Build on the supported package contract
Use @absolutejs/agent-exchange-mandate-webcrypto through its supported public entry points.
@absolutejs/agent-exchange-mandate-webcryptov0.2.0betaAINon-exportable WebCrypto ES256 JWS provider for Agent Exchange standing mandates.
bun add @absolutejs/agent-exchange-mandate-webcryptoInterchangeable WebCrypto ES256 compact-JWS signer and verifier for @absolutejs/agent-exchange standing mandates.
The signer requires a non-exportable P-256 private key. The verifier resolves a public key only from the independently trusted issuer and the protected kid, then enforces alg: ES256, the AbsoluteJS mandate typ, strict compact encoding, and a 64-byte JWS ECDSA signature.
This experimental 0.x package has not been independently audited. Production services should keep signing keys in a KMS or HSM; implement the same core signer contract with that service instead of exporting key material.
Outcomes
Use @absolutejs/agent-exchange-mandate-webcrypto through its supported public entry points.
Hardening checklist
Follow in order
Supported entry points declared by this package manifest.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.
type AgentExchangeMandatePublicKeyResolver = {
readonly resolve: (input: {
readonly issuer: AgentExchangeMandatePrincipal;
readonly keyId: string;
}) => Promise<CryptoKey> | CryptoKey;
};@absolutejs/agent-exchange-mandate-webcrypto