{"_id":"@dexterai/dextercard","_rev":"3-c05772bb40520fab0240f1b9e1e1f9c5","name":"@dexterai/dextercard","dist-tags":{"latest":"0.5.0"},"versions":{"0.3.0":{"name":"@dexterai/dextercard","version":"0.3.0","keywords":["dextercard","dexter","card","agents","stablecoin","x402","mastercard"],"license":"MIT","_id":"@dexterai/dextercard@0.3.0","maintainers":[{"name":"nrsander","email":"nrsander@gmail.com"}],"homepage":"https://github.com/Dexter-DAO/opendexter-ide#readme","bugs":{"url":"https://github.com/Dexter-DAO/opendexter-ide/issues"},"dist":{"shasum":"a867e2011988c9a92f5d6a110e09d1fa9cfb30c5","tarball":"https://registry.npmjs.org/@dexterai/dextercard/-/dextercard-0.3.0.tgz","fileCount":14,"integrity":"sha512-HLR6SZQHIfSVfQA7tl9UdEy8AJoV7naGw0gkln+1Bf2d5upTEgdZ/Y41xvVC0r74uctjYpe7Zw1EpQ/a6IeOQQ==","signatures":[{"sig":"MEUCIQCZ8KxsLVz8BwP+O/HmBiVwbaX20ZqtJVxtywJWHCmBbgIgJ4jur39oKPMlW4ODv8hzUVJkLhanVz1UmpoqQ9FyKew=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75777},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","module":"dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"057a384d72492202f47b7a397a807bffef94bee7","scripts":{"dev":"tsup src/index.ts --format esm,cjs --watch --no-sourcemap","build":"tsup src/index.ts --format esm,cjs --clean --no-sourcemap && tsc --emitDeclarationOnly --outDir dist","release":"npm version patch && npm publish --access public","typecheck":"tsc --noEmit","_build_note":"DO NOT add --sourcemap to tsup. Sourcemaps would expose original TS source, comments, and architecture to anyone who runs `npm install`. See .npmignore.","prepublishOnly":"npm run build && node ./scripts/check-no-sourcemaps.cjs"},"_npmUser":{"name":"nrsander","email":"nrsander@gmail.com"},"repository":{"url":"git+https://github.com/Dexter-DAO/opendexter-ide.git","type":"git","directory":"packages/dextercard"},"_npmVersion":"10.9.3","description":"Dextercard SDK — issue and manage virtual cards for AI agents. Wraps a regulated card-issuance carrier with a clean TypeScript API, self-managed sessions, and a captcha-aware login flow.","directories":{},"_nodeVersion":"22.19.0","dependencies":{"zod":"^3.23.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","typescript":"^5.9.3","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/dextercard_0.3.0_1777674395625_0.2545321250320107","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@dexterai/dextercard","version":"0.4.0","keywords":["dextercard","dexter","card","agents","stablecoin","x402","mastercard"],"license":"MIT","_id":"@dexterai/dextercard@0.4.0","maintainers":[{"name":"nrsander","email":"nrsander@gmail.com"}],"homepage":"https://github.com/Dexter-DAO/opendexter-ide#readme","bugs":{"url":"https://github.com/Dexter-DAO/opendexter-ide/issues"},"dist":{"shasum":"32971ffba718463fe342810e48693f2f9a51eeab","tarball":"https://registry.npmjs.org/@dexterai/dextercard/-/dextercard-0.4.0.tgz","fileCount":15,"integrity":"sha512-JHElK7YQ9JZUr/HjGpF/0bQ/EN7AxjZoVNBsSNrVnuMInTJUtvWO6W7cRfT8tTZwai5eEHi9r1VFlfiPeJKrsw==","signatures":[{"sig":"MEUCIQCTeghmhrTPQVq1Z3e7ss6AUedejuNfurrS83W9taNDbwIgK6c22AZoubSpQCE5hdBlhz2qZIaHDS4o6+NQtCA+jPQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":83878},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","module":"dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"197b8681f10faea5dcf8c37a032069568f0db878","scripts":{"dev":"tsup src/index.ts --format esm,cjs --watch --no-sourcemap","build":"tsup src/index.ts --format esm,cjs --clean --no-sourcemap && tsc --emitDeclarationOnly --outDir dist","release":"npm version patch && npm publish --access public","typecheck":"tsc --noEmit","_build_note":"DO NOT add --sourcemap to tsup. Sourcemaps would expose original TS source, comments, and architecture to anyone who runs `npm install`. See .npmignore.","prepublishOnly":"npm run build && node ./scripts/check-no-sourcemaps.cjs"},"_npmUser":{"name":"nrsander","email":"nrsander@gmail.com"},"repository":{"url":"git+https://github.com/Dexter-DAO/opendexter-ide.git","type":"git","directory":"packages/dextercard"},"_npmVersion":"10.9.3","description":"Dextercard SDK — issue and manage virtual cards for AI agents. Wraps a regulated card-issuance carrier with a clean TypeScript API, self-managed sessions, and a captcha-aware login flow.","directories":{},"_nodeVersion":"22.19.0","dependencies":{"zod":"^3.23.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","typescript":"^5.9.3","@types/node":"^22.10.0"},"_npmOperationalInternal":{"tmp":"tmp/dextercard_0.4.0_1777675220320_0.9698827894799464","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@dexterai/dextercard","version":"0.5.0","description":"Dextercard SDK — issue and manage virtual cards for AI agents. Wraps a regulated card-issuance carrier with a clean TypeScript API, self-managed sessions, and a captcha-aware login flow.","type":"module","main":"dist/index.js","module":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./browser":{"types":"./dist/browser.d.ts","import":"./dist/browser.js","require":"./dist/browser.cjs"}},"scripts":{"_build_note":"DO NOT add --sourcemap to tsup. Sourcemaps would expose original TS source, comments, and architecture to anyone who runs `npm install`. See .npmignore.","build":"tsup src/index.ts src/browser.ts --format esm,cjs --clean --no-sourcemap && tsc --emitDeclarationOnly --outDir dist","dev":"tsup src/index.ts src/browser.ts --format esm,cjs --watch --no-sourcemap","typecheck":"tsc --noEmit","prepublishOnly":"npm run build && node ./scripts/check-no-sourcemaps.cjs","release":"npm version patch && npm publish --access public"},"keywords":["dextercard","dexter","card","agents","stablecoin","x402","mastercard"],"license":"MIT","dependencies":{"zod":"^3.23.0"},"devDependencies":{"@types/node":"^22.10.0","tsup":"^8.5.1","typescript":"^5.9.3"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/Dexter-DAO/opendexter-ide.git","directory":"packages/dextercard"},"_id":"@dexterai/dextercard@0.5.0","gitHead":"58c54d06ab5bfff1df66975c04cc5edc2ba96768","bugs":{"url":"https://github.com/Dexter-DAO/opendexter-ide/issues"},"homepage":"https://github.com/Dexter-DAO/opendexter-ide#readme","_nodeVersion":"22.19.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-dXpWEyEgdanrheRjWQRtRD2DC1Dp9PMf+QJ+b3UQ9XRbEot3zVoK3XeeMCke9z7Y/gxrmT0fx7ePfq2qahLC6Q==","shasum":"3bc664f22f495aac0c94fba8ac583ca7630555e4","tarball":"https://registry.npmjs.org/@dexterai/dextercard/-/dextercard-0.5.0.tgz","fileCount":19,"unpackedSize":93583,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCm7aQm7q/UO2lphC+toOb8vc/YkOCpkaeVAmhtf1ql+gIgcJzVpaKPrC4JZsAdZTK53q5Z/8t2M9iLvvFDSwCmC4I="}]},"_npmUser":{"name":"nrsander","email":"nrsander@gmail.com"},"directories":{},"maintainers":[{"name":"nrsander","email":"nrsander@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dextercard_0.5.0_1777676594835_0.585406425342156"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-01T22:26:35.521Z","modified":"2026-05-01T23:03:15.116Z","0.3.0":"2026-05-01T22:26:35.792Z","0.4.0":"2026-05-01T22:40:20.523Z","0.5.0":"2026-05-01T23:03:14.980Z"},"bugs":{"url":"https://github.com/Dexter-DAO/opendexter-ide/issues"},"license":"MIT","homepage":"https://github.com/Dexter-DAO/opendexter-ide#readme","keywords":["dextercard","dexter","card","agents","stablecoin","x402","mastercard"],"repository":{"type":"git","url":"git+https://github.com/Dexter-DAO/opendexter-ide.git","directory":"packages/dextercard"},"description":"Dextercard SDK — issue and manage virtual cards for AI agents. Wraps a regulated card-issuance carrier with a clean TypeScript API, self-managed sessions, and a captcha-aware login flow.","maintainers":[{"name":"nrsander","email":"nrsander@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://raw.githubusercontent.com/Dexter-DAO/dexter-x402-sdk/main/assets/dexter-wordmark.svg\" alt=\"Dexter\" width=\"360\">\n</p>\n\n<h1 align=\"center\">@dexterai/dextercard</h1>\n\n<p align=\"center\">\n  <strong>Issue and manage virtual cards for AI agents.</strong>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/@dexterai/dextercard\"><img src=\"https://img.shields.io/npm/v/@dexterai/dextercard.svg\" alt=\"npm\"></a>\n  <a href=\"https://nodejs.org\"><img src=\"https://img.shields.io/badge/node-%3E=18-brightgreen.svg\" alt=\"Node\"></a>\n  <a href=\"https://dexter.cash\"><img src=\"https://img.shields.io/badge/Marketplace-dexter.cash-blueviolet\" alt=\"Marketplace\"></a>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://dexter.cash\"><strong>Browse Dexter →</strong></a>\n</p>\n\n---\n\n## What is Dextercard?\n\nDextercard is the card-issuance layer for the Dexter ecosystem. It turns an authenticated user's stablecoin treasury into a real virtual Mastercard that spends anywhere Mastercard is accepted, with a per-wallet spend cap that you control. The SDK wraps the underlying regulated card carrier with a clean TypeScript surface — auth (OTP + hCaptcha), self-managed sessions with auto-refresh, encrypted credential storage, and typed methods for every step of the card lifecycle (KYC onboarding, issue, reveal, link wallet, freeze, transactions).\n\nThis package is consumed by [`@dexterai/x402-mcp-tools`](https://www.npmjs.com/package/@dexterai/x402-mcp-tools) (which exposes the four `card_*` MCP tools used by the [Dexter MCP server](https://www.npmjs.com/package/@dexterai/opendexter)) and by the Dexter web app's card-issuance pages.\n\n---\n\n## Install\n\n```bash\nnpm install @dexterai/dextercard\n```\n\n## Quickstart\n\n```ts\nimport {\n  Dextercard,\n  LoginFlow,\n  EncryptedFileSessionStore,\n  DextercardNoAccountError,\n} from \"@dexterai/dextercard\";\n\nconst store = new EncryptedFileSessionStore(\n  `${process.env.HOME}/.config/dexter/dextercard.enc`,\n  process.env.DEXTERCARD_KEY!,\n);\n\n// First run: trigger OTP, exchange code, persist session.\nconst flow = new LoginFlow();\nawait flow.requestCode({ email, captchaToken });   // user solved hCaptcha\nconst { session } = await flow.completeWithCode({ email, code, store });\n\n// Every subsequent run: resume.\n// const session = await new LoginFlow().resume(store);\n\nconst card = new Dextercard({ session });\nconst user = await card.userRetrieve();           // { id, email }\n\ntry {\n  const status = await card.cardRetrieve();\n} catch (err) {\n  if (err instanceof DextercardNoAccountError) {\n    // user hasn't completed onboarding yet — kick them through KYC\n  } else throw err;\n}\n```\n\n---\n\n## Auth Model\n\n### `LoginFlow`\n\nHigh-level orchestration. Send the OTP, exchange the code for a session, optionally persist into a `SessionStore`, and resume across processes.\n\n### `DextercardSession`\n\nLong-lived session manager. Reads from a `SessionStore`, proactively refreshes JWTs before expiry, persists rotated refresh tokens. Concurrent calls coalesce into a single refresh. The `Dextercard` 401-retry path uses this to recover transparently when a JWT has been rejected mid-flight.\n\n### `EncryptedFileSessionStore`\n\nAES-256-GCM + scrypt encrypted file store. Pass any caller-controlled key material (passphrase, machine-bound random, KMS-fetched secret). Wrong key returns null instead of corrupting state. For environments where you've already protected the storage path with filesystem permissions, the simpler `JsonFileSessionStore` writes a plaintext 0600-mode file.\n\n### hCaptcha\n\nThe carrier protects the OTP-trigger endpoint with hCaptcha (sitekey exported as `DEXTERCARD_HCAPTCHA_SITEKEY`). For browser callers, use `renderDextercardHCaptcha`:\n\n```ts\nimport { renderDextercardHCaptcha, LoginFlow } from \"@dexterai/dextercard\";\n\nconst widget = await renderDextercardHCaptcha({ container: divEl });\nconst captchaToken = await widget.token;\nwidget.destroy();\n\nawait new LoginFlow().requestCode({ email, captchaToken });\n```\n\nServer-side / automation: use a captcha-solving service that returns a real hCaptcha response token, OR open a partnership with the carrier to request a captcha bypass for service-account flows.\n\n---\n\n## Methods\n\nEvery method on `Dextercard` maps 1:1 to a carrier tool (`POST /api/tools/<tool_name>`).\n\n### Account\n\n| Method | Returns |\n|--------|---------|\n| `userRetrieve()` | `{ id, email }` |\n\n### Card Lifecycle\n\n| Method | Description |\n|--------|-------------|\n| `cardOnboardingStart(input)` | Registers with the regulated card issuer; returns the KYC URL the user must complete in a browser. |\n| `cardOnboardingCheck()` | Polls KYC status; surfaces terms URLs once verified. |\n| `cardOnboardingFinish(input)` | Finalizes registration with residential address + accepted terms. |\n| `cardCreate()` | Issues the virtual Mastercard. |\n| `cardRetrieve()` | Current card metadata (status, last4, expiry). |\n| `cardFreeze()` / `cardUnfreeze()` | Pause and resume transactions. |\n| `cardReveal()` | Single-use PCI-safe URL with PAN, CVV, and expiry. |\n\n### Wallet Linking\n\n| Method | Description |\n|--------|-------------|\n| `cardWalletLink({ wallet, currency, amount })` | Delegate spend authority from a wallet to the card with a hard cap. |\n| `cardWalletUnlink({ wallet, currency })` | Revoke spend authority. |\n| `cardWalletCheck({ wallet, chain, currency })` | Inspect a wallet's link status. |\n| `cardWalletList()` | List all wallets currently linked to the card. |\n\n### Transactions\n\n| Method | Description |\n|--------|-------------|\n| `cardTransactionList({ dateFrom?, dateTo?, page? })` | Paginated transaction history with optional date window. |\n\n### Escape Hatch\n\nFor any tool not yet typed by the client:\n\n```ts\nconst data = await card.call<MyResponse>(\"some_new_tool\", { foo: 1 });\n```\n\n---\n\n## Errors\n\nAll non-2xx responses throw `DextercardApiError`. Two cases are pre-classified:\n\n| Class | When |\n|-------|------|\n| `DextercardNoAccountError` | User hasn't completed onboarding yet. The agent should suggest the issuance flow. |\n| `DextercardApiError` | Everything else (region restrictions, KYC failures, carrier errors, etc.). |\n\nBoth classes expose `tool`, `status`, and the raw `payload`.\n\n---\n\n## Region Availability\n\nCard issuance is gated by the underlying carrier and the regulated card issuer. As of `0.3.x`, the live regions are the **United Kingdom** and **LATAM**, with the **United States** and **EU** on the carrier's roadmap. US residents calling `cardOnboardingStart()` receive a `DextercardApiError` with a region-specific message:\n\n> MoonCard is not yet available for US residents. Check back soon — US support is on the roadmap.\n\nThe SDK does not gate region client-side — every request reaches the carrier and the carrier decides. This means region availability tracks reality without an SDK release.\n\n---\n\n## Status\n\n`0.3.x` — request shapes are pinned to the carrier's documented input surface. Response shapes are typed loosely for endpoints that require a provisioned card; they will tighten as additional captures land.\n\n---\n\n## Links\n\n- [Dexter Marketplace](https://dexter.cash)\n- [@dexterai/opendexter](https://www.npmjs.com/package/@dexterai/opendexter) — the npm CLI that consumes this SDK\n- [@dexterai/x402-mcp-tools](https://www.npmjs.com/package/@dexterai/x402-mcp-tools) — the MCP tool layer\n- [Twitter](https://twitter.com/dexteraisol)\n- [Telegram](https://t.me/dexterdao)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}