AbsoluteJS

@absolutejs/agent-exchange-secure-messaging

@absolutejs/agent-exchange-secure-messagingv0.1.0betaAI

Strict-E2EE request and receipt transport for model-blind AbsoluteJS Agent Exchange.

#Installation

BASH
bun add @absolutejs/agent-exchange-secure-messaging

#Capabilities

Overview

An interchangeable Agent Exchange transport over authenticated AbsoluteJS secure messaging. It carries the complete request, the already protected Agent Exchange envelope, and a standing-mandate JWS inside a strict-e2ee conversation. Only a redacted receipt returns.

Protocol contract 2 binds the original request expiry into the authenticated receipt and durable record. It is intentionally incompatible with contract 1.

Both request and receipt purposes are fixed authenticated MLS metadata. The adapter requires request.requester.deviceId and request.recipient.deviceId, checks them against the authenticated sending and local devices, validates a strict no-extension wire format, and bounds every identifier, JWS, envelope, and frame lifetime.

Show 3 more

createMemoryAgentExchangeSecureMessagingReceiptStore() is for examples and tests. Production deployments should use @absolutejs/agent-exchange-secure-messaging-stores. The store contract carries the authenticated request expiry and an explicit current time so backends can reject expired writes, hide expired reads, and expire durable records.

The recipient must use receiveAndHandle(), not ordinary receive(). This atomically queues the encrypted receipt with the inbound replay receipt and advanced MLS state before acknowledging delivery. Deterministic sinks must use the exchange ID as their downstream idempotency key so a crash immediately before that commit remains safe.

Licensed under Apache-2.0.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-secure-messaging through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-secure-messaging version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-secure-messaging example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/agent-exchange-secure-messaging quick start

Partial snippet

# @absolutejs/agent-exchange-secure-messaging

TS
const receipts = createMemoryAgentExchangeSecureMessagingReceiptStore();

const transport = createAgentExchangeSecureMessagingTransport({
  client: requesterMessaging,
  receipts,
  resolveRoute: (request) => ({
    conversationId: conversationFor(request.recipient),
    recipientDeviceId: request.recipient.deviceId!,
  }),
  resolveSignedMandate: (request) => mandates.get(request.mandateId!),
});

const handler = createAgentExchangeSecureMessagingHandler({
  authorizeRequest: ({ delivery, signedMandate }) =>
    mandateAuthority.authorize({
      expectedIssuer: owner,
      request: delivery.request,
      signedMandate,
    }),
  localDeviceId: "recipient-device",
  receipts,
  receiver,
});

await recipientMessaging.receiveAndHandle(handler);
await requesterMessaging.receiveAndHandle(handler);

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-secure-messagingPackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --target=node --external @absolutejs/agent-exchange --external @absolutejs/secure-messaging && tsc --project tsconfig.build.json
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

13 symbols
AGENT_EXCHANGE_SECURE_MESSAGING_CONTRACTvaluePermalinkSource
TS
const AGENT_EXCHANGE_SECURE_MESSAGING_CONTRACT: 2;
Exported from @absolutejs/agent-exchange-secure-messaging