{"_id":"@mizara/sdk","_rev":"31-f5e538871b4607f8b74a98298474af6d","name":"@mizara/sdk","dist-tags":{"latest":"1.2.0"},"versions":{"1.0.0":{"name":"@mizara/sdk","version":"1.0.0","keywords":["ai-agents","authorization","policy-engine","access-control","llm","agent-security"],"license":"Apache-2.0","_id":"@mizara/sdk@1.0.0","maintainers":[{"name":"mizara-dev","email":"mizara.domain@gmail.com"}],"homepage":"https://github.com/getmizara/mizara-node#readme","bugs":{"url":"https://github.com/getmizara/mizara-node/issues"},"bin":{"mizara":"dist/cli/index.js","mizara-mcp":"dist/mcp/index.js"},"dist":{"shasum":"3218623a79b98b3597bcba402e52ac34f79fd1a5","tarball":"https://registry.npmjs.org/@mizara/sdk/-/sdk-1.0.0.tgz","fileCount":55,"integrity":"sha512-cSs5R1Hn3kveWlvNsa2MraxjnTHS+EeIQmcZRsTtRtmavBBplKLSWG+353J8trKVtUwpscZguKiaj1fleKODGw==","signatures":[{"sig":"MEUCIQD5KZMCwnflmU6PPDpNGbk5C6wWgsVUOZc+6JDwCxsDMQIgZPpEA7vrBPUGLmf3N7RimqRXYkgSOGdLPffrls0tQR0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":109876},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./engine":{"types":"./dist/engine/decision-engine.d.ts","default":"./dist/engine/decision-engine.js"},"./package.json":"./package.json"},"gitHead":"e6dae053572b8e2ee2b7590210e827a8eb7b3d04","scripts":{"lint":"eslint src test demo","test":"vitest run","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit","test:watch":"vitest","demo:simulate":"tsx demo/simulate.ts"},"_npmUser":{"name":"mizara-dev","email":"mizara.domain@gmail.com"},"repository":{"url":"git+https://github.com/getmizara/mizara-node.git","type":"git"},"_npmVersion":"10.9.1","description":"Mizara - programmable authorization layer for AI actions","directories":{},"_nodeVersion":"20.11.1","dependencies":{"zod":"^4.4.3","jsep":"^1.3.9","@cedar-policy/cedar-wasm":"^4.11.2","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","eslint":"^9.0.0","vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^20.0.0","typescript-eslint":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.0.0_1785185550400_0.8411085340890874","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@mizara/sdk","version":"1.1.0","keywords":["ai-agents","authorization","policy-engine","access-control","llm","agent-security"],"license":"Apache-2.0","_id":"@mizara/sdk@1.1.0","maintainers":[{"name":"mizara-dev","email":"mizara.domain@gmail.com"}],"homepage":"https://github.com/getmizara/mizara-node#readme","bugs":{"url":"https://github.com/getmizara/mizara-node/issues"},"bin":{"mizara":"dist/cli/index.js","mizara-mcp":"dist/mcp/index.js"},"dist":{"shasum":"73dac875875b9e9cb1b02fd0f9fee6fa07c11bfd","tarball":"https://registry.npmjs.org/@mizara/sdk/-/sdk-1.1.0.tgz","fileCount":59,"integrity":"sha512-Qfh6RJiM9k3UHiLsTqEJkQncKTMj5l5Gwe0Ol8UefOktTUdiOVENHk0jRpD6Oelu74bGncI5B4pOAA1SfRSA2Q==","signatures":[{"sig":"MEUCIQCbfAAczCYb/7w8EJbkSKD5lKmfNgXhqiybejOrw/d65gIgJRdJo/yWCSBQExsVqvd3Xy2BKniWjD8HAg7b8NxLX0Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":122217},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./engine":{"types":"./dist/engine/decision-engine.d.ts","default":"./dist/engine/decision-engine.js"},"./package.json":"./package.json"},"gitHead":"6aae7e0964547af6096dd949c1e99384307e02ed","scripts":{"lint":"eslint src test demo","test":"vitest run","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit","test:watch":"vitest","demo:simulate":"tsx demo/simulate.ts"},"_npmUser":{"name":"mizara-dev","email":"mizara.domain@gmail.com"},"repository":{"url":"git+https://github.com/getmizara/mizara-node.git","type":"git"},"_npmVersion":"10.9.1","description":"Mizara - programmable authorization layer for AI actions","directories":{},"_nodeVersion":"20.11.1","dependencies":{"zod":"^4.4.3","jsep":"^1.3.9","@cedar-policy/cedar-wasm":"^4.11.2","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","eslint":"^9.0.0","vitest":"^2.1.0","typescript":"^5.7.0","@types/node":"^20.0.0","typescript-eslint":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.1.0_1785371158995_0.9185064918032264","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@mizara/sdk","version":"1.2.0","description":"Mizara - programmable authorization layer for AI actions","license":"Apache-2.0","keywords":["ai-agents","authorization","policy-engine","access-control","llm","agent-security"],"repository":{"type":"git","url":"git+https://github.com/getmizara/mizara-node.git"},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./engine":{"types":"./dist/engine/decision-engine.d.ts","default":"./dist/engine/decision-engine.js"},"./integrations/openai-agents":{"types":"./dist/integrations/openai-agents.d.ts","default":"./dist/integrations/openai-agents.js"},"./package.json":"./package.json"},"bin":{"mizara":"dist/cli/index.js","mizara-mcp":"dist/mcp/index.js"},"scripts":{"prepare":"tsc","build":"tsc","typecheck":"tsc --noEmit","test":"vitest run","test:watch":"vitest","lint":"eslint src test demo","demo:simulate":"tsx demo/simulate.ts"},"dependencies":{"@cedar-policy/cedar-wasm":"^4.11.2","@modelcontextprotocol/sdk":"^1.29.0","jsep":"^1.3.9","zod":"^4.4.3"},"peerDependencies":{"@openai/agents-core":"^0.12.0"},"peerDependenciesMeta":{"@openai/agents-core":{"optional":true}},"devDependencies":{"@openai/agents-core":"^0.12.1","@types/node":"^20.0.0","eslint":"^9.0.0","tsx":"^4.19.0","typescript":"^5.7.0","typescript-eslint":"^8.0.0","vitest":"^2.1.0"},"_id":"@mizara/sdk@1.2.0","gitHead":"4c669a57179a495046479ae52d5b73a105e59788","bugs":{"url":"https://github.com/getmizara/mizara-node/issues"},"homepage":"https://github.com/getmizara/mizara-node#readme","_nodeVersion":"20.11.1","_npmVersion":"10.9.1","dist":{"integrity":"sha512-r5nPZc4Kq2UBjmo+6KipQhFQEy/pl0aGWMjcRq5UuzR0LLCaSwuMsEXUsNB3SqICL2oH5lVYIKIXx+CROSkjbA==","shasum":"f159eed70c643f1cbb2bf6a511ada08e10db38a0","tarball":"https://registry.npmjs.org/@mizara/sdk/-/sdk-1.2.0.tgz","fileCount":63,"unpackedSize":128648,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCf9QAlyBYirUl+zbLhC8vRxGoL4f+WqaiLSA2WQaKc+QIgFOOn0KY9ymTZf/O3rZBmzbX4xoi4L1PgUo5TmnkTqOc="}]},"_npmUser":{"name":"mizara-dev","email":"mizara.domain@gmail.com"},"directories":{},"maintainers":[{"name":"mizara-dev","email":"mizara.domain@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_1.2.0_1785478788116_0.9940485207395173"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-01T00:19:38.112Z","modified":"2026-07-31T06:19:48.402Z","0.1.0":"2026-07-01T00:19:38.341Z","0.1.1":"2026-07-01T03:38:10.432Z","0.1.2":"2026-07-01T03:47:29.687Z","0.1.3":"2026-07-01T04:08:54.834Z","0.1.4":"2026-07-03T16:38:03.801Z","0.1.5":"2026-07-07T00:24:09.603Z","0.2.0":"2026-07-11T16:38:07.649Z","0.3.0":"2026-07-13T06:50:14.148Z","0.4.0":"2026-07-13T23:24:56.653Z","0.5.0":"2026-07-14T03:53:08.377Z","0.6.0":"2026-07-21T03:10:30.558Z","0.7.0":"2026-07-23T04:45:17.501Z","0.7.1":"2026-07-23T05:12:08.050Z","1.0.0":"2026-07-27T20:52:30.545Z","1.1.0":"2026-07-30T00:25:59.164Z","1.2.0":"2026-07-31T06:19:48.260Z"},"bugs":{"url":"https://github.com/getmizara/mizara-node/issues"},"license":"Apache-2.0","homepage":"https://github.com/getmizara/mizara-node#readme","keywords":["ai-agents","authorization","policy-engine","access-control","llm","agent-security"],"repository":{"type":"git","url":"git+https://github.com/getmizara/mizara-node.git"},"description":"Mizara - programmable authorization layer for AI actions","maintainers":[{"name":"mizara-dev","email":"mizara.domain@gmail.com"}],"readme":"<p align=\"center\">\n  <a href=\"https://mizara.ai\"><img src=\"assets/logo-banner.svg\" width=\"340\" alt=\"mizara\"></a>\n</p>\n\n<p align=\"center\"><a href=\"https://mizara.ai\">mizara.ai</a></p>\n\n<p align=\"center\">\n  <a href=\"https://github.com/getmizara/mizara-node/actions/workflows/ci.yml\"><img src=\"https://github.com/getmizara/mizara-node/actions/workflows/ci.yml/badge.svg\" alt=\"CI\"></a>\n  <a href=\"https://www.npmjs.com/package/@mizara/sdk\"><img src=\"https://img.shields.io/npm/v/%40mizara%2Fsdk?color=cb3837\" alt=\"npm\"></a>\n  <a href=\"https://github.com/getmizara/mizara-node/commits/main\"><img src=\"https://img.shields.io/github/last-commit/getmizara/mizara-node\" alt=\"Last commit\"></a>\n  <a href=\"LICENSE.md\"><img src=\"https://img.shields.io/badge/license-Apache%202.0-blue\" alt=\"License\"></a>\n</p>\n\nAuthorization layer for AI agents. Call `authorize()` before any consequential action. Sub-2ms evaluation, policy-as-data, cryptographic receipt on every decision.\n\nAlso available for Python: [`pip install mizara`](https://github.com/getmizara/mizara-python)\n\n## Install\n\n```bash\nnpm install @mizara/sdk\n```\n\n## Quickstart\n\n### Local policy file\n\n```ts\nimport { createMizaraClient } from '@mizara/sdk';\n\nconst mizara = createMizaraClient({ policyPath: './policy.json' });\n\nconst result = await mizara.authorize({\n  actor:    { id: 'agent_ops_v4', type: 'autonomous_agent' },\n  action:   { name: 'delete_production_resource' },\n  resource: { type: 'cloud_resource', id: 'res_9c21',\n               attributes: { environment: 'production' } },\n});\n\nif (result.status === 'DENY') {\n  throw new Error(result.enforcement.user_facing_error);\n}\n// result.status                   -> 'ALLOW' | 'DENY' | 'REDACT' | 'RE_ROUTE'\n// result.cryptographic_receipt.id -> 'rcpt_8f3c...'\n```\n\n### Hosted API\n\nSign up at [mizara.ai/signup](https://mizara.ai/signup) to skip the local file:\n\n```ts\nimport { createMizaraClient } from '@mizara/sdk';\n\nconst mizara = createMizaraClient({\n  apiKey:   process.env.MIZARA_API_KEY!,\n  clientId: 'acme_corp',\n});\n\nconst result = await mizara.authorize({\n  actor:    { id: 'agent_1', type: 'autonomous_agent' },\n  action:   { name: 'delete_production_resource' },\n  resource: { type: 'cloud_resource', id: 'res_1',\n               attributes: { environment: 'production' } },\n});\n```\n\nHosted mode evaluates locally against a policy snapshot that's refreshed in the background (every 10s by default). A Mizara outage doesn't fail every `authorize()` call, it keeps using the last policy successfully fetched. Receipts are generated locally and flushed to the hosted API asynchronously. For zero-loss delivery across a process crash, pass `receiptLogPath`:\n\n```ts\nconst mizara = createMizaraClient({\n  apiKey:   process.env.MIZARA_API_KEY!,\n  clientId: 'acme_corp',\n  receiptLogPath: './mizara-receipts.log',\n  onSyncError: (err) => console.error('[mizara] policy sync failing:', err.message),\n});\n```\n\nCall `mizara.close()` before your process exits to stop the background sync and flush timers (a no-op in local mode, safe to always call).\n\n### Waiting on a RE_ROUTE decision\n\nA `RE_ROUTE` result means the action is held pending human approval. In hosted mode, `waitForApproval` polls until it's approved, denied, or the timeout elapses:\n\n```ts\nconst result = await mizara.authorize({ /* ... */ });\n\nif (result.status === 'RE_ROUTE') {\n  const outcome = await mizara.waitForApproval!(result.cryptographic_receipt.id);\n  // outcome: 'APPROVED' | 'DENIED' | 'TIMEOUT'\n}\n```\n\nOnly present in hosted mode; local mode has no server to hold pending approval state. Defaults to polling every 3s for up to 25 minutes.\n\n### Verifying receipts\n\nEvery receipt is signed with Ed25519, an asymmetric algorithm. Verification only needs the public key, not a call back to Mizara or the signing secret:\n\n```ts\nimport { verifyReceipt, getPublicKey } from '@mizara/sdk';\n\nconst publicKey = getPublicKey(); // or fetch from GET /api/v1/public-key in hosted mode\nconst isValid = verifyReceipt(result.cryptographic_receipt, publicKey);\n```\n\nSet `MIZARA_SIGNING_PRIVATE_KEY` (a base64-encoded 32-byte Ed25519 seed) so the same key persists across restarts. Without it, a fresh key is generated per process and receipts stop being verifiable once it exits.\n\n## Policy format\n\nPlain JSON. No Rego, no Cedar syntax.\n\n```json\n{\n  \"policy_id\": \"pol_infra_guard_v1\",\n  \"client_id\": \"acme_corp\",\n  \"rules\": [\n    {\n      \"id\": \"rule_block_prod_delete\",\n      \"target_action\": \"delete_production_resource\",\n      \"condition\": \"resource.attributes.environment == 'production'\",\n      \"effect\": \"DENY\",\n      \"fallback_effect\": \"ALLOW\",\n      \"remediation_message\": \"Production deletion requires approval.\"\n    }\n  ]\n}\n```\n\nCondition expressions support comparisons, boolean logic, arithmetic, and `.contains()`:\n\n```text\nresource.attributes.amount <= 50.00\ncontext.jurisdiction == 'EU' && context.data_classification.contains('PII')\ncontext.session_total + resource.attributes.amount <= 500\n```\n\n## CLI\n\n```bash\nnpx mizara validate policy.json   # checks structure and condition syntax\nnpx mizara test policy.json       # checks coverage against 6 common risk scenarios\nnpx mizara test policy.json --json\n```\n\n`mizara test` runs six single-call scenarios spanning infrastructure, external\ncommunication, and sensitive data through your actual policy and reports, per\nscenario, whether a rule you wrote explicitly catches it (`PROTECTED`),\nwhether it's only blocked by the fail-closed default because nothing matched\n(`DEFAULT-DENIED`), or whether it would go through (`FAIL`). Exits non-zero if\nany scenario fails, so it drops into CI as-is.\n\n## Integrations\n\n| Framework | Example |\n| --- | --- |\n| LangGraph | [`examples/langgraph/`](examples/langgraph/) |\n| OpenAI Agents SDK | [`examples/openai-agents/`](examples/openai-agents/) |\n| Hosted API | [`examples/hosted-api/`](examples/hosted-api/) |\n| MCP (Claude Desktop, Claude Code) | see below |\n\n### OpenAI Agents SDK\n\n```ts\nimport { tool } from '@openai/agents';\nimport { createMizaraClient } from '@mizara/sdk';\nimport { mizaraGuardrail } from '@mizara/sdk/integrations/openai-agents';\n\nconst mizara = createMizaraClient({ policyPath: './policy.json' });\n\nconst deleteResource = tool({\n  name: 'delete_resource',\n  parameters: { /* ... */ },\n  inputGuardrails: [mizaraGuardrail(mizara)],\n  execute: async (params) => { /* ... */ },\n});\n```\n\n`mizaraGuardrail()` runs as an `inputGuardrail` - a policy decision happens\nbefore the tool executes, and a non-`ALLOW` result blocks the call. Unlike\nexposing `authorize()` as a separate tool the model has to remember to call,\nthis can't be skipped by the model just not calling it. Requires the\n`@openai/agents-core` peer dependency (already installed alongside\n`@openai/agents`).\n\n## MCP server\n\n`@mizara/sdk` ships an MCP server that exposes `authorize()` as a tool - `mizara_authorize` - to any MCP-compatible agent.\n\n```bash\nnpm install -g @mizara/sdk\n```\n\nAdd to your MCP client config (e.g. Claude Desktop's `claude_desktop_config.json`):\n\n```json\n{\n  \"mcpServers\": {\n    \"mizara\": {\n      \"command\": \"mizara-mcp\",\n      \"args\": [\"--policy\", \"/absolute/path/to/your/policy.json\"]\n    }\n  }\n}\n```\n\nRestart the client. The agent now has `mizara_authorize` in its tool list and gets a signed receipt back with every call.\n\n## Design choices\n\n**Fail closed.** No matching rule returns `DENY`, not `ALLOW`.\n\n**Most restrictive wins.** When more than one rule matches an action, the most restrictive triggered outcome wins - `DENY` > `RE_ROUTE` > `REDACT` > `ALLOW` - regardless of rule order.\n\n**Resilient by default, with one honest exception.** Hosted mode evaluates locally against a synced policy, so a Mizara outage doesn't stop your agent. A rule that uses `context.session_total` is the one case that can't get this guarantee: cumulative tracking is inherently centralized state, so if the session store is unreachable, that specific request fails closed rather than silently trusting a stale total.\n\n**Policy as data.** Rules live in a JSON file that non-engineers can edit without a deploy.\n\n**No Cedar or Rego.** Conditions are plain boolean expressions. The engine compiles them safely without `eval()`.\n\n**Receipt on every call.** Even `ALLOW` decisions are signed and stored. The audit trail is part of the product, not an afterthought.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}