Build on the supported package contract
Use @absolutejs/agent-exchange-oauth through its supported public entry points.
@absolutejs/agent-exchange-oauthv0.3.0betaAIHardened OAuth grant exchange using PAR, PKCE, RAR, resource indicators, issuer validation, and DPoP.
bun add @absolutejs/agent-exchange-oauthA deliberately strict OAuth authorization-code handoff for Agent Exchange.
The client requires HTTPS metadata, PAR (RFC 9126), S256 PKCE (RFC 7636), an exact authorization-server issuer (RFC 9207), one exact resource indicator (RFC 8707), Rich Authorization Requests (RFC 9396), and a DPoP-bound access token (RFC 9449). The recipient redeems the one-time grant and immediately performs a purpose-bound operation; the access token is never returned by this package.
This profile is intentionally not a general OAuth client. Provider-specific compatibility belongs in explicit adapters or the paid AbsoluteJS PaaS; the open package remains BYO authorization server and DPoP signer.
Outcomes
Use @absolutejs/agent-exchange-oauth through its supported public entry points.
Hardening checklist
Follow in order
Supported entry points declared by this package manifest.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.