TypeScript verifier SDK — deployment guide

Copy Markdown View Source

The TypeScript verifier SDK is published to npm as @bounded-authority-protocol/verifier and developed in its own graduated repository, baselabs/bounded_authority_protocol_typescript (per ADR 0015: SDKs are authored in this monorepo while unpublished and graduate to a per-SDK repository on first publication — this guide stays here because the protocol package remains the normative entry point).

The SDK is a pure, deterministic, fail-closed reimplementation of the wire profiles (contract-majors 1 and 2). It is a verifier: it returns redacted, value-bearing facts or a single Invalid outcome, never an authorization decision. See spec/bap-v1.md / spec/bap-v2.md (the normative authorities) and ADR 0014 for the packaging and derivation-hygiene decisions.

Runtime posture

  • Node >= 22; node:crypto for Ed25519 (zero non-stdlib dependencies).
  • Pure functions only: no clock, network, filesystem, or randomness in the verify path. Time, trusted keys, and expected context are explicit inputs.
  • Bundle shape: the published package carries the compiled verifier only (dist/src); the conformance corpora and runners live in the repository, not the tarball. Tree-shaking keeps serverless bundles small (the verifier core is a single module closure).

Install and releases

npm install @bounded-authority-protocol/verifier

Releases are two-stage by owner decision: the graduated repository's release workflow stages each version to npm with provenance (GitHub Actions OIDC trusted publishing — no tokens), and a human approves the staged version on npmjs.com under the org's 2FA requirement. CI cannot make a version live alone.

Corpus updates

The SDK vendors certified snapshots of both conformance corpora plus the local-loopback application-proof corpus and asserts each index.json SHA-256 at load. When this monorepo rotates a corpus, the SDK repository takes a snapshot-bump commit — the startup assertion fails loudly on any drift.