npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@agentcreds/runtime

v0.2.0

Published

Runtime AgentCreds agent-identity enforcement for Node - agent-to-agent (A2A) verification ONLY. Not an MCP policy enforcement point: R10 gates, step-up approval and the MCP enforcer are Python-only by design. Built on @agentcreds/sdk

Readme

@agentcreds/runtime

Runtime AgentCreds enforcement for Node, built on @agentcreds/sdk.

Scope: agent-to-agent (A2A) only - this is deliberate

This package verifies A2A requests: agent A hands a task directly to agent B, A attaches a self-contained identity header, and B verifies it offline. That is the whole supported surface, and it is complete for that surface.

It is not a Node port of agentcreds-runtime (Python). The following are Python-only and are not planned here:

| | Python | Node | |---|---|---| | A2A verifier, replay guard | DONE | DONE | | MCP IdentityEnforcer (sessionful, per-tool-call) | DONE | NO | | R10 execution-time gates + approval evidence | DONE | NO | | Step-up approval, approver directory | DONE | NO | | Key-history cache, trust-registry cache | DONE | NO | | Usage metering, Cedar policy hook, decision reporter | DONE | NO | | Session / idempotency / consumed-approval stores | DONE | NO |

Why say so rather than fix it. The enforcement layer is where the security-relevant behavior lives, and a second implementation of it would have to be kept correct twice - every gap closed in one would have to be closed again in the other, on a lag, with the conformance suite covering only the first. A partial second enforcement point that looks like the reference is worse than none: it invites a deployment that believes it has R10 and does not.

If you need MCP enforcement, R10 gates, or step-up approval, run the Python PEP. The capability lives behind an MCP endpoint, so the language of your agent is unconstrained - a Node agent talks to a Python PEP over the wire like any other client.

What the Node SDK does cover, in full

@agentcreds/sdk is at parity with the Python core binding: identities, credentials (including resources, accountableParty, partyVersion, partyCommitment), delegation tokens, presentations, proof of possession, revocation, key history and rotation, trust registry, approver directories, OwnershipRecord, and Authorization Decision Records including recording accountability and the R10 evaluation/admission verdicts.

So a Node service can issue, mint, attenuate, verify, and produce a complete, digest-covered decision record. What it cannot do is host the MCP policy enforcement point.

Conformance

The end-to-end enforcement harnesses are Python and exercise the Python enforcement path. Node has test/conformance.test.js (28 cases, the shared cross-language vector set) plus test/accountability.test.js, which pins that the party commitment computed here is byte-identical to Python's - without that, a Node verifier could not check a commitment a Python control plane stamped, and the disagreement would look like a tampered record rather than a binding mismatch.

Read a green Node run as "the SDK-layer vectors pass", never as "R10 is enforced".