npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@abstraxn/warrant-verifier

v0.1.0

Published

KYI Warrant receipt verifier — offline Ed25519 + optional on-chain MandateRegistry / ReceiptLog checks

Readme

@abstraxn/warrant-verifier

Offline verification for KYI Warrant decision receipts. Zero network calls to Warrant — auditors only need the signed receipt JSON and Warrant’s public key.

Related packages:

| Package | Role | |---------|------| | @abstraxn/warrant | Server / Node client | | @abstraxn/warrant-react | MandateForm + Readback | | @abstraxn/warrant-verifier | Offline receipt verify + CLI |

Installation

npm install @abstraxn/warrant-verifier
yarn add @abstraxn/warrant-verifier
pnpm add @abstraxn/warrant-verifier

Prerequisites

  • Node.js >= 18
  • Warrant Ed25519 public key (hex file, base64, or JSON { "publicKey": "…" })
    • From KYI: GET /v1/warrant/keys/receipt (or your deployed key material)

Library

import {
  verifyReceiptJson,
  verifyReceiptsJsonl,
  canonicalize,
  tamperReceiptsJsonl,
} from '@abstraxn/warrant-verifier';
import { readFileSync } from 'node:fs';

function hexToBytes(hex: string): Uint8Array {
  const clean = hex.trim().replace(/^0x/i, '');
  const out = new Uint8Array(clean.length / 2);
  for (let i = 0; i < out.length; i++) {
    out[i] = parseInt(clean.slice(i * 2, i * 2 + 2), 16);
  }
  return out;
}

const publicKey = hexToBytes(readFileSync('public.key', 'utf8').trim());
const jsonl = readFileSync('receipts.jsonl', 'utf8');

const rows = await verifyReceiptsJsonl(jsonl, publicKey);
for (const row of rows) {
  console.log(row.receipt_id, row.verdict, row.valid ? 'VALID' : row.error);
}

Single receipt

const result = await verifyReceiptJson(receiptObjectOrJsonString, publicKey);
// { receipt_id, verdict, reasons, valid, error? }

CLI

The package ships a warrant-verify binary:

npx warrant-verify receipts.jsonl --public-key=./public.key

Options

| Flag | Description | |------|-------------| | --public-key=<path> | Path to hex / base64 / JSON public key (default: config/keys/public.key) | | --tamper | Demo mode: mutate amount on the last receipt, write *.tamper.jsonl, then verify (signature stays intact → fails) |

Exit code 0 if all receipts are valid; 1 otherwise.

Tamper demo

npx warrant-verify receipts.jsonl --public-key=./public.key --tamper

Shows that changing receipt content without resigning fails verification.


API reference

| Export | Description | |--------|-------------| | verifyReceiptJson(lineOrObject, publicKey) | Verify one receipt (JSON string or object) | | verifyReceiptsJsonl(content, publicKey) | Verify each non-empty JSONL line | | canonicalize(value) | Deterministic JSON canonicalize used for the signed message | | tamperReceiptsJsonl(content) | Demo helper — mutates amount on the last receipt | | verifyMandateOnchain(…) | RPC: MandateRegistry content hash + active | | verifyReceiptOnchain(…) | RPC: ReceiptLog Merkle inclusion | | verifyMerkleProof(…) | Offline Merkle inclusion (sorted pairs) |

type VerifyResult = {
  receipt_id: string;
  verdict: string;
  reasons: string;
  valid: boolean;
  error?: string;
};

How verification works

  1. Strip signature from the receipt object
  2. Canonicalize the unsigned payload
  3. Ed25519-verify signature.sig (hex) against Warrant’s public key

On-chain Merkle / STH checks are planned when MandateRegistry / ReceiptLog contracts are live; this package already verifies cryptographic integrity offline.

On-chain helpers (optional RPC)

Auditors can also check MandateRegistry / ReceiptLog without calling the Warrant API:

import {
  verifyMandateOnchain,
  verifyReceiptOnchain,
  verifyMerkleProof,
  receiptLeafBytes32,
  canonicalize,
} from '@abstraxn/warrant-verifier';

const mandate = await verifyMandateOnchain({
  rpcUrl: process.env.RPC_URL!,
  mandateRegistry: '0x9f13744Cd7ca5b7851Aa21C9607617a83904A3b5',
  mandateId: 'mnd_sha256:…',
  contentHashHex: '…', // mandate.hash
  chainId: 80002,
});

// Offline Merkle (no RPC)
const leaf = receiptLeafBytes32(canonicalize(unsignedOrSignedReceipt));
const merkleOk = verifyMerkleProof({ leaf, proof, root });

const receipt = await verifyReceiptOnchain({
  rpcUrl: process.env.RPC_URL!,
  receiptLog: '0x65eDCae32a92eCCC47b7f0CBa06f2F924ce3A45E',
  leaf,
  proof,
  batchId: '1',
  root,
  chainId: 80002,
});

| Export | Description | |--------|-------------| | verifyMandateOnchain(…) | MandateRegistry.verifyMandate + isActive | | verifyReceiptOnchain(…) | ReceiptLog.verifyReceipt / verifyReceiptAgainstAnyBatch | | verifyMerkleProof(…) | Offline sorted-pair Merkle inclusion | | mandateIdBytes32 / contentHashBytes32 / receiptLeafBytes32 | Same encodings as KYI |

License

MIT