AbsoluteJS

@absolutejs/agent-exchange-webauthn

@absolutejs/agent-exchange-webauthnv0.4.1betaAI

Request-bound, user-verified WebAuthn approvals for @absolutejs/agent-exchange.

#Installation

BASH
bun add @absolutejs/agent-exchange-webauthn

#Capabilities

Overview

An interchangeable AgentExchangeApprovalProvider that binds a user-verified WebAuthn assertion to the exact Agent Exchange request digest.

It also provides createWebAuthnAgentExchangeMandateApprovalProvider() for standing mandates. That provider recomputes the domain-separated challenge over the complete mandate draft and requires the issuer authority and subject to match the verifier before beginning or verifying the ceremony.

The provider requires HTTPS, an RP ID valid for the configured verifier origin, an exact caller-provided challenge, user verification, credential ownership, and safe signature-counter progression. It does not persist raw assertions.

Show 2 more

Use the resulting provider with the phishing-resistant assurance profile in @absolutejs/agent-exchange@0.4.

For local development only, allowInsecureLocalhost: true permits an HTTP localhost origin and RP ID. It does not permit arbitrary HTTP hosts.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/agent-exchange-webauthn through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/agent-exchange-webauthn version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/agent-exchange-webauthn example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/agent-exchange-webauthn quick start

Partial snippet

# @absolutejs/agent-exchange-webauthn

TS
const approvalProvider = createWebAuthnAgentExchangeApprovalProvider({
  adapter,
  credentialStore,
  origin: "https://app.example.com",
  resolveUserId: async ({ subject }) => subject,
  rpId: "example.com",
});

#Public entry points

Supported entry points declared by this package manifest.

@absolutejs/agent-exchange-webauthnPackage entry point declared in package.json.

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/agent-exchange --external @absolutejs/auth && tsc --project tsconfig.build.json
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

5 symbols
WebAuthnAgentExchangeApprovalProviderOptionstypePermalinkSource
TS
type WebAuthnAgentExchangeApprovalProviderOptions = {
    readonly allowInsecureLocalhost?: boolean;
    readonly adapter: WebAuthnAdapter;
    readonly credentialStore: WebAuthnCredentialStore;
    readonly now?: () => number;
    readonly origin: string;
    readonly resolveUserId: (input: {
        readonly request: AgentExchangeRequest;
        readonly subject: string;
    }) => Promise<string> | string;
    readonly rpId: string;
};
Exported from @absolutejs/agent-exchange-webauthn