AbsoluteJS

@absolutejs/agent-exchange-email

@absolutejs/agent-exchange-emailv0.5.0betaAI

Deterministic, model-blind email verification-code source for @absolutejs/agent-exchange.

#Installation

BASH
bun add @absolutejs/agent-exchange-email

#Capabilities

Overview

Email one-time codes are bearer credentials. This source accepts either the explicit policy + bearer + purpose-bound profile or webauthn-verifier-bound + token-confined-broker + purpose-bound. The latter confines provider credentials and OTP processing to a trusted broker but does not make the upstream bearer credential phishing-resistant.

The 0.5.x line also accepts an exact, passkey-enrolled standing-mandate with the same token-confined and purpose-bound requirements. The signed mandate never broadens the host-owned mailbox profile.

An interchangeable, deterministic email source for @absolutejs/agent-exchange. It uses @absolutejs/email/verification to locate one exact verification message and returns the protected value directly to Agent Exchange for encryption.

Show 2 more

Gmail and Microsoft Graph lookups are browser-safe. IMAP is server-only and is created from @absolutejs/email/verification/imap before being passed here.

Pass source to createAgentExchangeSender. Do not register it as an MCP, A2A, manifest, or general agent tool. The source deliberately returns no string API; Agent Exchange encrypts its mutable byte result and clears it after delivery.

Fail-closed rules

Only tool-confined, single-use, email-one-time-code requests are accepted.

The request's exact provider, HTTPS origin, and operation must select exactly

one profile.

Show 10 more

challenge-text correlation is the default-safe profile mode: the request's

challengeId must occur exactly in the selected message body.

temporal-only profiles require both an explicit profile mode and

allowTemporalOnlyCorrelation: true; use this weaker mode only when an upstream email cannot echo a challenge.

The visible sender must have exactly one aligned DMARC pass from a configured,

mailbox-trusted RFC 8601 authserv-id.

The mailbox account reference is resolved through a host-owned directory; it

is never assumed to be an email address.

The default lookup window begins 30 seconds before the Agency request and ends

at the earlier of execution time or request expiry. Future clock skew must be enabled explicitly.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-email through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-email version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-email example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/agent-exchange-email quick start

Partial snippet

# @absolutejs/agent-exchange-email

BASH
bun add @absolutejs/agent-exchange @absolutejs/agent-exchange-email @absolutejs/email

#@absolutejs/agent-exchange-email quick start 2

Partial snippet

# @absolutejs/agent-exchange-email

TS
import { createEmailVerificationCodeSource } from "@absolutejs/agent-exchange-email";
import { createGmailVerificationMessageLookup } from "@absolutejs/email/verification";

const source = createEmailVerificationCodeSource({
  lookup: createGmailVerificationMessageLookup({ accountEmail, client: gmail }),
  profiles: [
    {
      bodyMarkers: ["verification code"],
      correlation: { mode: "challenge-text" },
      id: "accounts-example-six-digit-v1",
      operations: ["verification.submit"],
      origins: ["https://accounts.example.com"],
      providers: ["gmail"],
      senderAddresses: ["security@example.com"],
      senderAuthentication: {
        allowedHeaderFromDomains: ["example.com"],
        trustedAuthservIds: ["mx.mailbox.example"],
      },
      subjectIncludesAny: ["sign in"],
    },
  ],
  resolveAccountEmail: (request) =>
    mailboxDirectory.get(request.resource.accountRef),
});

#Public entry points

Supported entry points declared by this package manifest.

Package entry point declared in package.json.

@absolutejs/agent-exchange-email@absolutejs/agent-exchange-email/source-manifest@absolutejs/agent-exchange-email/manifest@absolutejs/agent-exchange-email/manifest.json

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts src/source-manifest.ts src/manifest.ts --outdir dist --root src --sourcemap --target=bun --external @absolutejs/agent-exchange --external '@absolutejs/agent-exchange/*' --external @absolutejs/email --external '@absolutejs/email/*' --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

8 symbols
EmailAgentExchangeCorrelationtypePermalinkSource
TS
type EmailAgentExchangeCorrelation = {
    readonly mode: "challenge-text";
} | {
    readonly mode: "temporal-only";
};
Exported from @absolutejs/agent-exchange-email