Build on the supported package contract
Use @absolutejs/agent-exchange-webauthn through its supported public entry points.
@absolutejs/agent-exchange-webauthnv0.4.1betaAIRequest-bound, user-verified WebAuthn approvals for @absolutejs/agent-exchange.
bun add @absolutejs/agent-exchange-webauthnAn interchangeable AgentExchangeApprovalProvider that binds a user-verified WebAuthn assertion to the exact Agent Exchange request digest.
It also provides createWebAuthnAgentExchangeMandateApprovalProvider() for standing mandates. That provider recomputes the domain-separated challenge over the complete mandate draft and requires the issuer authority and subject to match the verifier before beginning or verifying the ceremony.
The provider requires HTTPS, an RP ID valid for the configured verifier origin, an exact caller-provided challenge, user verification, credential ownership, and safe signature-counter progression. It does not persist raw assertions.
Use the resulting provider with the phishing-resistant assurance profile in @absolutejs/agent-exchange@0.4.
For local development only, allowInsecureLocalhost: true permits an HTTP localhost origin and RP ID. It does not permit arbitrary HTTP hosts.
Outcomes
Use @absolutejs/agent-exchange-webauthn through its supported public entry points.
Hardening checklist
Follow in order
# @absolutejs/agent-exchange-webauthn
const approvalProvider = createWebAuthnAgentExchangeApprovalProvider({
adapter,
credentialStore,
origin: "https://app.example.com",
resolveUserId: async ({ subject }) => subject,
rpId: "example.com",
});Supported entry points declared by this package manifest.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.
type WebAuthnAgentExchangeApprovalProviderOptions = {
readonly allowInsecureLocalhost?: boolean;
readonly adapter: WebAuthnAdapter;
readonly credentialStore: WebAuthnCredentialStore;
readonly now?: () => number;
readonly origin: string;
readonly resolveUserId: (input: {
readonly request: AgentExchangeRequest;
readonly subject: string;
}) => Promise<string> | string;
readonly rpId: string;
};@absolutejs/agent-exchange-webauthn