Build on the supported package contract
Use @absolutejs/agent-exchange-email through its supported public entry points.
@absolutejs/agent-exchange-emailv0.5.0betaAIDeterministic, model-blind email verification-code source for @absolutejs/agent-exchange.
bun add @absolutejs/agent-exchange-emailEmail one-time codes are bearer credentials. This source accepts either the explicit policy + bearer + purpose-bound profile or webauthn-verifier-bound + token-confined-broker + purpose-bound. The latter confines provider credentials and OTP processing to a trusted broker but does not make the upstream bearer credential phishing-resistant.
The 0.5.x line also accepts an exact, passkey-enrolled standing-mandate with the same token-confined and purpose-bound requirements. The signed mandate never broadens the host-owned mailbox profile.
An interchangeable, deterministic email source for @absolutejs/agent-exchange. It uses @absolutejs/email/verification to locate one exact verification message and returns the protected value directly to Agent Exchange for encryption.
Gmail and Microsoft Graph lookups are browser-safe. IMAP is server-only and is created from @absolutejs/email/verification/imap before being passed here.
Pass source to createAgentExchangeSender. Do not register it as an MCP, A2A, manifest, or general agent tool. The source deliberately returns no string API; Agent Exchange encrypts its mutable byte result and clears it after delivery.
Only tool-confined, single-use, email-one-time-code requests are accepted.
The request's exact provider, HTTPS origin, and operation must select exactly
one profile.
challenge-text correlation is the default-safe profile mode: the request's
challengeId must occur exactly in the selected message body.
temporal-only profiles require both an explicit profile mode and
allowTemporalOnlyCorrelation: true; use this weaker mode only when an upstream email cannot echo a challenge.
The visible sender must have exactly one aligned DMARC pass from a configured,
mailbox-trusted RFC 8601 authserv-id.
The mailbox account reference is resolved through a host-owned directory; it
is never assumed to be an email address.
The default lookup window begins 30 seconds before the Agency request and ends
at the earlier of execution time or request expiry. Future clock skew must be enabled explicitly.
Outcomes
Use @absolutejs/agent-exchange-email through its supported public entry points.
Hardening checklist
Follow in order
# @absolutejs/agent-exchange-email
bun add @absolutejs/agent-exchange @absolutejs/agent-exchange-email @absolutejs/email# @absolutejs/agent-exchange-email
import { createEmailVerificationCodeSource } from "@absolutejs/agent-exchange-email";
import { createGmailVerificationMessageLookup } from "@absolutejs/email/verification";
const source = createEmailVerificationCodeSource({
lookup: createGmailVerificationMessageLookup({ accountEmail, client: gmail }),
profiles: [
{
bodyMarkers: ["verification code"],
correlation: { mode: "challenge-text" },
id: "accounts-example-six-digit-v1",
operations: ["verification.submit"],
origins: ["https://accounts.example.com"],
providers: ["gmail"],
senderAddresses: ["security@example.com"],
senderAuthentication: {
allowedHeaderFromDomains: ["example.com"],
trustedAuthservIds: ["mx.mailbox.example"],
},
subjectIncludesAny: ["sign in"],
},
],
resolveAccountEmail: (request) =>
mailboxDirectory.get(request.resource.accountRef),
});Supported entry points declared by this package manifest.
Package entry point declared in package.json.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.