{"_id":"@makerchecker/embedded","_rev":"3-2d66db9311967396c3fa07a1c4fe5def","name":"@makerchecker/embedded","dist-tags":{"latest":"1.2.0"},"versions":{"1.1.3":{"name":"@makerchecker/embedded","version":"1.1.3","keywords":["agent-governance","authorization","separation-of-duties","deny-by-default","policy","audit","ed25519","makerchecker"],"license":"Apache-2.0","_id":"@makerchecker/embedded@1.1.3","maintainers":[{"name":"makerchecker","email":"suleiman@mashinii.com"}],"homepage":"https://github.com/sammysltd/makerchecker#readme","bugs":{"url":"https://github.com/sammysltd/makerchecker/issues"},"dist":{"shasum":"996caa23827e32be9f0315126632ebdeb24b5faf","tarball":"https://registry.npmjs.org/@makerchecker/embedded/-/embedded-1.1.3.tgz","fileCount":13,"integrity":"sha512-Qn9BZUvXbtTd9B1xvbz0V6hM8UGQ14uQjZb3zsHjKF47FgREWpRqO2yRkBbu1zQd0/Fa7P/N8iYmoo+j1m256w==","signatures":[{"sig":"MEUCIGFTXzHYMTJ25cif+i6Cam7uoPk5nFWZ9zCigbjhgk7uAiEA7j0cvftiYAPCfLnbMslTQzffqhsBM+uFkkZj0LKzA+M=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@makerchecker%2fembedded@1.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":90994},"main":"src/index.js","type":"module","_from":"file:makerchecker-embedded-1.1.3.tgz","types":"./src/index.d.ts","engines":{"node":">=18.4.0"},"exports":{".":{"types":"./src/index.d.ts","default":"./src/index.js"},"./audit":{"types":"./src/audit.d.ts","default":"./src/audit.js"},"./policy":{"types":"./src/policy.d.ts","default":"./src/policy.js"},"./governor":{"types":"./src/governor.d.ts","default":"./src/governor.js"}},"scripts":{"lint":"true","test":"node --test test/*.test.mjs","typecheck":"tsc -p tsconfig.json"},"_npmUser":{"name":"makerchecker","email":"suleiman@mashinii.com"},"_resolved":"/tmp/8c2c0621ce9e996cc011890814aeb22b/makerchecker-embedded-1.1.3.tgz","_integrity":"sha512-Qn9BZUvXbtTd9B1xvbz0V6hM8UGQ14uQjZb3zsHjKF47FgREWpRqO2yRkBbu1zQd0/Fa7P/N8iYmoo+j1m256w==","repository":{"url":"git+https://github.com/sammysltd/makerchecker.git","type":"git","directory":"packages/embedded"},"_npmVersion":"10.9.8","description":"In-process MakerChecker governance. Import the pure primitives — deny-by-default authorization + separation of duties — with no server, no Postgres, and no audit chain; add the signed, offline-verifiable chain only when you want it.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/embedded_1.1.3_1783178872329_0.44025084835873174","host":"s3://npm-registry-packages-npm-production"}},"1.1.4":{"name":"@makerchecker/embedded","version":"1.1.4","keywords":["agent-governance","authorization","separation-of-duties","deny-by-default","policy","audit","ed25519","makerchecker"],"license":"Apache-2.0","_id":"@makerchecker/embedded@1.1.4","maintainers":[{"name":"makerchecker","email":"suleiman@mashinii.com"}],"homepage":"https://github.com/sammysltd/makerchecker#readme","bugs":{"url":"https://github.com/sammysltd/makerchecker/issues"},"dist":{"shasum":"6a9e8c3c4d08d960e27c3a359484b07a9b0aef39","tarball":"https://registry.npmjs.org/@makerchecker/embedded/-/embedded-1.1.4.tgz","fileCount":13,"integrity":"sha512-2zSs7c7M5FY4/6NmnWnMYzlCxiF8/Kn6cDqENQ+ZY4ApGDrR50oG/A0t3l6zkyo8rUHFpFqPM3SUufJqVhQbXA==","signatures":[{"sig":"MEUCIHBVBAEiMFYkjCIK+8sIGCqyfltNwHjZZG1A+n1HO3JBAiEAsCOxP+amPCdsu21ykFwUESJdGELwAIjvSDmqzvZvP+g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@makerchecker%2fembedded@1.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":90994},"main":"src/index.js","type":"module","_from":"file:makerchecker-embedded-1.1.4.tgz","types":"./src/index.d.ts","engines":{"node":">=18.4.0"},"exports":{".":{"types":"./src/index.d.ts","default":"./src/index.js"},"./audit":{"types":"./src/audit.d.ts","default":"./src/audit.js"},"./policy":{"types":"./src/policy.d.ts","default":"./src/policy.js"},"./governor":{"types":"./src/governor.d.ts","default":"./src/governor.js"}},"scripts":{"lint":"true","test":"node --test test/*.test.mjs","typecheck":"tsc -p tsconfig.json"},"_npmUser":{"name":"makerchecker","email":"suleiman@mashinii.com"},"_resolved":"/tmp/59dd2c5eb6e3b05fec75ad1b6e5dd79b/makerchecker-embedded-1.1.4.tgz","_integrity":"sha512-2zSs7c7M5FY4/6NmnWnMYzlCxiF8/Kn6cDqENQ+ZY4ApGDrR50oG/A0t3l6zkyo8rUHFpFqPM3SUufJqVhQbXA==","repository":{"url":"git+https://github.com/sammysltd/makerchecker.git","type":"git","directory":"packages/embedded"},"_npmVersion":"10.9.8","description":"In-process MakerChecker governance. Import the pure primitives — deny-by-default authorization + separation of duties — with no server, no Postgres, and no audit chain; add the signed, offline-verifiable chain only when you want it.","directories":{},"_nodeVersion":"22.23.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/embedded_1.1.4_1783179245626_0.8280932453779386","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@makerchecker/embedded","version":"1.2.0","description":"In-process MakerChecker governance. Import the pure primitives — deny-by-default authorization + separation of duties — with no server, no Postgres, and no audit chain; add the signed, offline-verifiable chain only when you want it.","type":"module","main":"src/index.js","types":"./src/index.d.ts","exports":{".":{"types":"./src/index.d.ts","default":"./src/index.js"},"./policy":{"types":"./src/policy.d.ts","default":"./src/policy.js"},"./governor":{"types":"./src/governor.d.ts","default":"./src/governor.js"},"./audit":{"types":"./src/audit.d.ts","default":"./src/audit.js"}},"keywords":["agent-governance","authorization","separation-of-duties","deny-by-default","policy","audit","ed25519","makerchecker"],"repository":{"type":"git","url":"git+https://github.com/makerchecker/MakerChecker.git","directory":"packages/embedded"},"license":"Apache-2.0","engines":{"node":">=18.4.0"},"scripts":{"test":"node --test test/*.test.mjs","lint":"true","typecheck":"tsc -p tsconfig.json"},"_id":"@makerchecker/embedded@1.2.0","bugs":{"url":"https://github.com/makerchecker/MakerChecker/issues"},"homepage":"https://github.com/makerchecker/MakerChecker#readme","_integrity":"sha512-Sdrvv6M/1Nd/iSaMHRqyeDcMXlFd3sGd1+1RT0hjr9Un5T6JmXvA679w5mmtpwnE1aptQheMZ9xeLnoJOCWcbg==","_resolved":"/tmp/e71e882393ac416ee07efccba1c77973/makerchecker-embedded-1.2.0.tgz","_from":"file:makerchecker-embedded-1.2.0.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-Sdrvv6M/1Nd/iSaMHRqyeDcMXlFd3sGd1+1RT0hjr9Un5T6JmXvA679w5mmtpwnE1aptQheMZ9xeLnoJOCWcbg==","shasum":"d0b01a60ab4f554cb94c699fbabfa1105728aa06","tarball":"https://registry.npmjs.org/@makerchecker/embedded/-/embedded-1.2.0.tgz","fileCount":13,"unpackedSize":92136,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@makerchecker%2fembedded@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCH14WbYQXe7TiLKR0FwhqNy89SiVdXBj5sKQtPZMQL74CIQCMjDuH/UgP0N4fmNcuuo7/vgeJXx3R4Q82oQD6za+7TQ=="}]},"_npmUser":{"name":"makerchecker","email":"suleiman@mashinii.com"},"directories":{},"maintainers":[{"name":"makerchecker","email":"suleiman@mashinii.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/embedded_1.2.0_1783346116302_0.9389091353067309"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-04T15:27:52.209Z","modified":"2026-07-06T13:55:16.711Z","1.1.3":"2026-07-04T15:27:52.441Z","1.1.4":"2026-07-04T15:34:05.767Z","1.2.0":"2026-07-06T13:55:16.424Z"},"bugs":{"url":"https://github.com/makerchecker/MakerChecker/issues"},"license":"Apache-2.0","homepage":"https://github.com/makerchecker/MakerChecker#readme","keywords":["agent-governance","authorization","separation-of-duties","deny-by-default","policy","audit","ed25519","makerchecker"],"repository":{"type":"git","url":"git+https://github.com/makerchecker/MakerChecker.git","directory":"packages/embedded"},"description":"In-process MakerChecker governance. Import the pure primitives — deny-by-default authorization + separation of duties — with no server, no Postgres, and no audit chain; add the signed, offline-verifiable chain only when you want it.","maintainers":[{"name":"makerchecker","email":"suleiman@mashinii.com"}],"readme":"<div align=\"center\">\n\n# 🔒 @makerchecker/embedded\n\n### Governance primitives that run inside your agent — deny-by-default authorization and a signed audit trail, with no server and no database.\n\n`@makerchecker/embedded` is the importable enforcement layer for AI agents: a pure deny-by-default decision, a stateful governor that wraps your tools, and an optional Ed25519-signed, offline-verifiable audit chain. Import only the tier you need. This is what `mc scan --fix` scaffolds to.\n\n[![npm](https://img.shields.io/npm/v/@makerchecker/embedded?color=cb3837&logo=npm)](https://www.npmjs.com/package/@makerchecker/embedded)\n[![License](https://img.shields.io/badge/license-Apache--2.0-informational)](../../LICENSING.md)\n[![Zero dependencies](https://img.shields.io/badge/dependencies-0-brightgreen)](package.json)\n\n</div>\n\n> [!TIP]\n> **The one-liner** — a governor with the signed chain already attached, deny-by-default from the first call:\n> ```js\n> import { createGovernor } from \"@makerchecker/embedded\";\n>\n> const gov = createGovernor();\n> gov.defineSkill(\"execute-payment@1\", { riskTier: \"high\" })\n>    .defineRole(\"ap-bot\")\n>    .defineAgent(\"agent-1\", \"ap-bot\");   // NOT granted execute-payment\n>\n> const pay = gov.wrap(\"agent-1\", \"execute-payment@1\", async (i) => rail.wire(i));\n> await pay({ amountUsd: 1_000_000 });     // throws GovernanceDeniedError — executor never runs\n> ```\n\nIn-process MakerChecker governance in three composable tiers — take only the layer you need:\n\n| Import | You get | Pulls in |\n| --- | --- | --- |\n| `@makerchecker/embedded/policy` | the **pure decision** — deny-by-default authorization + separation of duties | nothing (no crypto, no clock, no state) |\n| `@makerchecker/embedded/governor` | a **stateful enforcement point** that wraps your tools and tracks who has acted | just `./policy` |\n| `@makerchecker/embedded/audit` | an **optional** genesis-rooted, Ed25519-signed, hash-chained log | `node:crypto` |\n| `@makerchecker/embedded` (root) | a governor with the signed chain **already attached** — the one-liner | all of the above |\n\n## Just the primitives — no chain, no database\n\nIf all you want is the enforcement decision, import `./policy`. It has zero\ndependencies, touches no crypto, keeps no state, and never reads a clock —\n`decide()` is a pure function you can call anywhere, including in a reducer, an\nedge function, or a test.\n\n```js\nimport { definePolicy, decide, enforce, GovernanceDeniedError } from \"@makerchecker/embedded/policy\";\n\nconst policy = definePolicy({\n  skills: { \"read-invoice@1\": {}, \"execute-payment@1\": { riskTier: \"high\" } },\n  roles:  { \"ap-bot\": { grants: [\"read-invoice@1\"] } },   // NOT execute-payment\n  agents: { \"agent-1\": { role: \"ap-bot\" } },\n});\n\ndecide(policy, { agent: \"agent-1\", skill: \"read-invoice@1\" });\n// { effect: \"allow\", code: null, reason: null }\n\ndecide(policy, { agent: \"agent-1\", skill: \"execute-payment@1\" });\n// { effect: \"deny\", code: \"skill_not_granted\", reason: \"...\" }\n\nenforce(policy, { agent: \"agent-1\", skill: \"execute-payment@1\" });\n// throws GovernanceDeniedError  (err.code === \"skill_not_granted\")\n```\n\nSeparation of duties is passed in as context — you tell `decide()` which roles\nhave already acted this session, and it stays pure. It needs a policy that\ndeclares the conflicting roles:\n\n```js\nconst sod = definePolicy({\n  skills: { \"submit-payment@1\": {}, \"approve-payment@1\": {} },\n  roles:  {\n    maker:   { grants: [\"submit-payment@1\"] },\n    checker: { grants: [\"approve-payment@1\"], conflicts: [\"maker\"] },\n  },\n  agents: { \"checker-bot\": { role: \"checker\" } },\n});\n\ndecide(sod, { agent: \"checker-bot\", skill: \"approve-payment@1\" }, { sessionActors: [\"maker\"] });\n// { effect: \"deny\", code: \"sod_violation\", ... }  — the \"maker\" role already acted this session\n```\n\nThe policy is a plain, serializable spec (`policy.toJSON()` / `policyToSpec`), so\nyou can load it from JSON/YAML and diff it in review like any other artifact.\n\n## Add enforcement — wrap your tools (`./governor`)\n\nThe governor lifts the one thing a decision can't be pure about — **which roles\nhave already acted in a session** — out of `decide()` and holds it for you. It\nwraps a tool so the call is authorized before it runs and refused before any side\neffect. It records nothing unless you give it an `onDecision` sink, and it never\nimports crypto.\n\n```js\nimport { createGovernor } from \"@makerchecker/embedded/governor\";\n\nconst gov = createGovernor({ onDecision: (event) => myLogger.info(event) });\ngov.defineSkill(\"execute-payment@1\", { riskTier: \"high\" })\n   .defineRole(\"ap-bot\")\n   .defineAgent(\"agent-1\", \"ap-bot\");\n\nconst pay = gov.wrap(\"agent-1\", \"execute-payment@1\", async (i) => rail.wire(i));\nawait pay({ amountUsd: 1_000_000 });   // throws GovernanceDeniedError — executor never runs\n```\n\n## Add the signed trail — the root export\n\nThe batteries-included root wires the `./audit` chain in as the governor's sink,\nso every allow and deny lands in a genesis-rooted, hash-chained, Ed25519-signed\nlog with one line of setup.\n\n```js\nimport { createGovernor } from \"@makerchecker/embedded\";\n\nconst gov = createGovernor();\ngov.defineSkill(\"read-invoice@1\")\n   .defineSkill(\"execute-payment@1\", { riskTier: \"high\" })\n   .defineRole(\"ap-bot\")\n   .grant(\"ap-bot\", \"read-invoice@1\")          // NOT execute-payment — deny by default\n   .defineAgent(\"agent-1\", \"ap-bot\");\n\nconst pay = gov.wrap(\"agent-1\", \"execute-payment@1\", async (i) => rail.wire(i));\nawait pay({ amountUsd: 1_000_000 });            // throws GovernanceDeniedError [skill_not_granted]\n```\n\nThe bundle it exports uses the **same chain format and the same verifier** as the\nfull server, so it verifies in the independent `@makerchecker/proof-verifier` with\nno trust in the producing process:\n\n```js\nimport { verifyBundle } from \"@makerchecker/proof-verifier/core\";\nimport { nodeCrypto } from \"@makerchecker/proof-verifier/node\";\n\nconst verdict = await verifyBundle(gov.exportBundle(), nodeCrypto); // { ok: true, ... }\n```\n\n## The rules (the same decision order as the server's `enforce()`)\n\nChecked in order, deny by default:\n\n1. the agent **exists** (`agent_not_found`) and is **active** (`agent_not_active`);\n2. the skill **exists** (`skill_not_found`) and is **published** (`skill_deprecated`);\n3. the skill is **granted** to the agent's role (`skill_not_granted`);\n4. a **high-risk** skill never runs inline — it requires a preceding\n   separation-enforcing approval gate decided by a separate party\n   (`high_risk_requires_gate`);\n5. **separation of duties** — no role in conflict with the agent's role may have\n   already acted in this session (`sod_violation`). Conflicts are stored\n   symmetrically, so the check fires no matter which side acted first.\n\n## What this is and is not\n\nThis package is the same decision rules and the same signed hash-chain **format**\nas the full server, held **in memory**, for the single-process case: a script, a\ntest, a demo, or one agent worker that wants a governance boundary with zero\ninfrastructure.\n\nIt is **not** a drop-in replacement for the server when you need:\n\n- **durability across processes / restarts** — the chain lives in memory here;\n  the server co-commits every decision and audit row in one Postgres transaction\n  so nothing is lost and nothing can be written after the fact;\n- **multi-writer / concurrent agents** sharing one ledger;\n- a **persistent signing key** so historic bundles keep verifying (the embedded\n  chain mints an **ephemeral** key unless you pass one in — `keyIsEphemeral`\n  tells you which you have);\n- the approval-gate workflow that lets a named human actually *release* a\n  high-risk action (here, high-risk is refused inline — the correct default, but\n  there is no in-process gate to approve it through).\n\nUse embedded to get a governance boundary — or just the decision primitive — with\na plain `npm install`; graduate to the server when you need a durable,\nmulti-writer, tamper-evident system of record.\n\n## API\n\n### `@makerchecker/embedded/policy` — pure\n\n- `definePolicy(spec)` → frozen `Policy` · `policyToSpec(policy)` → plain spec\n- `createPolicyBuilder(policy?)` → fluent builder (`.snapshot()` / `.freeze()`)\n- `decide(policy, { agent, skill }, { sessionActors?, hasSeparationGate? })` →\n  `{ effect, code, reason }` (pure, no side effects)\n- `enforce(policy, request, context?)` → allow decision, or throws\n  `GovernanceDeniedError`\n- `DECISION_CODES`, `GovernanceDeniedError` (`.code`, `.reason`)\n\n### `@makerchecker/embedded/governor` — stateful, no crypto\n\n- `createGovernor({ policy?, onDecision?, clock? })` → governor\n- `.defineSkill` / `.defineRole` / `.defineConflict` / `.grant` / `.defineAgent`\n- `.decide(agent, skill, opts?)` — dry-run, records nothing\n- `.check(agent, skill, opts?)` — records + advances the SoD actor set\n- `.wrap(agent, skill, executor, { sessionId? })` → governed async tool\n  (per-call `sessionId` / `hasSeparationGate` override as a second argument);\n  `.governedTool` is a backward-compatible alias\n- `.policy()` → frozen snapshot · `.sessionActors(sessionId?)`\n\n### `@makerchecker/embedded/audit` — optional, signed\n\n- `createAuditChain({ instanceId?, privateKey?, publicKeyPem? })` → chain\n- `.append(event)` → row · `.rows()` → rows · `.exportBundle()` → verifier-ready\n  bundle · `.keyIsEphemeral` · `.publicKeyPem`\n- `genesisPrevHash(instanceId)`, `SCHEMA_VERSION`\n\n### `@makerchecker/embedded` — root\n\n- `createGovernor({ instanceId?, privateKey?, publicKeyPem?, policy?, clock? })` →\n  governor with a signed chain attached\n- adds `.auditTrail()` → signed rows · `.exportBundle()` → bundle ·\n  `.auditChain` (escape hatch) · `.instanceId` · `.publicKeyPem`\n- re-exports every symbol from the three tiers (`createGovernorCore` is the\n  bare governor without a chain)\n","readmeFilename":"README.md"}