{"_id":"@cohesionauth/sdk","_rev":"10-f9f576f594df5f273791ad3aa969e7d6","name":"@cohesionauth/sdk","dist-tags":{"alpha":"1.2.0-alpha.1","latest":"1.5.0"},"versions":{"1.0.0":{"name":"@cohesionauth/sdk","version":"1.0.0","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.0.0","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/cohesion-auth/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"8f9995f46b81a9c20b23c88a5320aba60b96c048","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.0.0.tgz","fileCount":18,"integrity":"sha512-bR7VaEAYNNL4Zi/+qjE3Jry06rN2ebfAoyed4pkjvsu3lfcenA1fnwQ3QROfNRFqxleDPkANETrTqFN7YiXONA==","signatures":[{"sig":"MEUCIQCI0Tra0gzX5Sb86vFwqCLz36jzHIUauA2BzoaLea8aXwIgGvngVhFhCTYm6oOyFkQbVfM3RkOZ1DPJeYmtrT31PRw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":392498},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"gitHead":"3e18c7abcd5d706387addfaa0fe4e6f57176409b","scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && npm test && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"repository":{"url":"git+https://github.com/cohesion-auth/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.1.0","eslint":"^8.57.0","vitest":"^1.6.0","prettier":"^3.3.0","typescript":"^5.5.2","@types/node":"^20.14.0","@vitest/coverage-v8":"^1.6.0","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^7.13.0","@typescript-eslint/eslint-plugin":"^7.13.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.0.0_1776931810873_0.18097202592869976","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@cohesionauth/sdk","version":"1.0.1","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.0.1","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/cohesion-auth/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"c94ad12773b107d2e844b844cba866b6b49939fb","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.0.1.tgz","fileCount":18,"integrity":"sha512-KNG++ajU5J8NJR1/BsoNKm11fG767+O/OjFGD1TMJd3+fkzM2sGSw93VV/ftcqxI7tOaO2fMa16IuQDpwTEeyA==","signatures":[{"sig":"MEUCIGb4MEPp3cBJyiiM4eqbHcebN75mhSW54As2ueHjGzuwAiEAyGvcS0U9FTMQlL96WkT78+Ry+apaAR2OAVPIHdyYytY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":389221},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"gitHead":"3e18c7abcd5d706387addfaa0fe4e6f57176409b","scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && npm test && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"repository":{"url":"git+https://github.com/cohesion-auth/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.1.0","eslint":"^8.57.0","vitest":"^1.6.0","prettier":"^3.3.0","typescript":"^5.5.2","@types/node":"^20.14.0","@vitest/coverage-v8":"^1.6.0","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^7.13.0","@typescript-eslint/eslint-plugin":"^7.13.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.0.1_1776932605610_0.2208961623390877","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@cohesionauth/sdk","version":"1.1.0","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.1.0","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/cohesion-auth/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"318203cfd92b8284f5d33a8f37c06e716d03e104","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.1.0.tgz","fileCount":18,"integrity":"sha512-86nksxUbYR1GH5MUS+GghMi49zXEz4GjVdXgYcELE7cymwLJ9XqCQq1OQlKZt74s1ZhAv9zAn5noLroh671fUQ==","signatures":[{"sig":"MEQCIDXA6u4p/KE1jNYwxjpvjGgAqBBHN6pE0XB69HZ4vNodAiBLScUv+eFvuJ4yyZv1jwEh8u/PVK1gd0oy/yUtmweIng==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":481681},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"gitHead":"1db25e0c79f4e5519ad9425578995e003607a49a","scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && npm test && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"deprecated":"v1.1.0 was a stub returning {error:'drs_engine_not_yet_enabled'}. Upgrade to @cohesionauth/sdk@1.2.0+ for live DRS routing and Coverage Telemetry JOIN.","repository":{"url":"git+https://github.com/cohesion-auth/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.1.0","eslint":"^8.57.0","vitest":"^1.6.0","prettier":"^3.3.0","typescript":"^5.5.2","@types/node":"^20.14.0","@vitest/coverage-v8":"^1.6.0","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^7.13.0","@typescript-eslint/eslint-plugin":"^7.13.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.1.0_1777369776377_0.26963265929514435","host":"s3://npm-registry-packages-npm-production"}},"1.2.0-alpha.1":{"name":"@cohesionauth/sdk","version":"1.2.0-alpha.1","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.2.0-alpha.1","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"1d232521f1edf07f644b56a704ec0e3a72349988","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.2.0-alpha.1.tgz","fileCount":18,"integrity":"sha512-DTIHF4o9i7kyx8au+lUKBZvyhy8oGzXuOc5Yvpdd7AuEfd6ydhCnWPaJJ0VZmBWM3P7/bALfVb6Fg0Q+HlRG3g==","signatures":[{"sig":"MEQCIHT5rL7xKo/+qY34sJkjguPOcjkWTIIeEJYGwsT97CfDAiBbkJ43oA+ABfvQm3iBc8l/cv1C/2av59zks6/WrccoTA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":859585},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","prepare":"node scripts/prepare.mjs","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && vitest run && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"repository":{"url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"tsup":"^8.1.0","eslint":"^8.57.0","vitest":"^4.1.6","prettier":"^3.3.0","typescript":"^5.5.2","@types/node":"^20.14.0","@vitest/coverage-v8":"^4.1.6","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^7.13.0","@typescript-eslint/eslint-plugin":"^7.13.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.2.0-alpha.1_1778662819540_0.29601257963119143","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@cohesionauth/sdk","version":"1.2.0","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.2.0","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"d8a94ef3f2486788b75a50d5c56c9fb11de5d5ad","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.2.0.tgz","fileCount":18,"integrity":"sha512-RRdmbeM35b8/uEAU1NC2VUOLpDzZaUt6jYaW5DGpFXB58nZYebbKLRu3SLoBItf1FHnti2sEuD0V7AEbYf6jgQ==","signatures":[{"sig":"MEUCIQC112jqXEClsPcRxa+AeKtdeNR0LX++amcI0a7xWNE9CAIgBMLUeyzQyf7JfrxL43EfWCv94u8jiFtPxt3vaplVvgs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":859577},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","prepare":"node scripts/prepare.mjs","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && vitest run && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"repository":{"url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.1.0","eslint":"^8.57.0","vitest":"^4.1.6","prettier":"^3.3.0","typescript":"^5.5.2","@types/node":"^20.14.0","@vitest/coverage-v8":"^4.1.6","eslint-config-prettier":"^9.1.0","@typescript-eslint/parser":"^7.13.0","@typescript-eslint/eslint-plugin":"^7.13.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.2.0_1778753324354_0.8421460011125363","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@cohesionauth/sdk","version":"1.3.0","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.3.0","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"2f1ae3ca250e64d4af9966209b6359bc26c7f2bb","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.3.0.tgz","fileCount":18,"integrity":"sha512-h99e2wEunGNa5iUI+t8W0p+QsczTeuzvimV9OfgVnM/AJDWowIO/MOOp8zyysWMs10v3Wb+96lJlhycR5hWVAw==","signatures":[{"sig":"MEYCIQDIAfG17O/HIOBvCAbPUOVf6wqgbpVdfE8WFbFbMbUxeQIhALBhaOU6ZVFomi1x7TddjmVHltk3RwboHLFbkq49D172","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":898155},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22.12.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","prepare":"node scripts/prepare.mjs","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && vitest run && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"repository":{"url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","eslint":"^9.39.0","vitest":"^4.1.6","prettier":"^3.8.0","@eslint/js":"^9.39.0","typescript":"^5.9.0","@types/node":"^22.18.0","typescript-eslint":"^8.59.0","@vitest/coverage-v8":"^4.1.6","eslint-config-prettier":"^10.1.0","@typescript-eslint/parser":"^8.59.0","@typescript-eslint/eslint-plugin":"^8.59.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.3.0_1780754662177_0.605671118336861","host":"s3://npm-registry-packages-npm-production"}},"1.3.1":{"name":"@cohesionauth/sdk","version":"1.3.1","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.3.1","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"bfda299b14510ce76a3d4f0f6af6d774cda43bf2","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.3.1.tgz","fileCount":18,"integrity":"sha512-TeKOvjKbSGq8N5fkIKgedtiRNazzltYOqxGIBxBHevHTQXxkrfvx6zuWShRJ4kARqM7TOTePy6t2I4WFNYlAbA==","signatures":[{"sig":"MEUCIQDMjHQeHbdBa6hYOXueOQWKQNy5EGqOa0owjAPTnAt+qQIgSksIPLYjvXk0ngkdwtyJfgFk7ZaViGjM2tuDipoLPTc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1137882},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22.12.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./package.json":"./package.json"},"gitHead":"b8d7d86cc8bc5a94879cd5a19b62868d87cc4717","scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","prepare":"node scripts/prepare.mjs","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && vitest run && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"repository":{"url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","eslint":"^9.39.0","vitest":"^4.1.6","prettier":"^3.8.0","@eslint/js":"^9.39.0","typescript":"^5.9.0","@types/node":"^22.18.0","typescript-eslint":"^8.59.0","@vitest/coverage-v8":"^4.1.6","eslint-config-prettier":"^10.1.0","@typescript-eslint/parser":"^8.59.0","@typescript-eslint/eslint-plugin":"^8.59.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^8.0.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.3.1_1781173909365_0.6521446493404148","host":"s3://npm-registry-packages-npm-production"}},"1.3.2":{"name":"@cohesionauth/sdk","version":"1.3.2","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","_id":"@cohesionauth/sdk@1.3.2","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"homepage":"https://cohesionauth.com/api","bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"bin":{"cohesion":"dist/cli.js"},"dist":{"shasum":"c112b4676d2d6e2732d79fff9d7a913ef7706d34","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.3.2.tgz","fileCount":26,"integrity":"sha512-G30S6wJUXS+XpMmBwXHc7u/vtHIuCSRwW8t9vc1FiLCVZnS6FaDQzn49rXvdD30lQUVrSjBB8MUEeILMN8usMA==","signatures":[{"sig":"MEUCIQCm88QLfrLIafdOGxcFJbcSsX2065rxK34NMBsfJT0OawIgfQxPDFyKQBGNvWgUKGJDRuzZSuh7y5BjOpuqVgIX43c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1249662},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=22.12.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./writeback":{"types":"./dist/writeback.d.ts","import":"./dist/writeback.js","require":"./dist/writeback.cjs"},"./package.json":"./package.json"},"scripts":{"lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","test":"vitest run --coverage","build":"tsup","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","prepare":"node scripts/prepare.mjs","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test:watch":"vitest","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepublishOnly":"npm run lint && vitest run && npm run build"},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"overrides":{"esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.12.1","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","directories":{},"_nodeVersion":"25.9.0","dependencies":{},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.0","eslint":"^10.5.0","vitest":"^4.1.6","prettier":"^3.8.0","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.0.0","typescript-eslint":"^8.59.0","@vitest/coverage-v8":"^4.1.6","eslint-config-prettier":"^10.1.0","@typescript-eslint/parser":"^8.59.0","@typescript-eslint/eslint-plugin":"^8.59.0"},"peerDependencies":{"ai":">=3.0.0","openai":">=4.0.0","@langchain/core":">=0.2.0","@anthropic-ai/sdk":">=0.20.0"},"optionalDependencies":{"@sentry/node":"^10.58.0"},"peerDependenciesMeta":{"ai":{"optional":true},"openai":{"optional":true},"@langchain/core":{"optional":true},"@anthropic-ai/sdk":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/sdk_1.3.2_1782723252474_0.03550915665454912","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@cohesionauth/sdk","version":"1.5.0","description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","license":"Apache-2.0","author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"homepage":"https://cohesionauth.com/api","repository":{"type":"git","url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","directory":"sdk/typescript"},"bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./writeback":{"types":"./dist/writeback.d.ts","import":"./dist/writeback.js","require":"./dist/writeback.cjs"},"./writeback-connectors":{"types":"./dist/writeback-connectors.d.ts","import":"./dist/writeback-connectors.js","require":"./dist/writeback-connectors.cjs"},"./package.json":"./package.json"},"bin":{"cohesion":"dist/cli.js"},"engines":{"node":">=22.12.0"},"scripts":{"build":"tsup","types:gen":"echo 'Types are hand-written in src/types.ts, validated against website/api/openapi.yaml during CI. Regenerate via: npx openapi-typescript ../../website/api/openapi.yaml -o src/types.generated.ts'","test":"vitest run --coverage","test:watch":"vitest","lint":"eslint \"src/**/*.ts\" \"tests/**/*.ts\"","format":"prettier --write \"src/**/*.ts\" \"tests/**/*.ts\"","format:check":"prettier --check \"src/**/*.ts\" \"tests/**/*.ts\"","prepare":"node scripts/prepare.mjs","prepublishOnly":"npm run lint && vitest run && npm run build"},"dependencies":{},"optionalDependencies":{"@sentry/node":"^10.58.0"},"peerDependencies":{"@anthropic-ai/sdk":">=0.20.0","@langchain/core":">=0.2.0","ai":">=3.0.0","openai":">=4.0.0"},"peerDependenciesMeta":{"openai":{"optional":true},"@anthropic-ai/sdk":{"optional":true},"ai":{"optional":true},"@langchain/core":{"optional":true}},"overrides":{"esbuild":"^0.28.1"},"devDependencies":{"@eslint/js":"^10.0.1","@types/node":"^26.0.0","@typescript-eslint/eslint-plugin":"^8.59.0","@typescript-eslint/parser":"^8.59.0","@vitest/coverage-v8":"^4.1.6","eslint":"^10.5.0","eslint-config-prettier":"^10.1.0","prettier":"^3.8.0","tsup":"^8.5.0","typescript":"^6.0.3","typescript-eslint":"^8.59.0","vitest":"^4.1.6"},"gitHead":"bad2ee7aafd411484ea7c851b058937378ee685d","_id":"@cohesionauth/sdk@1.5.0","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-tHanvXCA7ZS9WyyPq+JWbgckMr34kk6KmIbLjhTWDLQRr9nOYD+36QLVno/6/eEtV3pF02arN+ZTak0pC8lXaQ==","shasum":"e88396fce8ab55fa96a1f3d1eb03c1610ebbbc5e","tarball":"https://registry.npmjs.org/@cohesionauth/sdk/-/sdk-1.5.0.tgz","fileCount":32,"unpackedSize":1422592,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDVPcH6IHr3zJRVWxKq72f6umPvJ7LNuVPKx0L778ATVAiB25N0IiNWtQe8aPQmQTX2NELkQmyIHAJpFf02iwgiZaA=="}]},"_npmUser":{"name":"peytonflock","email":"peyton@cohesionauth.com"},"directories":{},"maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sdk_1.5.0_1783687635356_0.41664747872956087"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-23T08:10:10.795Z","modified":"2026-07-10T12:47:15.676Z","1.0.0":"2026-04-23T08:10:11.027Z","1.0.1":"2026-04-23T08:23:25.753Z","1.1.0":"2026-04-28T09:49:36.548Z","1.2.0-alpha.1":"2026-05-13T09:00:19.721Z","1.2.0":"2026-05-14T10:08:44.574Z","1.3.0":"2026-06-06T14:04:22.343Z","1.3.1":"2026-06-11T10:31:49.618Z","1.3.2":"2026-06-29T08:54:12.670Z","1.5.0":"2026-07-10T12:47:15.548Z"},"bugs":{"url":"https://github.com/peytonflockk-web/cohesion-launch/issues"},"author":{"name":"COHESION AUTH LLC","email":"engineering@cohesionauth.com"},"license":"Apache-2.0","homepage":"https://cohesionauth.com/api","keywords":["cohesion","judgment-independence-score","ai-oversight","eu-ai-act","article-14","human-oversight","ai-governance","compliance","openai","anthropic","langchain","vercel-ai","mcp"],"repository":{"type":"git","url":"git+https://github.com/peytonflockk-web/cohesion-launch.git","directory":"sdk/typescript"},"description":"Official TypeScript SDK for the COHESION Judgment Independence Score API. Real-time oversight scoring for AI-assisted human decisions, per EU AI Act Article 14, Colorado SB 205, and NYC Local Law 144.","maintainers":[{"name":"peytonflock","email":"peyton@cohesionauth.com"}],"readme":"# @cohesionauth/sdk\n\n> Save humanity by keeping judgment alive in the age of AI.\n\nOfficial TypeScript SDK for the COHESION API. COHESION measures whether human\noversight of AI is real, durable, and reviewable. The SDK wraps the live scoring,\nrouting, audit-chain, and compliance-rollup endpoints; pair it with an OpenAI,\nAnthropic, Azure OpenAI, Bedrock, Vertex, or in-house model to instrument every\nhuman-AI interaction.\n\nReference scopes a buyer typically maps the evidence model to: EU AI Act Article 14,\nColorado SB 205, Colorado SB 26-189 ADMT, NYC Local Law 144, SR 11-7.\n\n- **npm:** `@cohesionauth/sdk`\n- **License:** Apache-2.0\n- **Requires:** Node.js 22.12 or later\n- **Base URL:** `https://api.cohesionauth.com` (human-readable docs at `https://cohesionauth.com/api`)\n\n## Evaluate COHESION in 30 minutes\n\nThe canonical buyer-engineer evaluation path. Each step has a runnable artifact.\n\n1. Curl the unauthenticated root: `curl -s https://api.cohesionauth.com/v1 | jq`.\n2. Get a key at `https://cohesionauth.com/pricing` (Starter $499/mo via the pricing page; FDP fit-call gated).\n3. `npm install @cohesionauth/sdk`.\n4. Score one decision (see _Quickstart_ below).\n5. Replay it via curl against the live endpoint: `curl https://api.cohesionauth.com/v1/decision/replay/$AI_DECISION_LOG_ID -H \"X-API-Key: $COHESION_API_KEY\"` (no SDK wrapper).\n6. Pull a compliance rollup: `await cohesion.complianceReport()`.\n7. Verify the audit chain via curl (admin-only, master-key auth, no SDK wrapper): `curl https://api.cohesionauth.com/v1/admin/audit/verify-chain -H \"X-API-Key: $COHESION_ADMIN_API_KEY\"`.\n8. Open `https://dashboard.cohesionauth.com` and search by `request_id`.\n\nIf any step stalls, email `peyton@cohesionauth.com` with the failing step and the\n`requestId` from the SDK error.\n\n## JIS vs DRS, when to use each\n\n| Engine | Question it answers | Subject of measurement | Primary endpoint |\n|---|---|---|---|\n| **JIS** (Judgment Independence Score) | Is the reviewer still exercising independent judgment? | The reviewer, scored against their own history | `POST /v1/score` |\n| **DRS** (Decision Risk Score) | Is this particular decision risky enough to require a human, an async review, or a block? | The individual decision, scored against policy | `POST /v1/decision/score` |\n\nDRS routes the decision; JIS scores whether the reviewer is a trustworthy router.\n\n## Pilot workflow: score one AI decision end-to-end\n\nThe same loop every production integration runs.\n\n1. Operator opens a task; your app records `session_id` + `operator_id`.\n2. Your app calls the AI provider.\n3. Your UI presents the AI recommendation; the SDK instruments the interaction in\n   the background.\n4. The operator commits a decision.\n5. Your app calls `cohesion.score(...)`; SDK attaches `Idempotency-Key` automatically.\n6. The engine returns the JIS envelope under 100ms p50.\n7. Your app stores `request_id` from the response against the decision. If you\n   are using the DRS gate (`cohesion.decisionScore()` / `gate()`), also store the\n   `ai_decision_log_id` it returns. That is the identifier\n   `GET /v1/decision/replay/{ai_decision_log_id}` accepts.\n\n## Generate an oversight evidence packet\n\nThe artifact a design partner gets at pilot close. Two SDK calls plus one curl\nassemble it. The audit-chain verifier is admin-only (master-key auth) and is not\nwrapped by the SDK; call it directly with curl.\n\n```typescript\nconst report  = await cohesion.complianceReport();\nconst profile = await cohesion.operatorProfile(\"analyst-42\");\n```\n\n```bash\n# Admin-only -- uses the scoped master key, NOT the customer scoring key.\ncurl https://api.cohesionauth.com/v1/admin/audit/verify-chain \\\n  -H \"X-API-Key: $COHESION_ADMIN_API_KEY\"\n```\n\nContents: org-level oversight band distribution, reviewer-level JIS band over time,\ndimension breakdowns, decay projection, and a tamper-evident audit chain.\n\n## Human oversight evidence model\n\nWhat the SDK produces, conceptually:\n\n1. Observable telemetry from the human-AI interaction (latency, hover, scroll,\n   alternative views, decision class, modification extent).\n2. A decision-level score (DRS) that routes the decision BEFORE it reaches the end-user.\n3. A reviewer-level score (JIS) that scores whether the reviewer is still functioning\n   as an oversight signal over time.\n4. A tamper-evident audit chain that connects telemetry, scores, and the resulting\n   routing into one verifiable record per decision.\n5. An evidence packet assembled from the rollup endpoints.\n\nInvisible-by-design: no extension, no survey, no offline assessment.\n\n## Example: healthcare intake workflow\n\nA clinical intake nurse uses an AI scribe to draft the chief complaint.\n\n```typescript\nawait cohesion.score({\n  operator_id: \"rn-22871\",\n  session_id: \"intake_2026_05_27_0094\",\n  domain: \"healthcare\",\n  interaction: {\n    ai_recommendation_presented: true,\n    time_to_decision_ms: 41200,\n    decision: \"modified\",\n    modification_extent: 0.45,\n    ai_available: true,\n    scenario_type: \"standard\",\n    outcome_correct: null,\n    hover_events: 6,\n    scroll_depth: 0.92,\n    alternative_views_checked: 2,\n  },\n});\n```\n\n## Example: lending decision workflow\n\nA loan officer reviews an AI-recommended credit decision. DRS gates first, then JIS\nscores the reviewer interaction.\n\n```typescript\nimport { gate } from \"@cohesionauth/sdk\";\n\nconst pre = await gate(cohesion, request, null);\nif (pre.routing_decision !== \"auto\") {\n  return routeToReviewer(pre);\n}\nconst aiOutput = await provider.complete(request);\nawait gate(cohesion, request, aiOutput); // post-AI strict gate\n\n// Then JIS-score the reviewer's commit.\nawait cohesion.score({\n  operator_id: \"officer-104\",\n  session_id: \"loan_8821\",\n  domain: \"financial\",\n  interaction: { /* ... */ },\n});\n```\n\n## Example: HR screening workflow\n\nA recruiter screens AI-shortlisted resumes under NYC Local Law 144. Every\naccept/reject is logged as an oversight event.\n\n```typescript\nawait cohesion.score({\n  operator_id: \"recruiter-58\",\n  session_id: \"screen_2026_05_27_0044\",\n  domain: \"general\",\n  interaction: {\n    ai_recommendation_presented: true,\n    time_to_decision_ms: 27800,\n    decision: \"rejected\",\n    modification_extent: 0,\n    ai_available: true,\n    scenario_type: \"standard\",\n    outcome_correct: null,\n    hover_events: 4,\n    scroll_depth: 0.7,\n    alternative_views_checked: 3,\n  },\n});\n```\n\nWhen the city audit window opens, `cohesion.complianceReport()` returns the\naggregate; the admin-only `GET /v1/admin/audit/verify-chain` endpoint (curl, master-key\nauth) proves the chain is unbroken.\n\n## Install\n\n```bash\nnpm install @cohesionauth/sdk\n```\n\n## Quickstart\n\nGet a key:\n- **New customer:** start at https://cohesionauth.com/pricing. Dev is free (raw JSON responses only). Starter is $499/mo or $4,990/yr. The Founding Design Partner cohort is $4,900 one-time, credited 100 percent toward the first year of any annual plan, founder-reviewed via a brief fit call; the cohort closes 2026-07-15. Audited is $1,999/mo or $19,900/yr. Enterprise starts at $50K and is scoped procurement, set up with the founder. Once checkout is live, a completed checkout provisions an org and delivers your API key by email. Key shown once, then rotate from your dashboard.\n- **Existing customer rotating a key:** https://cohesionauth.com/dashboard/api-keys\n\n```typescript\nimport { Cohesion } from \"@cohesionauth/sdk\";\n\nconst client = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\n\nconst result = await client.score({\n  session_id: \"sess_2026_04_22_001\",\n  operator_id: \"analyst-42\",\n  domain: \"financial\",\n  interaction: {\n    ai_recommendation_presented: true,\n    time_to_decision_ms: 3400,\n    decision: \"modified\",\n    modification_extent: 0.25,\n    ai_available: true,\n    scenario_type: \"standard\",\n    outcome_correct: null,\n    hover_events: 4,\n    scroll_depth: 0.9,\n    alternative_views_checked: 1,\n  },\n});\n\nconsole.log(`JIS ${result.jis} (${result.compliance.band})`);\n```\n\n## DRS gate -- the Authorized Inference Gateway\n\n`cohesion.gate()` wraps a regulated AI call with the Decision Risk Score engine. The contract is **strict-gate, fail-closed**: the SDK refuses to surface a final AI output unless DRS returned a clean `routing_decision` envelope.\n\n```typescript\nimport {\n  Cohesion,\n  gate,\n  CohesionPolicyBlockedError,\n  CohesionRequiresHumanReviewError,\n  CohesionMalformedDecisionError,\n} from \"@cohesionauth/sdk\";\n\nconst client = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\n\n// 1. Pre-AI pass: ask DRS whether the input is admissible at all.\nconst preDecision = await gate(client, request, null);\n\nif (preDecision.routing_decision !== \"auto\") {\n  // must_review / async_review / forced_escalation -- route to a human reviewer\n  // BEFORE calling the AI provider. preDecision.review_queue_id is the handle.\n  return routeToReviewer(preDecision);\n}\n\n// 2. Call the AI provider.\nconst aiOutput = await provider.complete(request);\n\n// 3. Post-AI pass: ask DRS whether to surface the AI output.\ntry {\n  const postDecision = await gate(client, request, aiOutput);\n  // routing_decision === 'auto', no forced escalation -- safe to surface.\n  return aiOutput;\n} catch (e) {\n  if (e instanceof CohesionPolicyBlockedError) {\n    // Hard block: never surface this AI output. e.decision.drs_reason_codes\n    // and e.decision.policy_evaluation.hard_failures explain why.\n    return blockResponse(e);\n  }\n  if (e instanceof CohesionRequiresHumanReviewError) {\n    // Route to reviewer; e.decision.review_queue_id is the handle.\n    return routeToReviewer(e.decision);\n  }\n  if (e instanceof CohesionMalformedDecisionError) {\n    // Fail-closed sentinel: DRS returned 2xx but the envelope was malformed.\n    // Treat as a hard block. Contact support with e.requestId.\n    return blockResponse(e);\n  }\n  // Network / 5xx / retry-exhausted -> caller MUST treat as fail-closed.\n  // Do NOT surface the AI output. The plain `CohesionError`, `ServerError`,\n  // `NetworkError` types preserve `requestId` for incident tracing.\n  return blockResponse(e);\n}\n```\n\n**The fail-closed contract on transport failure:** if DRS does not return a 2xx envelope (network error, 5xx after retries, abort), `gate()` re-throws the underlying error unchanged. The caller MUST NOT surface the AI output. Treat any non-resolution as a hard block.\n\n**Error class taxonomy:**\n\n| Error | Thrown on | Carries |\n|---|---|---|\n| `CohesionPolicyBlockedError` | `routing_decision === 'policy_blocked'` on either pass | `decision.drs_reason_codes`, `decision.policy_evaluation.hard_failures`, `decision.ai_decision_log_id` |\n| `CohesionRequiresHumanReviewError` | Post-AI `must_review` / `async_review` / non-empty `forced_escalation_rules_triggered` | `decision.review_queue_id` |\n| `CohesionMalformedDecisionError` | 2xx with missing or unrecognized envelope fields (fail-CLOSED) | `observedKeys`, `missingFields` |\n| `ServerError` / `NetworkError` | retry-exhausted transport failure | `requestId` |\n\nPre-AI `must_review` / `async_review` / forced escalation return the envelope without throwing -- that branch is the caller's signal to route to a reviewer **before** the AI call.\n\nSee `examples/07-live-gate.ts` for a runnable end-to-end demonstration.\n\n## Oversight receipts -- one signed record per gated decision\n\n`cohesion.getReceipt(decisionId)` returns a signed, portable oversight receipt for a decision produced by the DRS gate path (`gate()` / `decisionScore()`). The receipt serializes the existing decision and human-review records into one tamper-evident artifact: the DRS scores, routing outcome, any human-review entries, and the append-only evidence-chain anchor, all under a single HMAC signature.\n\nReceipts are served by a dedicated worker on `receipts.cohesionauth.com` (a separate host from the scoring API), configurable via `receiptsBaseUrl`. Pass the `ai_decision_log_id` the gate returned.\n\n```typescript\nimport { Cohesion } from \"@cohesionauth/sdk\";\n\nconst client = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\n\n// `decisionId` is the ai_decision_log_id returned by decisionScore() / gate().\nconst { receipt, signature } = await client.getReceipt(decisionId);\n\nconsole.log(receipt.chain_anchor.verified_at_issuance); // true on an issued receipt\nconsole.log(signature.receipt_hmac);                    // hex HMAC over the canonical receipt\nconsole.log(signature.key_id);                          // signing-key identifier, e.g. \"receipt-v1-...\"\n```\n\nThe worker re-verifies the decision and review chain anchors at issuance and fails closed rather than emit a receipt that does not verify. It returns `404` for an unknown or cross-tenant decision id (existence is never revealed) and `409` when a decision predates the field-covering evidence chain or fails verification.\n\nCall `getReceipt()` from server-side code (Node). The receipt host does not currently send CORS headers, so a browser `fetch` to it is preflight-blocked; the API key belongs on the server regardless. Browser support for this route is tracked separately.\n\nA receipt attaches to the gate path that produces one. The `score()` (JIS) path does not yet yield a receipt; a future canonical-evidence-record migration will make `score()` receipt-eligible too (see `docs/agentic-os/2026-06-16-evidence-record-unification-migration-plan.md`).\n\n## Side-by-side\n\nThe same request in three forms.\n\n**cURL**\n\n```bash\ncurl https://api.cohesionauth.com/v1/score \\\n  -H \"X-API-Key: $COHESION_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"Idempotency-Key: $(uuidgen)\" \\\n  -d @payload.json\n```\n\n**Python**\n\n```python\nfrom cohesion import Client\n\nclient = Client(api_key=os.environ[\"COHESION_API_KEY\"])\nresult = client.score(\n    session_id=\"sess_...\",\n    operator_id=\"analyst-42\",\n    domain=\"financial\",\n    interaction={...},\n)\n```\n\n**TypeScript**\n\n```typescript\nimport { Cohesion } from \"@cohesionauth/sdk\";\n\nconst client = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\nconst result = await client.score({ /* ... */ });\n```\n\n## 5-minute integrations (1.3.1)\n\nThree drop-in patterns. Pick the one that fits your stack.\n\n### Express\n\n```typescript\nimport express from \"express\";\nimport { Cohesion, cohesionExpress } from \"@cohesionauth/sdk\";\n\nconst cohesion = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\nconst app = express();\n\napp.use(\n  cohesionExpress({\n    client: cohesion,\n    domain: \"financial\",\n    operatorIdResolver: (req) => String(req.headers[\"x-user-id\"] ?? \"anon\"),\n  }),\n);\n```\n\n### Next.js (App Router route handler)\n\n```typescript\nimport { Cohesion, cohesionNextRoute } from \"@cohesionauth/sdk\";\n\nconst cohesion = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\n\nexport const POST = cohesionNextRoute(\n  async (req) => Response.json({ ok: true }),\n  {\n    client: cohesion,\n    domain: \"general\", // SOC alert-triage maps here per the v1.2 spec\n    operatorIdResolver: (req) => req.headers.get(\"x-user-id\") ?? \"anon\",\n  },\n);\n```\n\n### Decorator (any function -- class method or HOF wrap)\n\n```typescript\nimport { measure } from \"@cohesionauth/sdk\";\n\nconst handle = measure({\n  client: cohesion,\n  domain: \"financial\",\n  operatorIdResolver: ([req]: [{ userId: string }]) => req.userId,\n})(originalHandle);\n```\n\n`domain` is one of `healthcare | aviation | financial | legal | pharmaceutical | general`. SOC use cases map to `general` per v1.2 §4 Option A.\n\nFor chat-completion patterns (OpenAI / Anthropic / LangChain / Vercel AI), see _Provider integrations_ below or import the `chat` namespace:\n\n```typescript\nimport { chat } from \"@cohesionauth/sdk\";\nconst wrapped = chat.wrapOpenAI(openai, cohesion, ctx);\n```\n\nSix full integration examples live under [`examples/`](./examples).\n\n## Client options\n\n```typescript\nnew Cohesion({\n  apiKey: string,                                  // required\n  baseUrl?: string,        // default \"https://api.cohesionauth.com\"\n  receiptsBaseUrl?: string, // default \"https://receipts.cohesionauth.com\" (oversight receipts)\n  timeout?: number,        // default 30000 ms\n  maxRetries?: number,     // default 3\n  logger?: Logger,         // default createDefaultLogger()\n  enableTelemetry?: boolean, // default false (opt-in Sentry)\n});\n```\n\n`receiptsBaseUrl` configures the host for `getReceipt()`. Oversight receipts are served by a dedicated worker on `receipts.cohesionauth.com`, a separate host from the scoring API base; only `getReceipt()` uses it. Every other method targets `baseUrl`.\n\n## Method reference\n\n| Method | HTTP | Notes |\n|---|---|---|\n| `client.score(req)` | `POST /v1/score` | Idempotency-Key auto-generated |\n| `client.scoreBatch(req)` | `POST /v1/score/batch` | up to 100 interactions |\n| `client.operatorProfile(operatorId)` | `GET /v1/operator/:id/profile` | includes JIS history |\n| `client.organizationDashboard()` | `GET /v1/organization/dashboard` | aggregate metrics |\n| `client.maintenanceRecommend(req)` | `POST /v1/maintenance/recommend` | judgment-maintenance exercises |\n| `client.complianceReport()` | `GET /v1/compliance/report` | EU AI Act Article 14 rollup |\n| `client.getReceipt(decisionId)` | `GET /v1/decisions/:id/receipt` | signed oversight receipt; host = `receipts.cohesionauth.com` |\n| `client.adminKeyRotate()` | `POST /v1/admin/key/rotate` | returns new key ONCE |\n| `client.adminKeyRevoke()` | `POST /v1/admin/key/revoke` | sets org inactive |\n| `client.adminAuditLog(opts?)` | `GET /v1/admin/audit-log` | own-org events only |\n\n## AI-provider wrappers\n\nInstrument OpenAI, Anthropic, Azure OpenAI, Vercel AI SDK, or LangChain.\n\n```typescript\nimport OpenAI from \"openai\";\nimport { Cohesion, wrapOpenAI } from \"@cohesionauth/sdk\";\n\nconst cohesion = new Cohesion({ apiKey: process.env.COHESION_API_KEY! });\nconst openai = wrapOpenAI(new OpenAI(), cohesion, {\n  operatorId: \"analyst-42\",\n  sessionId: \"sess_...\",\n  domain: \"financial\",\n});\n\nconst { response, recordDecision } = await openai.chat.completions.create({\n  model: \"gpt-4\",\n  messages: [{ role: \"user\", content: \"Draft SAR narrative\" }],\n});\n\n// Present `response` to the human. After they decide:\nconst score = await recordDecision({\n  decision: \"modified\",\n  modificationExtent: 0.3,\n});\n```\n\nEquivalent helpers: `wrapAnthropic`, `wrapAzureOpenAI`, `vercelAIMiddleware`, `langChainHandler`.\n\n## Errors\n\nEvery SDK error carries `requestId` and `nextStep`.\n\n| Class | HTTP | Extra fields | `nextStep` example |\n|---|---|---|---|\n| `AuthenticationError` | 401 | | \"Check the 8-character prefix of your key. New customers start at cohesionauth.com/pricing; existing customers rotate at cohesionauth.com/dashboard/api-keys.\" |\n| `RateLimitError` | 429 | `retryAfter: number` | \"Retry after 7 seconds.\" |\n| `ValidationError` | 400, 413, 422 | `field`, `allowedValues` | \"scenario_type must be one of: standard, independent, trap, split.\" |\n| `ServerError` | 5xx | | populated only when actionable |\n| `NetworkError` | transport | `cause` | \"Check connectivity to api.cohesionauth.com and ensure TLS 1.3 egress is permitted from your environment.\" |\n| `CohesionError` | base | | hierarchy root |\n\n```typescript\nimport { RateLimitError } from \"@cohesionauth/sdk\";\n\ntry {\n  await client.score(req);\n} catch (err) {\n  if (err instanceof RateLimitError) {\n    console.log(`Retry in ${err.retryAfter}s. Hint: ${err.nextStep}`);\n  } else {\n    throw err;\n  }\n}\n```\n\n## CLI\n\n```bash\nnpx cohesion score --operator-id analyst-42 --from-file payload.json\n# or via stdin:\ncat payload.json | npx cohesion score --operator-id analyst-42 --from-file -\n```\n\n## Retry and idempotency\n\n- Exponential backoff with full jitter. Default max 3 retries.\n- Retries only on 429 and 5xx. All 4xx (except 429) fail fast.\n- Honors `Retry-After` header (integer seconds or HTTP-date).\n- Every POST auto-populates `Idempotency-Key` with a UUIDv4 so retries are safe to replay.\n\n## SDK parity matrix\n\nEvery documented endpoint is reachable from the TypeScript SDK, the Python SDK, and\nthe dashboard. Operator-only paths (key rotation, audit log inspection) are\nread-write in the SDKs and read in the dashboard.\n\n| Endpoint | TypeScript | Python | Dashboard |\n|---|---|---|---|\n| `POST /v1/score` | `client.score()` | `client.score()` | read |\n| `POST /v1/score/batch` | `client.scoreBatch()` | `client.score_batch()` | read |\n| `POST /v1/decision/score` | `client.decisionScore()` / `gate()` | `client.decision_score()` / `gate()` | read |\n| `GET /v1/decision/:id` | `client.getDecision()` | `client.get_decision()` | read |\n| `GET /v1/decision/queue` | `client.decisionQueue()` | `client.decision_queue()` | read |\n| `GET /v1/decisions/:id/receipt` (receipts.cohesionauth.com) | `client.getReceipt()` | `client.get_receipt()` | read |\n| `GET /v1/decision/replay/:id` | curl (no SDK wrapper) | curl (no SDK wrapper) | read |\n| `GET /v1/operator/:id/profile` | `client.operatorProfile()` | `client.operator_profile()` | read |\n| `GET /v1/organization/dashboard` | `client.organizationDashboard()` | `client.organization_dashboard()` | read |\n| `POST /v1/maintenance/recommend` | `client.maintenanceRecommend()` | `client.maintenance_recommend()` | read |\n| `GET /v1/compliance/report` | `client.complianceReport()` | `client.compliance_report()` | read + export |\n| `POST /v1/telemetry/ai-call-observed` | `client.telemetryAiCallObserved()` | `client.telemetry_ai_call_observed()` | n/a |\n| `GET /v1/admin/audit/verify-chain` | curl (master-key, no SDK wrapper) | curl (master-key, no SDK wrapper) | read |\n| `POST /v1/admin/key/rotate` | `client.adminKeyRotate()` | `client.admin_key_rotate()` | read + rotate |\n| `POST /v1/admin/key/revoke` | `client.adminKeyRevoke()` | `client.admin_key_revoke()` | read |\n| `GET /v1/admin/audit-log` | `client.adminAuditLog()` | `client.admin_audit_log()` | read |\n\nFull 50-endpoint catalog at the [OpenAPI schema](https://cohesionauth.com/api-docs/redoc).\n\n## Endpoint status classification\n\nEvery endpoint is tagged with one of four maturity classifications.\n\n| Class | Meaning | Backward compatibility |\n|---|---|---|\n| **Production** | Stable contract. SLA-backed. | 12-month deprecation notice via `Sunset` response header. |\n| **Beta** | Public, intentionally exposed, contract may change. | Notice via release notes; no `Sunset` guarantee. |\n| **Admin** | Org-scoped, owner-only. Key rotation, revocation, audit log. | Production-grade backward compatibility. |\n| **Internal** | Reserved for the dashboard + SDK. | No external contract. |\n\nThe `Production` class covers the entire surface listed in the parity matrix above.\nBeta endpoints are documented in release notes; Admin endpoints are tagged in the\nOpenAPI schema with `x-cohesion-class: admin`.\n\n## Errors and recovery\n\nEvery failure mode has a documented recovery path. Catch by class, never by string match.\n\n| Failure | HTTP | SDK class | Caller next step |\n|---|---|---|---|\n| Missing or wrong key | 401 | `AuthenticationError` | Check the key prefix. Rotate at `dashboard.cohesionauth.com/api-keys`. |\n| Bad payload field | 400 / 413 / 422 | `ValidationError` | Inspect `err.field` and `err.allowedValues`. |\n| Rate limit hit | 429 | `RateLimitError` | SDK auto-retries with backoff + jitter; honor `err.retryAfter` if surfaced after retries. |\n| Upstream model unavailable (5xx) | 503 / 504 | `ServerError` | SDK retries on 5xx; after retries, fail-closed (do NOT surface the AI output). |\n| Network down / DNS / TLS | transport | `NetworkError` | Verify egress to `api.cohesionauth.com`. Fail-closed. |\n| DRS envelope malformed | 2xx | `CohesionMalformedDecisionError` | Treat as hard block. Contact support with `err.requestId`. |\n\nEvery error carries `requestId` and `nextStep`. The `CohesionError` base is the safe\nfallback catch.\n\n## Compliance boundaries\n\nWhat the SDK helps customers prove, and what it does NOT prove.\n\n**The SDK measures:**\n\n- Whether a named human reviewer was present at the moment of decision.\n- Whether the reviewer's behavioral signals indicate engaged, independent review or a pattern of rapid, undifferentiated acceptance.\n- Whether the decision was risky enough to require an additional human, an async\n  review, or a hard block.\n- Whether the reviewer's oversight quality is degrading over time.\n- Whether the entire interaction is reconstructable from a tamper-evident audit chain.\n\n**The SDK does NOT:**\n\n- Render legal opinions or determine regulatory conformance on a customer's behalf.\n- Replace internal model-risk-management or model-validation processes.\n- Score the underlying AI model's correctness or bias.\n- Operate as a certification body.\n\nBuyers and their counsel are responsible for mapping the evidence model to specific\nregulatory obligations.\n\n## Data handling and retention\n\n- **Transport:** TLS 1.3 from your environment to `api.cohesionauth.com`.\n- **Storage region:** Cloudflare D1 in the customer's contracted region (EU customers\n  on EU edge; US customers on US edge).\n- **Retention windows:** Telemetry and score envelopes: 13 months default,\n  configurable per contract. Audit chain: indefinite (a chain cannot be truncated\n  without breaking proof).\n- **Redaction:** The default logger redacts API keys (pattern `ck_live_*`) and\n  `operator_id` values before emit. Free-text prompt content is NEVER stored by the\n  engine.\n- **Export:** `client.complianceReport()` + `client.adminAuditLog()` are\n  SDK-callable and downloadable.\n\n## Audit trail example\n\nA synthetic but realistic excerpt of the chain returned by\n`GET /v1/admin/audit/verify-chain` (admin-only, master-key auth, curl-only -- not\nwrapped by the SDK). Three consecutive decisions; the chain head proves none were\nsilently dropped or rewritten.\n\n```json\n{\n  \"chain_head\": \"sha256:a13c…f902\",\n  \"verified\": true,\n  \"entries\": [\n    {\n      \"request_id\": \"req_01HXG7K9Z2W4M6P8B0A2C4E6F8\",\n      \"timestamp\": \"2026-05-27T14:08:42.318Z\",\n      \"operator_id_hash\": \"h_e2a9…\",\n      \"decision_class\": \"modified\",\n      \"drs_routing\": \"auto\",\n      \"jis_band\": \"Strong\",\n      \"prev_hash\": \"sha256:9b71…a004\",\n      \"this_hash\": \"sha256:c84d…ee19\"\n    },\n    {\n      \"request_id\": \"req_01HXG7KCV4Y2T8M0R6E3K1Q9P2\",\n      \"timestamp\": \"2026-05-27T14:10:01.044Z\",\n      \"operator_id_hash\": \"h_e2a9…\",\n      \"decision_class\": \"rejected\",\n      \"drs_routing\": \"must_review\",\n      \"jis_band\": \"Strong\",\n      \"prev_hash\": \"sha256:c84d…ee19\",\n      \"this_hash\": \"sha256:1f02…7733\"\n    },\n    {\n      \"request_id\": \"req_01HXG7KFM8N0Q3D5W2A8H6Y1B6\",\n      \"timestamp\": \"2026-05-27T14:11:55.610Z\",\n      \"operator_id_hash\": \"h_e2a9…\",\n      \"decision_class\": \"accepted\",\n      \"drs_routing\": \"auto\",\n      \"jis_band\": \"Adequate\",\n      \"prev_hash\": \"sha256:1f02…7733\",\n      \"this_hash\": \"sha256:a13c…f902\"\n    }\n  ]\n}\n```\n\nEach entry's `this_hash` derives from its content plus the previous entry's hash.\nThe chain head is the cryptographic summary of every decision in-window.\n\n## Changelog and versioning policy\n\nSemver. The `/v1` prefix is the major-version contract; breaking changes ship under\n`/v2` with a 12-month overlap and `Deprecation` plus `Sunset` response headers per\nRFC 8594.\n\n- **Backward-compatible additions** (new endpoints, new optional fields) ship in\n  minor releases, no advance notice required.\n- **Deprecations** ship with `Deprecation` and `Sunset` response headers, minimum\n  12 months before removal.\n- **SDK versioning** follows API versioning. Patch releases for engine fixes; minor\n  releases for new endpoints; major releases only when the API major changes.\n- **Full release notes:** [`cohesionauth.com/changelog`](https://cohesionauth.com/changelog/).\n\n## Environment variables\n\n| Name | Purpose |\n|---|---|\n| `COHESION_API_KEY` | API key. Required for the CLI. |\n| `COHESION_BASE_URL` | Override the base URL (staging, self-hosted). |\n| `COHESION_LOG_FORMAT` | Set to `json` for structured logs. |\n| `COHESION_LOG_LEVEL` | `debug`, `info`, `warn`, or `error`. |\n| `COHESION_TEST_API_KEY` | Enables the live integration test. |\n| `COHESION_SENTRY_DSN` or `SENTRY_DSN` | Opt-in telemetry, only when `enableTelemetry: true`. |\n\n## Logging and redaction\n\nThe default logger redacts API keys (`ck_live_*`) and `operator_id` values before emit. Set `COHESION_LOG_FORMAT=json` for structured output suitable for Datadog, Sentry, or Cloudflare Logpush.\n\n## License\n\nApache License 2.0. See `LICENSE` and `NOTICE`.\n\nThe COHESION Judgment Independence Score methodology, scoring engine, and intervention protocol are patent-pending.\n","readmeFilename":"README.md"}