Overview
Interchangeable, security-profiled providers for @absolutejs/agent-exchange.
@absolutejs/agent-exchange-providersworkspacealphaAIInterchangeable, security-profiled providers for @absolutejs/agent-exchange.
git clone https://github.com/absolutejs/agent-exchange-providers.gitInterchangeable, security-profiled providers for @absolutejs/agent-exchange.
@absolutejs/agent-exchange-webauthn verifies a request-bound,
user-verified WebAuthn approval.
@absolutejs/agent-exchange-oauth implements a hardened OAuth grant
handoff using PAR, PKCE, issuer identification, resource indicators, RAR, and DPoP.
@absolutejs/agent-exchange-oauth-webcrypto supplies a
non-exportable ES256 DPoP signer.
@absolutejs/agent-exchange-oauth-stores supplies one-time
memory, Redis, and PostgreSQL authorization-session stores.
@absolutejs/agent-exchange-provider-conformance evaluates
provider security capabilities, verifies DPoP proofs, and actively tests A2A sandboxes for negotiation, preparation, credential separation, replay safety, and task/receipt redaction.
@absolutejs/agent-exchange-broker confines an upstream bearer
token to one tenant, exchange, provider, purpose, and deterministic operation.
15 public packages and 0 private workspace projects are versioned and developed together.
Outcomes
Interchangeable, security-profiled providers for @absolutejs/agent-exchange.
Hardening checklist
Follow in order
15 public packages and 0 private workspace projects are maintained in this repository.
Public package — Negotiated, authenticated A2A client and server adapters for model-blind AbsoluteJS Agent Exchange.
Public package — Tenant-fenced, one-time token-confined broker contracts for AbsoluteJS Agent Exchange.
Public package — Interchangeable, deterministic destination adapter contract for Agent Exchange.
Public package — Capability-declared BYO Google Gmail OAuth adapter for Agent Exchange.
Public package — Fixed-endpoint HTTPS verification-code destination adapter for Agent Exchange.
Public package — Atomic PostgreSQL and Redis stores for Agent Exchange standing mandates.
Public package — Non-exportable WebCrypto ES256 JWS provider for Agent Exchange standing mandates.
Public package — Capability-declared BYO Microsoft Graph OAuth adapter for Agent Exchange.
Public package — Hardened OAuth grant exchange using PAR, PKCE, RAR, resource indicators, issuer validation, and DPoP.
Public package — Memory, Redis, and PostgreSQL one-time OAuth session stores for Agent Exchange.
Public package — Non-exportable WebCrypto ES256 DPoP signer for Agent Exchange OAuth.
Public package — OAuth, DPoP, and black-box A2A security conformance checks for Agent Exchange providers.
Public package — Strict-E2EE request and receipt transport for model-blind AbsoluteJS Agent Exchange.
Public package — Tenant-scoped atomic memory, Redis, and PostgreSQL receipt stores for Agent Exchange secure messaging.
Public package — Request-bound, user-verified WebAuthn approvals for @absolutejs/agent-exchange.
Scripts declared by this project’s package manifest.