verified mandate). Use OVID for\n  identity, OVID-ME for policy evaluation and subset proof.\n- **Resource authorization.** OVID carries a Cedar policy set but doesn't\n  evaluate it. Pass the verified mandate to Cedar (Cedarling, OVID-ME, etc.)\n  to make an allow/deny decision for any specific action.\n\n## Quick Start\n\n### Install\n\n```bash\nnpm install @clawdreyhepburn/ovid\n```\n\n### Issue an OVID\n\n```typescript\nimport { generateKeypair, createOvid } from '@clawdreyhepburn/ovid';\n\n// Primary agent creates a keypair (do this once, persist it)\nconst primaryKeys = await generateKeypair();\n\n// Spawn a sub-agent with a signed identity and Cedar mandate\nconst reviewer = await createOvid({\n  issuerKeys: primaryKeys,\n  issuer: 'clawdrey',\n  mandate: {\n    rarFormat: 'cedar',\n    policySet: 'permit(principal, action == Ovid::Action::\"read_file\", resource);',\n  },\n  ttlSeconds: 1800, // 30 minutes\n});\n\nconsole.log(reviewer.jwt);                // standard JWT string\nconsole.log(reviewer.claims.authorization_details[0].policySet); // Cedar policy\n// In v0.4.0+, parent_chain is a ChainLink[] with cryptographic attestations.\n// A root token has exactly one self-signed link (binding its own agent_pub).\nconsole.log(reviewer.claims.authorization_details[0].parent_chain);\n```\n\n### Verify an OVID\n\n```typescript\nimport { verifyOvid } from '@clawdreyhepburn/ovid';\n\n// Preferred: options form with trustedRoots (v0.4.0+).\nconst result = await verifyOvid(reviewer.jwt, {\n  trustedRoots: [primaryKeys.publicKey],\n  maxChainDepth: 5,  // optional, defaults to 5\n});\n\nif (result.valid) {\n  console.log(result.principal);  // \"clawdrey/agent-7f3a\"\n  console.log(result.mandate);    // { type, rarFormat, policySet, ... }\n  console.log(result.chain);      // [\"clawdrey/agent-7f3a\"] — flattened sub list\n  console.log(result.expiresIn);  // seconds until expiry\n}\n\n// Legacy single-key overload (deprecated, emits console warning):\n// const result = await verifyOvid(reviewer.jwt, primaryKeys.publicKey);\n```\n\n### Delegation chains\n\nSub-agents can issue OVIDs to their own sub-agents:\n\n```typescript\nconst helper = await createOvid({\n  issuerKeys: reviewer.keys,\n  issuerOvid: reviewer,\n  mandate: {\n    rarFormat: 'cedar',\n    policySet: 'permit(principal, action == Ovid::Action::\"read_file\", resource);',\n  },\n  ttlSeconds: 600, // shorter than parent ✅\n});\n\n// v0.4.0: parent_chain is ChainLink[] with root first, leaf last.\nconst chain = helper.claims.authorization_details[0].parent_chain;\nconsole.log(chain.length);         // 2\nconsole.log(chain[0].sub);         // root's sub (e.g. \"clawdrey\")\nconsole.log(chain[1].sub);         // helper's sub\n// Each link carries { sub, agent_pub, iat, exp, sig } — the parent's signed\n// attestation binding the child's identity.\n```\n\n### Chain verification (v0.4.0+)\n\nEach delegation step emits a **ChainLink**: a compact signed attestation from\nthe parent binding the child's identity. The verifier walks the chain from\nleaf to root, verifying each link's signature against the preceding link's\n`agent_pub`, and anchors the root link against a caller-supplied set of\ntrusted root public keys.\n\nA `ChainLink` is:\n\n```typescript\ninterface ChainLink {\n  sub: string;        // the agent this link represents\n  agent_pub: string;  // base64url Ed25519 pubkey bound to sub\n  iat: number;        // issue time (unix seconds)\n  exp: number;        // expiry (unix seconds)\n  sig: string;        // base64url Ed25519 sig by PARENT over canonical bytes\n}\n```\n\nThe signature covers this exact byte string (UTF-8):\n\n```\novid-chain-link/v1\\n<sub>\\n<agent_pub>\\n<iat>\\n<exp>\n```\n\nwhere `<iat>` and `<exp>` are decimal integers with no leading zeros\n(`String(value)` in JavaScript). Roots self-sign (the root's link is verified\nagainst its own `agent_pub`, which must equal one of `trustedRoots`).\n\n**Implementation notes:**\n- JWT payloads in v0.4.0 are signed by the **leaf agent's own keypair** (the\n  one bound in the last `ChainLink`). This is a change from v0.3.x where\n  children's JWTs were signed by the parent's keys.\n- `renewOvid` can only renew **root** tokens. Chained tokens cannot be renewed\n  in place because only the parent holds the key needed to sign a new chain\n  link — request a fresh token from the parent instead.\n- Legacy (pre-0.4.0) tokens with `string[]` `parent_chain` are still accepted\n  by `verifyOvid` via a fallback path, but their chains are not cryptographically\n  walkable. A one-time deprecation warning is emitted per process.\n\n## API\n\n### `generateKeypair(): Promise<KeyPair>`\nGenerates an Ed25519 keypair using the Web Crypto API.\n\n### `exportPublicKeyBase64(key: CryptoKey): Promise<string>`\nExports a public key as a base64url string.\n\n### `createOvid(options: CreateOvidOptions): Promise<OvidToken>`\nIssues a new OVID JWT.\n\n| Option | Type | Required | Default | Description |\n|--------|------|----------|---------|-------------|\n| `issuerKeys` | `KeyPair` | yes | — | Issuing agent's keypair |\n| `issuerOvid` | `OvidToken` | no | — | Parent's OVID (omit for root) |\n| `mandate` | `CedarMandate` | yes | — | Cedar policy set |\n| `issuer` | `string` | no | — | Issuer ID |\n| `agentId` | `string` | no | auto | Unique agent ID |\n| `ttlSeconds` | `number` | no | `1800` | Time to live |\n| `kid` | `string` | no | — | Key ID for JWT header |\n\n### `verifyOvid(jwt, options): Promise<OvidResult>`\nVerifies an OVID JWT's signature and full delegation chain. The modern form takes an options object:\n\n```typescript\nverifyOvid(jwt, { trustedRoots: [rootPublicKey], maxChainDepth: 5 });\n```\n\nReturns `{ valid, principal, mandate, chain, expiresIn }`. A legacy single-key overload `verifyOvid(jwt, publicKey)` still works but is deprecated and emits a one-time warning.\n\n---\n\n## Mandate Builder\n\nWriting raw Cedar inside a spawn task is error-prone. `buildMandate()` compiles a **structured intent** into a Cedar policySet that the OVID-ME evaluator and `cedar-wasm` both accept — so the same mandate is enforceable *and* provable. This is the accurate on-the-fly authoring path: fill a form, not freeverse Cedar.\n\n```typescript\nimport { buildMandate, buildMandateTag } from '@clawdreyhepburn/ovid';\n\nconst { policySet, summary, warnings } = buildMandate({\n  ttlSeconds: 1800,\n  allow: [\n    { action: 'read',  resource: { type: 'File', pathLike: ['**/workspace/**'] } },\n    { action: 'exec',  resource: { type: 'Shell', in: ['git', 'gh', 'npm'] } },\n    { action: 'fetch', resource: { type: 'API',  in: ['api.github.com'] } },\n  ],\n  forbid: [\n    { action: 'exec', resource: { type: 'Shell', in: ['rm', 'sudo'] } },\n  ],\n});\n// policySet is ready to sign into an OVID mandate; forbid always wins.\n```\n\nVocabulary (shared across the stack, `src/schema/vocabulary.ts`):\n\n- **Actions:** `read write edit exec fetch search browse send delegate remember recall call_tool summarize`\n- **Resource kinds:** `File Shell Tool WebEndpoint Channel Memory Session` (`API` is accepted and normalized to `WebEndpoint`)\n- **Default (no intent):** `read`, `search`, `summarize`\n\nGrant shapes:\n\n| Intent | Emitted Cedar |\n|---|---|\n| `{ action: 'read' }` | `permit(principal, action == Ovid::Action::\"read\", resource);` |\n| `{ action: ['read','write'] }` | `... action in [Ovid::Action::\"read\", Ovid::Action::\"write\"] ...` |\n| `{ action:'exec', resource:{ type:'Shell', in:['git'] } }` | `... resource == Ovid::Shell::\"git\"` |\n| `{ action:'read', resource:{ type:'File', pathLike:['/src/*'] } }` | `... resource) when { resource.path like \"/src/*\" }` |\n| `{ effect:'forbid', ... }` | `forbid(...)` (always wins) |\n\nFor spawning sub-agents, `buildMandateTag()` returns a ready-to-prepend block that the `openclaw-ovid` hook parses:\n\n```typescript\nconst { tag } = buildMandateTag({ ttlSeconds: 1800, allow: [{ action: 'read' }] });\n// tag =\n// [OVID_TTL:1800]\n// [OVID_MANDATE]\n// permit(principal, action == Ovid::Action::\"read\", resource);\n// [/OVID_MANDATE]\nawait sessions_spawn({ task: `${tag}\\n\\n${realTask}` });\n```\n\nIds and path globs are validated against a conservative charset; unsafe values throw rather than emit injectable Cedar. Unknown actions are dropped with a warning. Empty grants compile to an explicit deny-all.\n\n---\n\n## Mandate Evaluation\n\n**Looking for Cedar policy evaluation, enforcement, audit logging, and a forensics dashboard?**\n\nSee **[@clawdreyhepburn/ovid-me](https://github.com/clawdreyhepburn/ovid-me)** (OVID Mandate Evaluation) — reads mandates from verified OVID tokens, evaluates tool calls against Cedar policies, provides three enforcement modes (enforce/dry-run/shadow), and includes a full audit + dashboard system.\n\n---\n\n## OVID JWT Format\n\nAn OVID is a JWT compliant with [RFC 7519](https://datatracker.ietf.org/doc/html/rfc7519), signed with EdDSA (Ed25519), with the dedicated media type `ovid+jwt`. The mandate travels in the `authorization_details` claim ([RFC 9396](https://datatracker.ietf.org/doc/html/rfc9396)) using the `cedar` profile from [draft-cecchetti-oauth-rar-cedar-02](https://datatracker.ietf.org/doc/html/draft-cecchetti-oauth-rar-cedar-02).\n\n### Header\n```json\n{ \"alg\": \"EdDSA\", \"typ\": \"ovid+jwt\" }\n```\n\n| Claim | Required | Notes |\n|-------|----------|-------|\n| `alg` | yes | Always `EdDSA` (Ed25519). |\n| `typ` | yes | Always `ovid+jwt`. Distinguishes OVIDs from generic JWTs at parse time. |\n\n### Payload — root token\n\nA root token (depth 1) is one a top-level agent issues to itself. Its `parent_chain` contains exactly one self-signed `ChainLink`, anchoring the chain to a `trustedRoots` key supplied at verify time.\n\n```json\n{\n  \"jti\": \"clawdrey/agent-7f3a\",\n  \"iss\": \"clawdrey\",\n  \"sub\": \"clawdrey/agent-7f3a\",\n  \"iat\": 1777561629,\n  \"exp\": 1777563429,\n  \"authorization_details\": [\n    {\n      \"type\": \"agent_mandate\",\n      \"rarFormat\": \"cedar\",\n      \"policySet\": \"permit(principal, action == Ovid::Action::\\\"read_file\\\", resource);\",\n      \"parent_chain\": [\n        {\n          \"sub\": \"clawdrey/agent-7f3a\",\n          \"agent_pub\": \"AVQXD2Fw6fdYMoFCMsYxTZ-km-Z9ZmmoBnlLIWOdPjo\",\n          \"iat\": 1777561629,\n          \"exp\": 1777563429,\n          \"sig\": \"KxbNAyLTXYPW6uBXrwPOwrw1h976K8SJZqeNZWF7WmreFEPKTgm0p-4I1m--16x-l16jWcoCPtszJ-pND3HUCw\"\n        }\n      ],\n      \"agent_pub\": \"AVQXD2Fw6fdYMoFCMsYxTZ-km-Z9ZmmoBnlLIWOdPjo\",\n      \"ovid_version\": \"0.4.1\"\n    }\n  ]\n}\n```\n\n### Payload — delegated token (depth 2)\n\nWhen a parent agent spawns a child, the child gets a fresh keypair and a new OVID with a `parent_chain` that grows by one link. The new link is signed by the parent's `agent_pub` and binds the child's `sub` and `agent_pub`. Lifetime is attenuated: `iat` and `exp` are clamped inside the parent's window.\n\n```json\n{\n  \"jti\": \"clawdrey/agent-7f3a/reviewer-9d2b\",\n  \"iss\": \"clawdrey\",\n  \"sub\": \"clawdrey/agent-7f3a/reviewer-9d2b\",\n  \"iat\": 1777561629,\n  \"exp\": 1777562229,\n  \"authorization_details\": [\n    {\n      \"type\": \"agent_mandate\",\n      \"rarFormat\": \"cedar\",\n      \"policySet\": \"permit(principal, action == Ovid::Action::\\\"read_file\\\", resource == Ovid::Resource::\\\"/tmp/report.md\\\");\",\n      \"parent_chain\": [\n        {\n          \"sub\": \"clawdrey/agent-7f3a\",\n          \"agent_pub\": \"AVQXD2Fw6fdYMoFCMsYxTZ-km-Z9ZmmoBnlLIWOdPjo\",\n          \"iat\": 1777561629,\n          \"exp\": 1777563429,\n          \"sig\": \"KxbNAyLTXYPW6uBXrwPOwrw1h976K8SJZqeNZWF7WmreFEPKTgm0p-4I1m--16x-l16jWcoCPtszJ-pND3HUCw\"\n        },\n        {\n          \"sub\": \"clawdrey/agent-7f3a/reviewer-9d2b\",\n          \"agent_pub\": \"4-1bUD-aCMszelJA_ZN15hwEWEf_yuU0mz1vq9qFDI4\",\n          \"iat\": 1777561629,\n          \"exp\": 1777562229,\n          \"sig\": \"pGmrWMsdRy1A_jYjo7SmO1s1TGMd2rvQlvvkP2O1cKGoysbwVpJKcItiDhACTZsT588V7P4I6g_eggqKOYCLCg\"\n        }\n      ],\n      \"agent_pub\": \"4-1bUD-aCMszelJA_ZN15hwEWEf_yuU0mz1vq9qFDI4\",\n      \"ovid_version\": \"0.4.1\"\n    }\n  ]\n}\n```\n\n### Multi-hop chains (depth 3 and beyond)\n\nA helper can spawn its own helper, which can spawn another, and so on. Each hop adds one signed link. The verifier walks the whole chain and enforces two rules **at every step**, not just the first:\n\n- **Lifetime can only shorten** — each link's expiry is clamped inside its parent's.\n- **Each link is signed by its immediate parent's key** — a grandchild's link must be signed by its parent, not by the root. A link signed by the wrong key fails verification.\n\nThis means the traceable chain-of-custody holds no matter how deep the delegation goes (up to `maxChainDepth`, default 5). The companion library [`@clawdreyhepburn/ovid-me`](https://github.com/clawdreyhepburn/ovid-me) additionally proves that each hop's *permissions* only ever narrow — a grandchild can never hold more authority than its parent, and that is checked with a formal proof engine at issuance time.\n\n### Top-level claims\n\n| Claim | Type | Required | Notes |\n|-------|------|----------|-------|\n| `jti` | `string` | yes | JWT ID. By convention the agent's path-style identifier (`<parent>/<child>`). |\n| `iss` | `string` | yes | Issuer ID — the human or organization the root agent serves. |\n| `sub` | `string` | yes | Subject — the agent this token identifies. Equal to `jti` for OVIDs. |\n| `iat` | `number` | yes | Issued-at, unix seconds. Must be `>=` parent's `iat`. |\n| `exp` | `number` | yes | Expiry, unix seconds. Must be `<=` parent's `exp` (lifetime attenuation). |\n| `authorization_details` | `AuthorizationDetail[]` | yes | RFC 9396 carrier for the agent's mandate(s). OVID currently issues exactly one entry. |\n| `parent_ovid` | `string` | legacy only | Pre-0.4.x tokens recorded the parent's `sub` here. Modern verifiers ignore it; the source of truth is `authorization_details[0].parent_chain`. |\n\n### `authorization_details` entry (the mandate)\n\nEach entry is an `AuthorizationDetail` — RFC 9396 with the `cedar` profile from `draft-cecchetti-oauth-rar-cedar-02`.\n\n| Field | Type | Required | Notes |\n|-------|------|----------|-------|\n| `type` | `string` | yes (RFC 9396) | Always `agent_mandate` for OVID. |\n| `rarFormat` | `\"cedar\"` | yes | Selects the Cedar profile. |\n| `policySet` | `string` | yes | Cedar policy text. The agent's mandate. |\n| `parent_chain` | `ChainLink[]` | yes (v0.4.0+) | Cryptographic delegation chain, root first, leaf last. Pre-0.4 tokens used `string[]` of `sub`s and are accepted via a fallback path but are not cryptographically verifiable. |\n| `agent_pub` | `string` | yes | Base64url Ed25519 public key bound to this token's `sub`. Equal to the leaf link's `agent_pub`. |\n| `ovid_version` | `string` | yes (modern) | **Wire protocol version** (currently `\"0.4.0\"`), not the npm package version. Verifiers branch on this for shape compatibility. Bumping `@clawdreyhepburn/ovid` on npm does **not** change this field. See `OVID_PROTOCOL_VERSION` / `CHAIN_PROTOCOL_VERSIONS` in the package exports. |\n\n### `ChainLink`\n\nEach link is a parent-signed attestation that some `sub` controls some `agent_pub` for some validity window.\n\n| Field | Type | Notes |\n|-------|------|-------|\n| `sub` | `string` | Subject this link represents. |\n| `agent_pub` | `string` | Base64url Ed25519 public key bound to `sub`. |\n| `iat` | `number` | Issued-at. Must be `>=` parent link's `iat`. |\n| `exp` | `number` | Expiry. Must be `<=` parent link's `exp`. |\n| `sig` | `string` | Base64url Ed25519 signature over the canonical bytes below, produced by the **parent** link's `agent_pub`. The root link is self-signed. |\n\nCanonical signed bytes (UTF-8, byte-exact for interop):\n\n```\novid-chain-link/v1\\n<sub>\\n<agent_pub>\\n<iat>\\n<exp>\n```\n\n`iat` and `exp` are decimal integers with no leading zeros.\n\n### Verification\n\n`verifyOvid(jwt, { trustedRoots, maxChainDepth })` (the preferred form) checks, in order:\n\n1. JWT signature (EdDSA) using `issuerPublicKey`.\n2. `typ === \"ovid+jwt\"`.\n3. `iat`, `exp` against current time.\n4. `parent_chain` is non-empty and bounded by `maxChainDepth` (default 5).\n5. The leaf link's `sub` and `agent_pub` match the token's `sub` and `authorization_details[0].agent_pub`.\n6. Each link's `iat`/`exp` is within its parent's window (lifetime attenuation).\n7. Each non-root link's `sig` verifies under its parent's `agent_pub`.\n8. The root link is self-signed and its `agent_pub` is a member of `trustedRoots`.\n\nA token that fails any check returns `{ valid: false, ... }`. A passing token returns `{ valid: true, principal, mandate, chain, expiresIn }`.\n\n---\n\n## Development\n\n```bash\ngit clone https://github.com/clawdreyhepburn/ovid.git\ncd ovid\nnpm install\nnpm test        # 48 tests via vitest\nnpm run build   # TypeScript → dist/\n```\n\n### Project structure\n\n```\novid/\n├── src/\n│   ├── index.ts       # Public API exports\n│   ├── keys.ts        # Ed25519 keypair generation\n│   ├── create.ts      # OVID issuance with lifetime attenuation\n│   ├── verify.ts      # Signature verification and claims validation\n│   └── types.ts       # TypeScript interfaces (including CedarMandate)\n├── test/\n│   ├── keys.test.ts\n│   ├── create.test.ts\n│   ├── verify.test.ts\n│   ├── chain.test.ts\n│   ├── renew.test.ts\n│   ├── delegation.test.ts\n│   └── depth3-chain-construction.test.ts   # multi-hop chain soundness\n├── docs/\n│   └── SECURITY.md\n├── ARCHITECTURE.md\n├── LICENSE\n├── NOTICE\n└── package.json\n```\n\n---\n\n## How OVID Fits the Stack\n\nOVID provides **identity and mandates** — it tells you who a sub-agent is and what authority was delegated to it. But OVID itself doesn't enforce anything. Enforcement is handled by two complementary layers:\n\n1. **[Carapace](https://github.com/clawdreyhepburn/carapace)** — the deployment-level ceiling. The human defines what tools are allowed at all via Cedar policies, enforced on every `before_tool_call` hook. Binary allow/deny. This is the human's hard limit — no agent can exceed it regardless of what mandate it carries.\n\n2. **[OVID-ME](https://github.com/clawdreyhepburn/ovid-me)** — mandate evaluation. Reads the Cedar policy from a verified OVID token and evaluates whether the specific tool call is permitted by the parent's delegation. Three modes: enforce, dry-run, shadow.\n\n**Both must allow a tool call to proceed.** Carapace gates what the human permits; OVID-ME gates what the parent delegated. A sub-agent with a broad mandate still can't exceed the deployment ceiling, and a sub-agent under a permissive deployment ceiling still can't exceed its parent's mandate.\n\n```\nTool call arrives\n  │\n  ├─ Carapace: \"Does the deployment policy allow this?\" ── deny ──> blocked\n  │                                                         │\n  │                                                       allow\n  │                                                         │\n  ├─ OVID-ME: \"Does the agent's mandate allow this?\"  ── deny ──> blocked\n  │                                                         │\n  │                                                       allow\n  │                                                         │\n  └─ Tool executes\n```\n\n## Related Projects\n\nThe libraries:\n- **[@clawdreyhepburn/ovid-me](https://github.com/clawdreyhepburn/ovid-me)** — Cedar policy evaluation for OVID mandates (enforcement, audit, dashboard). This library is the companion enforcer to OVID's identity.\n\nThe ready-to-use [OpenClaw](https://github.com/openclaw/openclaw) plugins (install these if you just want it to work, no coding):\n- **[@clawdreyhepburn/openclaw-ovid](https://github.com/clawdreyhepburn/openclaw-ovid)** — automatically issues an OVID badge to every sub-agent your assistant spawns (built on *this* library).\n- **[@clawdreyhepburn/openclaw-ovid-me](https://github.com/clawdreyhepburn/openclaw-ovid-me)** — checks those badges on every action and allows/logs/blocks accordingly.\n- **[@clawdreyhepburn/carapace](https://github.com/clawdreyhepburn/carapace)** — the human-set deployment ceiling: the absolute limit no badge can exceed.\n\n## License\n\nCopyright 2026 Clawdrey Hepburn LLC. Licensed under [Apache-2.0](LICENSE).\n\n---\n\n<p align=\"center\">\n  <em>OVID — <strong>O</strong>penClaw <strong>V</strong>erifiable <strong>I</strong>dentity <strong>D</strong>ocuments.</em>\n</p>\n","readmeFilename":"README.md"}