{"_id":"@decionis/presence-vercel","_rev":"4-3d4dea37b5f5872f4bfd1b4b48cede18","name":"@decionis/presence-vercel","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@decionis/presence-vercel","version":"0.1.0","license":"Apache-2.0","_id":"@decionis/presence-vercel@0.1.0","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://presence.decionis.com/developers/vercel","bugs":{"url":"https://github.com/decionis/Presence/issues"},"dist":{"shasum":"7a020909e24fc3a12f8268ae0bf08d8a4d99727a","tarball":"https://registry.npmjs.org/@decionis/presence-vercel/-/presence-vercel-0.1.0.tgz","fileCount":15,"integrity":"sha512-2DYyeD4QE/tFIFI3LANuT6qR6hSN86ymj/ODV+QCjNm/qTIdnlw98O3viJktNhqGTEB7TZoV82/fQi9/1g4PxQ==","signatures":[{"sig":"MEUCIQCjX98FciVObNxY2/cE5dPkU7UK4FBgb8Cc86/3HVZvrgIgIxeXqg3aAL6Tqo/xUh7UdOCylosMlBcQVeV5k5KCiuQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41048},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"74e32405bc8ced2f4f5fa37acd8fbc13218c8653","scripts":{"lint":"eslint src","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"decionis","email":"festus@binariesfort.com"},"deprecated":"Deprecated: use 0.1.1 or later; 0.1.0 documentation referenced a retired API hostname.","repository":{"url":"git+https://github.com/decionis/Presence.git","type":"git","directory":"packages/presence-vercel"},"_npmVersion":"11.12.1","description":"Presence Edge Middleware for Vercel / Next.js: gate sensitive routes on a verified Presence session or a locally-verified ES256 proof, at the Vercel edge, with no application code.","directories":{},"sideEffects":false,"_nodeVersion":"25.9.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.17.0","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.20.1","@edge-runtime/vm":"^5.0.0","@presence/config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/presence-vercel_0.1.0_1786279392799_0.25413668885872576","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@decionis/presence-vercel","version":"0.1.1","license":"Apache-2.0","_id":"@decionis/presence-vercel@0.1.1","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"homepage":"https://presence.decionis.com/developers/vercel","bugs":{"url":"https://github.com/decionis/Presence/issues"},"dist":{"shasum":"c1394fbfee2fe9cd618e1e22c4496acf248dbf8a","tarball":"https://registry.npmjs.org/@decionis/presence-vercel/-/presence-vercel-0.1.1.tgz","fileCount":15,"integrity":"sha512-9wvNX8x/3R2mkuBagfTecwlwkf2oLRmDASJ5VAsesZnKgmwOW6mOm8peKh1uWPkZY8fhhiWQt/hw/Pl8799xvQ==","signatures":[{"sig":"MEUCIQD3Txh034MRBMHDRRBolFJGwOYFizpuM1a3qwSPCZ7VFAIgTnxjbTSOIyx2Gocgy3wWUaTgzD6tU5hsps5uM3JHVGw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41032},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22.14.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"4666b7d673b17387ad31acbf79f9be7710e6b82f","scripts":{"lint":"eslint src","test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"decionis","email":"festus@binariesfort.com"},"repository":{"url":"git+https://github.com/decionis/Presence.git","type":"git","directory":"packages/presence-vercel"},"_npmVersion":"11.12.1","description":"Presence Edge Middleware for Vercel / Next.js: gate sensitive routes on a verified Presence session or a locally-verified ES256 proof, at the Vercel edge, with no application code.","directories":{},"sideEffects":false,"_nodeVersion":"25.9.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.17.0","vitest":"^2.1.8","typescript":"^5.7.2","@types/node":"^22.20.1","@edge-runtime/vm":"^5.0.0","@presence/config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/presence-vercel_0.1.1_1786280069205_0.13050916628758835","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@decionis/presence-vercel","version":"0.2.0","description":"Presence enforcement for Vercel / Next.js: gate sensitive routes on a verified Presence session or a locally-verified ES256 proof — as Edge Middleware with no application code, or as a withPresence wrapper on individual route handlers.","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/decionis/Presence.git","directory":"packages/presence-vercel"},"homepage":"https://presence.decionis.com/developers/vercel","bugs":{"url":"https://github.com/decionis/Presence/issues"},"type":"module","sideEffects":false,"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"devDependencies":{"@edge-runtime/vm":"^5.0.0","@types/node":"^22.20.1","eslint":"^9.17.0","typescript":"^5.7.2","vitest":"^2.1.8","@presence/config":"0.1.0"},"engines":{"node":">=22.14.0"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run","lint":"eslint src","typecheck":"tsc -p tsconfig.json --noEmit"},"_id":"@decionis/presence-vercel@0.2.0","_integrity":"sha512-jbchyVA9Xkke661kmkCQnm4Y///GJBQtlQt+crdUQjcDv/dOmZSJOWlCctlfuXfI5U8bLlVKtnnKerpGPWCOXQ==","_resolved":"/home/runner/work/Presence/Presence/artifacts/npm/decionis-presence-vercel-0.2.0.tgz","_from":"file:artifacts/npm/decionis-presence-vercel-0.2.0.tgz","_nodeVersion":"22.14.0","_npmVersion":"11.5.1","dist":{"integrity":"sha512-jbchyVA9Xkke661kmkCQnm4Y///GJBQtlQt+crdUQjcDv/dOmZSJOWlCctlfuXfI5U8bLlVKtnnKerpGPWCOXQ==","shasum":"7a97c6d71c9f11cfb763540e348307462d1de338","tarball":"https://registry.npmjs.org/@decionis/presence-vercel/-/presence-vercel-0.2.0.tgz","fileCount":23,"unpackedSize":53172,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDgUfb4wpwecRGkMl0VRJ+hCY/vyRrIu9wPGOvvM3zqvQIgB1c3ZtNAsiJt+9ZKp0ubMwomcqXooNzzYmvDwPNtfyk="}]},"_npmUser":{"name":"decionis","email":"festus@binariesfort.com"},"directories":{},"maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/presence-vercel_0.2.0_1786351524209_0.17509501429566376"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-09T12:43:12.647Z","modified":"2026-08-10T08:45:24.490Z","0.1.0":"2026-08-09T12:43:12.943Z","0.1.1":"2026-08-09T12:54:29.339Z","0.2.0":"2026-08-10T08:45:24.345Z"},"bugs":{"url":"https://github.com/decionis/Presence/issues"},"license":"Apache-2.0","homepage":"https://presence.decionis.com/developers/vercel","repository":{"type":"git","url":"git+https://github.com/decionis/Presence.git","directory":"packages/presence-vercel"},"description":"Presence enforcement for Vercel / Next.js: gate sensitive routes on a verified Presence session or a locally-verified ES256 proof — as Edge Middleware with no application code, or as a withPresence wrapper on individual route handlers.","maintainers":[{"name":"decionis","email":"festus@binariesfort.com"}],"readme":"# @decionis/presence-vercel\n\n**Presence adds execution-time human verification to sensitive Next.js routes.** It gates configured\n`POST`, `PUT`, and `DELETE` requests before they reach your application, validates Presence sessions\nand ES256 proofs locally at the edge, and returns explicit `403` or `503` outcomes when verification\nis denied or unavailable — the same enforcement contract (docs/41)\nthe Cloudflare and Fastly edge filters ship, with the execution mode as a developer choice.\n\n## Install\n\n```sh\nnpm install @decionis/presence-vercel\n```\n\nSet three Vercel environment variables (server-side only — the tenant secret never reaches the\nbrowser): `PRESENCE_API_SECRET`, `PRESENCE_TENANT_ID`, and optionally `PRESENCE_API_HOST`\n(defaults to `https://presence.decionis.com`).\n\n## Gate configured paths with the Edge Middleware\n\nRoute selection lives in `middleware.ts`, with no application code:\n\n```ts\n// middleware.ts\nimport { createPresenceMiddleware } from \"@decionis/presence-vercel\";\n\nexport const middleware = createPresenceMiddleware({\n  apiHost: \"https://presence.decionis.com\",\n  apiSecret: process.env.PRESENCE_API_SECRET!, // a Vercel env var, server-side only\n  tenantId: process.env.PRESENCE_TENANT_ID!,\n  protectedRoutes: \"/api/checkout/*,/api/transfer\",\n});\n\nexport const config = { matcher: [\"/api/:path*\"] };\n```\n\n## Or wrap a single route handler\n\nWhere the choice belongs in code, wrap the handler itself — there is no `protectedRoutes`, because\nwrapping **is** the selection:\n\n```ts\n// app/api/transfers/route.ts\nimport { withPresence } from \"@decionis/presence-vercel\";\n\nexport const POST = withPresence(async (req) => {\n  return Response.json({ ok: true });\n});\n```\n\n`withPresence` reads `PRESENCE_API_HOST` (defaulting to the production API), `PRESENCE_API_SECRET`,\nand `PRESENCE_TENANT_ID` from the environment at first request; a config object can also be passed\nas a second argument. A gated write whose configuration cannot verify anything fails closed (`503`),\nnever open.\n\n## One fail-closed gate\n\nBoth modes run the identical gate on write requests (`POST`/`PUT`/`DELETE`):\n\n| Condition                               | Result                                                  |\n| --------------------------------------- | ------------------------------------------------------- |\n| Valid `x-presence-proof`                | Verified locally against the JWKS, forwarded (no API)   |\n| `x-presence-token` valid, risk ≤ `0.75` | Forwarded to the app / handler                          |\n| Token missing                           | `403 { code: \"PRESENCE_TOKEN_MISSING\" }`                |\n| Token invalid / high-risk               | `403 { code: \"PRESENCE_CHALLENGE_FAILED\" }`             |\n| `/v1/verify` unavailable                | **Fail closed** `503 PRESENCE_VERIFICATION_UNAVAILABLE` |\n| Non-write method or unselected route    | Continues to the app                                    |\n\nThe middleware returns a `Response` to short-circuit, or `undefined` to continue — so it drops into\na Next.js `middleware.ts` or any Vercel Edge Function. `withPresence` returns the denial or the\nhandler's own `Response`, and passes the route context (`{ params }`) through untouched. Everything\nis Web APIs only, so it runs on the **Vercel Edge Runtime** and the Node runtime alike; the test\nsuite runs in the Edge Runtime (`vitest` `edge-runtime` environment). See docs/44 in the repository.\n\n## Support\n\n- [presence.decionis.com](https://presence.decionis.com) — product, security review, and developer quickstart\n- [GitHub Issues](https://github.com/decionis/Presence/issues)\n\n## License\n\nApache-2.0. Use of the hosted Presence service is governed separately.\n","readmeFilename":"README.md"}