{"_id":"@ekka-ai/sdk","_rev":"6-830e33d64c76c25e6107c5082f009d2c","name":"@ekka-ai/sdk","dist-tags":{"latest":"0.9.7"},"versions":{"0.9.3":{"name":"@ekka-ai/sdk","version":"0.9.3","keywords":["ekka","sdk","governance","policy"],"license":"MIT","_id":"@ekka-ai/sdk@0.9.3","maintainers":[{"name":"mpla101","email":"mpla@duck.com"}],"dist":{"shasum":"0d9723661c41110c75bfa8ff93c8dc51cfe5b5dd","tarball":"https://registry.npmjs.org/@ekka-ai/sdk/-/sdk-0.9.3.tgz","fileCount":49,"integrity":"sha512-nZsptoeXbrNY31e6H6m2QLlCW3uqbTyei0JOISR5Cj1JS+nFp//lmWVwBuWmT9VZL03dZoGTubCGaQKTfZzpSA==","signatures":[{"sig":"MEQCIFu7RuEeoOcSOJ7AnjOrs0hTptSflslpO3tWRE2l3FjyAiBRZ8XHvTeav9JtuShHg7ErGlvA2rbinKl9W/erBtBdzg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":130104},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./host":{"types":"./dist/host/index.d.ts","import":"./dist/host/index.js"},"./node":{"types":"./dist/node/loadScenarioPack.d.ts","import":"./dist/node/loadScenarioPack.js"},"./package.json":"./package.json"},"gitHead":"d2eec6d5cd0181be00095e3e60ae23a7241e9ff4","scripts":{"test":"vitest run","build":"tsc","prepack":"npm run build","release":"./scripts/release.sh","test:watch":"vitest","release:major":"./scripts/release.sh major","release:minor":"./scripts/release.sh minor","release:patch":"./scripts/release.sh patch","test:boundaries":"vitest run tests/public-boundary.test.ts"},"_npmUser":{"name":"mpla101","email":"mpla@duck.com"},"_npmVersion":"10.9.2","description":"EKKA SDK - TypeScript client for EKKA governance platform","directories":{},"_nodeVersion":"23.10.0","dependencies":{"@noble/ed25519":"^3.0.0","@ekka-ai/contracts":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^25.0.8","@tauri-apps/api":"^2.9.1"},"peerDependencies":{"@tauri-apps/api":"^2.0.0"},"peerDependenciesMeta":{"@tauri-apps/api":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.9.3_1769111282531_0.0894032986494846","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.9.4":{"name":"@ekka-ai/sdk","version":"0.9.4","keywords":["ekka","sdk","governance","policy"],"license":"MIT","_id":"@ekka-ai/sdk@0.9.4","maintainers":[{"name":"mpla101","email":"mpla@duck.com"}],"dist":{"shasum":"db240e91d349867de8807430e07d3c15036b2e00","tarball":"https://registry.npmjs.org/@ekka-ai/sdk/-/sdk-0.9.4.tgz","fileCount":50,"integrity":"sha512-H4e9zJvrYGsaYzFA1fLyinZRCZ8KA4dIh9Na5wjR0mPHl0pNmd+pBopHKkFMVM2Y4JB66TMemoZQk1u0CgfLLA==","signatures":[{"sig":"MEYCIQCrM4CGz3gfvfU6RTBa1fdvhCk2QVrfeuTL5mB3jNOuTwIhAI/XwTWrA4UZAfsdzUaim3x8fnTKJDxNNh19M35gc82T","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":133744},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./host":{"types":"./dist/host/index.d.ts","import":"./dist/host/index.js"},"./node":{"types":"./dist/node/loadScenarioPack.d.ts","import":"./dist/node/loadScenarioPack.js"},"./package.json":"./package.json"},"gitHead":"b789e589740e45e309621f3ddb2446a5669d3f74","scripts":{"test":"vitest run","build":"tsc","prepack":"npm run build","release":"./scripts/release.sh","test:watch":"vitest","release:major":"./scripts/release.sh major","release:minor":"./scripts/release.sh minor","release:patch":"./scripts/release.sh patch","test:boundaries":"vitest run tests/public-boundary.test.ts"},"_npmUser":{"name":"mpla101","email":"mpla@duck.com"},"_npmVersion":"10.9.2","description":"EKKA SDK - TypeScript client for EKKA governance platform","directories":{},"_nodeVersion":"23.10.0","dependencies":{"@noble/ed25519":"^3.0.0","@ekka-ai/contracts":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^25.0.8","@tauri-apps/api":"^2.9.1"},"peerDependencies":{"@tauri-apps/api":"^2.0.0"},"peerDependenciesMeta":{"@tauri-apps/api":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.9.4_1769111660463_0.9441246901803511","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.9.5":{"name":"@ekka-ai/sdk","version":"0.9.5","keywords":["ekka","sdk","governance","policy"],"license":"MIT","_id":"@ekka-ai/sdk@0.9.5","maintainers":[{"name":"mpla101","email":"mpla@duck.com"}],"dist":{"shasum":"e43d9619a289798a8e47f44fc0b8c13a01c90f47","tarball":"https://registry.npmjs.org/@ekka-ai/sdk/-/sdk-0.9.5.tgz","fileCount":52,"integrity":"sha512-2iZOBTjzXy2dkbbBU725dyAtAvAZqQ69YN5vWt4vKLAsUBD52bucRo3kYCQnM5qALNPNWmZqaWGo/uFrU+A6oA==","signatures":[{"sig":"MEYCIQC4Y3ylpwXLtwb293i9vcjG5zUT4Vch9gV526ROcJItVwIhAIGSkBir+9QrgLGFg8HeNT5YdxaI4AOAkYpSfDkznRzs","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":144973},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./host":{"types":"./dist/host/index.d.ts","import":"./dist/host/index.js"},"./node":{"types":"./dist/node/loadScenarioPack.d.ts","import":"./dist/node/loadScenarioPack.js"},"./package.json":"./package.json"},"gitHead":"9e2e223c8feda412068fb0d3b29387315a39dbe6","scripts":{"test":"vitest run","build":"tsc","prepack":"npm run build","release":"./scripts/release.sh","test:watch":"vitest","release:major":"./scripts/release.sh major","release:minor":"./scripts/release.sh minor","release:patch":"./scripts/release.sh patch","test:boundaries":"vitest run tests/public-boundary.test.ts"},"_npmUser":{"name":"mpla101","email":"mpla@duck.com"},"_npmVersion":"10.9.2","description":"EKKA SDK - TypeScript client for EKKA governance platform","directories":{},"_nodeVersion":"23.10.0","dependencies":{"@noble/ed25519":"^3.0.0","@ekka-ai/contracts":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^25.0.8","@tauri-apps/api":"^2.9.1"},"peerDependencies":{"@tauri-apps/api":"^2.0.0"},"peerDependenciesMeta":{"@tauri-apps/api":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.9.5_1769112734039_0.44001967495292305","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.9.6":{"name":"@ekka-ai/sdk","version":"0.9.6","keywords":["ekka","sdk","governance","policy"],"license":"MIT","_id":"@ekka-ai/sdk@0.9.6","maintainers":[{"name":"mpla101","email":"mpla@duck.com"}],"dist":{"shasum":"e02eeb4e13487c7362d9c55fdd7f646158144061","tarball":"https://registry.npmjs.org/@ekka-ai/sdk/-/sdk-0.9.6.tgz","fileCount":52,"integrity":"sha512-jloWeK8J7KNOETqq4rABH6gxBguD9E9fNO5tUNGqUHi75HuWz4PwUS75HEjHpe9Iv6isYe4PBvXPP3G4NCiloA==","signatures":[{"sig":"MEYCIQDs0qYo8yccAVRWwQ7kpDvclNcEdupuQ3Nxecljs5bkOAIhAPadc6dLflkufyJlMcLCgBGK2pi5rzgxw8WZcNVRbPeM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":156437},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./host":{"types":"./dist/host/index.d.ts","import":"./dist/host/index.js"},"./node":{"types":"./dist/node/loadScenarioPack.d.ts","import":"./dist/node/loadScenarioPack.js"},"./package.json":"./package.json"},"gitHead":"2e99323744a1e255caf349f7889a4d7819935a7a","scripts":{"test":"vitest run","build":"tsc","prepack":"npm run build","release":"./scripts/release.sh","test:watch":"vitest","release:major":"./scripts/release.sh major","release:minor":"./scripts/release.sh minor","release:patch":"./scripts/release.sh patch","test:boundaries":"vitest run tests/public-boundary.test.ts"},"_npmUser":{"name":"mpla101","email":"mpla@duck.com"},"_npmVersion":"10.9.2","description":"EKKA SDK - TypeScript client for EKKA governance platform","directories":{},"_nodeVersion":"23.10.0","dependencies":{"@noble/ed25519":"^3.0.0","@ekka-ai/contracts":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^25.0.8","@tauri-apps/api":"^2.9.1"},"peerDependencies":{"@tauri-apps/api":"^2.0.0"},"peerDependenciesMeta":{"@tauri-apps/api":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.9.6_1769114053002_0.11851255141937811","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.9.7":{"name":"@ekka-ai/sdk","version":"0.9.7","keywords":["ekka","sdk","governance","policy"],"license":"MIT","_id":"@ekka-ai/sdk@0.9.7","maintainers":[{"name":"mpla101","email":"mpla@duck.com"}],"dist":{"shasum":"c22f788de115e1b6477bfdf2af5436271ac21ffb","tarball":"https://registry.npmjs.org/@ekka-ai/sdk/-/sdk-0.9.7.tgz","fileCount":52,"integrity":"sha512-BHoyRlycvBJbiad9LEMsT5BKRW4S+XC8TiFB06p86teNWxf48uGY5AP3Ko+5H3rKAYQYqgJdTtUHGnsvF4J0BA==","signatures":[{"sig":"MEUCIEG6QsKjb98u75gUciQoJFuBlOj0/fbgdtlIRWF1F4n5AiEAwlnE9KJh2+SdSNyDvxwb2fglGQVqo4ip6qm37KaaLjs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":156106},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./host":{"types":"./dist/host/index.d.ts","import":"./dist/host/index.js"},"./node":{"types":"./dist/node/loadScenarioPack.d.ts","import":"./dist/node/loadScenarioPack.js"},"./package.json":"./package.json"},"gitHead":"1c27a6a985af8db08c7078fe7050122364440896","scripts":{"test":"vitest run","build":"tsc","prepack":"npm run build","release":"./scripts/release.sh","test:watch":"vitest","release:major":"./scripts/release.sh major","release:minor":"./scripts/release.sh minor","release:patch":"./scripts/release.sh patch","test:boundaries":"vitest run tests/public-boundary.test.ts"},"_npmUser":{"name":"mpla101","email":"mpla@duck.com"},"_npmVersion":"10.9.2","description":"EKKA SDK - TypeScript client for EKKA governance platform","directories":{},"_nodeVersion":"23.10.0","dependencies":{"@noble/ed25519":"^3.0.0","@ekka-ai/contracts":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.2.0","typescript":"^5.3.0","@types/node":"^25.0.8","@tauri-apps/api":"^2.9.1"},"peerDependencies":{"@tauri-apps/api":"^2.0.0"},"peerDependenciesMeta":{"@tauri-apps/api":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_0.9.7_1769114865780_0.8891649296542852","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2026-01-22T19:48:02.392Z","modified":"2026-09-27T02:45:56.147Z","0.9.3":"2026-01-22T19:48:02.687Z","0.9.4":"2026-01-22T19:54:20.696Z","0.9.5":"2026-01-22T20:12:14.198Z","0.9.6":"2026-01-22T20:34:13.140Z","0.9.7":"2026-01-22T20:47:45.920Z"},"license":"MIT","keywords":["ekka","sdk","governance","policy"],"description":"EKKA SDK - TypeScript client for EKKA governance platform","maintainers":[{"name":"mpla101","email":"mpla@duck.com"}],"readme":"# @ekka-ai/sdk\n\nTypeScript SDK for the EKKA governance platform. Provides cryptographic consent, policy enforcement, and secure action execution for applications operating under EKKA's security model.\n\nThis SDK implements a dual-layer architecture: a sandboxed public API for application code, and a privileged host API for trusted runtime environments.\n\n## Security Model\n\nEKKA SDK enforces strict separation between **App Mode** (sandboxed) and **Host Mode** (privileged).\n\n### App Mode — Public API\n\n```typescript\nimport { authorize, execute, EkkaError } from '@ekka-ai/sdk';\n```\n\nThe public API is designed for application code running in constrained environments (web apps, sandboxed processes, third-party integrations). All operations are:\n\n- Capability-gated by the host runtime\n- Audited with correlation IDs\n- Expressed as user intent, not infrastructure mechanics\n\nApp Mode applications interact with EKKA through intent-based abstractions (`authorize`, `execute`) that enforce policy at the transport layer.\n\n### Host Mode — Privileged API\n\n> **Note**: Host mode requires a trusted runtime environment. Importing `@ekka-ai/sdk/host` from a browser or sandboxed process will fail at module resolution.\n\n```typescript\nimport { createHostAdapter, HostAdapter } from '@ekka-ai/sdk/host';\n```\n\nThe host API is exclusively for EKKA-owned runtimes (Tauri desktop app, Node.js backend services, CLI tools). Host Mode provides:\n\n- Capability management and enforcement\n- Audit logging\n- Transport-level security controls\n\nHost applications mediate all App Mode requests through the `HostAdapter`.\n\n## Usage\n\n### Authorization Flow (App Mode)\n\n```typescript\nimport { authorize, sign, execute, ed25519 } from '@ekka-ai/sdk';\n\n// Generate ephemeral keypair\nconst keypair = await ed25519.generateKeypair();\n\n// Step 1: Request authorization\nconst auth = await authorize(jwt, {\n  tenant_id: 'tenant-001',\n  key_id: 'my-key',\n  action_id: 'transfer',\n  resources: [{ type: 'account', id: 'acc-123' }],\n  issued_at_iso_utc: new Date().toISOString(),\n});\n\n// Step 2: Sign the authorization payload\nconst signature = await sign(auth.payload, keypair.private_key_b64);\n\n// Step 3: Execute the authorized action\nconst result = await execute({\n  authorization_id: auth.authorization_id,\n  signature_b64: signature,\n  public_key_b64: keypair.public_key_b64,\n  key_id: 'my-key',\n});\n```\n\n### Combined Flow\n\n```typescript\nimport { authorizeAndExecute, ed25519 } from '@ekka-ai/sdk';\n\nconst keypair = await ed25519.generateKeypair();\n\nconst result = await authorizeAndExecute({\n  jwt,\n  tenant_id: 'tenant-001',\n  key_id: 'my-key',\n  action_id: 'approve',\n  resources: [],\n  issued_at_iso_utc: new Date().toISOString(),\n  public_key_b64: keypair.public_key_b64,\n}, keypair.private_key_b64);\n\nconsole.log(result.execution.execution_id);\n```\n\n### Host Mode\n\n```typescript\nimport { createHostAdapter } from '@ekka-ai/sdk/host';\n\nconst adapter = createHostAdapter({\n  appId: 'my-app',\n  hostType: 'node',\n  capabilities: {\n    authorization: { grant: true, revoke: true },\n    execution: { run: true, status: true },\n    network: { allowedHosts: ['api.ekka.ai'] },\n  },\n});\n\n// Host adapter mediates all privileged operations\n```\n\n---\n\n## Why EKKA Is Secure by Design\n\nEKKA's security model is built on four foundational principles:\n\n### 1. Intent-Based Authorization\n\nEvery action in EKKA begins with an explicit authorization request. Applications declare *what* they want to do and *which resources* they need access to. There is no implicit permission inheritance, no \"god mode\" tokens, and no hidden scopes.\n\n```\nUser Intent → Authorization Request → Explicit Grant → Signed Execution\n```\n\nThis ensures that every action is auditable, traceable, and revocable.\n\n### 2. Cryptographic Signatures Per Action\n\nEach authorized action requires a fresh cryptographic signature from the requesting party. This signature:\n\n- Binds the action to a specific moment in time\n- Cannot be reused for different actions\n- Cannot be forged without the private key\n- Is verified before any operation proceeds\n\nSignatures are not stored credentials—they are single-use proofs of intent.\n\n### 3. No Ambient Trust\n\nEKKA does not rely on ambient authority. Being \"logged in\" does not grant implicit permission to perform sensitive operations. Every action must be:\n\n- Explicitly requested\n- Explicitly authorized\n- Explicitly signed\n- Explicitly executed\n\nThis eliminates entire classes of privilege escalation attacks.\n\n### 4. Hard Security Boundaries\n\nThe Host Adapter acts as an uncircumventable security checkpoint. All App Mode requests must pass through this boundary, where:\n\n- Capabilities are verified\n- Audit logs are generated\n- Policy is enforced\n- Blast radius is contained\n\nThere is no way for application code to bypass the Host Adapter.\n\n---\n\n## App Mode vs Host Mode (At a Glance)\n\n| Aspect | App Mode | Host Mode |\n|--------|----------|-----------|\n| **Trust Level** | Untrusted | Trusted |\n| **Environment** | Web apps, sandboxed processes, third-party code | EKKA desktop app, backend services, CLI |\n| **API Access** | `@ekka-ai/sdk` (public) | `@ekka-ai/sdk/host` (privileged) |\n| **Can authorize actions** | ✓ Yes | ✓ Yes |\n| **Can sign payloads** | ✓ Yes | ✓ Yes |\n| **Can execute actions** | ✓ Yes (through Host) | ✓ Yes (directly) |\n| **Can access infrastructure** | ✗ No | ✓ Yes |\n| **Can bypass capability checks** | ✗ No | ✗ No |\n| **Audit logging** | Automatic | Automatic |\n| **Blast radius if compromised** | Limited to granted capabilities | Full host access |\n\n**Key insight**: App Mode applications can only do what they've been explicitly authorized to do. Even if an app is fully compromised, the attacker cannot exceed the app's granted capabilities.\n\n---\n\n## How It Works\n\n### App Mode Flow\n\n```\n┌─────────────────────────────────────────────────────────────────────┐\n│                         APP MODE FLOW                               │\n├─────────────────────────────────────────────────────────────────────┤\n│                                                                     │\n│   ┌─────────┐    ┌───────────┐    ┌──────────┐    ┌─────────────┐  │\n│   │   App   │───▶│ authorize │───▶│  User    │───▶│   execute   │  │\n│   │         │    │   ( )     │    │  Signs   │    │     ( )     │  │\n│   └─────────┘    └───────────┘    └──────────┘    └──────┬──────┘  │\n│                                                          │         │\n│                                                          ▼         │\n│                     ┌────────────────────────────────────────┐     │\n│                     │           HOST ADAPTER                 │     │\n│                     │  ┌──────────────────────────────────┐  │     │\n│                     │  │  • Verify capabilities           │  │     │\n│                     │  │  • Enforce policy                │  │     │\n│                     │  │  • Generate audit log            │  │     │\n│                     │  │  • Route to EKKA                 │  │     │\n│                     │  └──────────────────────────────────┘  │     │\n│                     └────────────────────────────────────────┘     │\n│                                       │                            │\n│                                       ▼                            │\n│                              ┌─────────────┐                       │\n│                              │    EKKA     │                       │\n│                              │  Platform   │                       │\n│                              └─────────────┘                       │\n│                                                                     │\n│   ▸ App NEVER touches infrastructure directly                      │\n│   ▸ User signature is REQUIRED for every action                    │\n│   ▸ Host Adapter is the ONLY path to EKKA                          │\n│                                                                     │\n└─────────────────────────────────────────────────────────────────────┘\n```\n\n### Host Mode Flow\n\n```\n┌─────────────────────────────────────────────────────────────────────┐\n│                        HOST MODE FLOW                               │\n├─────────────────────────────────────────────────────────────────────┤\n│                                                                     │\n│   ┌─────────────┐                                                   │\n│   │  Trusted    │                                                   │\n│   │  Host App   │                                                   │\n│   │  (Desktop,  │                                                   │\n│   │   CLI,      │                                                   │\n│   │   Service)  │                                                   │\n│   └──────┬──────┘                                                   │\n│          │                                                          │\n│          ▼                                                          │\n│   ┌────────────────────────────────────────────────────────────┐   │\n│   │                    HOST ADAPTER                             │   │\n│   │  ┌────────────────────────────────────────────────────┐    │   │\n│   │  │  Capabilities Configuration:                        │    │   │\n│   │  │  ┌────────────────┐  ┌────────────────────────┐    │    │   │\n│   │  │  │ authorization: │  │ network:               │    │    │   │\n│   │  │  │   grant: ✓     │  │   allowedHosts: [...]  │    │    │   │\n│   │  │  │   revoke: ✓    │  │                        │    │    │   │\n│   │  │  └────────────────┘  └────────────────────────┘    │    │   │\n│   │  └────────────────────────────────────────────────────┘    │   │\n│   └──────────────────────────┬─────────────────────────────────┘   │\n│                              │                                      │\n│                              ▼                                      │\n│                     ┌─────────────┐                                 │\n│                     │    EKKA     │                                 │\n│                     │  Platform   │                                 │\n│                     └─────────────┘                                 │\n│                                                                     │\n│   ▸ Host has direct infrastructure access                          │\n│   ▸ Capabilities STILL gate all operations                         │\n│   ▸ Audit logging is STILL mandatory                               │\n│                                                                     │\n└─────────────────────────────────────────────────────────────────────┘\n```\n\n---\n\n## Threat Model (Simplified)\n\n### What happens if an App Mode application is compromised?\n\n| Threat | Mitigation |\n|--------|------------|\n| Attacker tries to execute unauthorized actions | Blocked. Every action requires explicit authorization. |\n| Attacker tries to reuse a previous signature | Blocked. Signatures are bound to specific actions and timestamps. |\n| Attacker tries to forge a signature | Blocked. Requires the private key, which is never transmitted. |\n| Attacker tries to escalate privileges | Blocked. Host Adapter enforces capability boundaries. |\n| Attacker tries to access infrastructure directly | Blocked. Infrastructure APIs are not exposed to App Mode. |\n| Attacker tries to impersonate another user | Blocked. Signatures are tied to cryptographic identity. |\n\n**Blast radius**: A compromised App Mode application can only perform actions that:\n1. It was already authorized to perform\n2. The user explicitly signs\n3. Fall within its granted capabilities\n\n### Why signatures prevent replay attacks\n\nEach authorization is bound to:\n- A specific action type\n- Specific resources\n- A specific timestamp\n- A specific key identity\n\nReplaying a signature for a different action, different resources, or at a later time will fail verification.\n\n### Why the Host Adapter prevents privilege escalation\n\nThe Host Adapter is not a passthrough—it is an enforcement point. Every request is:\n\n1. **Validated** against the app's declared capabilities\n2. **Logged** for audit purposes\n3. **Rejected** if it exceeds granted permissions\n\nThere is no configuration option to disable these checks. The security boundary is architectural, not policy-based.\n\n---\n\n## API Surface\n\n### Public Exports (`@ekka-ai/sdk`)\n\n| Export | Purpose |\n|--------|---------|\n| `authorize` | Request authorization for an action |\n| `sign` | Sign an authorization payload |\n| `execute` | Execute an authorized action |\n| `authorizeAndExecute` | Combined authorize → sign → execute |\n| `EkkaError` | Typed error for EKKA operations |\n| `createEkkaClient` | Initialize SDK client |\n| `AppModeTransport` | Sandboxed transport for app code |\n| `auth` | Authentication utilities |\n| `ed25519` | Cryptographic signing |\n| `canonicalize` | Deterministic JSON serialization |\n\n### Host Exports (`@ekka-ai/sdk/host`)\n\n| Export | Purpose |\n|--------|---------|\n| `createHostAdapter` | Create capability-gated adapter |\n| `HostAdapter` | Capability enforcement boundary |\n| `TauriTransport` | Tauri IPC transport |\n\n### Node Utilities (`@ekka-ai/sdk/node`)\n\n| Export | Purpose |\n|--------|---------|\n| `loadScenarioPack` | Load scenario definitions from filesystem |\n\n## Security Guarantees\n\n- **Export boundaries enforced**: Only documented entry points are importable\n- **Capability gating**: All operations validate against declared capabilities\n- **Trusted runtime required**: `@ekka-ai/sdk/host` requires Node.js or Tauri\n- **No ambient authority**: Every action requires explicit authorization and signature\n\n## Version\n\n0.9.7\n\n## License\n\nMIT\n","readmeFilename":"README.md"}