{"_id":"@clossys/bouncer","_rev":"7-65bf77c29cf1b2a5742e569d41e94926","name":"@clossys/bouncer","dist-tags":{"latest":"0.1.10"},"versions":{"0.1.1":{"name":"@clossys/bouncer","version":"0.1.1","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"author":{"name":"Calvin Hung"},"license":"MIT","_id":"@clossys/bouncer@0.1.1","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","bugs":{"url":"https://github.com/clossys/foundry/issues"},"bin":{"bouncer-check":"dist/cli.js"},"dist":{"shasum":"9b55cccfceb9975a12809fd1a998c508fe1d6858","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.1.tgz","fileCount":174,"integrity":"sha512-byzh2hhFVIWUpfa1oVnYDtZbo+yMyPivfjh5RN37fUQ9g1JLlKP7c/fmoZjtG4dvkgL6Vi+wIp2GB3qgjx8SVg==","signatures":[{"sig":"MEYCIQDJS/E+dTSoNIVaJJqDid6S3uEJiFZ4Khr/DSSM/NCiRQIhAJUKVzT0To5bmxAY7FDBKcfq+U5GK+PAgBy6CU7GSzXM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":551527},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"_npmUser":{"name":"thecalvinhung","email":"hello@clossys.com"},"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.1","svix":"^1.96.0","react":"19.2.8","vitest":"^4.1.9","react-dom":"19.2.8","typescript":"~6.0.0","@types/node":"^22.10.0","@types/react":"^19.2.0","@clerk/nextjs":"7.7.5","@types/react-dom":"^19.2.0"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/bouncer_0.1.1_1788197384599_0.6294797372512722","host":"s3://npm-registry-packages-npm-production"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}},"0.1.2":{"name":"@clossys/bouncer","version":"0.1.2","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"author":{"name":"Calvin Hung"},"license":"MIT","_id":"@clossys/bouncer@0.1.2","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","bugs":{"url":"https://github.com/clossys/foundry/issues"},"bin":{"bouncer-check":"dist/cli.js"},"dist":{"shasum":"d2c285c84bd5b3479e7aaa3636fcab712c7cdfd5","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.2.tgz","fileCount":174,"integrity":"sha512-KRu9PMuXg1GBMcrD2ndkVyAn6RjKubdA4tEz7ArZCoxKx3h9pfNQh4/o0X+9N3+KZrPfi36foILEznSE6qMrxg==","signatures":[{"sig":"MEYCIQDusPD2E42EFY+8UIi+9CCSHjDctXdvwRf6g1lF/Lgr6wIhAOB6djVe14ngW20Rur7oIRERGCxqobrkfhge5PepFbES","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@clossys%2fbouncer@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":551774},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:25c9f070-e25c-4bed-9428-526936e29493"}},"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.1","svix":"^1.96.0","react":"19.2.8","vitest":"^4.1.9","react-dom":"19.2.8","typescript":"~6.0.0","@types/node":"^22.10.0","@types/react":"^19.2.0","@clerk/nextjs":"7.7.5","@types/react-dom":"^19.2.0"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/bouncer_0.1.2_1788269362771_0.03934256663193492","host":"s3://npm-registry-packages-npm-production"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}},"0.1.3":{"name":"@clossys/bouncer","version":"0.1.3","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"author":{"name":"Clossys"},"license":"MIT","_id":"@clossys/bouncer@0.1.3","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","bugs":{"url":"https://github.com/clossys/foundry/issues"},"bin":{"bouncer-check":"dist/cli.js"},"dist":{"shasum":"989c1bfcff4c2afcbec9a8acee4eaf4eef3ed99f","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.3.tgz","fileCount":174,"integrity":"sha512-7e9fXJjdOidz0us8KBQxuP4zW3RqL8cQhulOYLXHXSha3D5GGknEPdfQE61X1CwUJkfbG1jdlZ351A/7q3z3uQ==","signatures":[{"sig":"MEYCIQC1WOBsqCw/SLUfAtp69aDfBfNZTUJcGENZ5gDjhmwhZgIhAMh2zzdpscTgGwx2T8FBHPUN2+NOVucFPhfsO0SIjYc+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@clossys%2fbouncer@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":552211},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:25c9f070-e25c-4bed-9428-526936e29493"}},"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.1","svix":"^1.96.0","react":"19.2.8","vitest":"^4.1.9","react-dom":"19.2.8","typescript":"~6.0.0","@types/node":"^22.10.0","@types/react":"^19.2.0","@clerk/nextjs":"7.8.3","@types/react-dom":"^19.2.5"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/bouncer_0.1.3_1788456979648_0.7694282282715319","host":"s3://npm-registry-packages-npm-production"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}},"0.1.7":{"name":"@clossys/bouncer","version":"0.1.7","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"author":{"name":"Clossys"},"license":"MIT","_id":"@clossys/bouncer@0.1.7","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","bugs":{"url":"https://github.com/clossys/foundry/issues"},"bin":{"bouncer-check":"dist/cli.js"},"dist":{"shasum":"b84dcbe406f5e002d7d67df76cceeff54acce4e9","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.7.tgz","fileCount":174,"integrity":"sha512-/XuusonrhHU0VSCzn21e6dy78nwzX3SrbaIMQo4/JR360h6v9p0Ob53SoedaEHENT2hdlbYEB09j74y75PJDig==","signatures":[{"sig":"MEQCIGL1z9vnoA3ZYbRyIgBM15CQKTt6kZSXt2ozkbKnZZYkAiBqUjYr8j2cW5x4SCjIFEsTNc7I1deXuQpU+OQbxMFOKQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQD3Y5mV99EkE1GswxxaHA3wNj32EgHiGClELxWsiFIl3QIgJHiXdkK5H3ZmA0B2uLZTTxac9wPxSMf1XzHxXTyH4So=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@clossys%2fbouncer@0.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":586230},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:25c9f070-e25c-4bed-9428-526936e29493"}},"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.5","svix":"^1.96.0","react":"19.3.0","vitest":"^5.0.0","react-dom":"19.3.0","typescript":"~6.0.0","@types/node":"^26.5.1","@types/react":"^19.3.0","@clerk/nextjs":"7.9.1","@types/react-dom":"^19.3.0"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/bouncer_0.1.7_1789610769779_0.7950344182407079","host":"s3://npm-registry-packages-npm-production"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}},"0.1.8":{"name":"@clossys/bouncer","version":"0.1.8","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"author":{"name":"Clossys"},"license":"MIT","_id":"@clossys/bouncer@0.1.8","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","bugs":{"url":"https://github.com/clossys/foundry/issues"},"bin":{"bouncer-check":"dist/cli.js","bouncer-rate-check":"dist/unreconciled-grant-rate-cli.js"},"dist":{"shasum":"93b28fa393febdde74ff1eb0d94ad8729b2609bc","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.8.tgz","fileCount":184,"integrity":"sha512-fK0I6fFcEb2GpZCSKyAyDY51E41fzWX3ftpUsJ96jIBX4Bn4CnMBDeZPP9u8ehNZegddgN9I6ezU5x5ySTZ5Mg==","signatures":[{"sig":"MEYCIQCr2+CQ696rExzUYCmWut8ceiTsihZ+KY90FTrMzW0h9QIhAO7mo0wVOB/6sIg01v+TanDMDVG+DYI6TMJxVUwjBmcA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDxtoOYnRB0kUOGnJi2qrEXWOce1xJtUal+xyVt2oq5egIgM+frOvaMhEQyrCwJRVjILqHFK0aVsyGHCXhYuIxICGM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@clossys%2fbouncer@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":622409},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"foundry":{"assessment":{"bin":"bouncer-rate-check","invocation":"single-json-input"}},"private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:25c9f070-e25c-4bed-9428-526936e29493"}},"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.5","svix":"^1.96.0","react":"19.3.0","vitest":"^5.0.0","react-dom":"19.3.0","typescript":"~6.0.0","@types/node":"^26.5.1","@types/react":"^19.3.0","@clerk/nextjs":"7.9.1","@types/react-dom":"^19.3.0"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/bouncer_0.1.8_1789799491185_0.14423308369687837","host":"s3://npm-registry-packages-npm-production"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}},"0.1.9":{"name":"@clossys/bouncer","version":"0.1.9","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"author":{"name":"Clossys"},"license":"MIT","_id":"@clossys/bouncer@0.1.9","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","bugs":{"url":"https://github.com/clossys/foundry/issues"},"bin":{"bouncer-check":"dist/cli.js","bouncer-rate-check":"dist/unreconciled-grant-rate-cli.js"},"dist":{"shasum":"3b7728470890d5b8876332f582659770f5cbc04c","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.9.tgz","fileCount":184,"integrity":"sha512-s3TNsqHxOqdDMY1N8rMQw6EgQ55YAPkYUEFVOUdw/oR5zhS2/TXQUhIzIZZYBGBpJIDK1Teb/CpxaQohJakXpg==","signatures":[{"sig":"MEUCIGcIjif/Z6/7FsdzX0ytUK5/op9ahpbwqbweByr6ow6/AiEApMKPU/6Vcn3e8BVJMt2hyl6NkUNHCaZR/Dk7+QUmRLY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCDwvs+dD4mGaI7yu4D/tIhbhWE937yB4aAQ5Gl4UrgYQIhAPnRUNOEUey956FsbVK2pbVD/QXAhZTUWVdZ3RAuZRYF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@clossys%2fbouncer@0.1.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":625504},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"foundry":{"assessment":{"bin":"bouncer-rate-check","invocation":"single-json-input"}},"private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:25c9f070-e25c-4bed-9428-526936e29493"}},"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.5","svix":"^1.96.0","react":"19.3.0","vitest":"^5.0.0","react-dom":"19.3.0","typescript":"~6.0.0","@types/node":"^26.5.1","@types/react":"^19.3.0","@clerk/nextjs":"7.9.1","@types/react-dom":"^19.3.0"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/bouncer_0.1.9_1789876098268_0.7935674640734092","host":"s3://npm-registry-packages-npm-production"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}},"0.1.10":{"_id":"@clossys/bouncer@0.1.10","bin":{"bouncer-check":"dist/cli.js","bouncer-rate-check":"dist/unreconciled-grant-rate-cli.js"},"bugs":{"url":"https://github.com/clossys/foundry/issues"},"dist":{"shasum":"9972ed0a9f672939b68d4c62cd1b48f21246e1f4","tarball":"https://registry.npmjs.org/@clossys/bouncer/-/bouncer-0.1.10.tgz","fileCount":185,"integrity":"sha512-4omq2o//OLw+FclR/5h2LuLVOYDOGPhPpXnn3dtFAEhznvP3tsXmRwv+jmj37fbFS+bEXIjYRgzs4HG6oeqAKA==","signatures":[{"sig":"MEYCIQCkbWH2oQuoFo8s+gnZAbMiS0nkgyjC97DP9sFBcYntjwIhAPKy3DZxIw8XiGOjvt8lp5/Zi/dHWe6zRQPbh3JMi0Wr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDJV3ItV/hRg7pSnAigtXGakZ7nhOm/oSwyuYOfn04JXAIgP5e447G+bdw6UQdqoWg+kDd0zX12qfeEQgXM38UHnL0="}],"unpackedSize":627872},"main":"./dist/index.js","name":"@clossys/bouncer","type":"module","types":"./dist/index.d.ts","author":{"name":"Clossys"},"module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./agent":{"types":"./dist/agent/index.d.ts","import":"./dist/agent/index.js"},"./providers/clerk":{"types":"./dist/providers/clerk/index.d.ts","import":"./dist/providers/clerk/index.js"},"./providers/clerk/web":{"types":"./dist/providers/clerk/web/index.d.ts","import":"./dist/providers/clerk/web/index.js"},"./providers/clerk/web/proxy":{"types":"./dist/providers/clerk/web/proxy-entry.d.ts","import":"./dist/providers/clerk/web/proxy-entry.js"},"./providers/clerk/web/client":{"types":"./dist/providers/clerk/web/client-index.d.ts","import":"./dist/providers/clerk/web/client-index.js"},"./providers/clerk/web/server":{"types":"./dist/providers/clerk/web/server.d.ts","import":"./dist/providers/clerk/web/server.js"}},"foundry":{"assessment":{"bin":"bouncer-rate-check","invocation":"single-json-input"}},"license":"MIT","private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","prepublishOnly":"node ../../scripts/check-name-collision.mjs . && npm run build"},"version":"0.1.10","_npmUser":{"name":"thecalvinhung","email":"hello@clossys.com"},"homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"_npmVersion":"11.17.0","description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","directories":{},"maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"sideEffects":false,"_nodeVersion":"24.19.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.5","svix":"^1.96.0","react":"19.3.0","vitest":"^5.0.1","react-dom":"19.3.0","typescript":"~6.0.0","@types/node":"^26.5.1","@types/react":"^19.3.0","@clerk/nextjs":"7.9.4","@types/react-dom":"^19.3.0"},"peerDependencies":{"next":">=16 <17","svix":"^1.96.0","react":">=19 <20","react-dom":">=19 <20","@clerk/nextjs":">=7 <8"},"peerDependenciesMeta":{"next":{"optional":true},"svix":{"optional":true},"react":{"optional":true},"react-dom":{"optional":true},"@clerk/nextjs":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/bouncer_0.1.10_1790150895307_0.3847736699008424"},"foundryReleaseVerification":{"next":{"proxySubpaths":["./providers/clerk/web/proxy"],"clientSubpaths":["./providers/clerk/web","./providers/clerk/web/client"],"serverSubpaths":["./providers/clerk/web/server"]}}}},"time":{"created":"2026-08-31T17:29:44.409Z","modified":"2026-09-23T08:08:15.659Z","0.1.1":"2026-08-31T17:29:44.747Z","0.1.2":"2026-09-01T13:29:22.938Z","0.1.3":"2026-09-03T17:36:19.837Z","0.1.7":"2026-09-17T02:06:09.884Z","0.1.8":"2026-09-19T06:31:31.269Z","0.1.9":"2026-09-20T03:48:18.354Z","0.1.10":"2026-09-23T08:08:15.464Z"},"bugs":{"url":"https://github.com/clossys/foundry/issues"},"author":{"name":"Clossys"},"license":"MIT","homepage":"https://github.com/clossys/foundry/tree/main/packages/bouncer#readme","keywords":["authorization","identity","entitlement","delegation","reconciliation","gate","typescript"],"repository":{"url":"git+https://github.com/clossys/foundry.git","type":"git","directory":"packages/bouncer"},"description":"The bouncer role: is this actor who they claim, and is what they are doing still inside what they were granted? Dependency-free machinery for a consumer's own authority records: a closed consumer-declared role hierarchy, a fail-closed session predicate, e","maintainers":[{"name":"thecalvinhung","email":"hello@clossys.com"}],"readme":"# @clossys/bouncer\n\n**Everything about who you are, what you can do, and how that changes over\ntime.**\n\nThe question this role answers, and no other role does:\n\n> **Is this actor who they claim, and is what they are doing still inside what\n> they were granted?**\n\n## The case this package exists for\n\nA weaker tool checks that a session exists.\n\nIt passes while the role behind that session was revoked upstream an hour ago.\nThe session is real. It is well-formed. It is not expired. Nothing local has\nchanged, so nothing local can notice — and the provider of record, which does\nknow, was never asked.\n\n**Presence of a session is not currency of a grant.** Every checker here is\nbuilt so that the only way to reach a clean answer is to have compared against\nthe provider and seen it answer. And when the provider cannot be reached, the\nanswer is neither \"yes\" nor \"no\": it is `unverifiable`, and the gate exits `2`.\n\n## The closed loop\n\n| Stage | Here |\n| --- | --- |\n| Setpoint | Declared authority — the grants live in your own system |\n| Act | A grant, or a denial |\n| Observation | Reconciliation against every provider of record |\n| Comparison | Drift between what is live and what is still backed |\n| Correction | Revoke, or re-assert |\n\nA package that only answers \"may they?\" at runtime, without ever reconciling,\nhas a setpoint and an act and nothing else — half a loop, and the missing half\nis the half that notices.\n\n**Gate count:** *unreconciled grant surface* — authority live here that no\nprovider still backs. `checkAuthorityReconciliation` counts it. That count is\n0 on an empty set and is not the charter metric.\n\n**Charter metric:** *unreconciled grant rate* — live grants not independently\nbacked by their current provider of record / all live grants evaluated.\n`assessUnreconciledGrantRate()` computes it.\n\n**Runtime verdict:** `authorized` / `denied` / `unverifiable`.\n\n## Install\n\n```sh\nnpm install @clossys/bouncer\n```\n\nThis package is published to the public npm registry, `https://registry.npmjs.org`.\nInstalling it needs no authentication: no npm token, no `.npmrc` registry\noverride, and no GitHub credential of any kind.\n\nNothing is required alongside it. This package declares **zero runtime\ndependencies** — only optional peers (`@clerk/nextjs`, `next`, `react`,\n`react-dom`, `svix`), each needed by exactly one subpath and installed only if\nyou import that subpath. The provider-neutral root, and `./agent`, need none of\nthem.\n\n## Unreconciled grant rate\n\nIndependent consumer evidence shows the position's owned metric meets its\nsetpoint over the declared review cadence. The owned metric is `unreconciled\ngrant rate`, computed by `assessUnreconciledGrantRate()`. An empty evaluated\nset is `indeterminate`, never a perfect rate of 0.\n`checkAuthorityReconciliation` still reports unreconciled grant surface as a\ncount; that count is not this rate. Unverifiable observations stay\nunevaluated and are never folded into the rate. Grant expiry is not this\nmetric. This package does not measure consumer evidence and does not close\nthe loop. A green run of this package's tests is not a close.\n\n```ts\nimport { assessUnreconciledGrantRate } from \"@clossys/bouncer\";\n\nconst report = assessUnreconciledGrantRate(input);\n```\n\n```bash\nbouncer-rate-check assessment.json\n```\n\nThe command prints JSON and exits `0` for satisfied, `1` for violated, and\n`2` for indeterminate, unreadable, or invalid input.\n\nThis package declares that command as its first-day assessment surface in\nits own manifest:\n\n```json\n\"foundry\": { \"assessment\": { \"bin\": \"bouncer-rate-check\", \"invocation\": \"single-json-input\" } }\n```\n\nOnboarding discovers that declaration from the installed manifest and never\ninfers a surface. `bouncer-check` remains the three-gate CLI and is not the\nassessment surface. Bouncer is not a required first-day role; Advisor\nremains the only required first-day assessment.\n\n## The three gates\n\nAll three are reachable from the single `bouncer-check` bin. The charter\nassessment is a second mapped bin, `bouncer-rate-check`, and is not a fourth\ngate on this dispatcher.\n\n```sh\nbouncer-check authority-reconciliation grants.json providers.json --at 2026-08-22T12:00:00.000Z\nbouncer-check delegation-ceiling actors.json\nbouncer-check provider-contract mappings.json shapes.json\n```\n\n### `authority-reconciliation`\n\nEvery live grant traces to a provider that still backs it. Fails when a grant\nis revoked upstream, is not backed by its provider of record at all, or has\npassed its own declared expiry.\n\n**Exits `2`, never `0`, when a provider could not be reached.** An unreachable\nprovider means the comparison did not happen, and the local view is exactly\nwhat must not be reported on its own. It is not a denial either: fold\n`unverifiable` into `denied` and a provider outage becomes a mass revocation;\nfold it into `authorized` and the same outage becomes a silent blanket grant.\n\nThe same precedence holds inside a single run: if some grants were found\nunreconciled *and* some providers were unreachable, the run reports\nindeterminate. The findings it did produce are still printed — it is the exit\ncode that refuses to call the list complete. When the surface is non-zero, the\nunreconciled line names its provider reference: the `providerId` of each\nfailing grant's provider of record, so a run spanning several owners' grants\nnames the failing side.\n\n### `delegation-ceiling`\n\nA machine actor with no declared spend ceiling is a finding, **never an\nunlimited default**.\n\n`monetaryLimitAmount` has three distinguishable states and the distinction is\nthe point:\n\n| Value | Meaning | Gate |\n| --- | --- | --- |\n| a number | a declared ceiling | clean, given a currency to read it in |\n| `null` | \"this actor has no monetary surface\" | a finding, unless the record also carries `\"unlimitedSpendIsDeclared\": true` |\n| absent | nobody decided | always a finding — there is no opt-out for a question nobody asked |\n\nAlso fails on: an amount with no currency, a currency with no amount, an actor\nnaming no responsible human, and an empty tool scope.\n\nThe runtime guard in `./agent` reads `null` as unlimited amount authority and\nproceeds. The two disagree on purpose, at different times, about different\nquestions. The runtime asks \"may this call proceed?\" — and there is nothing\nuseful to do at that moment with a number nobody declared except refuse every\nactor that has none, which would strand actors that legitimately have no\nmonetary surface. The gate asks \"did anybody ever decide what this actor may\nspend?\", and treats silence as a finding rather than as consent.\n\n### `provider-contract`\n\nThe adapter's mapping still matches the provider's declared shape. Checked in\nboth directions, because the two silences are different:\n\n- **adapter → provider** — a field read, or an event recognised, that the\n  provider no longer declares. The adapter is reading air.\n- **provider → adapter** — an event the provider declares and the adapter does\n  not recognise. The provider is talking to nobody.\n\nPlus the subtler one: a field the provider still declares, but only\n`\"sometimes\"`, against an adapter that fails without it — a mapping that works\nuntil the first payload that omits it.\n\nThis package never fetches a provider's live schema. A gate that needed network\naccess, credentials and a per-provider client could not run in the offline,\nhermetic position where a gate belongs. Transcribing the provider's declared\nshape is yours; keeping the transcription honest against the adapter is the\ngate's.\n\n### Exit codes\n\n`0` clean · `1` findings · `2` could not run.\n\n`2` is not a variant of failure. It covers a missing, unreadable, unparseable\nor schema-invalid record store; an empty record set; an unreachable or\nunobserved provider; a provider shape that was never supplied; and — a bare\n`bouncer-check` with **no gate selected at all**, which is a run that never\nhappened and prints its usage to stderr. An explicitly requested `--help` is\nthe one argument-shaped `0`: a help that was asked for did what was asked.\n\n## Exports\n\n### Root — `@clossys/bouncer`\n\nProvider-neutral. Nothing reachable from here imports a vendor SDK, a\nframework, or React.\n\n#### Authority records and their validators\n\n| Export | What it is |\n| --- | --- |\n| `Grant` | One authority live in your own system: `grantId`, `actorId`, `subjectId`, `providerId`, `authority`, `grantedAt`, optional `expiresAt` and `sessionId` |\n| `ProviderAssertion` | One observation of one provider of record, carrying `reachability` as its own field |\n| `BackedAuthority` | One authority a provider still (or no longer) stands behind |\n| `BackedAuthorityStatus` | `\"active\"` \\| `\"revoked\"` |\n| `ProviderReachability` | `\"reachable\"` \\| `\"unreachable\"` |\n| `DelegatedActor` | A delegated machine actor and its declared ceiling |\n| `AdapterMapping` / `MappedField` | What an adapter reads and which events it recognises |\n| `ProviderShape` / `DeclaredField` / `FieldPresence` | The provider's own declared shape, as you transcribed it |\n| `BACKED_AUTHORITY_STATUSES`, `PROVIDER_REACHABILITIES`, `FIELD_PRESENCES` | The closed vocabularies, exported so a consumer can enumerate rather than restate them |\n| `validateGrant` / `validateGrants` | Hand-rolled validators over `unknown`. Never throw |\n| `validateProviderAssertion` / `validateProviderAssertions` | As above, for provider observations |\n| `validateDelegatedActor` / `validateDelegatedActors` | As above, for machine actors |\n| `validateAdapterMapping` / `validateAdapterMappings` | As above, for adapter mappings |\n| `validateProviderShape` / `validateProviderShapes` | As above, for declared provider shapes |\n| `isGrant`, `isProviderAssertion`, `isDelegatedActor` | Type guards over the same readers |\n| `ValidationIssue`, `ValidationResult`, `Validator` | The shared validation result shape |\n\n#### The verdict and the gates\n\n| Export | What it is |\n| --- | --- |\n| `evaluateGrant` | One live grant against one provider observation. Returns `AuthorityDecision` |\n| `AuthorityDecision` | `authorized` \\| `denied` \\| `unverifiable`, each naming the actor, the subject and the provider |\n| `AuthorityDenialReason` | `revoked-upstream` \\| `not-backed` \\| `grant-expired` |\n| `AuthorityUnverifiableReason` | `provider-unreachable` \\| `provider-not-observed` \\| `provider-mismatch` \\| `unreadable-clock` |\n| `checkAuthorityReconciliation` | Gate 1. Returns `AuthorityReconciliationResult`, carrying the unreconciled grant surface |\n| `AuthorityReconciliationResult`, `ReconciliationFinding`, `ReconciliationFindingKind`, `ReconciliationFailureReason` | Its result shape |\n| `assessUnreconciledGrantRate` | Charter close metric. Returns `UnreconciledGrantRateAssessment` from consumer-supplied independent observations. Not `checkAuthorityReconciliation`. |\n| `UnreconciledGrantRateAssessment`, `UnreconciledGrantRateFinding`, `UnreconciledGrantRateState` | Its result shape |\n| `checkDelegationCeiling` | Gate 2. Returns `DelegationCeilingResult` |\n| `DelegationCeilingResult`, `DelegationFinding`, `DelegationFindingKind`, `DelegationFailureReason` | Its result shape |\n| `checkProviderContract` | Gate 3. Returns `ProviderContractResult` |\n| `ProviderContractResult`, `ProviderContractFinding`, `ProviderContractFindingKind`, `ProviderContractFailureReason` | Its result shape |\n\nEvery checker is pure: no I/O, no clock read, no ambient state. The instant to\njudge against is a parameter, so the same inputs always produce the same\nanswer.\n\n#### Runtime primitives\n\n| Export | What it is |\n| --- | --- |\n| `defineRoleHierarchy` | Creates a closed, least-to-most-privileged hierarchy from your own role names. Rejects duplicates and blanks |\n| `RoleHierarchy`, `Viewer` | Its types |\n| `getRoleRank`, `isKnownRole`, `hasRoleAtLeast` | Rank lookups that fail closed for a role the hierarchy does not know |\n| `resolveViewerRole`, `viewerHasAccess` | A viewer's configured role, never an unknown provider-supplied value |\n| `isAuthorized` | Runs your predicate, denying missing, invalid, expired and throwing sessions before it is ever called |\n| `Session`, `SessionResolver`, `AuthorizationPredicate` | Its types |\n| `reconcileExternalMembership` | Idempotent, ordered reconciliation of provider membership events against your own store |\n| `ExternalMembership`, `ExternalMembershipCreateInput`, `ExternalMembershipEvent`, `ExternalMembershipEventClaim`, `ExternalMembershipEventCursor`, `ExternalMembershipIdentity`, `ExternalMembershipReconciliationResult`, `ExternalMembershipRepository`, `ReconcileExternalMembershipCommand` | Its ports and result types |\n| `QueryAdapter`, `TransactionalQueryAdapter`, `WithTransactionQueryAdapter` | The host-supplied storage seam. Statements and result shapes stay yours |\n| `isQueryAdapter`, `isTransactionalQueryAdapter`, `requireTransactionalQueryAdapter` | Its guards, normalising a `withTransaction` pool without replacing its scoped query |\n| `createAllowedOriginPolicy`, `isAllowedOrigin`, `resolveSafeRedirect` | A strict redirect allowlist. Every rejection returns `undefined` rather than a caller-controlled fallback |\n| `AllowedOriginPolicy` | Its type |\n\n### `./agent`\n\nDelegated machine-actor authority. Provider-neutral, framework-neutral, and the\nsubpath `delegation-ceiling` reads records for.\n\n`assertAgentCanCall`, `assertAgentMonetaryAuthority`,\n`describeAgentLifecycleState`, `isAgentContextActive`,\n`AgentAuthorizationError`, and the types `GenericAgentContext`,\n`AgentLifecycleState`, `AgentAuthorizationFailureReason`,\n`BaseAgentAuditRecord`, `IsoDateTime`.\n\n### `./providers/clerk` and its subpaths\n\nEvery provider adapter is isolated behind its own subpath, and the root never\nimports one. The Clerk adapter ships as `./providers/clerk` (event mapping and\nwebhook verification) plus `./providers/clerk/web`,\n`./providers/clerk/web/client`, `./providers/clerk/web/server`, and\n`./providers/clerk/web/proxy`, split so importing the edge-safe proxy entry\nnever pulls `next/headers`, `next/navigation`, React, or client components.\n\n`./providers/clerk` (guards `svix`) and `./providers/clerk/web/server`\n(guards both `@clerk/nextjs` and `next`) each guard every optional peer they\nimport with `assertPeerVersion`, evaluated once at import time, checking the\ninstalled version against this package's declared range.\n`./providers/clerk/web` and its `/client` subpath guard `react` the same\nway, but do NOT range-check `@clerk/nextjs`: that peer's own `exports` map\ndeclares no `./package.json` subpath and its public surface exports no\nversion constant of any kind, so there is no signal a browser-safe module\ncan read without `node:fs` (which cannot resolve in a browser bundle at\nall). `./providers/clerk/web/proxy` guards `next` the same way `server`\ndoes — `next` declares no `exports` field at all, so its `package.json` is\nreadable as an ordinary JSON import, with no `node:fs` involved — but for\nthe identical reason, does not range-check `@clerk/nextjs` either: an Edge\nMiddleware bundle has no filesystem, the same constraint as the browser\nside. See `client.tsx`'s and `proxy.ts`'s own doc comments for the exact,\nchecked shape of this — every subpath either range-guards a peer it\nimports or is a named, tested exception, confirmed by this package's own\ninternal build-graph coverage test (not part of the published package);\nnothing is silently uncovered.\n\nEvery entry point still guards each optional peer's PRESENCE, range-checked\nor not: the unconditional import throws Node's own named\n`ERR_MODULE_NOT_FOUND` if the peer is not installed at all, before this\npackage's own code ever runs — that case never reaches `assertPeerVersion`'s\nown \"not installed\" message, because every call site sits behind a static\nESM import, and an absent package fails module resolution first. What `assertPeerVersion` covers, where it runs, is\nspecifically the installed-but-incompatible case: a version that resolves\nbut falls outside this package's declared range gets a named, actionable\nerror instead of whatever the peer's own call surface happened to crash on.\nAn installed version this guard cannot parse at all is treated as\nindeterminate and warns rather than blocking a build.\n\n## One-way, for public consumption\n\nNo values, roles, tiers, ceilings, currencies, providers or policies of ours\nappear anywhere in this package. There is no role vocabulary, no entitlement\ncatalogue, and no jurisdiction logic. Every declaration is authored by the\nconsumer.\n\nActor and subject stay separate identifiers in every signature, and neither is\never derived from the other: an operator acting on their own account and an\noperator acting on somebody else's are different events with different\nconsequences, and one conflated identifier makes them indistinguishable\nforever — after the fact, in the only record anyone will still have.\n\nStorage and audit are host-supplied ports. This package writes nothing, stores\nnothing, and commits no person-attributable record anywhere.\n\n**Ships the schema and the checkers; every consumer authors its own values.**\n","readmeFilename":"README.md"}