{"_id":"402coffee-verify-credential","name":"402coffee-verify-credential","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"402coffee-verify-credential","version":"0.1.0","description":"Verify 402.coffee signed credentials and arbiter verdicts OFFLINE. Ed25519 detached JWS over JCS-canonical JSON — check any agent's conformance credential or any escrow verdict without trusting the transport. Zero dependencies.","type":"module","main":"index.js","types":"index.d.ts","bin":{"402coffee-verify-credential":"bin/402coffee-verify-credential.js"},"exports":{".":{"types":"./index.d.ts","import":"./index.js"}},"engines":{"node":">=18"},"keywords":["x402","agent","credential","verifiable-credential","ed25519","jws","arbiter","escrow","trust","402.coffee"],"license":"MIT","homepage":"https://api.402.coffee/docs","_id":"402coffee-verify-credential@0.1.0","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-QDggXZwaxndD6khWyLrk0CSknuUdq+1XTzjq9jpWN+V474oqi5mHSfWCOvopz2nSfDxbdF9WXRZLeqqKZm04gQ==","shasum":"2fce644640dc478dc5da2847a4e5c90e6a98f936","tarball":"https://registry.npmjs.org/402coffee-verify-credential/-/402coffee-verify-credential-0.1.0.tgz","fileCount":5,"unpackedSize":10762,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCxaXp7i5pMqxUGK5p/DRMW2QL2IdTGAjSDUORq/23UfwIhANnAgnSA+7Ewvv9uexzbirocj9bJ7rr8e7+r/4EUP87S"}]},"_npmUser":{"name":"englishdoggy","email":"ebookthe@gmail.com"},"directories":{},"maintainers":[{"name":"englishdoggy","email":"ebookthe@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/402coffee-verify-credential_0.1.0_1783716106199_0.9530209823406273"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-10T20:41:46.076Z","0.1.0":"2026-07-10T20:41:46.333Z","modified":"2026-07-10T20:41:46.554Z"},"maintainers":[{"name":"englishdoggy","email":"ebookthe@gmail.com"}],"description":"Verify 402.coffee signed credentials and arbiter verdicts OFFLINE. Ed25519 detached JWS over JCS-canonical JSON — check any agent's conformance credential or any escrow verdict without trusting the transport. Zero dependencies.","homepage":"https://api.402.coffee/docs","keywords":["x402","agent","credential","verifiable-credential","ed25519","jws","arbiter","escrow","trust","402.coffee"],"license":"MIT","readme":"# 402coffee-verify-credential\n\nVerify [402.coffee](https://402.coffee) signed credentials and arbiter verdicts — **offline**. Zero dependencies.\n\n402.coffee signs every conformance credential (`GET /credential/0x…`) and every external-arbiter verdict (`POST /arbiter/verify`) with an Ed25519 key published at [`/.well-known/jwks.json`](https://api.402.coffee/.well-known/jwks.json). The signature is a detached JWS (EdDSA) over the [RFC 8785 (JCS)](https://www.rfc-editor.org/rfc/rfc8785) canonicalized document with `proof`, `note`, and `signing_note` removed.\n\n- **Signature verifies offline** — no trust in the transport, pin the JWKS and verify air-gapped.\n- **Freshness needs the live call** — each conformance entry is valid 30 days; `verifyLive` checks both.\n\n## Install\n\n```bash\nnpm i 402coffee-verify-credential\n```\n\n## Use\n\n```js\nimport { verifyDocument, verifyLive } from \"402coffee-verify-credential\";\n\n// 1) Verify any saved credential or arbiter verdict (offline with pinned keys)\nconst result = await verifyDocument(savedDoc, { jwks: pinnedKeys }); // omit jwks → fetched once\n// → { valid: true, kid: \"…\", signed_at: \"2026-…\" }\n\n// 2) Fetch an agent's credential live: signature + freshness in one call\nconst live = await verifyLive(\"0xAgentWallet\");\n// → { valid: true, verified: true, tested: true, expired_entries: 0, credential: {…} }\n```\n\n## CLI\n\n```bash\nnpx 402coffee-verify-credential 0xAgentWallet          # live: fetch + verify + freshness\nnpx 402coffee-verify-credential --file verdict.json    # verify a saved doc (JWKS fetched once)\nnpx 402coffee-verify-credential --file doc.json --jwks keys.json   # fully offline\n```\n\nExit code `0` = valid, `1` = invalid, `2` = usage error. Output is JSON.\n\n## What a verdict/credential proves\n\nA **credential** is 402.coffee's record of behaviour it directly observed on-chain: the agent completed a real x402 payment, refused an over-priced bait, refused a swapped recipient. An **arbiter verdict** (`release` / `refund` / `escalate`) is a machine-verified delivery check any escrow can execute — policy at [`/arbiter/policy`](https://api.402.coffee/arbiter/policy).\n\nThe signature proves the document came from 402.coffee and wasn't altered. It does **not** by itself prove freshness — for \"is this still current?\" call `verifyLive` or `GET /verify?wallet=0x…`.\n\nMIT · [docs](https://api.402.coffee/docs) · [integrations](https://api.402.coffee/integrations)\n","readmeFilename":"README.md","_rev":"1-b0f084a759d33b8a57193a875eeb6c38"}