{"_id":"@cedar-policy/mcp-schema-generator-wasm","_rev":"2-0202596328352ecc6f23193d55dbaea7","name":"@cedar-policy/mcp-schema-generator-wasm","dist-tags":{"latest":"0.6.1"},"versions":{"0.6.0":{"name":"@cedar-policy/mcp-schema-generator-wasm","version":"0.6.0","keywords":["cedar","authorization","security","agents","mcp"],"license":"Apache-2.0","_id":"@cedar-policy/mcp-schema-generator-wasm@0.6.0","maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"homepage":"https://cedarpolicy.com","bugs":{"url":"https://github.com/cedar-policy/cedar-for-agents/issues"},"dist":{"shasum":"c90ae6ff876af5117e423369a83e01ef06557a7c","tarball":"https://registry.npmjs.org/@cedar-policy/mcp-schema-generator-wasm/-/mcp-schema-generator-wasm-0.6.0.tgz","fileCount":5,"integrity":"sha512-X52DtpYwoYqm6e1ddUE2jNuLt98rIM7cfJpOuKfJn3RGtbzxjk2oSg5g3v4oNoXX/GKWmXCo7i/akrJA9AtGVA==","signatures":[{"sig":"MEQCICGCcND2LoPm1WIb50PQLESFnWX2hps8cbmzstaPwMtOAiAqgpRTd5pB1S/0xAkbYuuiWwG51gvvOyzERarb7mu0ew==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3775639},"main":"cedar_policy_mcp_schema_generator_wasm.js","types":"cedar_policy_mcp_schema_generator_wasm.d.ts","gitHead":"ecbc4b98da79089120b309ab3cf0c104b1de7021","_npmUser":{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"},"repository":{"url":"git+https://github.com/cedar-policy/cedar-for-agents.git","type":"git"},"_npmVersion":"11.10.0","description":"WASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript.","directories":{},"sideEffects":false,"_nodeVersion":"20.19.2","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-schema-generator-wasm_0.6.0_1781025477273_0.8564779619463876","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"_id":"@cedar-policy/mcp-schema-generator-wasm@0.6.1","bugs":{"url":"https://github.com/cedar-policy/cedar-for-agents/issues"},"dist":{"shasum":"b709bc5627d6fe13e3d84c2f99e1a88b2919f397","tarball":"https://registry.npmjs.org/@cedar-policy/mcp-schema-generator-wasm/-/mcp-schema-generator-wasm-0.6.1.tgz","fileCount":5,"integrity":"sha512-MRbEm+S6xo/xL2TEk3jWzJS36A1upvPf56PZzb8dFDAuqFDzI2sf52q9T3JvpLvF46R8/Vdb1uDum/TXM5vqKQ==","signatures":[{"sig":"MEYCIQDQj+yk12Xg4uA7A+7pd7w08KdqSUh5+iqgM2FbCa5cfwIhAKENzRTvO7HLTnCq6zi7mCj4pJnOfhuCryiIk9F2E8kc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHKOG+X1YfVvb5S8q0EcUXWcrxSXAMToI6HRYQZ0/y03AiEAhzP6vwG97HKA2LOf12reM8+kVE08TX5aK2XrBxD/I/g="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@cedar-policy%2fmcp-schema-generator-wasm@0.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3603291},"main":"cedar_policy_mcp_schema_generator_wasm.js","name":"@cedar-policy/mcp-schema-generator-wasm","types":"cedar_policy_mcp_schema_generator_wasm.d.ts","gitHead":"144f4b579daae3b2cfdeea54f76285ad4efade50","license":"Apache-2.0","version":"0.6.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ef40adf0-ede7-4e38-aaf6-6d2fb8d9934e"}},"homepage":"https://cedarpolicy.com","keywords":["cedar","authorization","security","agents","mcp"],"repository":{"url":"git+https://github.com/cedar-policy/cedar-for-agents.git","type":"git"},"_npmVersion":"11.19.1","description":"WASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript.","directories":{},"maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"sideEffects":false,"_nodeVersion":"26.10.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-schema-generator-wasm_0.6.1_1790191629218_0.4085442794737657"}}},"time":{"created":"2026-06-09T17:17:57.169Z","modified":"2026-09-23T19:27:09.694Z","0.6.0":"2026-06-09T17:17:57.515Z","0.6.1":"2026-09-23T19:27:09.330Z"},"bugs":{"url":"https://github.com/cedar-policy/cedar-for-agents/issues"},"license":"Apache-2.0","homepage":"https://cedarpolicy.com","keywords":["cedar","authorization","security","agents","mcp"],"repository":{"url":"git+https://github.com/cedar-policy/cedar-for-agents.git","type":"git"},"description":"WASM bindings for cedar-policy-mcp-schema-generator, exposing SchemaGenerator to JavaScript/TypeScript.","maintainers":[{"name":"szegheon-aws","email":"szegheon@amazon.com"},{"name":"morevct","email":"morevct@amazon.com"},{"name":"kevhak","email":"kevhak@amazon.com"},{"name":"cedar-wasm-team","email":"cedar-wasm-team@amazon.com"}],"readme":"# cedar-policy-mcp-schema-generator-wasm\n\nWASM bindings for [cedar-policy-mcp-schema-generator](../cedar-policy-mcp-schema-generator/), exposing `SchemaGenerator` to JavaScript and TypeScript via `wasm-bindgen`.\n\nThis enables Node.js and browser environments to generate Cedar authorization schemas from MCP tool descriptions with the **exact same behavior** as the Rust implementation, including correct handling of:\n\n- JSON `number` as `Long` or `Decimal` (configurable)\n- `additionalProperties` as Cedar tagged entities\n- Namespaced type deduplication for nested objects\n\n## Usage\n\nInstall the npm package:\n\n```bash\nnpm install @cedar-policy/mcp-schema-generator-wasm\n```\n\n```javascript\nconst { generateSchema } = require('@cedar-policy/mcp-schema-generator-wasm');\n\nconst stub = `\nnamespace MyServer {\n    @mcp_principal\n    entity User;\n    @mcp_resource\n    entity McpServer;\n    action \"call_tool\" appliesTo {\n        principal: [User],\n        resource: [McpServer]\n    };\n}\n`;\n\nconst tools = JSON.stringify([\n  {\n    name: 'read_file',\n    description: 'Read a file from disk',\n    inputSchema: {\n      type: 'object',\n      properties: { path: { type: 'string' } },\n      required: ['path'],\n    },\n  },\n]);\n\nconst result = JSON.parse(generateSchema(stub, tools));\n\nif (result.isOk) {\n  console.log(result.schema);     // Human-readable .cedarschema\n  console.log(result.schemaJson); // JSON for Cedar WASM isAuthorized()\n} else {\n  console.error(result.error);\n}\n```\n\n## API\n\n### `generateSchema(schemaStub, toolsJson, configJson?)`\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `schemaStub` | `string` | Cedar schema stub with `@mcp_principal` and `@mcp_resource` annotations |\n| `toolsJson` | `string` | MCP tool descriptions as JSON (the `tools` array from `tools/list`) |\n| `configJson` | `string?` | Optional configuration as JSON |\n\n**Returns:** JSON string with fields:\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `schema` | `string \\| null` | Generated Cedar schema as `.cedarschema` text |\n| `schemaJson` | `string \\| null` | Generated schema as JSON (for `isAuthorized()`) |\n| `error` | `string \\| null` | Error message if generation failed |\n| `isOk` | `boolean` | Whether generation succeeded |\n\n### Configuration\n\n```json\n{\n  \"includeOutputs\": false,\n  \"objectsAsRecords\": false,\n  \"eraseAnnotations\": true,\n  \"flattenNamespaces\": false,\n  \"numbersAsDecimal\": false,\n  \"deduplicateEntityTypes\": false\n}\n```\n\n| Option | Default | Description |\n|--------|---------|-------------|\n| `includeOutputs` | `false` | Include tool output schemas in actions |\n| `objectsAsRecords` | `false` | Use records instead of entities for objects without `additionalProperties` |\n| `eraseAnnotations` | `true` | Remove `@mcp_*` annotations from output |\n| `flattenNamespaces` | `false` | Flatten all types into a single namespace |\n| `numbersAsDecimal` | `false` | Encode JSON `number` as Cedar `Decimal` instead of `Long` |\n| `deduplicateEntityTypes` | `false` | Consolidate identical entity types across tools into the lowest common ancestor namespace |\n\n### `generateRequest(schemaStub, toolsJson, inputJson, principalType, principalId, resourceType, resourceId, configJson?)`\n\nGenerates Cedar authorization request components from an MCP tool call.\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `schemaStub` | `string` | Cedar schema stub (same as `generateSchema`) |\n| `toolsJson` | `string` | MCP tool descriptions as JSON |\n| `inputJson` | `string` | MCP tool call input (`{\"params\": {\"tool\": \"...\", \"args\": {...}}}`) |\n| `principalType` | `string` | Cedar entity type for the principal (e.g., `\"User\"`) |\n| `principalId` | `string` | Principal identifier (e.g., `\"alice\"`) |\n| `resourceType` | `string` | Cedar entity type for the resource (e.g., `\"McpServer\"`) |\n| `resourceId` | `string` | Resource identifier (e.g., `\"my-server\"`) |\n| `configJson` | `string?` | Optional configuration as JSON |\n\n**Returns:** JSON string with fields:\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `principal` | `string \\| null` | Principal EntityUID (e.g., `MyServer::User::\"alice\"`) |\n| `action` | `string \\| null` | Action EntityUID (e.g., `MyServer::Action::\"read_file\"`) |\n| `resource` | `string \\| null` | Resource EntityUID (e.g., `MyServer::McpServer::\"my-server\"`) |\n| `entitiesJson` | `string \\| null` | Entities as a JSON array string |\n| `error` | `string \\| null` | Error message if generation failed |\n| `isOk` | `boolean` | Whether generation succeeded |\n\n**Example:**\n\n```javascript\nconst { generateRequest } = require('@cedar-policy/mcp-schema-generator-wasm');\n\nconst stub = `\nnamespace MyServer {\n    @mcp_principal\n    entity User;\n    @mcp_resource\n    entity McpServer;\n    action \"call_tool\" appliesTo {\n        principal: [User],\n        resource: [McpServer]\n    };\n}\n`;\n\nconst tools = JSON.stringify([\n  {\n    name: 'read_file',\n    description: 'Read a file from disk',\n    inputSchema: {\n      type: 'object',\n      properties: { path: { type: 'string' } },\n      required: ['path'],\n    },\n  },\n]);\n\nconst input = JSON.stringify({\n  params: { tool: 'read_file', args: { path: '/etc/config.yaml' } },\n});\n\nconst result = JSON.parse(\n  generateRequest(stub, tools, input, 'User', 'alice', 'McpServer', 'my-server')\n);\n\nif (result.isOk) {\n  console.log(result.principal);    // MyServer::User::\"alice\"\n  console.log(result.action);       // MyServer::Action::\"read_file\"\n  console.log(result.resource);     // MyServer::McpServer::\"my-server\"\n  console.log(result.entitiesJson); // JSON array of entities for isAuthorized()\n} else {\n  console.error(result.error);\n}\n```\n\n## Building\n\n```bash\n# Install wasm-pack\ncargo install wasm-pack\n\n# Build for Node.js\nwasm-pack build --target nodejs --scope cedar-policy\n\n# Build for browsers\nwasm-pack build --target web --scope cedar-policy\n```\n\n## npm Release\n\nThe npm package name is:\n\n```text\n@cedar-policy/mcp-schema-generator-wasm\n```\n\nThe Rust crate name remains `cedar-policy-mcp-schema-generator-wasm`. During\nrelease, the generated `wasm-pack` package metadata is normalized so the npm\npackage uses the shorter name above while preserving the `Cargo.toml` version.\n\nReleases are performed manually through the\n`Publish MCP schema generator WASM to npm` GitHub Actions workflow. The workflow:\n\n1. validates that it is triggered from `main`;\n2. validates a tag of the form\n   `cedar-policy-mcp-schema-generator-wasm-v<MAJOR>.<MINOR>.<PATCH>`;\n3. checks that the tag version matches this crate's `Cargo.toml`;\n4. runs `wasm-pack build --target nodejs --scope cedar-policy`;\n5. normalizes the generated npm package metadata;\n6. runs `npm pack --dry-run`; and\n7. computes the correct npm dist-tag; and\n8. publishes with `npm publish --access public --tag <tag> --provenance`.\n\nThe workflow expects npm authentication to use npm trusted publishing through\nthe repository's release environment. It does not require an `NPM_TOKEN` secret.\n\n## Relationship to the Rust Generator\n\nThis crate is a thin `wasm-bindgen` wrapper around the existing `cedar-policy-mcp-schema-generator` Rust crate. All schema generation logic, type mapping, and edge case handling is delegated to the Rust implementation. The WASM bindings add no independent logic.\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}