{"_id":"@concrete-security/atlas-wasm","_rev":"3-7ce3bb9cef0bf1a046effd6d4fe059fd","name":"@concrete-security/atlas-wasm","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@concrete-security/atlas-wasm","version":"0.1.0","keywords":["wasm","tls","attestation","tee","tdx","confidential-computing"],"license":"MIT","_id":"@concrete-security/atlas-wasm@0.1.0","maintainers":[{"name":"jfrery","email":"contact@concrete-security.com"}],"homepage":"https://github.com/concrete-security/atlas#readme","bugs":{"url":"https://github.com/concrete-security/atlas/issues"},"dist":{"shasum":"af5b881d1bccd4542c772c46c43acea7b000ea67","tarball":"https://registry.npmjs.org/@concrete-security/atlas-wasm/-/atlas-wasm-0.1.0.tgz","fileCount":8,"integrity":"sha512-P0KwEVKJPAvS1wX8gHlt3EeBabMFnBuMrA9Zq0pAKMyH5SM8L40wL8l0O6tNNN1fCA6angNnIsQECXZPMci4gA==","signatures":[{"sig":"MEYCIQC9CqZQ0zBMO+vZfbS/6MNsOitwB6m8B3zBBL59VDImnAIhAKicy9QK6tB1phruQ3P70BI9hGNXOXsDQCNhY4+JADqf","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2368213},"main":"ratls-fetch.js","type":"module","types":"ratls-fetch.d.ts","exports":{".":{"types":"./ratls-fetch.d.ts","import":"./ratls-fetch.js"},"./ratls_wasm":{"types":"./ratls_wasm.d.ts","import":"./ratls_wasm.js"},"./ratls-fetch":{"types":"./ratls-fetch.d.ts","import":"./ratls-fetch.js"}},"gitHead":"701fdfa4e7251e855aebfb72c43d520fd61634cf","_npmUser":{"name":"jfrery","email":"contact@concrete-security.com"},"repository":{"url":"git+https://github.com/concrete-security/atlas.git","type":"git","directory":"wasm"},"_npmVersion":"10.8.2","description":"WASM client for attested TLS (aTLS) connections to Trusted Execution Environments","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"20.19.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/atlas-wasm_0.1.0_1769512912511_0.6384276565172085","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@concrete-security/atlas-wasm","version":"0.2.0","keywords":["atls","tee","tdx","sgx","attestation","wasm","fetch","confidential-computing"],"license":"MIT","_id":"@concrete-security/atlas-wasm@0.2.0","maintainers":[{"name":"jfrery","email":"contact@concrete-security.com"}],"homepage":"https://github.com/concrete-security/atlas#readme","bugs":{"url":"https://github.com/concrete-security/atlas/issues"},"dist":{"shasum":"e4c3a75b01618aba93236a42f1a32fc30ff74494","tarball":"https://registry.npmjs.org/@concrete-security/atlas-wasm/-/atlas-wasm-0.2.0.tgz","fileCount":5,"integrity":"sha512-KU0odhjGK2j2ZVueIQji8i3koZ9wFsReXGGWGdNVCYJTJHYGMAhWVe618l/oKR6NTbFIhJckBD0vQJmHlr4drg==","signatures":[{"sig":"MEUCICRI5ui+g/+vL5gvxzT5wFc56LBxRRindFt7yYaFa2a4AiEA/0z/dtCr46UYLe7HzbEO5EfSJhU740ekSJS/Hca6vF8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@concrete-security%2fatlas-wasm@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2690450},"main":"atlas_wasm.js","type":"module","types":"atlas_wasm.d.ts","gitHead":"738800cc02cfdc3f81aed78c24d47dcacfdd14f9","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f4d6fc6d-a9d2-4c4a-a720-73c5bf83a2fc"}},"repository":{"url":"git+https://github.com/concrete-security/atlas.git","type":"git","directory":"wasm"},"_npmVersion":"11.9.0","description":"aTLS client for browsers - attested fetch for Trusted Execution Environments","directories":{},"sideEffects":["./snippets/*"],"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/atlas-wasm_0.2.0_1770370090371_0.004641403267394706","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-01-27T11:21:52.378Z","modified":"2026-05-07T09:37:53.517Z","0.1.0":"2026-01-27T11:21:52.694Z","0.2.0":"2026-02-06T09:28:10.577Z"},"bugs":{"url":"https://github.com/concrete-security/atlas/issues"},"license":"MIT","homepage":"https://github.com/concrete-security/atlas#readme","keywords":["atls","tee","tdx","sgx","attestation","wasm","fetch","confidential-computing"],"repository":{"url":"git+https://github.com/concrete-security/atlas.git","type":"git","directory":"wasm"},"description":"aTLS client for browsers - attested fetch for Trusted Execution Environments","maintainers":[{"email":"celia.kherfallah@zama.ai","name":"kcelia"},{"email":"contact@concrete-security.com","name":"jfrery"}],"readme":"# atlas-wasm\n\nattested TLS (aTLS) connections for Wasm. Connect securely to Trusted Execution Environments (TEEs) from the browser.\n\n> **For aTLS protocol details, policy configuration, and security features, see [core/README.md](../core/README.md)**\n\n## Installation\n\n```bash\nnpm install @concrete-security/atlas-wasm\n```\n\nThe package includes prebuilt WASM binaries for browser use.\n\n## Architecture\n\nThe WASM module handles **attested TLS + HTTP/1.1 protocol** (including chunked transfer encoding for streaming LLM responses).\n\n```\nBrowser (atls-fetch.js)          WASM (atlas_wasm)           Proxy              TEE\n        │                               │                       │                  │\n        │──── AtlsHttp.connect ───────►│                       │                  │\n        │                               │──── WebSocket ───────►│                  │\n        │                               │                       │──── TCP ────────►│\n        │                               │◄──── TLS handshake + attestation ───────►│\n        │◄─── attestation result ───────│                       │                  │\n        │                               │                       │                  │\n        │──── http.fetch(method,...) ──►│──── HTTP/1.1 req ────►│──── raw ────────►│\n        │◄─── {status,headers,body} ────│◄──── HTTP/1.1 res ────│◄──── raw ────────│\n```\n\nA proxy is required since the Browser/Wasm environment doesn't have a socket API. So we implement aTLS over a WebSocket-to-TCP tunnel.\n\n\n## Building from Source\n\nThe npm package includes prebuilt WASM binaries. To build from source:\n\n```bash\n# From repo root\nmake build-wasm\n```\n\n**macOS note:** Requires Clang with WebAssembly target support (Apple's Xcode clang doesn't support WASM). The build process automatically detects and uses Homebrew's LLVM if available. If you haven't installed it yet:\n\n```bash\nmake setup-wasm\nmake build-wasm\n```\n\n## API\n\n### `createAtlsFetch(options)`\n\nFetch-compatible API (HTTP handling in Rust/WASM):\n\n```javascript\nimport { init, createAtlsFetch } from \"@concrete-security/atlas-wasm\";\n\nawait init();\n\nconst fetch = createAtlsFetch({\n  proxyUrl: \"ws://127.0.0.1:9000\",\n  targetHost: \"vllm.example.com\",\n  policy: { type: \"dstack_tdx\" },  // Required: verification policy\n  onAttestation: (att) => console.log(\"TEE:\", att.teeType)\n});\n\n// Use like regular fetch\nconst response = await fetch(\"/v1/chat/completions\", {\n  method: \"POST\",\n  headers: { \"Content-Type\": \"application/json\" },\n  body: JSON.stringify({ model: \"gpt\", messages: [...] })\n});\n\nconsole.log(response.status);\nconsole.log(response.attestation); // { trusted: true, teeType: \"Tdx\", ... }\n```\n\n### Low-level: `AtlsHttp`\n\nHTTP client with streaming body support:\n\n```javascript\nimport init, { AtlsHttp } from \"@concrete-security/atlas-wasm\";\n\nawait init();\n\nconst http = await AtlsHttp.connect(\n  \"ws://127.0.0.1:9000?target=vllm.example.com:443\",\n  \"vllm.example.com\"\n);\n\nconsole.log(http.attestation()); // { trusted, teeType, tcbStatus }\n\nconst result = await http.fetch(\"POST\", \"/v1/chat/completions\", \"vllm.example.com\",\n  [[\"Content-Type\", \"application/json\"]],\n  new TextEncoder().encode('{\"model\":\"gpt\"}')\n);\n\n// result.body is a ReadableStream (handles chunked encoding automatically)\nconst reader = result.body.getReader();\n// ... stream response ...\n```\n\n### Lowest-level: `AttestedStream`\n\nDirect access to the raw attested TLS stream (no HTTP handling):\n\n```javascript\nimport init, { AttestedStream } from \"@concrete-security/atlas-wasm\";\n\nawait init();\n\nconst stream = await AttestedStream.connect(\n  \"ws://127.0.0.1:9000?target=vllm.example.com:443\",\n  \"vllm.example.com\"\n);\n\nconsole.log(stream.attestation()); // { trusted, teeType, tcbStatus }\n\nawait stream.send(new TextEncoder().encode(\"GET / HTTP/1.1\\r\\n\\r\\n\"));\nconst reader = stream.readable.getReader();\n// ... read raw response bytes ...\n```\n\n## Proxy\n\nBrowser deployments require a WebSocket-to-TCP proxy since browsers cannot make raw TCP connections.\n\n**Quick Start:**\n\n```bash\n# Required: set allowlist for security\nexport ATLS_PROXY_ALLOWLIST=\"vllm.example.com:443,other.tee.com:443\"\nexport ATLS_PROXY_LISTEN=\"127.0.0.1:9000\"\n\ncargo run -p atlas-proxy\n```\n\n**Key Points:**\n- Proxy only forwards bytes (no TLS termination)\n- All encryption and attestation verification happens in the browser\n- Allowlist is required for security (prevents SSRF attacks)\n\nFor detailed configuration, deployment patterns, and security considerations, see [proxy/README.md](proxy/README.md).\n\n## Demo\n\nA minimal browser demo is in `demo/`:\n\n```bash\n# From repo root - starts proxy + serves demo\nmake demo-wasm\n\n# Then open: http://localhost:8080/demo/minimal.html\n```\n\nThe demo shows:\n1. Connecting to a non-TEE server (google.com) fails attestation\n2. Connecting to a real TEE server succeeds with valid attestation\n\n## Policy Configuration\n\nPolicies control what attestations are accepted. Configure via the `policy` option:\n\n```javascript\nconst fetch = createAtlsFetch({\n  proxyUrl: \"ws://127.0.0.1:9000\",\n  targetHost: \"vllm.example.com\",\n  policy: {\n    type: \"dstack_tdx\",\n    allowed_tcb_status: [\"UpToDate\", \"SWHardeningNeeded\"],\n    expected_bootchain: {\n      mrtd: \"b24d3b24...\",\n      rtmr0: \"24c15e08...\",\n      rtmr1: \"6e1afb74...\",\n      rtmr2: \"89e73ced...\"\n    }\n  }\n})\n```\n\nFor complete policy field descriptions and verification flow, see [core/README.md#policy-configuration](../core/README.md#policy-configuration).\n\n## Protocol Details\n\nBrowser WASM bindings follow the same aTLS protocol as other platforms.\n\nFor detailed protocol specification and security features, see [core/README.md#protocol-specification](../core/README.md#protocol-specification).\n","readmeFilename":"README.md"}