AbsoluteJS

Secure Messaging Federation

@absolutejs/secure-messaging-federationv0.1.0betaMessaging

Provider-neutral, downgrade-resistant secure messaging federation for AbsoluteJS.

#Installation

BASH
bun add @absolutejs/secure-messaging-federation

#Capabilities

Overview

Provider-neutral secure messaging federation for AbsoluteJS. The stable core keeps domain authentication, transports, and abuse-evidence cryptography behind interchangeable contracts while enforcing one downgrade-resistant API.

The first release provides:

exact bilateral profile matching; profiles bind the federation protocol and

Show 10 more

revision, E2EE protocol, content types, feature set, frame limit, and explicit strict-e2ee or managed-recovery security mode;

transcript hashes over both offers and mutual domain signatures before a

session becomes active;

signed opaque envelopes bound to that transcript, with expiry, clock-skew,

size, local-domain, route, and durable replay checks;

strict bounded wire codecs and explicit transport acknowledgement, allowing a

delivery bridge to acknowledge only after durable MLS processing;

confidential abuse-evidence contracts that require a concrete user approval

or standing-policy mandate and disclose only ciphertext to federation code.

There is deliberately no plaintext, legacy, or weaker-mode fallback. If peers do not advertise an exactly matching locally preferred profile, negotiation fails. Managed recovery also has to name the same recovery authority on both sides.

Standards position

The IETF MIMI architecture and protocol are active Internet-Drafts, not finished standards. This core therefore does not claim MIMI interoperability. A MIMI adapter must identify and pin the exact draft revision, expose it in the negotiated profile, require explicit experimental opt-in, and fail when the peer does not match. The separation lets AbsoluteJS track MIMI without destabilizing the application API.

The model follows MLS's authenticated epoch and group-state boundaries from RFC 9420, the federation roles and minimal-provider-access direction in the MIMI architecture draft, and bilateral capability/message-franking work in the MIMI protocol draft.

Abuse and AI safety

Evidence sealing happens at the endpoint. The report object carries sealed bytes and bounded metadata, never a plaintext field. receiver-asserted means a recipient supplied the evidence and could have fabricated it; only a provider that actually validates a sender-bound cryptographic frank may return franked. Message franking in MIMI remains draft work.

An agent must not infer permission from the content it sees. It must supply either a phishing-resistant user-approved approval ID or an exact standing-policy mandate ID before evidence can be sealed. Applications should show the recipient, reason, messages, destination moderation key, and disclosure scope outside model-controlled content.

Outcomes

What you can build

Overview

Provider-neutral secure messaging federation for AbsoluteJS. The stable core keeps domain authentication, transports, and abuse-evidence cryptography behind interchangeable contracts while enforcing one downgrade-resistant API.

Standards position

The IETF MIMI architecture and protocol are active Internet-Drafts, not finished standards. This core therefore does not claim MIMI interoperability. A MIMI adapter must identify and pin the exact draft revision, expose it in the negotiated profile, require explicit experimental opt-in, and fail when the peer does not match. The separation lets AbsoluteJS track MIMI without destabilizing the application API.

Abuse and AI safety

Evidence sealing happens at the endpoint. The report object carries sealed bytes and bounded metadata, never a plaintext field. receiver-asserted means a recipient supplied the evidence and could have fabricated it; only a provider that actually validates a sender-bound cryptographic frank may return franked. Message franking in MIMI remains draft work.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/secure-messaging-federation version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/secure-messaging-federation example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/secure-messaging-federation quick start

Partial snippet

# @absolutejs/secure-messaging-federation

TS
const transcript = await negotiateFederation({
  initiatorOffer,
  responderOffer,
  preferredProfileIds: ["abs.mls.strict.v1"],
  sessionId: "random-session-id",
  limits,
  now: Date.now(),
});

// Each domain signs the exact transcript through a signature provider.
const session = await activateFederationSession({
  initiatorOffer,
  responderOffer,
  transcript,
  initiatorConfirmation,
  responderConfirmation,
  signatureProvider,
  now: Date.now(),
});

#Public entry points

Supported entry points declared by this project’s package manifest. Internal dist paths are not part of the package contract.

Public package entry point declared in package.json.

@absolutejs/secure-messaging-federation@absolutejs/secure-messaging-federation/manifest@absolutejs/secure-messaging-federation/manifest.json

#Package commands

Scripts declared by this project’s package manifest.

bun run buildrm -rf dist && bun build src/index.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit
bun run check:packagebun run format:check && bun run typecheck && bun run test && bun run build && bun run verify-package && absolute-changelog check
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run format:checkprettier --check "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

36 symbols
createFederationAbuseReportvaluePermalink
TS
const createFederationAbuseReport: (input: {
    readonly allegedSender: string;
    readonly authorization: FederationAbuseAuthorization;
    readonly createdAt: number;
    readonly evidence: Uint8Array;
    readonly evidenceProvider: FederationAbuseEvidenceProvider;
    readonly expiresAt: number;
    readonly maximumEvidenceBytes: number;
    readonly maximumSealedEvidenceBytes: number;
    readonly maximumTtlMs: number;
    readonly messageIds: readonly string[];
    readonly reason: FederationAbuseReason;
    readonly recipientKeyId: string;
    readonly reportId: string;
    readonly roomId: string;
}) => Promise<FederationAbuseReport>;
Exported from @absolutejs/secure-messaging-federation