@agenticprimitives/agentic-authorization
v0.0.0-alpha.4
Published
Native Agentic authorization discovery: the /.well-known/agentic-authorization document builder, the io.agentictrustlabs.authority MCP extension carrier (read/write), and version negotiation. Public on-chain-derivable config only; not an OAuth authorizati
Maintainers
Readme
@agenticprimitives/agentic-authorization
Part of Agentic Primitives — the open-source trust substrate for agentic applications: identity that can sign, authority checked at act time, evidence the owner carries. Developer kit · All packages
Native Agentic authorization discovery — let Agentic-aware clients self-configure deterministically without pretending to be an OAuth authorization server.
Instead of describing an OAuth AS we deliberately are not (ADR-0041), this package publishes the authority surface — the chain, the on-chain contracts, the authorization modes + signature schemes, and the token/proof versions — as a small, public, on-chain-derivable document. It also ships the MCP extension that carries spec 287's invocation proof, and version negotiation for MCP's coming extension framework.
See spec 292.
The discovery document
import { buildAgenticAuthorizationProfile, serveAgenticAuthorization, WELL_KNOWN_PATH } from '@agenticprimitives/agentic-authorization';
// Generated from contracts/deployments-<network>.json — public config only, no secrets.
const profile = buildAgenticAuthorizationProfile({
chainId: 8453,
entryPoint: d.entryPoint,
delegationManager: d.delegationManager,
universalSignatureValidator: d.universalSignatureValidator,
});
app.get(WELL_KNOWN_PATH, () => serveAgenticAuthorization(profile));
// → { profile: 'io.agentictrustlabs.authority/v1', chainId, entryPoint, delegationManager,
// universalSignatureValidator, authorizationModes, signatureSchemes,
// delegationTokenVersion, invocationProofVersion, audiences }The MCP extension (io.agentictrustlabs.authority)
The structured carrier for the spec-287 invocation proof in MCP terms:
import { writeAuthorityExtension, readAuthorityExtension } from '@agenticprimitives/agentic-authorization';
const envelope = writeAuthorityExtension({
version: '1',
delegationToken,
invocationProof: { argumentsHash, requestId, signature },
entitlementRefs: ['urn:ap:entitlement:...'],
});
const ext = readAuthorityExtension(mcpRequest.extensions); // undefined if absent/malformed → fail closedVersion negotiation
import { negotiateExtensionVersion, readMcpRoutingHeaders } from '@agenticprimitives/agentic-authorization';
negotiateExtensionVersion(clientVersions, ['1']); // highest common, or null
readMcpRoutingHeaders(headers); // { method?, name? } from Mcp-Method/Mcp-NameMCP's extension framework + Mcp-Method/Mcp-Name headers are in the 2026-07-28 release candidate —
negotiate, never hard-require the unreleased final. When the headers are present an edge can route +
rate-limit without inspecting (or modifying) the signed body; when absent it falls back.
License
MIT
