{"_id":"@claxedo/workspace-relay-protocol","_rev":"7-ce1159436f03e97dc2587af587f9e632","name":"@claxedo/workspace-relay-protocol","dist-tags":{"latest":"0.8.0"},"versions":{"0.1.0":{"name":"@claxedo/workspace-relay-protocol","version":"0.1.0","_id":"@claxedo/workspace-relay-protocol@0.1.0","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"dist":{"shasum":"c7cc3610ff8420cfd0dd30feb5df0421344365cf","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.1.0.tgz","fileCount":4,"integrity":"sha512-+rUiLgBXplO2aTThfAy4cPNus0nZvHv0ToOPMuMA8dKYKdL0LToXzHsRcVuFAfpk+PaqqlIK6F3VQabdVrMk/w==","signatures":[{"sig":"MEUCIEmL3cT56GAN+j5kIy0euHULWmxulnz4wQFhZVRMOOUqAiEA3Nf8tWyEssk4WQxLs+5UcwqHZAfVoygv50ZmS+LiGM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":8760},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.ts","gitHead":"25db7e7a68de7a628bc53847b2db00dced45a5d5","scripts":{"test":"bun test src","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"_npmVersion":"11.12.1","directories":{},"_nodeVersion":"25.9.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.0.0","esbuild":"^0.25.0","@types/bun":"catalog:","typescript":"catalog:","@tsconfig/node-lts":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/workspace-relay-protocol_0.1.0_1779196785572_0.9336759556964349","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@claxedo/workspace-relay-protocol","version":"0.5.0","_id":"@claxedo/workspace-relay-protocol@0.5.0","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"dist":{"shasum":"ec169515309e46029cd675769c91c945f53566f8","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.5.0.tgz","fileCount":5,"integrity":"sha512-4gQ7BciEOJkoJ3nGv7mrX3wvmW+blRFlKSBResykhI85fhrxNWZHg0eip5SvqIOjpvIaC3rwnhBNA4aVpSdHOQ==","signatures":[{"sig":"MEYCIQDmAVICw7TTfipBLAdPAB9sCyyBq4zdpzGgWCHHXw00jAIhAOmM2SSs4bxwftYzGVI0xuvfEgaS6z9b+v/bjAN65eDL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66862},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.ts","exports":{".":{"bun":"./dist/index.mjs","types":"./dist/index.d.ts","import":"./dist/index.mjs","default":"./dist/index.mjs","development":"./dist/index.mjs"}},"gitHead":"76982dadead99e05f3b952bf3475da3c5dd27ef6","scripts":{"test":"bun test src","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"_npmVersion":"10.9.8","description":"Shared wire types and token-verifier contracts for Claxedo workspace relay traffic. This package intentionally has no Hono, Bun, or server dependency so workspace hosts and non-Node clients can validate tunnel frames without pulling in the relay implement","directories":{},"_nodeVersion":"22.22.3","dependencies":{"jose":"6.0.11"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.22.3","esbuild":"0.25.12","@types/bun":"1.3.13","typescript":"5.8.2","@tsconfig/node-lts":"22.0.4"},"_npmOperationalInternal":{"tmp":"tmp/workspace-relay-protocol_0.5.0_1782924815795_0.7206351483056963","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@claxedo/workspace-relay-protocol","version":"0.5.1","_id":"@claxedo/workspace-relay-protocol@0.5.1","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"dist":{"shasum":"5aacdf2918b66f92fbb2f4aa68b656a248f9bddb","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.5.1.tgz","fileCount":5,"integrity":"sha512-1BOq9IEiXQJOFJax/wwMe7G/4cyCDougrqANeOmTiI781cJdJ1zS5ka6G5+VN4gRjQHgLI5VEWu8QYU278LMsg==","signatures":[{"sig":"MEYCIQC76bvA23V49pH2RcaifNCZebC1iHuU/wjYTTeelI+dHgIhALTwwUO+oVMaBqGl41jcZ7D959CShC8LQkXyxllR/6M3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":66862},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.ts","exports":{".":{"bun":"./dist/index.mjs","types":"./dist/index.d.ts","import":"./dist/index.mjs","default":"./dist/index.mjs","development":"./dist/index.mjs"}},"gitHead":"76982dadead99e05f3b952bf3475da3c5dd27ef6","scripts":{"test":"bun test src","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"_npmVersion":"10.9.8","description":"Shared wire types and token-verifier contracts for Claxedo workspace relay traffic. This package intentionally has no Hono, Bun, or server dependency so workspace hosts and non-Node clients can validate tunnel frames without pulling in the relay implement","directories":{},"_nodeVersion":"22.22.3","dependencies":{"jose":"6.0.11"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.22.3","esbuild":"0.25.12","@types/bun":"1.3.13","typescript":"5.8.2","@tsconfig/node-lts":"22.0.4"},"_npmOperationalInternal":{"tmp":"tmp/workspace-relay-protocol_0.5.1_1782925025398_0.4760036878888063","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@claxedo/workspace-relay-protocol","version":"0.5.2","keywords":["claxedo","relay","tunnel","protocol"],"license":"MIT","_id":"@claxedo/workspace-relay-protocol@0.5.2","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"homepage":"https://github.com/kyashrathore/Claxedo#readme","bugs":{"url":"https://github.com/kyashrathore/Claxedo/issues"},"dist":{"shasum":"41584beb8bda3af4102179fc446c223f6cd68b4b","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.5.2.tgz","fileCount":6,"integrity":"sha512-9JIZOfIxhsJxVqLHj+0UhJ9seWrLI0YmS9RjPypeM4Y9Sjwz25aPX05RZMm5sfDFr+dZeg1JZOKJA+kEGbNpGA==","signatures":[{"sig":"MEUCIQDINIqswZ/whkekSW4Mk3sfmbiqRMSiTSCz4KFAw3de9gIgNH1IFy7Li6/I/RnEKJgJPziTSBWW+XZtYMmOZvdx45c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25126},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.ts","exports":{".":{"bun":"./dist/index.mjs","types":"./dist/index.d.ts","import":"./dist/index.mjs","default":"./dist/index.mjs","development":"./dist/index.mjs"}},"gitHead":"689fe2da7c48b9a1eb894146840413577e25e3e1","scripts":{"test":"bun test src","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"repository":{"url":"git+https://github.com/kyashrathore/Claxedo.git","type":"git","directory":"packages/workspace-relay-protocol"},"_npmVersion":"10.9.8","description":"Wire types, message validation, and token verifier interfaces for the Claxedo workspace relay tunnel protocol","directories":{},"_nodeVersion":"22.22.3","dependencies":{"jose":"6.0.11"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.22.3","esbuild":"0.25.12","@types/bun":"1.3.13","typescript":"catalog:","@tsconfig/node-lts":"22.0.4"},"_npmOperationalInternal":{"tmp":"tmp/workspace-relay-protocol_0.5.2_1784389207132_0.38073878382994164","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@claxedo/workspace-relay-protocol","version":"0.6.0","keywords":["claxedo","relay","tunnel","protocol"],"license":"MIT","_id":"@claxedo/workspace-relay-protocol@0.6.0","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"homepage":"https://github.com/kyashrathore/Claxedo#readme","bugs":{"url":"https://github.com/kyashrathore/Claxedo/issues"},"dist":{"shasum":"b2f7c7220589aa1a5e9e424b0cb812033fa7415f","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.6.0.tgz","fileCount":6,"integrity":"sha512-QHSMqckoRhZPNgJn9cKVWAEwq2wxcx5gywO4KXu7nn5XcKLu8+G8qB4kx7htKM9lu5T+zj1HXU5xneVUFpDXWQ==","signatures":[{"sig":"MEUCIBK4mt5dr0rxsvFYCaiSqND1kyUb+aa693ZB4NTZXlSnAiEAha8LgGNAQ1Ztrpc/ZYFlgyKzzFKzGegaAUcMlZxDG+A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25126},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.ts","exports":{".":{"bun":"./dist/index.mjs","types":"./dist/index.d.ts","import":"./dist/index.mjs","default":"./dist/index.mjs","development":"./dist/index.mjs"}},"gitHead":"3437f51de5ae445f0e88add1b95f9428ddcce4c6","scripts":{"test":"bun test src","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"repository":{"url":"git+https://github.com/kyashrathore/Claxedo.git","type":"git","directory":"packages/workspace-relay-protocol"},"_npmVersion":"10.9.8","description":"Wire types, message validation, and token verifier interfaces for the Claxedo workspace relay tunnel protocol","directories":{},"_nodeVersion":"22.22.3","dependencies":{"jose":"6.0.11"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.22.3","esbuild":"0.25.12","@types/bun":"1.3.13","typescript":"catalog:","@tsconfig/node-lts":"22.0.4"},"_npmOperationalInternal":{"tmp":"tmp/workspace-relay-protocol_0.6.0_1784556745901_0.054795325053472954","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@claxedo/workspace-relay-protocol","version":"0.7.0","keywords":["claxedo","relay","tunnel","protocol"],"license":"MIT","_id":"@claxedo/workspace-relay-protocol@0.7.0","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"homepage":"https://github.com/kyashrathore/Claxedo#readme","bugs":{"url":"https://github.com/kyashrathore/Claxedo/issues"},"dist":{"shasum":"cc830421dcd2b2c978bf2b153064192e69a93d98","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.7.0.tgz","fileCount":6,"integrity":"sha512-mLcESmyPgT0YZOuxW9mTBO5KJQFWNA2OcryG8JghnYF0C9uGKZXma56RHRGa5jm07/8JeoS/2nwiem6PHoZsKQ==","signatures":[{"sig":"MEUCID7iGz/u+bh1pcfDtNkKNfAHM/bU64Qzj4SIZzdbh6O+AiEAp3tU1xanaJ3a6iVsKbKPRXMyRpfk13h/AbBy1GZAfV0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@claxedo%2fworkspace-relay-protocol@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":25293},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.ts","exports":{".":{"bun":"./dist/index.mjs","types":"./dist/index.d.ts","import":"./dist/index.mjs","default":"./dist/index.mjs","development":"./dist/index.mjs"}},"gitHead":"eff8f2bf1d4c99bd1afdc0f269ff4f5d427fc872","scripts":{"test":"mkdir -p .artifacts/unit && bun test src --reporter=junit --reporter-outfile=.artifacts/unit/junit.xml","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"repository":{"url":"git+https://github.com/kyashrathore/Claxedo.git","type":"git","directory":"packages/workspace-relay-protocol"},"_npmVersion":"10.9.8","description":"Wire types, message validation, and token verifier interfaces for the Claxedo workspace relay tunnel protocol","directories":{},"_nodeVersion":"22.23.1","dependencies":{"jose":"6.0.11"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.22.3","esbuild":"0.25.12","@types/bun":"1.3.13","typescript":"catalog:","@tsconfig/node-lts":"22.0.4"},"_npmOperationalInternal":{"tmp":"tmp/workspace-relay-protocol_0.7.0_1785430360121_0.4128112630349672","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"_id":"@claxedo/workspace-relay-protocol@0.8.0","bugs":{"url":"https://github.com/kyashrathore/Claxedo/issues"},"dist":{"shasum":"5b4dbf0ea380769b3d60892b5e17af548c29e248","tarball":"https://registry.npmjs.org/@claxedo/workspace-relay-protocol/-/workspace-relay-protocol-0.8.0.tgz","fileCount":6,"integrity":"sha512-Wp5IqpF3oAr5dDl6/BmU7aWDLXAmNG1Vw0hlVvZIK5Aotw2vS4Y/iBJJGkXe8B7lsfOKG9FYRqxbeq3FvcFZcA==","signatures":[{"sig":"MEYCIQDwoL7VjI72gF6Mt9mCTk8TQV6M3ShHldwK1P5vZazJ7gIhAIylh+Cw+x5TmqV/NOf02k+FepGgHkvC7hN4OQV15Td2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIH8Klx057jJlacdUOSbxapKwHGA+RA5qxt0QRa8nR4pDAiEA6IIVnB3BtYQOFOcOSmuuFeYRjFcMkqt1FGk75a3IZx0="}],"unpackedSize":26620},"main":"./dist/index.mjs","name":"@claxedo/workspace-relay-protocol","type":"module","types":"./dist/index.d.ts","exports":{".":{"bun":"./src/index.ts","types":"./dist/index.d.ts","import":"./dist/index.mjs","default":"./dist/index.mjs","development":"./src/index.ts"}},"license":"MIT","scripts":{"test":"mkdir -p .artifacts/unit && node ../../scripts/test-deadline.mjs bun test src --reporter=junit --reporter-outfile=.artifacts/unit/junit.xml","build":"tsx scripts/build.ts","typecheck":"tsc --noEmit -p tsconfig.json","prepublishOnly":"npm run build"},"version":"0.8.0","_npmUser":{"name":"kyashrathore","email":"kanusdlp@gmail.com"},"homepage":"https://github.com/kyashrathore/Claxedo#readme","keywords":["claxedo","relay","tunnel","protocol"],"repository":{"url":"git+https://github.com/kyashrathore/Claxedo.git","type":"git","directory":"packages/workspace-relay-protocol"},"_npmVersion":"11.19.0","description":"Wire types, message validation, and token verifier interfaces for the Claxedo workspace relay tunnel protocol","directories":{},"maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"_nodeVersion":"26.8.1","dependencies":{"jose":"6.0.11","@claxedo/helpers":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"4.22.3","esbuild":"0.25.12","@types/bun":"1.3.13","typescript":"catalog:","@tsconfig/node-lts":"22.0.4"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/workspace-relay-protocol_0.8.0_1789461897989_0.5414970002371211"}}},"time":{"created":"2026-05-19T13:19:45.488Z","modified":"2026-09-15T08:44:58.252Z","0.1.0":"2026-05-19T13:19:45.721Z","0.5.0":"2026-07-01T16:53:35.945Z","0.5.1":"2026-07-01T16:57:05.528Z","0.5.2":"2026-07-18T15:40:07.271Z","0.6.0":"2026-07-20T14:12:26.095Z","0.7.0":"2026-07-30T16:52:40.285Z","0.8.0":"2026-09-15T08:44:58.071Z"},"bugs":{"url":"https://github.com/kyashrathore/Claxedo/issues"},"license":"MIT","homepage":"https://github.com/kyashrathore/Claxedo#readme","keywords":["claxedo","relay","tunnel","protocol"],"repository":{"url":"git+https://github.com/kyashrathore/Claxedo.git","type":"git","directory":"packages/workspace-relay-protocol"},"description":"Wire types, message validation, and token verifier interfaces for the Claxedo workspace relay tunnel protocol","maintainers":[{"name":"kyashrathore","email":"kanusdlp@gmail.com"}],"readme":"# `@claxedo/workspace-relay-protocol`\n\nShared wire types and token-verifier contracts for Claxedo workspace relay\ntraffic. This package intentionally has no Hono, Bun, or server dependency so\nworkspace hosts and non-Node clients can validate tunnel frames without pulling\nin the relay implementation.\n\n## Install\n\n```sh\nnpm install @claxedo/workspace-relay-protocol\n```\n\n## Quickstart\n\n```ts\nimport { createStaticTokenVerifier, isTunnelMessage, validateTunnelMessage } from \"@claxedo/workspace-relay-protocol\"\n\n// Validate an inbound tunnel frame before acting on it.\nconst result = validateTunnelMessage(JSON.parse(rawFrame))\nif (!result.ok) {\n  throw new Error(`invalid tunnel frame: ${result.reason}`)\n}\n// result.message is a narrowed TunnelMessage here.\n\n// Or use the boolean type guard when you just need a filter.\nconst frames = incoming.filter(isTunnelMessage)\n\n// A fixed token table for tests and single-tenant self-hosted deployments.\nconst verifier = createStaticTokenVerifier({\n  tokens: {\n    \"test-token\": {\n      subject: \"workspace-abc\",\n      scopes: [\"relay:connect\"],\n      claims: {\n        iss: \"claxedo-test\",\n        aud: \"workspace-relay\",\n        sub: \"workspace-abc\",\n        workspace_id: \"workspace-abc\",\n        host_id: \"host-1\",\n        exp: Math.floor(Date.now() / 1000) + 3600,\n        iat: Math.floor(Date.now() / 1000),\n        jti: \"jti-1\",\n      },\n    },\n  },\n})\nconst claims = await verifier.verify(\"test-token\")\n```\n\n## Public Surface\n\n| Export | Stability | Purpose |\n| --- | --- | --- |\n| `TUNNEL_PROTOCOL_VERSION` | Stable | Current tunnel protocol version. |\n| `TunnelMessage` and message subtypes | Stable | Discriminated union for HTTP, WebSocket, heartbeat, host-registration, flow-control, and error frames. |\n| `TunnelHostRegistrationUpdate` / `\"host.registration.update\"` | Stable | Frame a host sends to update the set of workspace IDs it serves and its auth token. |\n| `validateTunnelMessage`, `isTunnelMessage` | Stable | Runtime validation for protocol, message type, and per-message payload shape. |\n| `TunnelMessageValidation` | Stable | Result type returned by `validateTunnelMessage` — `{ ok: true, message }` or a typed failure (`protocol_mismatch` / `invalid`). |\n| `makeTunnelPing`, `makeTunnelPong` | Stable | Helpers for heartbeat requests and replies. |\n| `TokenVerifier` and claim types | Stable | Narrow verifier interface shared by relay/runtime boundaries. |\n| `RelayHostVerifierClaims` (incl. `role`) | Stable | Claims shape for host-side verification: org, `role` (`viewer` \\| `editor` \\| `admin` \\| `owner`), and cloud/user-hosted backing discriminant. |\n| `createOidcTokenVerifier` | Public beta | Verifies session JWTs with issuer, audience, JWKS, and algorithm constraints. |\n| `createHttpTokenVerifier` | Public beta | Calls an operator-controlled verifier endpoint over HTTP. |\n| `createStaticTokenVerifier` | Test/single-tenant only | Fixed token table for tests and isolated self-hosted deployments. |\n\n## Tunnel Validation\n\n`validateTunnelMessage(input)` rejects:\n\n- non-objects;\n- protocol mismatches;\n- unknown message types;\n- missing required fields for the selected message type;\n- malformed header maps;\n- invalid base64 fields;\n- invalid HTTP status or WebSocket close-code fields.\n\nThe validator allows extra object fields for forward-compatible metadata, but\nconsumers should ignore fields they do not understand.\n\n## Token Verifiers\n\n`TokenVerifier` is deliberately small:\n\n```ts\nexport type TokenVerifier<TClaims extends Record<string, unknown> = Record<string, unknown>> = {\n  verify(token: string): Promise<TokenClaims<TClaims>>\n}\n```\n\nVerifier implementations own issuer checks, audience checks, key selection,\nexpiry, replay policy, and any revocation/introspection calls. Relay and\nruntime packages validate the returned claims again at their own boundaries.\n\n### HTTP Verifier Endpoint\n\n`createHttpTokenVerifier({ endpoint })` posts `{ token }` to the configured\nendpoint and expects `{ subject, scopes?, claims }` back. The endpoint is a\ntrusted operator configuration value. Do not derive it from a request, tenant\nrecord, query string, workspace config, or other user-controlled input.\n\nThe endpoint should normally be an HTTPS URL on infrastructure you control. It\nmust enforce issuer, audience, expiry, key selection, and replay/revocation\npolicy before returning claims. Treat a compromised verifier endpoint as\nequivalent to a compromised token issuer.\n\n### Static Verifier\n\n`createStaticTokenVerifier` is for tests, local demos, and isolated\nsingle-tenant deployments where tokens are provisioned out of band. It is not a\nmulti-tenant production verifier because it has no issuer rotation, expiry\nenforcement, replay cache, or revocation source unless the caller adds those\noutside the static table.\n\n## Compatibility Policy\n\nThe current wire version is `1`. Patch and minor releases may add optional\nfields to existing message objects. They must not change the meaning or type of\nexisting fields within the same protocol version.\n\nBreaking message changes require a new `TUNNEL_PROTOCOL_VERSION`. Relays and\nhosts should reject unsupported protocol versions with a protocol-mismatch\nerror instead of trying to coerce frames across versions.\n","readmeFilename":"README.md"}