{"_id":"@cowdao-grants/cow-sdk-wasm","_rev":"2-17fd5e16be9d213b22e1cedfd0bbda06","name":"@cowdao-grants/cow-sdk-wasm","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@cowdao-grants/cow-sdk-wasm","version":"0.1.0","license":"GPL-3.0-or-later","_id":"@cowdao-grants/cow-sdk-wasm@0.1.0","maintainers":[{"name":"rpunkt","email":"jose@bleu.studio"}],"homepage":"https://github.com/cowdao-grants/cow-rs#readme","bugs":{"url":"https://github.com/cowdao-grants/cow-rs/issues"},"dist":{"shasum":"c25cbb64485707a0153befb7e8fdab8dade2e93e","tarball":"https://registry.npmjs.org/@cowdao-grants/cow-sdk-wasm/-/cow-sdk-wasm-0.1.0.tgz","fileCount":10,"integrity":"sha512-8Jic8nZuzq6l3HKO2+EvR7jzxLNpcDhUEGRXSn1D8+MXd7rEXLPdEGXo+nRdO9itAsvYE43+oZh+XTjeVLC7yg==","signatures":[{"sig":"MEYCIQDj2U1eW8N2WZ6ZlrxY8UxES8dtW/vuRG7XE8FD1gTxrQIhAK8TnxYy1Xm9voLoRJliDt2Sqg6xiYZt0Gb94Cmr3g4t","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":954384},"main":"./nodejs/cow_sdk_wasm.cjs","type":"module","types":"./cow_sdk_wasm.d.ts","module":"./web/cow_sdk_wasm.js","browser":"./web/cow_sdk_wasm.js","exports":{".":{"node":"./nodejs/cow_sdk_wasm.cjs","types":"./cow_sdk_wasm.d.ts","browser":"./web/cow_sdk_wasm.js","default":"./bundler/cow_sdk_wasm.js"},"./cow_sdk_wasm_bg.wasm":"./cow_sdk_wasm_bg.wasm"},"gitHead":"da0b59562276f69ba71f389457847b2f9a49f7d4","_npmUser":{"name":"rpunkt","email":"jose@bleu.studio"},"repository":{"url":"git+https://github.com/cowdao-grants/cow-rs.git","type":"git"},"_npmVersion":"11.16.0","description":"JavaScript bindings for the cowprotocol Rust SDK. Publishes to npm as @cowdao-grants/cow-sdk-wasm; not published to crates.io.","directories":{},"sideEffects":false,"_nodeVersion":"24.11.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/cow-sdk-wasm_0.1.0_1782781751418_0.020672610144642167","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-06-30T01:09:11.244Z","modified":"2026-06-30T05:20:58.548Z","0.1.0":"2026-06-30T01:09:11.599Z"},"bugs":{"url":"https://github.com/cowdao-grants/cow-rs/issues"},"license":"GPL-3.0-or-later","homepage":"https://github.com/cowdao-grants/cow-rs#readme","repository":{"url":"git+https://github.com/cowdao-grants/cow-rs.git","type":"git"},"description":"JavaScript bindings for the cowprotocol Rust SDK. Publishes to npm as @cowdao-grants/cow-sdk-wasm; not published to crates.io.","maintainers":[{"email":"mfw78@nullis.xyz","name":"mfw78"},{"email":"jose@bleu.studio","name":"rpunkt"}],"readme":"# cow-sdk-wasm\n\nRust source for the `@cowdao-grants/cow-sdk-wasm` npm package: a thin\n`wasm-bindgen` shim that exposes the `cowprotocol` SDK to JavaScript\ncallers.\n\nPublished to npm as `@cowdao-grants/cow-sdk-wasm`. Not published to\ncrates.io.\n\n## Status\n\nAlpha. The exported functions mirror the cow-py / cow-sdk feature set\nwe considered most useful for browser and Node consumers, but the\nbinding is young and the API may evolve before a 1.0.\n\n## Quick example\n\n```js\nimport init, {\n  chain_info,\n  get_quote_simple,\n  order_uid,\n} from '@cowdao-grants/cow-sdk-wasm';\n\nawait init();\n\nconst info = chain_info('mainnet');\nconsole.log(info.settlement, info.orderbookBaseUrl);\n\nconst { response, uid } = await get_quote_simple(\n  'mainnet',\n  '0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48', // USDC\n  '0x6B175474E89094C44Da98b954EedeAC495271d0F', // DAI\n  '0x70997970C51812dc3A010C7d01b50e0d17dc79C8',\n  '100000000',\n);\n```\n\nSee `test-harness/index.html` in the repository root for a complete\nend-to-end example running against the live orderbook.\n\n## Submit an order with your own wallet\n\nThe wasm shim never holds private keys in the default build. The\ntypical flow is: quote on this side, sign with `viem` /\n`window.ethereum` / Safe, submit on this side. The orderbook attributes\nthe order back to this SDK because every exported helper that hashes\napp-data carries the `appCode: \"cow-rs-wasm\"` tag plus this package's\nversion in `metadata.quote.version`.\n\n```js\nimport init, {\n  get_quote,\n  to_signed_order_data,\n  eip712_payload,\n  build_order_creation,\n  post_order,\n  sdk_app_data_json,\n  sdk_app_data_hash,\n} from '@cowdao-grants/cow-sdk-wasm';\nimport { createWalletClient, custom } from 'viem';\nimport { base } from 'viem/chains';\n\nawait init();\n\nconst account = '0x26394373F96950025DA55b07809c976a4768c995';\n\n// 1. Quote. The shim cross-checks the response against the request\n//    before returning, so a hostile orderbook cannot hand us a swapped\n//    sellToken / buyToken / receiver / from / kind to feed downstream.\nconst request = {\n  sellToken: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913', // USDC on Base\n  buyToken:  '0xEeeeeEeeeEeEeeEeEeEeeEEEeeeeEeeeeeeeEEeE', // ETH placeholder\n  from:      account,\n  kind:      'sell',\n  sellAmountBeforeFee: '25000000', // 25 USDC, 6 decimals\n};\nconst response = await get_quote('base', request);\n\n// 2. Build this SDK's attribution app-data so the orderbook indexer\n//    can count the order. Pure compute, no network.\nconst appDataJson = sdk_app_data_json();   // canonical JSON string\nconst appDataHash = sdk_app_data_hash();   // keccak256 hex\n\n// 3. Project the response into the 12-field OrderData the wallet will\n//    sign. `to_signed_order_data` is the only blessed assembly path:\n//    it re-validates the response against `request` (now also against\n//    the pinned appData hash) and refuses to project mismatched\n//    fields, so a swapped-token response never reaches `signTypedData`.\nconst orderData = to_signed_order_data(request, response, appDataHash);\n\n// 4. Ask the SDK for the EIP-712 typed-data envelope; sign it with\n//    whatever wallet you have. viem returns a 0x-prefixed 65-byte hex.\nconst typedData = eip712_payload(orderData, 'base');\nconst wallet = createWalletClient({\n  chain: base,\n  transport: custom(window.ethereum),\n});\nconst signatureHex = await wallet.signTypedData({\n  account,\n  ...typedData,\n});\n\n// 5. Unpack (r, s, v) for build_order_creation. The orderbook expects\n//    the bytes split out from the 0x{r}{s}{v} hex blob.\nconst r = '0x' + signatureHex.slice(2, 66);\nconst s = '0x' + signatureHex.slice(66, 130);\nconst v = parseInt(signatureHex.slice(130, 132), 16);\n\nconst creation = build_order_creation(\n  orderData,\n  { signingScheme: 'eip712', r, s, v },\n  account,\n  'base', // chain: selects the EIP-712 domain used for owner recovery\n  appDataJson, // PUT against /api/v1/app_data/{hash} by the orderbook\n  response.id, // quote_id for solver fee accounting\n);\n\n// 6. POST /api/v1/orders. Returns the assigned 56-byte UID.\nconst uid = await post_order('base', creation);\nconsole.log(`https://explorer.cow.fi/base/orders/${uid}`);\n```\n\nFor ethers v6 the signing block is the same shape — call\n`signer.signTypedData(typedData.domain, typedData.types, typedData.message)`\nand slice the result the same way.\n\nIf you want the SDK to hold the private key in wasm linear memory (for\ntests, scripts, or local replays), build with the `in_shim_signing`\ncargo feature and replace step 4 with one of `sign_eip712` /\n`sign_ethsign`. The default build leaves those off so the shipped\n`.wasm` stays slim.\n\n## Cargo features\n\n| Feature | Default | What it adds |\n| --- | --- | --- |\n| `in_shim_signing` | off | Exports `sign_eip712`, `sign_ethsign`, `cancel_order_signed`. Pulls in `alloy-signer-local` so the shim can accept a private-key hex string and produce signatures inside wasm linear memory. Adds ~80–120 KB to the wasm binary. |\n\nProduction integrations sign with viem / ethers / Safe outside the wasm\nboundary and feed the `(r, s, v)` triple back through `build_order_creation`.\nFor tests, scripts, or browser playgrounds where private keys already\nexist in JS memory, enabling `in_shim_signing` is convenient.\n\n## Build targets\n\nThree wasm-pack targets, all built via the workspace `justfile`:\n\n```sh\njust wasm-build-web      # ES modules; what the test-harness uses\njust wasm-build-bundler  # webpack / Vite / Rollup\njust wasm-build-nodejs   # Node 18+ CommonJS\njust wasm-build-all      # all three\njust wasm-size           # build all three, then print .wasm byte sizes\n```\n\nEach lands in its own `pkg-{web,bundler,nodejs}/` directory under\n`crates/cow-sdk-wasm/`, all of which are git-ignored.\n\n## Publishing to npm (maintainer flow)\n\nThe crate is configured to publish under the `@cowdao-grants` npm scope.\nThe Cargo `version` in `crates/cow-sdk-wasm/Cargo.toml` is the source of\ntruth; `wasm-pack` propagates it into the generated `package.json`.\n\n```sh\n# 1. Bump version in crates/cow-sdk-wasm/Cargo.toml.\n# 2. Build each target you want to publish.\njust wasm-build-all\n\n# 3. Pick a target's pkg directory (usually pkg-bundler for general use)\n#    and publish.\ncd crates/cow-sdk-wasm/pkg-bundler\nnpm publish --access public\n```\n\n`wasm-pack publish` also works if you prefer one command; it accepts the\nsame `--scope cowdao-grants` flag the build commands use.\n\n## Why is the crate name `cow-sdk-wasm` and not `cowprotocol-wasm`?\n\nThe Rust crate on crates.io is `cowprotocol`. The npm equivalent at\n`@cowprotocol/cow-sdk` is the TypeScript SDK maintained by the\ncowprotocol organisation. To avoid name collisions and signal that this\nis a community-built wasm binding, the npm package uses\n`@cowdao-grants/cow-sdk-wasm` (under the grants org, where the parent\nrepository lives) and the Cargo crate matches.\n","readmeFilename":"README.md"}