{"_id":"@digitaldefiance/enclave-bridge-client","_rev":"9-e8a6427e8f43303af0874b1809a461ec","name":"@digitaldefiance/enclave-bridge-client","dist-tags":{"latest":"1.3.0"},"versions":{"1.0.0":{"name":"@digitaldefiance/enclave-bridge-client","version":"1.0.0","keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"author":{"name":"Digital Defiance"},"license":"MIT","_id":"@digitaldefiance/enclave-bridge-client@1.0.0","maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"homepage":"https://github.com/Digital-Defiance/enclave#readme","bugs":{"url":"https://github.com/Digital-Defiance/enclave/issues"},"dist":{"shasum":"fd8cb78aa2fe43c554c7c346e948eb170b80e820","tarball":"https://registry.npmjs.org/@digitaldefiance/enclave-bridge-client/-/enclave-bridge-client-1.0.0.tgz","fileCount":16,"integrity":"sha512-iStlpz5NO0mF4N9QYI4TUn+LDwA5p/mXjuGDNa1JsTHdc4sZCis0AbAz99W8u21wtzwrRfQ1Yq/WYr4lMA7YoQ==","signatures":[{"sig":"MEYCIQCUDk5uqdEdrQs73hposw+zM9Udq4lhyk4xfVMOPEWFKAIhAK8QN7gu6qlJHDf1NDiUlhhO0E3Y8NUnrL4NAnw616sI","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":164185},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"33593f9142de40dd693c315c260738736d2bc8ed","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup","clean":"rm -rf dist","test:all":"npm run test:unit && npm run test:integration","test:e2e":"npx tsx tests/e2e/enclave-bridge.e2e.ts","test:unit":"vitest run src/","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build","test:integration":"vitest run tests/integration/"},"_npmUser":{"name":"jessica-mulein","email":"jessica@mulein.com"},"deprecated":"1.0.0","repository":{"url":"git+https://github.com/Digital-Defiance/enclave.git","type":"git","directory":"enclave-bridge-client"},"_npmVersion":"10.9.4","description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","directories":{},"_nodeVersion":"22.22.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.0.1","eslint":"^8.55.0","vitest":"^1.0.0","typescript":"^5.3.0","@types/node":"^20.10.0"},"peerDependencies":{"@digitaldefiance/node-ecies-lib":">=4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/enclave-bridge-client_1.0.0_1769388007540_0.7910465336954291","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@digitaldefiance/enclave-bridge-client","version":"1.0.1","keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"author":{"name":"Digital Defiance"},"license":"MIT","_id":"@digitaldefiance/enclave-bridge-client@1.0.1","maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"homepage":"https://github.com/Digital-Defiance/enclave-bridge#readme","bugs":{"url":"https://github.com/Digital-Defiance/enclave-bridge/issues"},"dist":{"shasum":"a09e8981b2b10ad2d78af9033c4e956cbc98e27a","tarball":"https://registry.npmjs.org/@digitaldefiance/enclave-bridge-client/-/enclave-bridge-client-1.0.1.tgz","fileCount":16,"integrity":"sha512-rqhNXv8juH4SmmesfvWWOFWwbbMkQQQD925dCSvdNgxsaQilhzpFC86REqnF/jiEHklgw7b9e8ZykukQK4/gLg==","signatures":[{"sig":"MEUCIHaHRPCoSOobe0Ve9abhLmlSOVTYUWEgup467EIRtq5iAiEA72Kjg/P58HAdyyA/3xEqK8cQuaNOxrEqFXkdBrT5IEY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":164262},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"be36283db8393ce296e1688db50f447bd11181a8","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup","clean":"rm -rf dist","test:all":"npm run test:unit && npm run test:integration","test:e2e":"npx tsx tests/e2e/enclave-bridge.e2e.ts","test:unit":"vitest run src/","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build","test:integration":"vitest run tests/integration/"},"_npmUser":{"name":"jessica-mulein","email":"jessica@mulein.com"},"deprecated":"1.0.0","repository":{"url":"git+https://github.com/Digital-Defiance/enclave-bridge.git","type":"git","directory":"enclave-bridge-client"},"_npmVersion":"10.9.4","description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","directories":{},"_nodeVersion":"22.22.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.0.1","eslint":"^8.55.0","vitest":"^1.0.0","typescript":"^5.3.0","@types/node":"^20.10.0"},"peerDependencies":{"@digitaldefiance/node-ecies-lib":">=4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/enclave-bridge-client_1.0.1_1769396201883_0.10865877817452518","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@digitaldefiance/enclave-bridge-client","version":"1.0.2","keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"author":{"name":"Digital Defiance"},"license":"MIT","_id":"@digitaldefiance/enclave-bridge-client@1.0.2","maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"homepage":"https://github.com/Digital-Defiance/enclave-bridge#readme","bugs":{"url":"https://github.com/Digital-Defiance/enclave-bridge/issues"},"dist":{"shasum":"558361cb296f6f47e737d815dd0c5ccc2b3dc560","tarball":"https://registry.npmjs.org/@digitaldefiance/enclave-bridge-client/-/enclave-bridge-client-1.0.2.tgz","fileCount":16,"integrity":"sha512-yjzAHQj/OEbOfjM90MwmeQGrFa4SNPzZ/hzXx+UOqJUAmOl01WO4fmOFx7Z19WdgWfkc74txCp2tEigQTm4S8w==","signatures":[{"sig":"MEUCIQCrAZIF7+YDKkYsIlygE0aIDq1WNTuYk1BgYepVIvsRGgIgUHbMU1o83OJWqMi4nFNeEZGtLoZEFYf7IgKyrSrDWRE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":176766},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"2799e7b5b6178e6891e04aa603f354ed9769287c","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup","clean":"rm -rf dist","test:all":"npm run test:unit && npm run test:integration","test:e2e":"npx tsx tests/e2e/enclave-bridge.e2e.ts","test:unit":"vitest run src/","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build","test:integration":"vitest run tests/integration/"},"_npmUser":{"name":"jessica-mulein","email":"jessica@mulein.com"},"deprecated":"1.0.0","repository":{"url":"git+https://github.com/Digital-Defiance/enclave-bridge.git","type":"git","directory":"enclave-bridge-client"},"_npmVersion":"10.9.4","description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","directories":{},"_nodeVersion":"22.22.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.0.1","eslint":"^8.55.0","vitest":"^1.0.0","typescript":"^5.3.0","@types/node":"^20.10.0"},"peerDependencies":{"@digitaldefiance/node-ecies-lib":">=4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/enclave-bridge-client_1.0.2_1769402693524_0.1545500681950236","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@digitaldefiance/enclave-bridge-client","version":"1.0.3","keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"author":{"name":"Digital Defiance"},"license":"MIT","_id":"@digitaldefiance/enclave-bridge-client@1.0.3","maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"homepage":"https://github.com/Digital-Defiance/enclave-bridge#readme","bugs":{"url":"https://github.com/Digital-Defiance/enclave-bridge/issues"},"dist":{"shasum":"f74b2b46f0f8b1731a5a31ce5f558cc3b7b2f80a","tarball":"https://registry.npmjs.org/@digitaldefiance/enclave-bridge-client/-/enclave-bridge-client-1.0.3.tgz","fileCount":17,"integrity":"sha512-j3KhTNgHtAQ5YS7AY+I0hUD5/OUmRjNkdUvHbDmVn4clCZaEJSXlE2+zeJuE/7D1vwA0zVOlbIBuDdFnB7Buog==","signatures":[{"sig":"MEQCIEmQQuM4FhVf+pn905h+UgYmJYpWIEGAs5p0VJssSJXfAiApE6rNX+TvWlULJMx+1sZdTV8JyWtG0nv68hTqSFl+Cw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":177839},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"2102598c418aba495418bfd76369c3bf680586ab","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup","clean":"rm -rf dist","test:all":"npm run test:unit && npm run test:integration","test:e2e":"npx tsx tests/e2e/enclave-bridge.e2e.ts","test:unit":"vitest run src/","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build","test:integration":"vitest run tests/integration/"},"_npmUser":{"name":"jessica-mulein","email":"jessica@mulein.com"},"repository":{"url":"git+https://github.com/Digital-Defiance/enclave-bridge.git","type":"git","directory":"enclave-bridge-client"},"_npmVersion":"10.9.4","description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","directories":{},"_nodeVersion":"22.22.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.0.1","eslint":"^8.55.0","vitest":"^1.0.0","typescript":"^5.3.0","@types/node":"^20.10.0"},"peerDependencies":{"@digitaldefiance/node-ecies-lib":">=4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/enclave-bridge-client_1.0.3_1769456941505_0.13761572032557456","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@digitaldefiance/enclave-bridge-client","version":"1.1.0","keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"author":{"name":"Digital Defiance"},"license":"MIT","_id":"@digitaldefiance/enclave-bridge-client@1.1.0","maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"homepage":"https://github.com/Digital-Defiance/enclave-bridge#readme","bugs":{"url":"https://github.com/Digital-Defiance/enclave-bridge/issues"},"dist":{"shasum":"8e45592ecfc9e6fd4c63655b49f836ad615fb92e","tarball":"https://registry.npmjs.org/@digitaldefiance/enclave-bridge-client/-/enclave-bridge-client-1.1.0.tgz","fileCount":17,"integrity":"sha512-RGAd2sulCxQqrMzBnYqI5z8vagNOH8mlVnFVzGxEr0dLsgmJAr5BEfc07czzfVF9nGoGVDjgV5KzLfyFcUhbYQ==","signatures":[{"sig":"MEUCIQCU3noeyrQZzY7OxFfLTiZys5Rt3UwFkOFhxcXqNX1F3gIgfPyRyE1GN93ccGlcNlpXHMeaG6izHbyDPNdrGBeonEA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":390030},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"gitHead":"8ee5a086c77b5d0d56c8e3a931e5e252eb57daad","scripts":{"dev":"tsup --watch","lint":"eslint src --ext .ts","test":"vitest run","build":"tsup","clean":"rm -rf dist","test:all":"npm run test:unit && npm run test:integration","test:e2e":"npx tsx tests/e2e/enclave-bridge.e2e.ts","test:unit":"vitest run src/","typecheck":"tsc --noEmit","test:watch":"vitest","prepublishOnly":"npm run build","test:integration":"vitest run tests/integration/"},"_npmUser":{"name":"jessica-mulein","email":"jessica@mulein.com"},"repository":{"url":"git+https://github.com/Digital-Defiance/enclave-bridge.git","type":"git","directory":"enclave-bridge-client"},"_npmVersion":"10.9.4","description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","directories":{},"_nodeVersion":"22.22.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.0.1","eslint":"^8.55.0","vitest":"^1.0.0","typescript":"^5.3.0","@types/node":"^20.10.0"},"peerDependencies":{"@digitaldefiance/node-ecies-lib":">=4.0.0"},"_npmOperationalInternal":{"tmp":"tmp/enclave-bridge-client_1.1.0_1769465181361_0.19749118668431653","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@digitaldefiance/enclave-bridge-client","version":"1.3.0","description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","main":"dist/index.js","types":"dist/index.d.ts","type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"scripts":{"build":"tsup","build:prod":"npm run clean && tsup --minify","dev":"tsup --watch","test":"vitest run","test:watch":"vitest","test:unit":"vitest run src/","test:integration":"vitest run tests/integration/","test:e2e":"npx tsx tests/e2e/enclave-bridge.e2e.ts","test:all":"npm run test:unit && npm run test:integration","lint":"eslint src --ext .ts","typecheck":"tsc --noEmit","clean":"rm -rf dist","prepublishOnly":"npm run build:prod","publish:npm":"npm publish --access public"},"keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"author":{"name":"Digital Defiance"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/Digital-Defiance/enclave-bridge.git","directory":"enclave-bridge-client"},"engines":{"node":">=18.0.0"},"devDependencies":{"@types/node":"^20.10.0","@types/speakeasy":"^2","@types/validator":"^13","eslint":"^8.55.0","tsup":"^8.0.1","tsx":"^4.7.0","typescript":"^5.3.0","vitest":"^1.0.0"},"dependencies":{"@digitaldefiance/branded-interface":"^0.0.5","@digitaldefiance/mongoose-types":"^8.20.9","@digitaldefiance/node-ecies-lib":"^4.19.13","@noble/curves":"^1.4.0","@noble/hashes":"^1.4.0","bip39":"^3.1.0","speakeasy":"^2.0.0","validator":"^13.15.26"},"_id":"@digitaldefiance/enclave-bridge-client@1.3.0","gitHead":"21c2705cf8cf3462c9d1c5b46aa6f6822bae41ef","bugs":{"url":"https://github.com/Digital-Defiance/enclave-bridge/issues"},"homepage":"https://github.com/Digital-Defiance/enclave-bridge#readme","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-02xkY1T7dEEyqQekeeouOWgZENXFdoXx6itwLs9/IGQ6NbN9OStFnzZBMCL1M0m7Dluxnb7i11bBa1XLsz30gQ==","shasum":"53765cdb9919d706794f33a7e7a82b4883bec9c7","tarball":"https://registry.npmjs.org/@digitaldefiance/enclave-bridge-client/-/enclave-bridge-client-1.3.0.tgz","fileCount":17,"unpackedSize":592005,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDnqjuNTuJsyR9HRucyEypdMNPbpMeev4LYtSFZH+3F1QIhAIr/yFFQobsQ2K/JQDIgcW4seBq4mXmKUXbt7c0bBA2E"}]},"_npmUser":{"name":"jessica-mulein","email":"jessica@mulein.com"},"directories":{},"maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/enclave-bridge-client_1.3.0_1779490671376_0.5835814929740368"},"_hasShrinkwrap":false}},"time":{"created":"2026-01-26T00:40:07.471Z","modified":"2026-05-22T22:57:51.719Z","1.0.0":"2026-01-26T00:40:07.679Z","1.0.1":"2026-01-26T02:56:42.085Z","1.0.2":"2026-01-26T04:44:53.696Z","1.0.3":"2026-01-26T19:49:01.673Z","1.1.0":"2026-01-26T22:06:21.518Z","1.3.0":"2026-05-22T22:57:51.560Z"},"bugs":{"url":"https://github.com/Digital-Defiance/enclave-bridge/issues"},"author":{"name":"Digital Defiance"},"license":"MIT","homepage":"https://github.com/Digital-Defiance/enclave-bridge#readme","keywords":["secure-enclave","apple","macos","cryptography","ecies","secp256k1","bridge","ipc","unix-socket"],"repository":{"type":"git","url":"git+https://github.com/Digital-Defiance/enclave-bridge.git","directory":"enclave-bridge-client"},"description":"TypeScript client for Enclave Bridge - Node.js to Apple Secure Enclave bridge","maintainers":[{"name":"jessica-mulein","email":"jessica@mulein.com"}],"readme":"# @digitaldefiance/enclave-bridge-client\n\nTypeScript client for **BrightNexus** (formerly Enclave Bridge) — a macOS app that bridges Node.js to Apple's Secure Enclave via Unix domain socket. Ships the EBP/1 surface and the BrightLink v1 `linkRegister()` flow.\n\n## Features\n\n- 🔐 **Secure Enclave Integration** - Sign data with P-256 keys stored in Apple's Secure Enclave\n- 🔑 **ECIES Encryption** - Encrypt/decrypt data with secp256k1 ECIES (compatible with `@digitaldefiance/node-ecies-lib`)\n- 🔌 **Unix Socket IPC** - Fast local communication with the native macOS bridge app\n- 📦 **TypeScript First** - Full type definitions included\n- ⚡ **Async/Await** - Modern Promise-based API\n- 🔄 **Auto-Reconnection** - Configurable reconnection with exponential backoff\n- 📊 **Request Queuing** - Concurrent request handling with configurable limits\n- 💾 **Key Caching** - Optional caching for frequently-used public keys\n- 🌊 **Streaming Support** - Process large files with chunked encryption/decryption\n- 🏊 **Connection Pooling** - Manage multiple connections for high-throughput scenarios\n- 🛰️ **BrightLink v1 client** - `linkRegister()` with bilateral HKDF, SEP-signed transcript verification, TOFU pinning. Implements [RFC §4.5](https://github.com/Digital-Defiance/bsh/blob/main/docs/rfc-brightlink.md). `linkDeliver()` for credential delivery is on the queue (the demo path runs through bsh; this method is for non-bsh integrations).\n\n- 🔑 **Optional TOTP 2FA** - Per-key two-factor authentication (RFC 6238, compatible with Google Authenticator, Authy, etc.)\n\n## Prerequisites\n\n- macOS with Apple Silicon (M1/M2/M3/M4) chip\n- [BrightNexus](https://github.com/Digital-Defiance/BrightNexus) macOS app running (formerly published as Enclave Bridge). The package name `@digitaldefiance/enclave-bridge-client` is unchanged across the rename.\n- Node.js 18+\n\n## Installation\n\n```bash\nnpm install @digitaldefiance/enclave-bridge-client\n```\n\n### Optional Dependencies\n\nFor client-side encryption support, install:\n\n```bash\nnpm install @digitaldefiance/node-ecies-lib\n```\n\n## Quick Start\n\n```typescript\nimport { EnclaveBridgeClient } from '@digitaldefiance/enclave-bridge-client';\n\nasync function main() {\n  // Create and connect client\n  const client = new EnclaveBridgeClient();\n  await client.connect();\n\n  try {\n    // Get the secp256k1 public key for ECIES encryption\n    const publicKey = await client.getPublicKey();\n    console.log('ECIES Public Key:', publicKey.hex);\n\n    // Get the Secure Enclave P-256 public key\n    const enclaveKey = await client.getEnclavePublicKey();\n    console.log('Enclave Public Key:', enclaveKey.hex);\n\n    // Sign data with Secure Enclave\n    const signature = await client.enclaveSign(Buffer.from('Hello, Secure Enclave!'));\n    console.log('Signature:', signature.hex);\n\n    // Decrypt ECIES-encrypted data\n    // (encrypted with the public key from getPublicKey())\n    const decrypted = await client.decrypt(encryptedBuffer);\n    console.log('Decrypted:', decrypted.text);\n  } finally {\n    await client.disconnect();\n  }\n}\n\nmain().catch(console.error);\n```\n\n## API Reference\n### TOTP 2FA Methods\n\n#### `enableTOTP(keyId: string, account: string, issuer: string): Promise<string>`\nEnable TOTP for a key and receive provisioning URI for authenticator apps.\n\n```typescript\nconst provisioningURI = await client.enableTOTP('ecies-secp256k1', 'user@example.com', 'MyApp');\nconsole.log('Scan this URI in your authenticator app:', provisioningURI);\n```\n\n#### `exportKey(keyId: string, totpCode?: string): Promise<PublicKeyInfo>`\nExport key material (public key) with optional TOTP code. If TOTP is enabled for the key, a valid code is required.\n\n```typescript\nconst key = await client.exportKey('ecies-secp256k1', '123456'); // TOTP code from app\nconsole.log('Exported key:', key.base64);\n```\n\n### Constructor\n\n```typescript\nnew EnclaveBridgeClient(options?: EnclaveBridgeClientOptions)\n```\n\n**Options:**\n\n| Option | Type | Default | Description |\n|--------|------|---------|-------------|\n| `socketPath` | `string` | `${HOME}/.brightchain/brightnexus/brightnexus.sock` | Path to Unix socket. Falls back to `$BRIGHTNEXUS_SOCKET` env var if set. |\n| `timeout` | `number` | `30000` | Operation timeout in ms |\n| `autoReconnect` | `boolean` | `true` | Auto-reconnect on disconnect |\n| `maxReconnectAttempts` | `number` | `5` | Max reconnection attempts |\n| `reconnectDelay` | `number` | `1000` | Initial reconnect delay in ms |\n| `maxReconnectDelay` | `number` | `30000` | Max reconnect delay (backoff cap) |\n| `debug` | `boolean` | `false` | Enable verbose debug logging |\n| `logger` | `function` | `console.log` | Custom logging function |\n| `cacheKeys` | `boolean` | `true` | Cache public keys |\n| `maxConcurrentRequests` | `number` | `1` | Max concurrent requests to server |\n| `enableHeartbeat` | `boolean` | `false` | Enable automatic heartbeat |\n| `heartbeatInterval` | `number` | `30000` | Heartbeat interval in ms |\n\n### Static Methods\n\n#### `EnclaveBridgeClient.isSupported(socketPath?): Promise<PlatformSupport>`\n\nCheck if the current platform supports Enclave Bridge.\n\n```typescript\nconst support = await EnclaveBridgeClient.isSupported();\nif (!support.supported) {\n  console.log('Not supported:', support.reason);\n}\n```\n\n### Connection Methods\n\n#### `connect(): Promise<void>`\n\nConnect to the EnclaveBridge socket server.\n\n```typescript\nawait client.connect();\n```\n\n#### `disconnect(): Promise<void>`\n\nDisconnect from the server.\n\n```typescript\nawait client.disconnect();\n```\n\n#### `isConnected: boolean`\n\nCheck if currently connected.\n\n#### `connectionState: ConnectionState`\n\nGet current state: `'disconnected' | 'connecting' | 'connected' | 'reconnecting' | 'error'`\n\n### Key Operations\n\n#### `getPublicKey(): Promise<PublicKeyInfo>`\n\nGet the secp256k1 public key used for ECIES operations. This key is persisted in the macOS Keychain.\n\n```typescript\nconst key = await client.getPublicKey();\nconsole.log(key.base64);  // Base64 encoded\nconsole.log(key.hex);     // Hex encoded\nconsole.log(key.buffer);  // Raw Buffer\n```\n\n#### `getEnclavePublicKey(): Promise<PublicKeyInfo>`\n\nGet the Secure Enclave P-256 public key. The private key never leaves the Secure Enclave.\n\n```typescript\nconst enclaveKey = await client.getEnclavePublicKey();\n```\n\n#### `setPeerPublicKey(publicKey: string | Buffer): Promise<void>`\n\nSet a peer's public key for ECDH operations.\n\n```typescript\nawait client.setPeerPublicKey(peerPublicKeyHex);\n```\n\n#### `listKeys(): Promise<KeyList>`\n\nList all available keys (requires server support).\n\n```typescript\nconst keys = await client.listKeys();\nkeys.keys.forEach(key => {\n  console.log(key.keyId, key.keyType, key.createdAt);\n});\n```\n\n#### `rotateKey(): Promise<KeyRotationResult>`\n\nRotate the current key (requires server support).\n\n```typescript\nconst result = await client.rotateKey();\nconsole.log('New key ID:', result.newKeyId);\n```\n\n### Cryptographic Operations\n\n#### `enclaveSign(data: Buffer | string): Promise<SignatureResult>`\n\nSign data using the Secure Enclave P-256 key. The data is hashed with SHA-256 before signing.\n\n```typescript\nconst signature = await client.enclaveSign('message to sign');\nconsole.log(signature.hex);\n```\n\n#### `decrypt(encryptedData: Buffer): Promise<DecryptionResult>`\n\nDecrypt ECIES-encrypted data. Compatible with `@digitaldefiance/node-ecies-lib` format.\n\n```typescript\nconst result = await client.decrypt(encryptedBuffer);\nconsole.log(result.text);    // As UTF-8 string\nconsole.log(result.buffer);  // As Buffer\n```\n\n#### `encrypt(data: Buffer, publicKey: Buffer): Promise<Buffer>`\n\nEncrypt data using ECIES (requires `@digitaldefiance/node-ecies-lib`).\n\n```typescript\nconst publicKey = await client.getPublicKey();\nconst encrypted = await client.encrypt(\n  Buffer.from('secret'),\n  publicKey.buffer\n);\n```\n\n#### `verifySignature(signature: Buffer, data: Buffer, publicKey: Buffer): Promise<boolean>`\n\nVerify a P-256 signature.\n\n```typescript\nconst isValid = await client.verifySignature(\n  signatureBuffer,\n  dataBuffer,\n  publicKeyBuffer\n);\n```\n\n#### `enclaveGenerateKey(): Promise<KeyGenerationResult>`\n\nGenerate a new ephemeral key.\n\n```typescript\nconst newKey = await client.enclaveGenerateKey();\nconsole.log(newKey.publicKey.hex);\n```\n\n### Server Commands\n\n#### `heartbeat(): Promise<HeartbeatResponse>`\n\nSend a heartbeat to the server.\n\n```typescript\nconst response = await client.heartbeat();\nconsole.log('Server time:', response.timestamp);\n```\n\n#### `getVersion(): Promise<ServerVersion>`\n\nGet the server version information.\n\n```typescript\nconst version = await client.getVersion();\nconsole.log(version.version, version.protocol);\n```\n\n#### `getStatus(): Promise<ServerStatus>`\n\nGet detailed server status.\n\n```typescript\nconst status = await client.getStatus();\nconsole.log(status.status, status.connections, status.uptime);\n```\n\n#### `getMetrics(): Promise<ServerMetrics>`\n\nGet server performance metrics.\n\n```typescript\nconst metrics = await client.getMetrics();\nconsole.log('Total requests:', metrics.totalRequests);\n```\n\n#### `getHealthStatus(): Promise<HealthStatus>`\n\nGet comprehensive health status.\n\n```typescript\nconst health = await client.getHealthStatus();\nconsole.log(health.isHealthy, health.uptime);\n```\n\n### Events\n\nThe client extends `EventEmitter` and emits:\n\n| Event | Description | Payload |\n|-------|-------------|---------|\n| `connect` | Connected to bridge | None |\n| `disconnect` | Disconnected from bridge | None |\n| `error` | Error occurred | `Error` |\n| `stateChange` | Connection state changed | `ConnectionState` |\n| `reconnecting` | Attempting reconnection | `{ attempt, maxAttempts, delay }` |\n| `reconnected` | Successfully reconnected | None |\n| `reconnectFailed` | All reconnection attempts failed | None |\n| `beforeDisconnect` | About to disconnect | None |\n| `debug` | Debug log message | `{ message, meta }` |\n| `requestSent` | Request sent to server | `{ command, payload }` |\n| `responseReceived` | Response received | `response` |\n\n```typescript\nclient.on('connect', () => console.log('Connected!'));\nclient.on('reconnecting', ({ attempt, maxAttempts }) => {\n  console.log(`Reconnecting: attempt ${attempt}/${maxAttempts}`);\n});\nclient.on('error', (err) => console.error('Error:', err));\n```\n\n## Advanced Usage\n\n### Connection Pooling\n\nFor high-throughput scenarios, use the connection pool:\n\n```typescript\nimport { ConnectionPool } from '@digitaldefiance/enclave-bridge-client';\n\nconst pool = new ConnectionPool({ poolSize: 3 });\nawait pool.initialize();\n\n// Execute with automatic connection management\nconst signature = await pool.execute(async (client) => {\n  return await client.enclaveSign('data');\n});\n\n// Or manually manage connections\nconst client = await pool.acquire();\ntry {\n  await client.enclaveSign('data');\n} finally {\n  pool.release(client);\n}\n\nawait pool.close();\n```\n\n### Streaming Support\n\nFor large files, use streaming to process data in chunks:\n\n```typescript\nimport {\n  encryptStream,\n  decryptStream,\n  encryptFile,\n  decryptToFile\n} from '@digitaldefiance/enclave-bridge-client/streaming';\n\n// Encrypt a file with progress callback\nawait encryptFile(\n  client,\n  publicKey,\n  '/path/to/input.txt',\n  '/path/to/output.enc',\n  { chunkSize: 1024 * 1024 }, // 1MB chunks\n  (progress) => console.log(`${progress.percentage}% complete`)\n);\n\n// Decrypt a file\nawait decryptToFile(\n  client,\n  '/path/to/input.enc',\n  '/path/to/output.txt'\n);\n```\n\n### Auto-Reconnection\n\nConfigure automatic reconnection with exponential backoff:\n\n```typescript\nconst client = new EnclaveBridgeClient({\n  autoReconnect: true,\n  maxReconnectAttempts: 10,\n  reconnectDelay: 500,       // Start at 500ms\n  maxReconnectDelay: 60000,  // Cap at 60 seconds\n});\n\nclient.on('reconnecting', ({ attempt, delay }) => {\n  console.log(`Reconnecting in ${delay}ms (attempt ${attempt})`);\n});\n\nclient.on('reconnected', () => {\n  console.log('Successfully reconnected!');\n});\n\nclient.on('reconnectFailed', () => {\n  console.error('All reconnection attempts failed');\n});\n```\n\n### Request Queuing\n\nMultiple concurrent requests are automatically queued:\n\n```typescript\nconst client = new EnclaveBridgeClient({\n  maxConcurrentRequests: 1, // Serialize requests\n});\n\n// These will be queued and processed sequentially\nconst [key1, key2, sig] = await Promise.all([\n  client.getPublicKey(),\n  client.getEnclavePublicKey(),\n  client.enclaveSign('data'),\n]);\n```\n\n### Debug Logging\n\nEnable verbose logging for troubleshooting:\n\n```typescript\nconst client = new EnclaveBridgeClient({\n  debug: true,\n  logger: (level, message, meta) => {\n    console.log(`[${level}] ${message}`, meta);\n  },\n});\n\nclient.on('debug', (message, meta) => {\n  // Handle debug events\n});\n```\n\n## Custom Error Types\n\nThe library provides specific error types for better error handling:\n\n```typescript\nimport {\n  EnclaveBridgeError,\n  ConnectionError,\n  TimeoutError,\n  DecryptionError,\n  EncryptionError,\n  SignatureError,\n  InvalidOperationError,\n  ProtocolError,\n  PlatformError,\n} from '@digitaldefiance/enclave-bridge-client';\n\ntry {\n  await client.connect();\n} catch (err) {\n  if (err instanceof ConnectionError) {\n    console.error('Connection failed:', err.code);\n  } else if (err instanceof TimeoutError) {\n    console.error('Timed out:', err.operation, err.timeoutMs);\n  } else if (err instanceof PlatformError) {\n    console.error('Platform not supported:', err.message);\n  }\n}\n```\n\n## ECIES Format\n\nThe client uses the `@digitaldefiance/node-ecies-lib` ECIES format:\n\n| Field | Size | Description |\n|-------|------|-------------|\n| Version | 1 byte | Protocol version |\n| Cipher Suite | 1 byte | Cipher suite identifier |\n| Encryption Type | 1 byte | 33=Basic, 66=WithLength, 99=Multiple |\n| Ephemeral Public Key | 33 bytes | Compressed secp256k1 key |\n| IV | 12 bytes | Initialization vector |\n| Auth Tag | 16 bytes | GCM authentication tag |\n| Ciphertext | Variable | Encrypted data |\n\n## Protocol\n### TOTP 2FA API\n\n| Command         | Payload                                 | Description                                 |\n|-----------------|-----------------------------------------|---------------------------------------------|\n| `ENABLE_TOTP`   | `{ keyId, account, issuer }`            | Enable TOTP for a key, returns provisioning URI |\n| `EXPORT_KEY`    | `{ keyId, totpCode? }`                  | Export key, requires TOTP if enabled        |\n## End-to-End Testing\n\nE2E tests for TOTP 2FA and all bridge features are included:\n\n- Run: `npx tsx tests/e2e/enclave-bridge.e2e.ts` from the enclave-bridge-client directory\n- Tests cover TOTP enable, provisioning URI, key export with valid/invalid TOTP, and error handling\n\nCommunication uses a JSON-based protocol over Unix domain socket:\n\n**Request Format:**\n```json\n{ \"cmd\": \"COMMAND_NAME\", \"data\": \"optional_payload\" }\n```\n\n**Response Format:**\n```json\n{ \"publicKey\": \"base64_data\" }  // Success\n{ \"error\": \"error_message\" }     // Error\n```\n\n### Commands\n\n| Command | Payload | Description |\n|---------|---------|-------------|\n| `GET_PUBLIC_KEY` | None | Get secp256k1 public key |\n| `GET_ENCLAVE_PUBLIC_KEY` | None | Get Secure Enclave P-256 key |\n| `SET_PEER_PUBLIC_KEY` | `{ publicKey }` | Store peer's public key |\n| `ENCLAVE_SIGN` | `{ data }` | Sign with Secure Enclave |\n| `ENCLAVE_DECRYPT` | `{ data }` | Decrypt ECIES data |\n| `ENCLAVE_GENERATE_KEY` | None | Generate new key |\n| `HEARTBEAT` | None | Server heartbeat |\n| `VERSION` | None | Get server version |\n| `STATUS` | None | Get server status |\n| `METRICS` | None | Get server metrics |\n| `LIST_KEYS` | None | List available keys |\n| `ENCLAVE_ROTATE_KEY` | None | Rotate current key |\n\n## Example: Encrypt in Node.js, Decrypt in Secure Enclave\n\n```typescript\nimport { eciesEncrypt } from '@digitaldefiance/node-ecies-lib';\nimport { EnclaveBridgeClient } from '@digitaldefiance/enclave-bridge-client';\n\nasync function encryptAndDecrypt() {\n  const client = new EnclaveBridgeClient();\n  await client.connect();\n\n  // Get the bridge's public key\n  const { buffer: publicKey } = await client.getPublicKey();\n\n  // Encrypt a message using node-ecies-lib\n  const message = Buffer.from('Secret message');\n  const encrypted = eciesEncrypt(publicKey, message);\n\n  // Decrypt using the Secure Enclave bridge\n  const decrypted = await client.decrypt(encrypted);\n  console.log('Decrypted:', decrypted.text); // \"Secret message\"\n\n  await client.disconnect();\n}\n```\n\n## Security Considerations\n\n- **Secure Enclave Keys**: Private keys for P-256 operations never leave the Secure Enclave hardware\n- **secp256k1 Keys**: Stored in macOS Keychain with access control\n- **Local Only**: Communication is via Unix domain socket (local only)\n- **No Network**: The bridge does not expose any network interfaces\n- **Key Caching**: Public keys can be cached in memory to reduce socket calls\n\n## Migration Guide\n\n### From v1.x to v2.x\n\nThe v2.x release adds new features while maintaining backward compatibility:\n\n1. **Connection State**: Now includes `'reconnecting'` state\n2. **Error Types**: Use specific error classes for better handling\n3. **Event Names**: New events added (`reconnecting`, `reconnected`, `debug`, etc.)\n\nNo breaking changes - existing code continues to work.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}