{"_id":"@dankest-llc/xchain-sdk","_rev":"20-8bf8f2df0bdc718841ae562b72786324","name":"@dankest-llc/xchain-sdk","dist-tags":{"latest":"0.21.3"},"versions":{"2.0.0":{"name":"@dankest-llc/xchain-sdk","version":"2.0.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@2.0.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://github.com/XChain-platform/xchain-sdk#readme","bugs":{"url":"https://github.com/XChain-platform/xchain-sdk/issues"},"dist":{"shasum":"bb3791987a45993cbc85f38d54074a9dd8a1b550","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-2.0.0.tgz","fileCount":114,"integrity":"sha512-hjQJmW+DhEYK48v6F8mqfsRK2oUn+QGKlGBdHI+FhS9XDnd9rUKXv8sGHBXA510XNz/bSykVU/graIxuK7M9bw==","signatures":[{"sig":"MEYCIQC81pkh9AmDqOIr2l7vuP0UDsHQgLiyzr44guxurVEp5gIhAOsua3NaPIAFPsEmF+kUK3cCq1MbZ94FuA+RmERbW3b5","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1760128},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"f2c50e56318ec427d2d2ed2a1ba64cd7dc2e13ae","scripts":{"ci":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","cosigner:init-window":"node scripts/cosigner-init-window.js"},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.0","fast-uri":"^3.1.4","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","shell-quote":"^1.9.0","brace-expansion":"^5.0.8","serialize-javascript":"^7.0.5"},"deprecated":"superseded by the platform version stream; install 0.10.0 or later","repository":{"url":"git+https://github.com/XChain-platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_2.0.0_1785612042540_0.11688813604947978","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"name":"@dankest-llc/xchain-sdk","version":"2.0.1","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@2.0.1","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://github.com/XChain-platform/xchain-sdk#readme","bugs":{"url":"https://github.com/XChain-platform/xchain-sdk/issues"},"dist":{"shasum":"9699a4ca4b331a5ba5d672eeec43bcc23830fdc3","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-2.0.1.tgz","fileCount":114,"integrity":"sha512-EmGKB7YvgpKi5zZ1L2JRyWTPSI3mvzH8+Oe8r7NRJrOj9XGaBfptTjALDO1r+7FeYs0XUfz5mujBF9d27RSGkg==","signatures":[{"sig":"MEUCIBDoXn5O1PlVbsAYN+/6dUJ68VfWMmhzyeLPHZEt5z84AiEAu5Mk8kmgU8z6sZphYAe3rEJfuc9Ho/gBPN2pzqMtPUY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1760632},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"359a5e49321ec344f82f1bca3a90c4a4ba083a5b","scripts":{"ci":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","cosigner:init-window":"node scripts/cosigner-init-window.js"},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.0","fast-uri":"^3.1.4","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","shell-quote":"^1.9.0","brace-expansion":"^5.0.8","serialize-javascript":"^7.0.5"},"deprecated":"superseded by the platform version stream; install 0.10.0 or later","repository":{"url":"git+https://github.com/XChain-platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_2.0.1_1785614927587_0.4013518787410091","host":"s3://npm-registry-packages-npm-production"}},"2.0.2":{"name":"@dankest-llc/xchain-sdk","version":"2.0.2","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@2.0.2","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://github.com/XChain-Platform/xchain-sdk#readme","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"45ef83992b47162eafc002f396748257cf800d16","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-2.0.2.tgz","fileCount":114,"integrity":"sha512-lvHGYCiCFFSGjNDe0td69RoUnuzpvhigVhR6EB29smkDxV5GMHnImRLQrBvs3mPb6Xv7I03gGicrmb7LHPtoUg==","signatures":[{"sig":"MEYCIQCj7F48ztlBmBVC29F/7i8YvKjPf1F+ji7gIvQ/ozp93wIhAI1XX7Lbt8DPuJwxOLfiijwxxLh7uk1nqM37e90w40oh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1770718},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","cosigner:init-window":"node scripts/cosigner-init-window.js"},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.0","fast-uri":"^3.1.4","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","shell-quote":"^1.9.0","brace-expansion":"^5.0.8","serialize-javascript":"^7.0.5"},"deprecated":"superseded by the platform version stream; install 0.10.0 or later","repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_2.0.2_1785769675930_0.5672859773405117","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@dankest-llc/xchain-sdk","version":"0.10.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.10.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"59534e8164aaa0f66466a886c05b14586847deb8","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.10.0.tgz","fileCount":120,"integrity":"sha512-jWNsVPkZ6UQBUShYjz+aihIgTz922Vnq7FrTg6W5VnB80Cq6vF5oCuiDqCH38/vHb8A7gp+i3Qi/tP0VrcHeXA==","signatures":[{"sig":"MEUCIBge0N3VX/93fBBLbMcWihPagyyMA2YzqlCp68g4SoqkAiEAtoPmj9CJSe8SzB+qFcxnBbwd1sEiXaYI9WJJg2Szoq4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2108054},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.1","fast-uri":"^3.1.5","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.10.0_1787372642720_0.11878585888114546","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@dankest-llc/xchain-sdk","version":"0.11.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.11.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"79ed0139545eb4271c1a6991470b445cfcca69d1","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.11.0.tgz","fileCount":120,"integrity":"sha512-iAfSnSTxdC17CkmFM2dNyFIjahgcCPtnGg3gRE3j6sY9jqFzfTMPjSDCkDfz/iZdRO/29euIOZeFvVpoGPfonw==","signatures":[{"sig":"MEUCIQDPSBQ5N6wJxkLxpw/bOGp5Kf2bOnKtHAxdFfdZgCaaSgIgRwyXXj9GrrEsS2nnUZcojDVlEXNJ1BboxL5eAfXDcss=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2140189},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.1","fast-uri":"^3.1.5","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.11.0_1787716278461_0.31948024010499565","host":"s3://npm-registry-packages-npm-production"}},"0.11.1":{"name":"@dankest-llc/xchain-sdk","version":"0.11.1","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.11.1","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"5f5a8163f28dc6c86a38a4fe19d028116715b7bc","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.11.1.tgz","fileCount":120,"integrity":"sha512-9s3TQwFiadltaKYPo42FyR/EJUA7oUDOM+1D2FKL7tuou2i3yy3Vxs7hT2Q3aARbPe+ED/eNtyAEGQXS2HwYNw==","signatures":[{"sig":"MEUCIQDEH+1J/gtTbrEXKIv4xwA7lhiQNw4Rk/I3cH21V28uDgIgYekfJGzT7kNC5wNIXbsfFQxvYuIeHKgzRFmk88vqbXA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2160938},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"c2474aba30fff52130ac9947a4ffde4b5de4c112","scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.1","fast-uri":"^3.1.5","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.11.1_1787937325858_0.7887406065668343","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@dankest-llc/xchain-sdk","version":"0.12.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.12.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"3f95280f825910f1229049a2216673e4da51439d","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.12.0.tgz","fileCount":123,"integrity":"sha512-d7+VCrZVzeh1ek0WXjg+5dLk7Tj+SvovG9sJA+w/MSJYioPUyQNtrZ8ZnobWf6LvjqXc2ScrIuhg8NYm9uwoww==","signatures":[{"sig":"MEUCIQDF37H3AHrbLV0Xbu7i7ucv607lZb12S4IZM8xG+mTiNwIgBJoMPJAli9bOFpG/7ggGCTyZLVN0fs3QREC6d3UAaqQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2198236},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.15.2","diff":"^8.0.4","js-yaml":"^4.3.1","fast-uri":"^3.1.5","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.12.0_1788218399299_0.02583695331473579","host":"s3://npm-registry-packages-npm-production"}},"0.15.1":{"name":"@dankest-llc/xchain-sdk","version":"0.15.1","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.15.1","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"3ed7ee50ff0084db5120e9f367073885eb53b601","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.15.1.tgz","fileCount":125,"integrity":"sha512-o+FhVCsx8NB/DMIm5YmzGSK9Ke/0y6KvPKmwAdTQ0fv5YEz/L5g8Qbc8sVAjJ4OWrKrUYyiukTUdHO3feTGwHg==","signatures":[{"sig":"MEYCIQCyX0T2Kl6aCd9fChzJ7OuKsrVlBnboeU8rrAwXF03NFwIhAJAgLzPCuIkTCchSQzVxQvZo935Fwzg2FccJ2yD4/pLu","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2324443},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"ffb9a7314865376413ca62b6f8c4c9d0e5337ccf","scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.19.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.15.1_1788801999098_0.11153040361202549","host":"s3://npm-registry-packages-npm-production"}},"0.15.3":{"name":"@dankest-llc/xchain-sdk","version":"0.15.3","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.15.3","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"f38761ca650253395bb2a4655abb013fb7b5695d","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.15.3.tgz","fileCount":125,"integrity":"sha512-dhs080sbQP4DuZf3OmCHIO7SPfdm0fG+TXll3taY1cI/R1dT7LSm2A7z4mWNxfXai/QSIfqsHCP4ReU/HYbcnQ==","signatures":[{"sig":"MEUCIQCZC9b/bOY2W1uJ1nbJNYUoz57VZYxQHo/A0diepbrx4wIgEQ1lEPV+EK03ib6uAD/iTnp3IJNMPcIZ9Jm5ryLo9UU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2332391},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.19.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.15.3_1788833755042_0.10607399918741822","host":"s3://npm-registry-packages-npm-production"}},"0.16.0":{"name":"@dankest-llc/xchain-sdk","version":"0.16.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.16.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"afa0a60df06a6f0cfe4159e5c3ebca186a8c3e58","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.16.0.tgz","fileCount":125,"integrity":"sha512-BI4B7NiilMuYGOzfbS4LnjGybbAgiyoYs9IQ74ntfKN2kIxzvGb+Jll29v6XgRxfRK6zrFdsnDZhAxhFuQboHw==","signatures":[{"sig":"MEQCIAUPz6tB5/5T4uWO4PMT0qKkjY/PmFZUb3haY0HuZHsoAiAF16nfYU1OWUyC+ib3WWXIlUAzTqJpvpRt5/49JogifQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2342051},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.16.0_1788912122986_0.6412715036095413","host":"s3://npm-registry-packages-npm-production"}},"0.17.0":{"name":"@dankest-llc/xchain-sdk","version":"0.17.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.17.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"1c86ea15ee255127256f6a0b2afd1102d68cea40","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.17.0.tgz","fileCount":125,"integrity":"sha512-EZou+xN9VrsFcSFE/IDfVG8jvkDkcwpg+YD6EP+zg9tf7zl5VWF6hUVHjfnT3WHS6PqtKHE9UfHQMPdp+LtZCQ==","signatures":[{"sig":"MEUCIQDUcg9rywrIzVWW4LBsPaydWGT5V6ePtIReueh7vZfkwgIgCR90ICe+MOUKfiRlE0wv5g32KV46t5dXoJ8drrXUphU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2404805},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.19.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.17.0_1789092770973_0.19345133624949407","host":"s3://npm-registry-packages-npm-production"}},"0.18.0":{"name":"@dankest-llc/xchain-sdk","version":"0.18.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.18.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"e16c79f012ecc42107ebb3cc4c7ef8e2c8a5fb3d","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.18.0.tgz","fileCount":125,"integrity":"sha512-Miv2Tff3R6nfSkcfH7cjDbI3GvrbX5LidMpbl+1+cxnLwAFFrP8u0Ox7KbDCu/pto40sjqC49x8pHkyH9I4YzA==","signatures":[{"sig":"MEUCIQCya2jwrhsEu//2cVhSQBzsU8SlKFSB0OmeVyyjIknzgAIgav1kWBtKcTWcHSkuvud25tSvkRUgmhAqHzqrBgulrwY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2420707},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api.js","repl":"node src/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.eval.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. SKIPS clean with no sibling xchain-indexer checkout, so a single-repo clone is unaffected. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.19.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.18.0_1789220840578_0.5809977633391081","host":"s3://npm-registry-packages-npm-production"}},"0.19.0":{"name":"@dankest-llc/xchain-sdk","version":"0.19.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.19.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"b5fb9c779a8a87e1791d8293bdb36024ca343bf6","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.19.0.tgz","fileCount":260,"integrity":"sha512-lUCqEenXMaEjH/dhpUoOGsA+4PUF3PNhKaQ/68vlxGYcA4X/EG6B1XYx4xUeAOuRTbf4wnYfhEeOUDCP4q3AAw==","signatures":[{"sig":"MEYCIQDKJNUioNj5jYuFLs0fJAS02BYKZUPpJ/qVxrbn86JE4gIhAO5qg5wKMN5/67dyDQE24JAnp7Zt+3N62TZZj+xnKMCN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQD/MdkCEBx8oI/KK6w5liq6W/0MH9/bNvgAQB3UKQqqKwIhAJISmsM+lNqBnKf5qO3Yu3hYTC2ZC80CVx02RRnxbfIa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2867964},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api/index.js","lint":"eslint src test bin","repl":"node src/cli/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.test.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","comment:lint":"The file-level half of the code-style rules, from the vendored eslint.config.js. Advisory: the pre-push structure gate is what actually binds, and it depends on neither eslint nor that file.","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. FAILS when no sibling xchain-indexer checkout resolves, naming every path it tried: a clean skip there exits 0 having compared nothing, which turns a dropped checkout step into a green run. A clone that has no sibling on purpose sets XCHAIN_ALLOW_NO_INDEXER=1; CI does not need it, because .ci-siblings declares xchain-indexer. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.19.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","eslint":"^9.39.5","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.19.0_1789588459197_0.5910883140719521","host":"s3://npm-registry-packages-npm-production"}},"0.20.0":{"name":"@dankest-llc/xchain-sdk","version":"0.20.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.20.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"5c51e686873b49e2a6c87508572f2d2f8bdde226","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.20.0.tgz","fileCount":259,"integrity":"sha512-yZya1XUZ29OELOeLL5gu5cSxbhWMt7so30PzLGs1eiUqZZV1bBLFNugWhn/7UteRYeT4bUGiF8C7/LJYIqpyTQ==","signatures":[{"sig":"MEQCIFksChXyB8wpzHDkbXjKf0Fvp1uYL79pY5RQ1f1BU642AiAwKjoSH+CfcfLpIhDCn7KOATr+sAL87Opx/BONmyTGQw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQD4R31pLtsjx4QhrJtaiYyrsec777R0qNijzi/4ZS2eYwIgW8VjBHrEy3bgg4qIp/9p5v7J5WXg+lomOvs0BxGLDac=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2870751},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api/index.js","lint":"eslint src test bin","repl":"node src/cli/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.test.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","comment:lint":"The file-level half of the code-style rules, from the vendored eslint.config.js. Advisory: the pre-push structure gate is what actually binds, and it depends on neither eslint nor that file.","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. FAILS when no sibling xchain-indexer checkout resolves, naming every path it tried: a clean skip there exits 0 having compared nothing, which turns a dropped checkout step into a green run. A clone that has no sibling on purpose sets XCHAIN_ALLOW_NO_INDEXER=1; CI does not need it, because .ci-siblings declares xchain-indexer. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"dankest-llc","email":"info@dankest.llc"},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"10.9.8","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","eslint":"^9.39.5","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.20.0_1789785035608_0.9279624132196163","host":"s3://npm-registry-packages-npm-production"}},"0.20.1":{"name":"@dankest-llc/xchain-sdk","version":"0.20.1","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.20.1","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"001bc469eda6b11660d0d5b78ddd0c1ba6d89aa1","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.20.1.tgz","fileCount":259,"integrity":"sha512-e+36e0Q02k8uY7RBXbUUc3SgtpX5ojmaLdJRybYwKJpwM7HHSMmZl99svHYmeLz/NuG8vCLnWtMGrtwQcC15rQ==","signatures":[{"sig":"MEUCIQDP51qXN9hbbISDjlTekIs7ybHMzLiF7tkCZhvtCEu1pQIgHKHY31FxGESFEfOpcDDQv9hgH82p+aP98/HTqh9G0xc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIH67si0mLHfWcU6lLC+B0Bef7j8sdx0gCh6ysk46m1vyAiBeVRA64koEfmvcJS7W5BxPRokBfM2Zv5iv3YByLYHTgA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dankest-llc%2fxchain-sdk@0.20.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2890141},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"fc192852f0b86a489b45689eb940f3e710ae4e98","scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api/index.js","lint":"eslint src test bin","repl":"node src/cli/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"c8 --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:eval":"mocha --timeout 30000 --recursive 'test/eval/**/*.test.js'","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","comment:lint":"The file-level half of the code-style rules, from the vendored eslint.config.js. Advisory: the pre-push structure gate is what actually binds, and it depends on neither eslint nor that file.","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"c8 --check-coverage --lines 93.9 --statements 93.9 --branches 82.6 --functions 86.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. FAILS when no sibling xchain-indexer checkout resolves, naming every path it tried: a clean skip there exits 0 having compared nothing, which turns a dropped checkout step into a green run. A clone that has no sibling on purpose sets XCHAIN_ALLOW_NO_INDEXER=1; CI does not need it, because .ci-siblings declares xchain-indexer. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:e52b4e63-b5b9-41ed-b027-d559a5f59856"}},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.20.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","eslint":"^9.39.5","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.20.1_1790223596800_0.39179550703198096","host":"s3://npm-registry-packages-npm-production"}},"0.21.0":{"name":"@dankest-llc/xchain-sdk","version":"0.21.0","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.21.0","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"75efec1c7d2408adfb9f160b6c020dc27e7ef47e","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.21.0.tgz","fileCount":262,"integrity":"sha512-TVMTbY17qeFORdEd9/c/xYqSOz2bD16vPVdvgbRp13RhrNAR7zfmWb+iXkZuKo3gi4Dt/bWJ6+kCbTAR0D9+1w==","signatures":[{"sig":"MEUCIBbSMMUyxxyURlH8+ZhVnJJTJXGZl1mo4Lqqm24sGUvFAiEAu+lyzle20tAI+4C8l+xDuxV1+CH4GxVtWXBcGByUoL0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDXewjVem2hMA9sal/abfB4pwLL/yk7k4GZqk1pPsae0AIgHA0zszeei/HuAsdmyWJhz3G4ZV7UKE/uH6Aswa0Sd58=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dankest-llc%2fxchain-sdk@0.21.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2937935},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"6631e9ae7eac9c40e23cf24a7ef84ebfaf82131c","scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api/index.js","repl":"node src/cli/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"HOME=\"$PWD/coverage\" c8 --all --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"HOME=\"$PWD/coverage\" c8 --all --check-coverage --lines 95.2 --statements 95.2 --branches 83.5 --functions 85.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. FAILS when no sibling xchain-indexer checkout resolves, naming every path it tried: a clean skip there exits 0 having compared nothing, which turns a dropped checkout step into a green run. A clone that has no sibling on purpose sets XCHAIN_ALLOW_NO_INDEXER=1; CI does not need it, because .ci-siblings declares xchain-indexer. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"e52b4e63-b5b9-41ed-b027-d559a5f59856"}},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.20.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.18.1","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","eslint":"^9.39.5","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.21.0_1790733394181_0.7132488120646776","host":"s3://npm-registry-packages-npm-production"}},"0.21.1":{"name":"@dankest-llc/xchain-sdk","version":"0.21.1","license":"AGPL-3.0-or-later","_id":"@dankest-llc/xchain-sdk@0.21.1","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"homepage":"https://xchain.io/","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"c6887970dfd578ac9877ca68e08f496ff13b42db","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.21.1.tgz","fileCount":273,"integrity":"sha512-JI7nXnF5mFNZpbKSx8Qo1Q7miGe7D0wWRROZ6ZxrX11uH8DQlMtkFzV0BE9ET6HZtsVC80dj80dRRZ+DzfVzug==","signatures":[{"sig":"MEUCIG9V/2ULc9yq0+SWYkaAP4EuXTOZdFq6puspsYRP9fRxAiEAngYYDY/j5QqxmX3IcuAaDbss5vuL0SHO+H3o1yptlPI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIBx26tcxBD7oaB0yJpSdEAYGUcnG4RTOdTE9BrCxEYD8AiEAzhIrM6doVnvZ2/mKkoPUhDyfrgAyAMLBdqS+8venjgk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dankest-llc%2fxchain-sdk@0.21.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2987039},"main":"index.js","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"32a0593e3945dcca495dada9b12756e0341a2a29","scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api/index.js","repl":"node src/cli/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"HOME=\"$PWD/coverage\" c8 --all --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"HOME=\"$PWD/coverage\" c8 --all --check-coverage --lines 95.2 --statements 95.2 --branches 83.5 --functions 85.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. FAILS when no sibling xchain-indexer checkout resolves, naming every path it tried: a clean skip there exits 0 having compared nothing, which turns a dropped checkout step into a green run. A clone that has no sibling on purpose sets XCHAIN_ALLOW_NO_INDEXER=1; CI does not need it, because .ci-siblings declares xchain-indexer. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"e52b4e63-b5b9-41ed-b027-d559a5f59856"}},"overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.21.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.20.0","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","eslint":"^9.39.5","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"tmp":"tmp/xchain-sdk_0.21.1_1790894236371_0.9418718479269881","host":"s3://npm-registry-packages-npm-production"}},"0.21.3":{"_id":"@dankest-llc/xchain-sdk@0.21.3","bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"dist":{"shasum":"17de2e135e2fa5982da3f040531aae4d76e00fdf","tarball":"https://registry.npmjs.org/@dankest-llc/xchain-sdk/-/xchain-sdk-0.21.3.tgz","fileCount":275,"integrity":"sha512-OhlRi5cTCIaV/lmiXIF/DmND0oU1D0rBGO5ADOcaSaKDO5QnfmxSSpRjS/nOkFlIDa9tQsq+Nd/v/BFoNkHoiw==","signatures":[{"sig":"MEYCIQDIEaqt4Cn55zYQgWxJRE2apaBDChDQkMlBAePdHqT9ngIhALBBhp2ILXeOY+/ToVTn5yMvIpUKzS651ccTw0DWtKd7","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFQdCBAwYYSdT1MgkWcwXVJXe3qoTF98J4Wii37IjH0iAiEAnkslry7xx46hvhOW6HBu1tshbCzS3HUWLEo5r8HtLwM="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@dankest-llc%2fxchain-sdk@0.21.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3014901},"main":"index.js","name":"@dankest-llc/xchain-sdk","types":"index.d.ts","browser":{"@brandonblack/musig/base_crypto":"@brandonblack/musig/lib/base_crypto.js"},"engines":{"node":">=22.0.0"},"gitHead":"da0e03ddf0546f029809657ca412c953878a14b3","license":"AGPL-3.0-or-later","scripts":{"ci":"npm run ci:drift:soft && mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit && npm run ci:security && npm run ci:regression && npm run ci:drift:verdict","api":"node ./src/api/index.js","repl":"node src/cli/repl.js","test":"mocha --timeout 5000 --recursive 'test/unit/**/*.test.js'","build":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] | npx uglify-js --compress --mangle -o dist/xchain_sdk.min.js","ci:full":"bash bin/ci-full.sh","ci:drift":"node bin/check-preflight-drift.js","coverage":"HOME=\"$PWD/coverage\" c8 --all --reporter=text --reporter=html --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","test:all":"mocha --timeout 0 --recursive test/","build:dev":"npx browserify index.js -s XChainSDK -t [ babelify --presets [ @babel/preset-env ] --global ] -o dist/xchain_sdk.js","test:fuzz":"mocha --timeout 0 --recursive 'test/fuzz/**/*.test.js'","test:chaos":"mocha --timeout 10000 --recursive 'test/chaos/**/*.test.js'","test:smoke":"mocha --timeout 15000 --recursive 'test/smoke/**/*.test.js'","ci:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js' --exit","ci:drift:soft":"node bin/check-preflight-drift.js --soft","ci:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js' --exit","test:boundary":"mocha --timeout 5000 --recursive 'test/boundary/**/*.test.js'","test:security":"mocha --timeout 10000 --recursive 'test/security/**/*.test.js'","coverage:check":"HOME=\"$PWD/coverage\" c8 --all --check-coverage --lines 95.2 --statements 95.2 --branches 83.5 --functions 85.2 --reporter=text-summary --include 'src/**/*.js' mocha --timeout 5000 --recursive 'test/unit/**/*.test.js' --exit","sync:templates":"node scripts/sync-templates.js","test:regression":"mocha --timeout 30000 --recursive 'test/regression/**/*.test.js'","ci:drift:verdict":"node bin/check-preflight-drift.js --verdict","comment:ci:drift":"Pre-flight <-> indexer-handler drift gate (spec 8.5), strict: it answers what the suites structurally cannot, whether the Tier-2 mirrors still match the handlers they mirror, and exits 1 when they do not. What the CI drift jobs on both repos run, and what to run by hand. FAILS when no sibling xchain-indexer checkout resolves, naming every path it tried: a clean skip there exits 0 having compared nothing, which turns a dropped checkout step into a green run. A clone that has no sibling on purpose sets XCHAIN_ALLOW_NO_INDEXER=1; CI does not need it, because .ci-siblings declares xchain-indexer. It used to run in CI only, so a local `npm run ci` never showed it and it sat red on master unread for two weeks; the ci chain now runs it locally too, in the soft/verdict pair below.","test:integration":"mocha --timeout 30000 --recursive 'test/integration/**/*.test.js'","test:performance":"mocha --timeout 60000 --recursive 'test/performance/**/*.test.js'","release:npm-check":"node scripts/npm-sync-check.js","cosigner:init-window":"node scripts/cosigner-init-window.js","comment:ci:drift:soft":"The same gate, reporting without exiting 1. It opens the ci chain in this mode because a fatal first link would kill the run before mocha loads: no tally and no named failing test, which the shared pre-push gate reads as THE SUITE NEVER RAN, unable to tell a bad commit from a bad venue. Soft is not a waiver; ci:drift:verdict closes the chain and fails it.","comment:ci:drift:verdict":"The closing half of the pair: re-evaluates muted and exits 1 on the finding the soft run already printed, as the LAST link of ci so the failure lands after a tally exists. Muted so one run does not print the report twice.","comment:release:npm-check":"Release-ceremony gate: fails while registry.npmjs.org serves a version other than this repo's, for the SDK and for mcp/. Run as the closing act of the publish step; red means an unpublished or half-published cut. Needs network by design, so it is not part of the ci chain."},"version":"0.21.3","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"e52b4e63-b5b9-41ed-b027-d559a5f59856"}},"homepage":"https://xchain.io/","overrides":{"qs":"^6.16.0","diff":"^8.0.4","hono":"^4.13.5","js-yaml":"^4.3.1","fast-uri":"^3.1.7","form-data":"^4.0.6","minimatch":"^10.2.5","decimal.js":"10.4.3","ip-address":"^10.3.1","shell-quote":"^1.9.0","brace-expansion":"^5.0.9","serialize-javascript":"^7.0.5"},"repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"_npmVersion":"11.21.0","description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","directories":{},"maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"_nodeVersion":"22.22.3","dependencies":{"ws":"^8.21.0","zod":"^4.4.3","cors":"^2.8.5","acorn":"8.16.0","axios":"^1.20.0","bip174":"2.1.1","dotenv":"^16.4.5","ecpair":"2.1.0","helmet":"^8.2.0","mathjs":"15.2.0","astring":"1.9.0","express":"^5.2.1","acorn-walk":"8.3.5","@noble/curves":"1.9.1","@noble/hashes":"^1.8.0","bitcoinjs-lib":"6.1.7","bitcoinjs-message":"^2.2.0","@brandonblack/musig":"0.0.1-alpha.1","@bitcoinerlab/secp256k1":"^1.2.0","express-json-rpc-router":"^1.4.0","@modelcontextprotocol/sdk":"^1.29.0"},"comment:files":"Publish allowlist. Everything not listed (test/, coverage/, dist/, docs/, scripts/, bin/, mcp/, docker files) stays out of the tarball; mcp/ ships separately as the xchain-mcp package.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"comment:browser":"Browserify's resolver predates the package `exports` field, so it can't map @brandonblack/musig's './base_crypto' subpath to lib/base_crypto.js. Alias it to the concrete file for bundling only; Node still resolves the subpath via exports.","devDependencies":{"c8":"^11.0.0","chai":"^4.5.0","nock":"^14.0.0","mocha":"^11.7.5","sinon":"^21.0.3","eslint":"^9.39.5","babelify":"^10.0.0","uglify-js":"^3.19.3","browserify":"^17.0.1","@babel/core":"^7.29.0","@babel/preset-env":"^7.29.2"},"comment:homepage":"The npm package page links wherever this points, and it points at the platform site (xchain.io's deep-link backlinks 301 away to tokenscan.io, so operator-controlled touchpoints are what still build its authority).","_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/xchain-sdk_0.21.3_1791040871051_0.7656653462105008"}}},"time":{"created":"2026-08-01T19:20:42.380Z","modified":"2026-10-03T15:21:11.539Z","2.0.0":"2026-08-01T19:20:42.764Z","2.0.1":"2026-08-01T20:08:47.747Z","2.0.2":"2026-08-03T15:07:56.150Z","0.10.0":"2026-08-22T04:24:02.894Z","0.11.0":"2026-08-26T03:51:18.660Z","0.11.1":"2026-08-28T17:15:26.110Z","0.12.0":"2026-08-31T23:19:59.520Z","0.15.1":"2026-09-07T17:26:39.288Z","0.15.3":"2026-09-08T02:15:55.400Z","0.16.0":"2026-09-09T00:02:03.187Z","0.17.0":"2026-09-11T02:12:51.161Z","0.18.0":"2026-09-12T13:47:20.737Z","0.19.0":"2026-09-16T19:54:19.307Z","0.20.0":"2026-09-19T02:30:35.752Z","0.20.1":"2026-09-24T04:19:56.945Z","0.21.0":"2026-09-30T01:56:34.318Z","0.21.1":"2026-10-01T22:37:16.487Z","0.21.3":"2026-10-03T15:21:11.186Z"},"bugs":{"url":"https://github.com/XChain-Platform/xchain-sdk/issues"},"license":"AGPL-3.0-or-later","homepage":"https://xchain.io/","repository":{"url":"git+https://github.com/XChain-Platform/xchain-sdk.git","type":"git"},"description":"xchain-sdk generates XChain Platform ACTION commands and encodes them into unsigned blockchain transactions as well as pulls data from the XChain APIs such as balances and transaction history.","maintainers":[{"name":"dankest-llc","email":"info@dankest.llc"}],"readme":"<!-- SPDX-License-Identifier: AGPL-3.0-or-later -->\n<!-- Copyright © 2025-2026 Dankest, LLC -->\n\n# XChain Platform - Software Developer Kit (SDK)\n\n<p align=\"center\">\n  <img src=\"https://img.shields.io/npm/v/%40dankest-llc%2Fxchain-sdk\" alt=\"npm version\">\n  <img src=\"https://img.shields.io/badge/tests-5%2C089%2B%20passing-brightgreen\" alt=\"Tests\">\n  <img src=\"https://img.shields.io/badge/node-%3E%3D22-green\" alt=\"Node\">\n  <img src=\"https://img.shields.io/badge/license-AGPL--3.0--or--later-blue\" alt=\"License\">\n</p>\n\n<p align=\"center\">\n  <img src=\"https://img.shields.io/badge/coverage-unit%20%7C%20integration%20%7C%20boundary%20%7C%20fuzz%20%7C%20chaos%20%7C%20smoke%20%7C%20security%20%7C%20regression%20%7C%20performance-brightgreen\" alt=\"Coverage\">\n</p>\n\nDeveloper-facing SDK for the [XChain Platform](https://xchain.io/): generate XChain transactions and query blockchain data.\n\n## Features\n\n- **31 ACTION types**: `sdk.send()`, `sdk.issue()`, `sdk.mint()`, `sdk.stake()`, and 27 more convenience methods\n- **Transaction lifecycle**: `sdk.submitAction()` handles the full encode -> sign -> broadcast -> wait pipeline in one call\n- **Wallet sessions**: `sdk.session(wif)` bundles address/key/UTXO state for repeated actions from one address\n- **Fee estimation**: `sdk.estimateFees()` returns fee info without signing or broadcasting\n- **UTXO chaining**: in-memory UTXO cache prevents double-spend on rapid sequential transactions\n- **Workflow recipes**: `sdk.issueAndDistribute()`, `sdk.deployAndFund()`, `sdk.stakeAndDelegate()`, and more\n- **Cross-chain helpers**: coordinate swaps and parallel actions across BTC, LTC, and DOGE SDK instances\n- **Event-driven confirmation**: `sdk.waitForAction(txid)` resolves when the indexer processes a transaction\n- **Contract settle gate**: `sdk.waitForContractState(index, { key: 'status', equals: 'FUNDED' })` and `sdk.waitForContractBalance(index, tick, { minQuantity })` wait on the contract's own state, which is the only signal that cannot race the indexer; `submitAction({ awaitContract: {...} })` runs the same gate inline, so a deposit does not hand control back before the contract has been credited\n- **Interactive REPL**: `npm run repl` drops into a live session with a pre-configured SDK instance\n- **Automatic format selection**: picks the smallest encoding format for every action\n- **PSBT generation**: integrates with xchain-encoder to produce unsigned transactions\n- **115+ explorer query methods**: balances, tokens, transactions, markets, history, contracts\n- **Batch builder**: fluent API: `await sdk.batch().send({...}).mint({...}).build()` (`build()` is async)\n- **Real-time events**: WebSocket streaming with automatic reconnection and catch-up via `onBlock()`, `onAction()`, `onAddress()`, `onToken()`, `onMarket()`, `onDispenser()`, `onBetFeed()`, `onXcall()`, `onAttestation()`, and more; `sdk.ws` exposes the low-level client (`subscribe()`, `on()`, `listSubscriptions()`, ...) directly\n- **Encrypted messaging**: ECIES, ECDH, and AES encryption for MESSAGE actions; `messaging.send()` accepts a `Buffer` payload and `getMessages()` exposes `msg.bytes` for binary ECIES\n- **Token-gated file publishing**: `sdk.gatedFile.encryptFileBytes()` and `sdk.gatedFile.encryptPack()` produce AES-256-GCM ciphertext + key for FILE v1 gated content; key handoff as a compact 33-byte binary payload via `serializeKeyPayload()` / `parseKeyPayload()` (sent through ECIES in binary mode). See [Token-Gated Content](https://docs.xchain.io/protocol/token-gated-content)\n- **Attestation envelope helpers**: `AttestationHelpers.llm({...})` builds the JSON envelope a VM contract passes to `xchain.attestation.request(...)` with provider_id `'llm'`; `AttestationHelpers.httpGet({url})` validates the URL and returns the payload string for `'http_get'`; `AttestationHelpers.requestOptions({redundancy, deadlineBlocks})` builds the gateway options object. By design these are envelope builders only: there is no user-submittable ATTEST action. ATTEST v0 (request) and v1 (response) are VM-emitted: a contract calls `xchain.attestation.request(...)` and validators emit the on-chain attestation. So the SDK helps you shape the request a contract makes, and you read the results via `getAttestations()`. It does not (and cannot) encode an ATTEST action directly, the same way XCALL is VM-emission-only.\n- **Token-ownership trading helpers**: `ORDER`/`SWAP`/`DISPENSER` v0 carry `GIVE_OWNERSHIP` / `GET_OWNERSHIP` flags; `SWEEP` carries independent `ORDERS` / `SWAPS` / `DISPENSERS` flags (was a single `ESCROWS` flag)\n- **HTTP 402 payments**: `X402Client` and `X402Gateway` implement an XChain-native, x402-shaped pay-per-call flow over on-chain SEND actions, with `xchain-send` (pay-per-call), `xchain-dispenser` (hold-to-access), and `xchain-deposit` (metered spend ledger) schemes; fail-closed by default on `maxAmount`. See [x402 Payments](https://github.com/XChain-Platform/xchain-documentation/blob/master/protocol/x402-payments.md)\n- **Contract-targeted staking**: `session.stakeToContract({ amount, signingPubkey, targetContractIndex, tick })`, `session.unstakeFromContract({...})`, and `session.delegateForContract({...})` emit STAKE v3 / UNSTAKE v1 / DELEGATE v1 against a smart contract deployed via DEPLOY v1 (with `COOLDOWN_BLOCKS` + `SLASH_DESTINATION`). High-level recipes: `sdk.deployStakeableContract()` and `sdk.stakeToContractAndDelegate()`\n- **NFT helpers**: `sdk.nft.unique()`, `sdk.nft.edition()`, `sdk.nft.collectionItem()`, `sdk.nft.attachContentParams()`, and `sdk.nft.isNft()` for building the NFT pattern (ISSUE with DECIMALS=0 + LOCK_MAX_SUPPLY=1) plus high-level `sdk.issueNft()`, `sdk.issueNftEdition()`, `sdk.issueCollectionItem()`, and `sdk.attachContent()` submit recipes\n- **Project registry helpers**: `sdk.project.rosterParams()` and `sdk.project.rosterEditParams()` build LIST actions for owner-attested token rosters; `sdk.setRoster()` runs LIST then LINK and waits for the indexer\n- **Ticker compaction**: on by default; resolves token tickers to their compact `^id` wire form via the explorer before encoding to shrink on-chain payload size; opt out with `{ compactTickers: false }`\n- **MCP server**: `npx xchain-mcp` exposes all explorer query tools as Model Context Protocol tools for AI agent use\n- **Wallet & auth**: key management, PSBT signing, challenge-response verification\n- **Smart contracts**: deploy, execute, deposit, withdraw via xchain-vm integration\n- **Contract identity pre-flight**: a deployed contract must export `meta: { name, description, version }` (`CONTRACT_META_REQUIRED`). `sdk.deploy()`, `session.deploy()`, `session.deployChunk()`, `sdk.deployAndFund()` and `sdk.deployStakeableContract()` read it statically before the action is composed and refuse with the chain's own verdict string, so a contract the indexer will reject never costs a fee. `sdk.contracts.getExportedMeta(source)` exposes the same read\n- **Hub discovery**: auto-resolves service endpoints from xchain-hub\n- **Retry with backoff**: handles HTTP 429/502/503/504, respects `Retry-After` headers\n- **Request hooks**: `onRequest`, `onResponse`, `onError`, `onRetry` callbacks\n- **TypeScript definitions**: full `.d.ts` for IDE autocomplete\n- **Browser bundle**: Browserify build for client-side use\n\n## Documentation\n\nFull SDK developer guide is published at [docs.xchain.io/components/sdk](https://docs.xchain.io/components/sdk/):\n\n| Document | Description |\n|---|---|\n| [README](https://docs.xchain.io/components/sdk/) | Overview, installation, usage modes |\n| [Configuration](https://docs.xchain.io/components/sdk/configuration) | Constructor options, env vars, hub discovery, retry, pooling, hooks |\n| [Actions](https://docs.xchain.io/components/sdk/actions) | All 31 ACTION types: params, validation rules, format versions, examples |\n| [Transaction Lifecycle](https://docs.xchain.io/components/sdk/lifecycle) | submitAction, fee estimation, UTXO chaining, P2SH two-phase handling |\n| [Wallet Sessions](https://docs.xchain.io/components/sdk/sessions) | Bound wallet sessions, convenience methods, UTXO cache |\n| [Workflows](https://docs.xchain.io/components/sdk/workflows) | High-level recipes: issueAndDistribute, deployAndFund, stakeAndDelegate |\n| [Cross-Chain](https://docs.xchain.io/components/sdk/crosschain) | Multi-chain coordination: parallel actions, swaps, links |\n| [Explorer](https://docs.xchain.io/components/sdk/explorer) | All 115+ query methods: balances, tokens, transactions, markets |\n| [Encoder](https://docs.xchain.io/components/sdk/encoder) | PSBT generation: encoding types, options, pre-flight validation, P2SH two-phase |\n| [Batch Builder](https://docs.xchain.io/components/sdk/batch) | Fluent API for multi-action transactions |\n| [Contracts](https://docs.xchain.io/components/sdk/contracts) | VM smart contract integration: deploy, execute, deposit, withdraw |\n| [WebSocket](https://docs.xchain.io/components/sdk/websocket) | Real-time event streaming: blocks, actions, addresses, markets |\n| [Wallet & Auth](https://docs.xchain.io/components/sdk/wallet) | Key management, PSBT signing, challenge-response verification |\n| [Messaging](https://docs.xchain.io/components/sdk/messaging) | ECIES/ECDH/AES encryption for MESSAGE actions |\n| [Light Client (SPV)](https://docs.xchain.io/components/sdk/light-client) | Cryptographic balance/action verification against stake-weighted checkpoints |\n| [NFT & Registry Builders](https://docs.xchain.io/components/sdk/nft-and-registry) | NFT pattern builders, collection/content attachment, project roster LIST/LINK |\n| [Format Selection](https://docs.xchain.io/components/sdk/format-selection) | How the SDK picks the optimal format version |\n| [Errors](https://docs.xchain.io/components/sdk/errors) | All error classes, codes, and troubleshooting |\n| [Examples](https://docs.xchain.io/components/sdk/examples) | End-to-end code examples |\n\n## Install\n\n```bash\nnpm install @dankest-llc/xchain-sdk\n```\n\nNode 22 or newer. For development against the source, clone this repository and `npm install` inside it; the companion MCP server for AI agents is published separately as [`xchain-mcp`](https://www.npmjs.com/package/xchain-mcp).\n\n## Quick Start\n\n```js\nconst { XChainSDK } = require('@dankest-llc/xchain-sdk');\n\n// Zero-config: a network alone targets the public XChain Platform.\n// Mainnet/testnet default to the public hosts (hub.xchain.io discovers\n// explorer/encoder, falling back to explorer.xchain.io / encoder.xchain.io);\n// any *-regtest network defaults to localhost.\nconst sdk = new XChainSDK({ network: 'bitcoin-mainnet' });\n\n// To point at your own services, pass full URLs (include the scheme; a\n// bare host is treated as http://host:<dev-port>):\n// const sdk = new XChainSDK({\n//     network: 'bitcoin-mainnet',\n//     explorerUrl: 'https://explorer.example.com',\n//     encoderUrl:  'https://encoder.example.com'\n// });\n\n// Generate an action string\nconst result = await sdk.send({\n    tick: 'MYTOKEN',\n    amount: '100',\n    destination: 'bc1q...',\n    memo: 'Payment'\n});\nconsole.log(result.actionString); // 'SEND|0|MYTOKEN|100|bc1q...|Payment'\n\n// Multi-destination SEND: one entry per recipient. The wire format version\n// is chosen from the legs (v1 shared tick, v2 per-leg tick, v3 per-leg memo).\n// A flat {tick, amount, destination} map can only ever express ONE leg, so\n// the SDK refuses one against a multi-leg format instead of repeating leg 1.\nconst multi = await sdk.send({\n    tick: 'MYTOKEN',\n    legs: [\n        { amount: '100', destination: 'bc1qaddr1...' },\n        { amount: '250', destination: 'bc1qaddr2...' }\n    ]\n});\nconsole.log(multi.actionString); // 'SEND|1|MYTOKEN|100|bc1qaddr1...|250|bc1qaddr2...'\n\n// Full lifecycle: create, encode, sign, broadcast, wait for indexer\nconst tx = await sdk.submitAction(\n    { action: 'SEND', params: { tick: 'MYTOKEN', amount: '100', destination: 'bc1q...' } },\n    { pubkey: '02abc123...' },\n    { wif: 'your-wif-key' }\n);\nconsole.log(tx.txid);    // transaction hash\nconsole.log(tx.indexed); // action data from the indexer\n\n// Wallet session: bind to a key and send multiple actions\nconst session = sdk.session('your-wif-key');\nawait session.send({ tick: 'MYTOKEN', amount: '50', destination: 'bc1q...' });\nawait session.send({ tick: 'MYTOKEN', amount: '50', destination: 'bc1q...' });\nconst balances = await session.getBalances();\n\n// Workflow recipes: multi-step operations in one call\nawait sdk.issueAndDistribute('your-wif-key',\n    { tick: 'NEWTOKEN', maxSupply: '1000000', decimals: 8 },\n    [\n        { destination: 'bc1qaddr1...', amount: '500000' },\n        { destination: 'bc1qaddr2...', amount: '300000' }\n    ]\n);\n\n// Deploy a smart contract. Every contract must export its identity: `meta.name`\n// and `meta.description` are consensus-required (CONTRACT_META_REQUIRED), and\n// `meta.version` is optional but indexed. Use STRING LITERALS: the chain evaluates\n// `meta` at deploy, so a computed name is not what you read in the source, and the\n// pre-flight cannot check it for you.\nconst code = `module.exports = {\n    meta: {\n        name:        'Escrow',                           // 1..64 bytes\n        description: 'Two-party escrow with an arbiter', // 1..512 bytes\n        version:     '1.0.0'                             // optional, 1..32 bytes\n    },\n    permissions: ['SEND'],\n    initialize(xchain) { xchain.state.set('status', 'OPEN'); }\n};`;\nawait session.deploy({ code, gasLimit: 200000 });\n\n// A contract with no conforming meta is refused BEFORE anything is composed,\n// signed or broadcast, with the exact verdict the indexer would have written:\n//   SDKContractError: invalid: CONTRACT_MANIFEST (meta required)\n// Pass { preflight: 'warn' | 'off' } (session/workflow seams) or\n// { lint: 'warn' | 'off' } (sdk.deploy) to downgrade or skip the check; the\n// deploy is still rejected on-chain. A computed or unreadable `meta` only warns.\nsdk.contracts.getExportedMeta(code);  // { status: 'present', name: 'Escrow', ... }\n\n// Query blockchain data. The token record arrives NESTED under `info`:\nconst token = await sdk.getToken('MYTOKEN');\ntoken.info.tick_id;   // '42'   <- the fields live here\ntoken.tick_id;        // undefined\n\n// A tick that does not exist answers HTTP 404, so getToken() THROWS\n// SDKExplorerError (code EXPLORER_HTTP_404) instead of answering an empty\n// body. Use these for an existence check rather than a try/catch:\nawait sdk.tokenExists('MYTOKEN');   // true / false, never throws on absence\nawait sdk.findToken('MYTOKEN');     // the unwrapped info record, or null\n\n// Both answer \"absent\" only for the 404. A timeout, network failure, 429 or\n// 5xx still throws, because an explorer that could not answer is not proof\n// that the ticker is free.\n```\n\n## Configuration\n\n| Variable | Required | Default | Description |\n|---|---|---|---|\n| `NETWORK` | Yes | (none) | Default coin and network (e.g. `bitcoin-regtest`, `dogecoin-mainnet`) |\n| `SDK_API_PORT` | No | `3005` | Port for the optional SDK helper API |\n| `SDK_API_KEY` | No | (none) | API key for the helper API; required as `Authorization: Bearer <key>` on every method except `ping` (methods reject with 401 when unset) |\n| `CORS_ORIGIN` | No | Disabled | CORS allowed origin for the helper API |\n| `SDK_API_MAX_BATCH` | No | `20` | Maximum JSON-RPC calls in one array (batch) body. A non-numeric or non-positive value falls back to `20`; no value disables the cap |\n| `SDK_API_RATE_LIMIT` | No | `300` | Requests per window per credential (per source address when unauthenticated). A non-numeric or negative value falls back to `300`; an explicit `0` disables the limiter and is the only way to turn it off |\n| `SDK_API_RATE_WINDOW_MS` | No | `60000` | Length of the fixed rate-limit window, in milliseconds. A non-numeric or non-positive value falls back to `60000` |\n| `EXPLORER_URL` / `EXPLORER_PORT` | No | `127.0.0.1` / `8080` | xchain-explorer location |\n| `ENCODER_URL` / `ENCODER_PORT` | No | `127.0.0.1` / `3003` | xchain-encoder location |\n| `ENCODER_API_KEY` | No | (none) | API key sent as `x-api-key` to an xchain-encoder whose operator set `API_KEY`; also settable per instance as the `encoderApiKey` option. With no pinned `ENCODER_URL` it is also sent to whatever encoder host hub discovery names |\n| `HUB_URL` | No | (none) | Full xchain-hub URL |\n| `HUB_API_HOST` / `HUB_PORT` | No | (none) | xchain-hub host/port form used by some SDK paths |\n| `HUB_API_KEY` | No | (none) | API key for `getallconfigs` against keyed hubs; public zero-config discovery should use the hub's chain-registry endpoint instead |\n| `WEBSOCKET_URL` / `WEBSOCKET_PORT` | No | `127.0.0.1` / `3007` | Explorer WebSocket endpoint for live updates |\n\n## Scripts\n\n| Command | Description |\n|---|---|\n| `npm run api` | Start JSON-RPC server (port from `SDK_API_PORT`, default 3005) |\n| `npm test` | Run unit tests (4,786 tests) |\n| `npm run repl` | Start interactive REPL with a pre-configured SDK instance |\n| `npm run build` | Production browser bundle -> `dist/xchain_sdk.min.js` |\n| `npm run build:dev` | Development browser bundle -> `dist/xchain_sdk.js` |\n\n### API server module\n\n`npm run api` (`node ./src/api/index.js`) runs the JSON-RPC server as a standalone process, opening a listener on `SDK_API_PORT` at load. A consumer that wants to own the server instead, mounting it under an existing express app, choosing its own listen path, or starting and stopping it from a test, requires the module directly rather than shelling out to the script:\n\n```js\nconst { createApp, startApi } = require('@dankest-llc/xchain-sdk/src/api');\n\n// createApp(sdk) is synchronous and listener-free: it wires the same guard\n// stack (rate limit, auth gate, batch cap, /openrpc.json, JSON-RPC router)\n// as the CLI entry and returns the express app to mount yourself.\nconst app = createApp(sdk);\n\n// startApi({ port }) builds the SDK from the environment, runs hub discovery,\n// and resolves to the listening http.Server (port 0 for an ephemeral port).\nconst server = await startApi({ port: 0 });\nawait new Promise((resolve) => server.close(resolve));\n```\n\nRequiring `src/api` never opens a socket; only the CLI entry (`npm run api` / `node ./src/api/index.js`) starts listening automatically.\n\n## Test Suite\n\n| Type | Tests |\n|---|---|\n| Unit: actions, validators, format selection, convenience methods, explorer, encoder, retry, WebSocket, wallet, auth, contracts, co-signer | 3206+ |\n| Integration: cross-module flows, VM/contract integration, hub discovery | 98+ |\n| Security: input attack surface, auth gates | 18+ |\n| Regression: curated critical-path suite, including round-trip serialize -> parse -> verify | 23+ |\n| Boundary: exact encoding limits | 35+ |\n| Fuzz: garbage types, unicode, prototype pollution | 65+ |\n| Chaos: malformed responses, HTTP errors, timeouts | 27+ |\n| Smoke: boot API server, end-to-end JSON-RPC | 9+ |\n| Performance | 3 |\n| **Total** | **3484+** |\n\n---\n\n**Copyright &copy; 2025-2026 Dankest, LLC**\n\n**Based on XChain Platform by Dankest, LLC &ndash; https://dankest.llc**\n\nLicensed under the **GNU Affero General Public License v3.0** (AGPL-3.0-or-later)\nwith a commercial license available for proprietary use.\n\nYou may use, modify, and distribute this material under the terms of the License.\nSee [LICENSE](./LICENSE.md) and [NOTICE](./NOTICE.md) for full terms.\nSee the [licensing overview](https://docs.xchain.io/legal/licensing).\n","readmeFilename":"README.md"}