Build on the supported package contract
Use @absolutejs/secure-messaging-federation-delivery through its supported public entry points.
@absolutejs/secure-messaging-federation-deliveryv0.0.1betaMessagingDeliveryService bridge from AbsoluteJS secure messaging to authenticated federation transports.
bun add @absolutejs/secure-messaging-federation-deliveryAn adapter from AbsoluteJS secure messaging's DeliveryService to an authenticated, interchangeable federation transport. It carries the actual protected messaging frame as opaque bytes; it does not replace MLS or decrypt application content.
Outbound application routing is converted into a provider-local opaque routeId. Inbound code resolves only a preconfigured session before checking the remote-domain signature. The application conversation and recipient route are resolved only after authentication and replay checks succeed.
The selected strict-e2ee or managed-recovery mode must exactly match the negotiated federation session. Modes are never inferred or silently downgraded.
Use random, non-semantic conversation and route identifiers. MLS authenticated data can be visible to a delivery provider even though application plaintext is encrypted; do not place email addresses, usernames, or other personal data in identifiers.
Pass delivery to createSecureMessagingClient. The directory is the policy boundary: it must return negotiated, unexpired sessions and opaque routes for the current tenant.
This package is an AbsoluteJS bridge, not a claim of independent MIMI interoperability. Use the revision-pinned MIMI adapter for experiments with the active Internet-Drafts and the HTTPS adapter for the hardened network hop.
Outcomes
Use @absolutejs/secure-messaging-federation-delivery through its supported public entry points.
Hardening checklist
Follow in order
Working example for Usage.
import { createFederatedDeliveryService } from "@absolutejs/secure-messaging-federation-delivery";
const delivery = createFederatedDeliveryService({
directory,
limits,
localDomain: "alice.example",
maximumMessagesPerReceive: 100,
replayStore,
signatureProvider,
transport,
});Supported entry points declared by this package manifest.
Package entry point declared in package.json.
Scripts declared by this package manifest.
Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.