{"_id":"@open-policy-agent/opa","_rev":"2-ab8f083e63ef7ba83007ae97490f406d","name":"@open-policy-agent/opa","dist-tags":{"latest":"2.0.0"},"versions":{"1.7.11":{"name":"@open-policy-agent/opa","version":"1.7.11","keywords":["OPA","Open Policy Agent","authorization","policy","permissions","rbac","role based access control"],"author":{"name":"The OPA Authors"},"license":"Apache-2.0","_id":"@open-policy-agent/opa@1.7.11","maintainers":[{"name":"patrick-styra","email":"patrick@styra.com"},{"name":"styrainc","email":"npm@styra.com"},{"name":"srenatus","email":"stephan@styra.com"}],"homepage":"https://github.com/open-policy-agent/opa-typescript#readme","bugs":{"url":"https://github.com/open-policy-agent/opa-typescript/issues"},"dist":{"shasum":"081bb4d9d60090a07974d7c35664ccf3e552f300","tarball":"https://registry.npmjs.org/@open-policy-agent/opa/-/opa-1.7.11.tgz","fileCount":691,"integrity":"sha512-CRrmLkUjTqG3Rvpr+RahWn+EBgtfaJ7uMlhDGYSjJZXEohtPIkja5Tvqgn5nmjZmuVdnC8TNyRb5Zj+g6wLhRA==","signatures":[{"sig":"MEQCIGJJxbHJxbWUa1SimHokt5iokU5l73Z1vHZCTOcLAoVlAiAHHq5RvLyfUDcqsLO3ioJIp0mWb4UcDzksOg10D7jkkA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1813335},"main":"./dist/commonjs/index.js","tshy":{"exports":{".":"./src/index.ts","./*":"./src/*.ts","./*.js":"./src/*.ts","./types":"./src/types/index.ts","./package.json":"./package.json","./sdk/models/errors":"./src/sdk/models/errors/index.ts","./sdk/models/components":"./src/sdk/models/components/index.ts","./sdk/models/operations":"./src/sdk/models/operations/index.ts"},"sourceDialects":["@open-policy-agent/opa/source"]},"type":"module","types":"./dist/commonjs/index.d.ts","module":"./dist/esm/index.js","exports":{".":{"import":{"types":"./dist/esm/index.d.ts","default":"./dist/esm/index.js","@open-policy-agent/opa/source":"./src/index.ts"},"require":{"types":"./dist/commonjs/index.d.ts","default":"./dist/commonjs/index.js"}},"./*":{"import":{"types":"./dist/esm/*.d.ts","default":"./dist/esm/*.js","@open-policy-agent/opa/source":"./src/*.ts"},"require":{"types":"./dist/commonjs/*.d.ts","default":"./dist/commonjs/*.js"}},"./*.js":{"import":{"types":"./dist/esm/*.d.ts","default":"./dist/esm/*.js","@open-policy-agent/opa/source":"./src/*.ts"},"require":{"types":"./dist/commonjs/*.d.ts","default":"./dist/commonjs/*.js"}},"./types":{"import":{"types":"./dist/esm/types/index.d.ts","default":"./dist/esm/types/index.js","@open-policy-agent/opa/source":"./src/types/index.ts"},"require":{"types":"./dist/commonjs/types/index.d.ts","default":"./dist/commonjs/types/index.js"}},"./package.json":"./package.json","./sdk/models/errors":{"import":{"types":"./dist/esm/sdk/models/errors/index.d.ts","default":"./dist/esm/sdk/models/errors/index.js","@open-policy-agent/opa/source":"./src/sdk/models/errors/index.ts"},"require":{"types":"./dist/commonjs/sdk/models/errors/index.d.ts","default":"./dist/commonjs/sdk/models/errors/index.js"}},"./sdk/models/components":{"import":{"types":"./dist/esm/sdk/models/components/index.d.ts","default":"./dist/esm/sdk/models/components/index.js","@open-policy-agent/opa/source":"./src/sdk/models/components/index.ts"},"require":{"types":"./dist/commonjs/sdk/models/components/index.d.ts","default":"./dist/commonjs/sdk/models/components/index.js"}},"./sdk/models/operations":{"import":{"types":"./dist/esm/sdk/models/operations/index.d.ts","default":"./dist/esm/sdk/models/operations/index.js","@open-policy-agent/opa/source":"./src/sdk/models/operations/index.ts"},"require":{"types":"./dist/commonjs/sdk/models/operations/index.d.ts","default":"./dist/commonjs/sdk/models/operations/index.js"}}},"gitHead":"9a9228391fcb5dbec085e06cdd6f68daf4ee3ba3","scripts":{"lint":"eslint --cache --max-warnings=0 src","build":"tshy","prepublishOnly":"npm run build"},"_npmUser":{"name":"styrainc","email":"npm@styra.com"},"repository":{"url":"git+https://github.com/open-policy-agent/opa-typescript.git","type":"git","directory":"packages/opa"},"_npmVersion":"10.9.3","description":"Driver to connect to Open Policy Agent (OPA) and EOPA deployments.","directories":{},"sideEffects":false,"_nodeVersion":"22.18.0","dependencies":{"@open-policy-agent/ucast-prisma":"^0.1.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","zod":"^3.23.4","tshy":"^2.0.0","eslint":"^9.34.0","globals":"^15.14.0","typedoc":"^0.28.11","@eslint/js":"^9.19.0","typescript":"^5.4.5","@types/node":"^22.13.14","testcontainers":"^11.5.1","typescript-eslint":"^8.22.0","typedoc-plugin-extras":"^4.0.1","typedoc-plugin-replace-text":"^4.2.0"},"peerDependencies":{"zod":">= 3"},"_npmOperationalInternal":{"tmp":"tmp/opa_1.7.11_1756799752869_0.25706121058703824","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@open-policy-agent/opa","version":"2.0.0","author":{"name":"The OPA Authors"},"publishConfig":{"access":"public"},"keywords":["OPA","Open Policy Agent","authorization","policy","permissions","rbac","role based access control"],"license":"Apache-2.0","type":"module","tshy":{"sourceDialects":["@open-policy-agent/opa/source"],"exports":{".":"./src/index.ts","./package.json":"./package.json","./types":"./src/types/index.ts","./sdk/models/errors":"./src/sdk/models/errors/index.ts","./sdk/models/components":"./src/sdk/models/components/index.ts","./sdk/models/operations":"./src/sdk/models/operations/index.ts","./*.js":"./src/*.ts","./*":"./src/*.ts"}},"sideEffects":false,"repository":{"type":"git","url":"git+https://github.com/open-policy-agent/opa-typescript.git","directory":"packages/opa"},"scripts":{"lint":"eslint --cache --max-warnings=0 src","build":"tshy","prepublishOnly":"npm run build"},"peerDependencies":{"zod":"^3.25.0 || ^4.0.0"},"devDependencies":{"@eslint/js":"^9.35.0","@types/node":"^24.3.0","eslint":"^9.35.0","globals":"^16.3.0","testcontainers":"^11.5.1","tshy":"^2.0.0","tsx":"^4.20.5","typedoc":"^0.28.13","typedoc-plugin-extras":"^4.0.1","typedoc-plugin-replace-text":"^4.2.0","typescript":"^5.9.2","typescript-eslint":"^8.44.1","zod":"^4.1.8"},"dependencies":{"@open-policy-agent/ucast-prisma":"^0.1.6"},"exports":{".":{"import":{"@open-policy-agent/opa/source":"./src/index.ts","types":"./dist/esm/index.d.ts","default":"./dist/esm/index.js"},"require":{"types":"./dist/commonjs/index.d.ts","default":"./dist/commonjs/index.js"}},"./package.json":"./package.json","./types":{"import":{"@open-policy-agent/opa/source":"./src/types/index.ts","types":"./dist/esm/types/index.d.ts","default":"./dist/esm/types/index.js"},"require":{"types":"./dist/commonjs/types/index.d.ts","default":"./dist/commonjs/types/index.js"}},"./sdk/models/errors":{"import":{"@open-policy-agent/opa/source":"./src/sdk/models/errors/index.ts","types":"./dist/esm/sdk/models/errors/index.d.ts","default":"./dist/esm/sdk/models/errors/index.js"},"require":{"types":"./dist/commonjs/sdk/models/errors/index.d.ts","default":"./dist/commonjs/sdk/models/errors/index.js"}},"./sdk/models/components":{"import":{"@open-policy-agent/opa/source":"./src/sdk/models/components/index.ts","types":"./dist/esm/sdk/models/components/index.d.ts","default":"./dist/esm/sdk/models/components/index.js"},"require":{"types":"./dist/commonjs/sdk/models/components/index.d.ts","default":"./dist/commonjs/sdk/models/components/index.js"}},"./sdk/models/operations":{"import":{"@open-policy-agent/opa/source":"./src/sdk/models/operations/index.ts","types":"./dist/esm/sdk/models/operations/index.d.ts","default":"./dist/esm/sdk/models/operations/index.js"},"require":{"types":"./dist/commonjs/sdk/models/operations/index.d.ts","default":"./dist/commonjs/sdk/models/operations/index.js"}},"./*.js":{"import":{"@open-policy-agent/opa/source":"./src/*.ts","types":"./dist/esm/*.d.ts","default":"./dist/esm/*.js"},"require":{"types":"./dist/commonjs/*.d.ts","default":"./dist/commonjs/*.js"}},"./*":{"import":{"@open-policy-agent/opa/source":"./src/*.ts","types":"./dist/esm/*.d.ts","default":"./dist/esm/*.js"},"require":{"types":"./dist/commonjs/*.d.ts","default":"./dist/commonjs/*.js"}}},"main":"./dist/commonjs/index.js","types":"./dist/commonjs/index.d.ts","module":"./dist/esm/index.js","_id":"@open-policy-agent/opa@2.0.0","gitHead":"118610d92f4055546542e8f1e0bf5a9a05a213d6","description":"Driver to connect to Open Policy Agent (OPA) and EOPA deployments.","bugs":{"url":"https://github.com/open-policy-agent/opa-typescript/issues"},"homepage":"https://github.com/open-policy-agent/opa-typescript#readme","_nodeVersion":"22.19.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-gtSZKm9eWU9FC7lJ7A2sbyNc+ukTddZ2t6WtJGCtHc+ze6tvhJ7xtLQmlCWLmkyIu+6TGVRn/fr2JGdKgVLdtQ==","shasum":"8bccdc960e8b08c5340c41f745a5885f39cd3b12","tarball":"https://registry.npmjs.org/@open-policy-agent/opa/-/opa-2.0.0.tgz","fileCount":691,"unpackedSize":1826951,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDj7g5gvlY1/5HMDOSB9XjWOVePAehIQD5qNtxTuyAiugIhAL6VWx7jnYzSsKVkdcI+NkRvucv49ce6UVWkHOJ0lS/C"}]},"_npmUser":{"name":"styrainc","email":"npm@styra.com"},"directories":{},"maintainers":[{"name":"patrick-styra","email":"patrick@styra.com"},{"name":"styrainc","email":"npm@styra.com"},{"name":"srenatus","email":"stephan@styra.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/opa_2.0.0_1759247017719_0.18820981834153483"},"_hasShrinkwrap":false}},"time":{"created":"2025-09-02T07:55:52.687Z","modified":"2025-09-30T15:43:38.144Z","1.7.11":"2025-09-02T07:55:53.125Z","2.0.0":"2025-09-30T15:43:37.935Z"},"bugs":{"url":"https://github.com/open-policy-agent/opa-typescript/issues"},"author":{"name":"The OPA Authors"},"license":"Apache-2.0","homepage":"https://github.com/open-policy-agent/opa-typescript#readme","keywords":["OPA","Open Policy Agent","authorization","policy","permissions","rbac","role based access control"],"repository":{"type":"git","url":"git+https://github.com/open-policy-agent/opa-typescript.git","directory":"packages/opa"},"description":"Driver to connect to Open Policy Agent (OPA) and EOPA deployments.","maintainers":[{"name":"patrick-styra","email":"patrick@styra.com"},{"name":"styrainc","email":"npm@styra.com"},{"name":"srenatus","email":"stephan@styra.com"}],"readme":"# OPA Typescript SDK\n\nDriver to connect to Open Policy Agent (OPA) and EOPA deployments.\n\n[![License](https://img.shields.io/badge/License-Apache_2.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n[![NPM Version](https://img.shields.io/npm/v/%40open-policy-agent%2Fopa?style=flat&color=%2324b6e0)](https://www.npmjs.com/package/@open-policy-agent/opa)\n[![JSR](https://jsr.io/badges/@open-policy-agent/opa)](https://jsr.io/@open-policy-agent/opa)\n\n> Reference documentation available at <https://open-policy-agent.github.io/opa-typescript>\n\nYou can use the OPA SDK to connect to [Open Policy Agent](https://www.openpolicyagent.org/) and [EOPA](https://github.com/open-policy-agent/eopa) deployments.\n\n## SDK Installation\n\n### NPM\n\n```bash\nnpm add @open-policy-agent/opa\n```\n\n### PNPM\n\n```bash\npnpm add @open-policy-agent/opa\n```\n\n### Bun\n\n```bash\nbun add @open-policy-agent/opa\n```\n\n### Yarn\n\n```bash\nyarn add @open-policy-agent/opa zod\n\n# Note that Yarn does not install peer dependencies automatically. You will need\n# to install zod as shown above.\n```\n<!-- No SDK Installation [installation] -->\n\n<!-- Start Summary [summary] -->\n## Summary\n\nFor more information about the API: [OpenAPI definition](https://github.com/open-policy-agent/eopa/tree/main/openapi)\n<!-- End Summary [summary] -->\n\n<!-- Start Table of Contents [toc] -->\n## Table of Contents\n<!-- $toc-max-depth=2 -->\n* [OPA Typescript SDK](#opa-typescript-sdk)\n  * [SDK Installation](#sdk-installation)\n  * [Requirements](#requirements)\n  * [SDK Example Usage (high-level)](#sdk-example-usage-high-level)\n* [OPA OpenAPI SDK (low-level)](#opa-openapi-sdk-low-level)\n  * [Available Resources and Operations](#available-resources-and-operations)\n  * [Retries](#retries)\n  * [Authentication](#authentication)\n  * [Debugging](#debugging)\n  * [Standalone functions](#standalone-functions)\n  * [Community](#community)\n\n<!-- End Table of Contents [toc] -->\n\n<!-- Start Requirements [requirements] -->\n## Requirements\n\nFor supported JavaScript runtimes, please consult [RUNTIMES.md](RUNTIMES.md).\n<!-- End Requirements [requirements] -->\n\n## SDK Example Usage (high-level)\n\nThe following examples assume an OPA server equipped with the following Rego policy:\n\n```rego\npackage authz\nimport rego.v1\n\ndefault allow := false\nallow if input.subject == \"alice\"\n```\n\nand this data:\n\n```json\n{\n  \"roles\": {\n    \"admin\": [\"read\", \"write\"]\n  }\n}\n```\n\n### Simple Query\n\nFor a simple boolean response without input, use the SDK as follows:\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"authz/allow\";\n\nconst allowed = await opa.evaluate(path);\nconsole.log(allowed ? \"allowed!\" : \"denied!\");\n```\n\n### Default Rule\n\nFor evaluating the default rule (configured with your OPA service), use `evaluateDefault`. `input` is optional, and left out in this example:\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\n\nconst allowed = await opa.evaluateDefault();\nconsole.log(allowed ? \"allowed!\" : \"denied!\");\n```\n\n### Input\n\nInput is provided as a second (optional) argument to `evaluate`:\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"authz/allow\";\n\nconst input = { subject: \"alice\" };\nconst allowed = await opa.evaluate(path, input);\nconsole.log(allowed ? \"allowed!\" : \"denied!\");\n```\n\n### Default Rule with Input\n\nInput is provided as an (optional) argument to `evaluateDefault`:\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\n\nconst input = { subject: \"alice\" };\nconst allowed = await opa.evaluateDefault(input);\nconsole.log(allowed ? \"allowed!\" : \"denied!\");\n```\n\n> [!NOTE]\n> Everything that follows applies in the same way to `evaluateDefault` and `evaluate`.\n\n### Input and Result Types\n\nIt's possible to provide your own types for input and results.\nThe `evaluate` function will then return a typed result, and TypeScript will ensure that you pass the proper types (as declared) to `evaluated`.\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"authz\";\n\ninterface myInput {\n  subject: string;\n}\ninterface myResult {\n  allow: boolean;\n}\nconst input: myInput = { subject: \"alice\" };\nconst result = await opa.evaluate<myInput, myResult>(path, input);\nconsole.log(result);\n```\n\nIf you pass in an arbitrary object as input, it'll be stringified (`JSON.stringify`):\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"authz/allow\";\n\nclass User {\n  subject: string;\n  constructor(name: string) {\n    this.subject = name;\n  }\n}\n\nconst inp = new User(\"alice\");\nconst allowed = await opa.evaluate<User, boolean>(path, inp);\nconsole.log(allowed);\n```\n\nYou can control the input that's constructed from an object by implementing `ToInput`:\n\n```ts\nimport { OPAClient, ToInput } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"authz/allow\";\n\nclass User implements ToInput {\n  private n: string;\n  constructor(name: string) {\n    this.n = name;\n  }\n  toInput(): Input {\n    return { subject: this.n };\n  }\n}\n\nconst inp = new User(\"alice\");\nconst allowed = await opa.evaluate<User, boolean>(path, inp);\nconsole.log(allowed);\n```\n\n### Result Transformations\n\nIf the result format of the policy evaluation does not match what you want it to be, you can provide a _third argument_, a function that transforms the API result.\n\nAssuming that the policy evaluates to\n\n```json\n{\n  \"allowed\": true,\n  \"details\": [\"input.a is OK\", \"input.b is OK\"]\n}\n```\n\nlike this (contrived) example:\n\n```rego\npackage authz\nimport rego.v1\ngood_a := [\"a\", \"A\", \"A!\"]\ngood_b := [\"b\"]\nresponse.allowed if input.subject == \"alice\"\nresponse.details contains \"input.a is OK\" if input.a in good_a\nresponse.details contains \"input.b is OK\" if input.b in good_b\n```\n\nyou can turn it into a boolean result like this:\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"authz/response\";\nconst input = { subject: \"alice\", a: \"A\", b: \"b\" };\n\nconst allowed = await opa.evaluate<any, boolean>(\n  path,\n  input,\n  {\n    fromResult: (r?: Result) => (r as Record<string, any>)[\"allowed\"] ?? false,\n  },\n);\nconsole.log(allowed);\n```\n\n### Batched Queries\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\n\nconst serverURL = \"http://localhost:8181\";\nconst path = \"authz/allow\";\nconst opa = new OPAClient(serverURL);\n\nconst alice = { subject: \"alice\" };\nconst bob = { subject: \"bob\" };\nconst inputs = { alice: alice, bob: bob };\nconst responses = await opa.evaluateBatch(path, inputs);\n\nfor (const key in responses) {\n    console.log(key + \": \" + (responses[key] ? \"allowed!\" : \"denied!\"));   // Logic here\n}\n```\n\n<details>\n  <summary>Result</summary>\n\n```txt\nalice: allowed!\nbob: denied!\n```\n\n</details>\n\n## Get Filters\n\nTo use the translation of Rego data filter policies into SQL or UCAST expressions, you need to use a recent version of OPA (>=v1.9.0) or EOPA (>=v1.44.0).\nThese examples assume you run OPA or EOPA with the following Rego policy:\n\n```rego\npackage filters\n\n# METADATA\n# scope: document\n# compile:\n#   unknowns: [\"input.fruits\"]\n#   mask_rule: masks\ninclude if input.fruits.colour in input.fav_colours\n\nmasks.fruits.supplier.replace.value := \"<supplier>\"\n```\n\n### For Prisma\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"filters/include\";\nconst input = { fav_colours: [\"red\", \"green\"] };\nconst primary = \"fruits\";\n\nconst { query, mask } = await opa.getFilters(path, input, primary);\nconsole.log(query);\n```\n\nHere, `query` is an object that can readly be used in a Prisma lookup's `where` field:\n\n```ts\n{ colour: { in: [ \"red\", \"green\" ] } }\n```\n\n`mask` is a function that can be applied to the values returned by that lookup.\n\nFor example:\n\n```ts\nconst { query, mask } = await opa.getFilters(path, input, primary);\nconst fruits = (\n  await prisma.fruits.findMany({\n    where: query,\n  })\n).map((fruit) => mask(fruit));\n```\n\n### For SQL\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"filters/include\";\nconst input = { fav_colours: [\"red\", \"green\"] };\nconst opts = { target: \"postgresql\" };\n\nconst { query, masks } = await opa.getFilters(path, input, opts);\nconsole.log({ query, masks });\n```\n\nHere we get a SQL WHERE clause as `query`,\n\n```sql\nWHERE fruits.colour IN (E'red', E'green')\n```\n\nand `masks` contains the evaluated mask rule:\n\n```ts\n{ fruits: { supplier: { replace: { value: \"<supplier>\" } } } }\n```\n\n#### Table name mappings\n\nGenerate a SQL filter with different column and table names via `tableMappings`:\n\n```ts\nconst opts = {\n  target: \"postgresql\",\n  tableMappings: {\n    \"fruits\": { $self: \"f\", colour: \"col\"}\n  }\n};\n```\n\nthis will generate the SQL clause\n\n```sql\nWHERE f.col IN (E'red', E'green')\n```\n\n### For multiple data sources\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL);\nconst path = \"filters/include\";\nconst input = { fav_colours: [\"red\", \"green\"] };\nconst opts = { targets: [\"postgresql\", \"mysql\", \"ucastPrisma\"] };\n\nconst result = await opa.getMultipleFilters(path, input, opts);\nconsole.dir(result, {depth: null});\n```\n\nThis produces an object keyed by the requested targets:\n\n```ts\n{\n  ucast: {\n    query: {\n      type: \"field\",\n      operator: \"in\",\n      field: \"fruits.colour\",\n      value: [ \"red\", \"green\" ]\n    },\n    masks: {\n      fruits: { supplier: { replace: { value: \"<supplier>\" } } }\n    }\n  },\n  postgresql: {\n    query: \"WHERE fruits.colour IN (E'red', E'green')\",\n    masks: {\n      fruits: { supplier: { replace: { value: \"<supplier>\" } } }\n    }\n  },\n  mysql: {\n    query: \"WHERE fruits.colour IN ('red', 'green')\",\n    masks: {\n      fruits: { supplier: { replace: { value: \"<supplier>\" } } }\n    }\n  }\n}\n```\n\n## Advanced options\n\n### Request Headers\n\nYou can provide your custom headers -- for example for bearer authorization -- via an option argument to the `OPAClient` constructor.\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nconst serverURL = \"http://localhost:8181\";\nconst opa = new OPAClient(serverURL, { headers: { authorization: \"Bearer opensesame\" } });\nconst path = \"authz/allow\";\nconst allowed = await opa.evaluate(path);\nconsole.log(allowed);\n```\n\n### HTTPClient\n\nYou can supply an instance of `HTTPClient` to supply your own hooks, for example to examine the request sent to OPA:\n\n```ts\nimport { OPAClient } from \"@open-policy-agent/opa\";\nimport { HTTPClient } from \"@open-policy-agent/opa/lib/http\";\nconst httpClient = new HTTPClient({});\nhttpClient.addHook(\"response\", (response, request) => {\n  console.group(\"Request Debugging\");\n  console.log(request.headers);\n  console.log(`${request.method} ${request.url} => ${response.status} ${response.statusText}`);\n  console.groupEnd();\n});\nconst serverURL = \"http://localhost:8181\";\nconst headers = { authorization: \"Bearer opensesame\" };\nconst opa = new OPAClient(serverURL, { sdk: { httpClient }, headers });\nconst path = \"authz/allow\";\n\nconst allowed = await opa.evaluate(path);\nconsole.log(allowed);\n```\n\n### Example Projects\n\n#### Express\n\nIn [the StyraOSS/styra-demo-tickethub repository](https://github.com/StyraOSS/styra-demo-tickethub/tree/main/server/node), you'll find a NodeJS backend service that is using `@open-policy-agent/opa`:\n\n```javascript\nrouter.get(\"/tickets/:id\", [param(\"id\").isInt().toInt()], async (req, res) => {\n  const {\n    params: { id },\n  } = req;\n  await authz.evaluated(path, { action: \"get\", id }, req);\n\n  const ticket = await prisma.tickets.findUniqueOrThrow({\n    where: { id },\n    ...includeCustomers,\n  });\n  return res.status(OK).json(toTicket(ticket));\n});\n```\n\n#### NestJS\n\nIn [opa-sdk-demos/nestjs-demo](https://github.com/open-policy-agent/opa-sdk-demos/tree/main/nestjs-demo), we have an decorator-based API authorization example using `@open-policy-agent/opa`:\n\n```ts\n@Controller(\"cats\")\n@AuthzQuery(\"cats/allow\")\n@AuthzStatic({ resource: \"cat\" })\nexport class CatsController {\n  constructor(private catsService: CatsService) {}\n\n  @Post()\n  @Authz(({ body: { name } }) => ({ name, action: \"create\" }))\n  async create(@Body() createCatDto: CreateCatDto) {\n    this.catsService.create(createCatDto);\n  }\n\n  @Get(\":name\")\n  @AuthzQuery(\"cats\") // For illustration, we're querying the package extent\n  @Decision((r) => r.allow)\n  @Authz(({ params: { name } }) => ({\n    name,\n    action: \"get\",\n  }))\n  async findByName(@Param(\"name\") name: string): Promise<Cat> {\n    return this.catsService.findByName(name);\n  }\n}\n```\n\nPlease refer to [the repository's README.md](https://github.com/open-policy-agent/opa-sdk-demos/tree/main/nestjs-demo) for more details.\n\n> [!NOTE]\n> For low-level SDK usage, see the sections below.\n\n---\n\n# OPA OpenAPI SDK (low-level)\n\n<!--\nWe've removed most of the auto-generated Speakeasy examples because they generate the wrong import path.\n-->\n\n<!-- No SDK Example Usage [usage] -->\n\n<!-- Start Available Resources and Operations [operations] -->\n## Available Resources and Operations\n\n<details open>\n<summary>Available methods</summary>\n\n### [OpaApiClient SDK](docs/sdks/opaapiclient/README.md)\n\n* [executeDefaultPolicyWithInput](docs/sdks/opaapiclient/README.md#executedefaultpolicywithinput) - Execute the default decision  given an input\n* [executePolicy](docs/sdks/opaapiclient/README.md#executepolicy) - Execute a policy\n* [executePolicyWithInput](docs/sdks/opaapiclient/README.md#executepolicywithinput) - Execute a policy given an input\n* [executeBatchPolicyWithInput](docs/sdks/opaapiclient/README.md#executebatchpolicywithinput) - Execute a policy given a batch of inputs\n* [compileQueryWithPartialEvaluation](docs/sdks/opaapiclient/README.md#compilequerywithpartialevaluation) - Partially evaluate a query\n* [health](docs/sdks/opaapiclient/README.md#health) - Verify the server is operational\n\n</details>\n<!-- End Available Resources and Operations [operations] -->\n\n<!-- No Error Handling [errors] -->\n\n<!-- No Server Selection [server] -->\n\n<!-- No Custom HTTP Client [http-client] -->\n\n<!-- Start Retries [retries] -->\n## Retries\n\nSome of the endpoints in this SDK support retries.  If you use the SDK without any configuration, it will fall back to the default retry strategy provided by the API.  However, the default retry strategy can be overridden on a per-operation basis, or across the entire SDK.\n\nTo change the default retry strategy for a single API call, simply provide a retryConfig object to the call:\n\n```typescript\nimport { OpaApiClient } from \"@open-policy-agent/opa\";\n\nconst opaApiClient = new OpaApiClient();\n\nasync function run() {\n  const result = await opaApiClient.executeDefaultPolicyWithInput(4963.69, {\n    retries: {\n      strategy: \"backoff\",\n      backoff: {\n        initialInterval: 1,\n        maxInterval: 50,\n        exponent: 1.1,\n        maxElapsedTime: 100,\n      },\n      retryConnectionErrors: false,\n    },\n  });\n\n  // Handle the result\n  console.log(result);\n}\n\nrun();\n\n```\n\nIf you'd like to override the default retry strategy for all operations that support retries, you can provide a retryConfig at SDK initialization:\n\n```typescript\nimport { OpaApiClient } from \"@open-policy-agent/opa\";\n\nconst opaApiClient = new OpaApiClient({\n  retryConfig: {\n    strategy: \"backoff\",\n    backoff: {\n      initialInterval: 1,\n      maxInterval: 50,\n      exponent: 1.1,\n      maxElapsedTime: 100,\n    },\n    retryConnectionErrors: false,\n  },\n});\n\nasync function run() {\n  const result = await opaApiClient.executeDefaultPolicyWithInput(4963.69);\n\n  // Handle the result\n  console.log(result);\n}\n\nrun();\n\n```\n<!-- End Retries [retries] -->\n\n<!-- Start Authentication [security] -->\n## Authentication\n\n### Per-Client Security Schemes\n\nThis SDK supports the following security scheme globally:\n\n| Name         | Type | Scheme      |\n| ------------ | ---- | ----------- |\n| `bearerAuth` | http | HTTP Bearer |\n\nTo authenticate with the API the `bearerAuth` parameter must be set when initializing the SDK client instance. For example:\n\n```typescript\nimport { OpaApiClient } from \"@open-policy-agent/opa\";\n\nconst opaApiClient = new OpaApiClient({\n  bearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n});\n\nasync function run() {\n  const result = await opaApiClient.executeDefaultPolicyWithInput(4963.69);\n\n  // Handle the result\n  console.log(result);\n}\n\nrun();\n\n```\n<!-- End Authentication [security] -->\n\n<!-- Start Debugging [debug] -->\n## Debugging\n\nYou can setup your SDK to emit debug logs for SDK requests and responses.\n\nYou can pass a logger that matches `console`'s interface as an SDK option.\n\n> [!WARNING]\n> Beware that debug logging will reveal secrets, like API tokens in headers, in log messages printed to a console or files. It's recommended to use this feature only during local development and not in production.\n\n```typescript\nimport { OpaApiClient } from \"@open-policy-agent/opa\";\n\nconst sdk = new OpaApiClient({ debugLogger: console });\n```\n<!-- End Debugging [debug] -->\n\n<!-- Start Standalone functions [standalone-funcs] -->\n## Standalone functions\n\nAll the methods listed above are available as standalone functions. These\nfunctions are ideal for use in applications running in the browser, serverless\nruntimes or other environments where application bundle size is a primary\nconcern. When using a bundler to build your application, all unused\nfunctionality will be either excluded from the final bundle or tree-shaken away.\n\nTo read more about standalone functions, check [FUNCTIONS.md](./FUNCTIONS.md).\n\n<details>\n\n<summary>Available standalone functions</summary>\n\n* [`compileQueryWithPartialEvaluation`](docs/sdks/opaapiclient/README.md#compilequerywithpartialevaluation) - Partially evaluate a query\n* [`executeBatchPolicyWithInput`](docs/sdks/opaapiclient/README.md#executebatchpolicywithinput) - Execute a policy given a batch of inputs\n* [`executeDefaultPolicyWithInput`](docs/sdks/opaapiclient/README.md#executedefaultpolicywithinput) - Execute the default decision  given an input\n* [`executePolicy`](docs/sdks/opaapiclient/README.md#executepolicy) - Execute a policy\n* [`executePolicyWithInput`](docs/sdks/opaapiclient/README.md#executepolicywithinput) - Execute a policy given an input\n* [`health`](docs/sdks/opaapiclient/README.md#health) - Verify the server is operational\n\n</details>\n<!-- End Standalone functions [standalone-funcs] -->\n\n<!-- Placeholder for Future Speakeasy SDK Sections -->\n\n## Community\n\nIf there's something you'd like to have added to the roadmap, either open an issue, or reach out in the community Slack!\n","readmeFilename":"README.md"}