AbsoluteJS

@absolutejs/agent-exchange-oauth-webcrypto

@absolutejs/agent-exchange-oauth-webcryptov0.2.1betaAI

Non-exportable WebCrypto ES256 DPoP signer for Agent Exchange OAuth.

#Installation

BASH
bun add @absolutejs/agent-exchange-oauth-webcrypto

#Capabilities

Overview

An ES256 DPoP signer backed by WebCrypto. Generated private keys are non-exportable. Every proof uses a fresh 128-bit jti, normalized htu, current iat, optional server nonce, and ath when an access token is supplied.

Version 0.2.1 uses the canonical-base64url-enforcing 0.3.1 conformance verifier so alternate compact proof encodings cannot alias the same signature.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-oauth-webcrypto through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-oauth-webcrypto version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-oauth-webcrypto example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-oauth-webcryptoPackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange-oauth --external @absolutejs/agent-exchange-provider-conformance && tsc --project tsconfig.build.json
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

3 symbols
WebCryptoDpopProofSignertypePermalinkSource
TS
type WebCryptoDpopProofSigner = DpopProofSigner & {
    readonly publicJwk: Readonly<JsonWebKey>;
};
Exported from @absolutejs/agent-exchange-oauth-webcrypto