AbsoluteJS

@absolutejs/agent-exchange-mandate-webcrypto

@absolutejs/agent-exchange-mandate-webcryptov0.2.0betaAI

Non-exportable WebCrypto ES256 JWS provider for Agent Exchange standing mandates.

#Installation

BASH
bun add @absolutejs/agent-exchange-mandate-webcrypto

#Capabilities

Overview

Interchangeable WebCrypto ES256 compact-JWS signer and verifier for @absolutejs/agent-exchange standing mandates.

The signer requires a non-exportable P-256 private key. The verifier resolves a public key only from the independently trusted issuer and the protected kid, then enforces alg: ES256, the AbsoluteJS mandate typ, strict compact encoding, and a 64-byte JWS ECDSA signature.

This experimental 0.x package has not been independently audited. Production services should keep signing keys in a KMS or HSM; implement the same core signer contract with that service instead of exporting key material.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-mandate-webcrypto through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-mandate-webcrypto version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-mandate-webcrypto example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-mandate-webcryptoPackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange && tsc --project tsconfig.build.json
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

3 symbols
AgentExchangeMandatePublicKeyResolvertypePermalinkSource
TS
type AgentExchangeMandatePublicKeyResolver = {
    readonly resolve: (input: {
        readonly issuer: AgentExchangeMandatePrincipal;
        readonly keyId: string;
    }) => Promise<CryptoKey> | CryptoKey;
};
Exported from @absolutejs/agent-exchange-mandate-webcrypto