Overview
Provider-neutral key-transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.
@absolutejs/key-transparencyv0.2.0betaMessagingProvider-neutral key transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.
bun add @absolutejs/key-transparencyProvider-neutral key-transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.
This is an early 0.x foundation. It does not implement the IETF KEYTRANS cryptography and it does not turn an ordinary key directory into a transparency log. Providers must verify the protocol's proofs and signatures before returning results through these contracts.
MLS protects conversation content, but its Authentication Service binds identities to device signature keys. A compromised or malicious Authentication Service can issue a valid credential for a ghost device. Key transparency makes those key bindings append-only, searchable, monitorable, and capable of exposing inconsistent views.
Keeping @absolutejs/key-transparency separate from @absolutejs/e2ee prevents the encryption provider or identity authority from silently acting as its own independent verifier.
Providers live in key-transparency-providers and follow the package pattern @absolutejs/key-transparency-. A provider owns draft-specific proof parsing and cryptographic verification. This package additionally enforces:
an exact protocol revision rather than a floating “KEYTRANS compatible” claim;
operation, label, value, provider, and tree-head binding for evidence;
monotonically increasing locally persisted tree views;
compare-and-set persistence so concurrent clients cannot overwrite newer views;
explicit contact monitoring, owner monitoring, auditor, privacy, and assurance
capabilities;
independent audit evidence before an audited claim is accepted.
Applications pass opaque, application-derived label bytes. Raw email addresses, phone numbers, usernames, and other enumerable identifiers should not cross this boundary.
The memory view store is for tests and short-lived demos. Production clients need durable, rollback-resistant storage.
Provider manifests are claims; certification reports are evidence tied to one exact provider version, protocol revision, runtime, completion time, scenario set, and evidence digest. Production admission should require fresh conformance and adversarial claims. Official vectors, cross-implementation behavior, and an independent audit are separate claims and cannot be declared without their corresponding evidence.
The package currently pins draft-ietf-keytrans-protocol-05 and draft-ietf-keytrans-architecture-09. Internet-Drafts are works in progress and can change. Providers must publish a new 0.x version when changing protocol revision; the selector never silently treats revisions as equivalent.
Protocol:
Architecture:
MLS architecture:
Public TypeScript contracts use type aliases rather than interfaces.
Outcomes
Provider-neutral key-transparency contracts, local rollback protection, provider selection, and conformance tools for AbsoluteJS.
MLS protects conversation content, but its Authentication Service binds identities to device signature keys. A compromised or malicious Authentication Service can issue a valid credential for a ghost device. Key transparency makes those key bindings append-only, searchable, monitorable, and capable of exposing inconsistent views.
Providers live in key-transparency-providers and follow the package pattern @absolutejs/key-transparency-. A provider owns draft-specific proof parsing and cryptographic verification. This package additionally enforces:
Hardening checklist
Follow in order
Providers live in key-transparency-providers and follow the package pattern @absolutejs/key-transparency-. A provider owns draft-specific proof parsing and cryptographic verification. This package additionally enforces:
import {
createKeyTransparencyClient,
createMemoryKeyTransparencyViewStore,
selectKeyTransparencyProvider,
} from "@absolutejs/key-transparency";
const provider = selectKeyTransparencyProvider(providers, {
minimumAssurance: "reviewed",
protocolRevision: "draft-ietf-keytrans-protocol-05",
requireContactMonitoring: true,
requireOwnerMonitoring: true,
requireSplitViewDetection: true,
roles: ["client", "monitor"],
runtime: "browser",
});
const client = createKeyTransparencyClient({
provider,
store: createMemoryKeyTransparencyViewStore(),
});Supported entry points declared by this project’s package manifest. Internal dist paths are not part of the package contract.
Public package entry point declared in package.json.
Scripts declared by this project’s package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.
const keyTransparencyLabelDigest: (label: KeyTransparencyLabel) => Promise<string>;@absolutejs/key-transparency