AbsoluteJS

@absolutejs/agent-exchange-oauth

@absolutejs/agent-exchange-oauthv0.3.0betaAI

Hardened OAuth grant exchange using PAR, PKCE, RAR, resource indicators, issuer validation, and DPoP.

#Installation

BASH
bun add @absolutejs/agent-exchange-oauth

#Capabilities

Overview

A deliberately strict OAuth authorization-code handoff for Agent Exchange.

The client requires HTTPS metadata, PAR (RFC 9126), S256 PKCE (RFC 7636), an exact authorization-server issuer (RFC 9207), one exact resource indicator (RFC 8707), Rich Authorization Requests (RFC 9396), and a DPoP-bound access token (RFC 9449). The recipient redeems the one-time grant and immediately performs a purpose-bound operation; the access token is never returned by this package.

This profile is intentionally not a general OAuth client. Provider-specific compatibility belongs in explicit adapters or the paid AbsoluteJS PaaS; the open package remains BYO authorization server and DPoP signer.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-oauth through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-oauth version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-oauth example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-oauthPackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange && tsc --project tsconfig.build.json
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

11 symbols
OAuthAuthorizationDetailstypePermalinkSource
TS
type OAuthAuthorizationDetails = {
    readonly actions: readonly string[];
    readonly identifier?: string;
    readonly locations: readonly string[];
    readonly type: string;
};
Exported from @absolutejs/agent-exchange-oauth