@astrasyncai/adapter-edge
v1.9.1
Published
AstraSync Trusted Agent Gateway — edge adapters for Vercel Edge, Cloudflare Workers, and Fastly Compute
Readme
@astrasyncai/adapter-edge
AstraSync Trusted Agent Gateway — edge adapters for Vercel Edge, Cloudflare Workers, and Fastly Compute. The gateway classifies and verifies inbound AI-agent traffic in front of your existing site. Zero site changes; observe-only by default.
Every request is classified into a visibility tier — verified AstraSync agents, identified-but-unregistered agents (payment-rail credentials such as Visa Intelligent Commerce, Mastercard Agent Pay, Visa TAP, Web Bot Auth, ACP, UCP, AP2, MPP, x402, or platform-agent UAs like Claude and ChatGPT), anonymous bots, and humans. Humans and static assets are untouched — zero API calls, zero added latency. Cryptographic verification of rail credentials happens server-side at AstraSync's verify-access; the edge only sniffs and forwards raw artifacts.
Fail-open guarantee: if the gateway can't reach AstraSync it always falls back to observe + pass-through. An unreachable backend — or a misconfigured gateway — can never break your site.
All three adapters share the same engine
(@astrasyncai/verification-gateway/edge-core) as the Lambda@Edge adapter
(@astrasyncai/adapter-lambda); use that package for CloudFront.
Install
npm install @astrasyncai/adapter-edgeQuickstart
Cloudflare Workers
// src/worker.ts
import { createGatewayHandler } from '@astrasyncai/adapter-edge/cloudflare';
export default { fetch: createGatewayHandler() };Set the environment bindings on the worker (wrangler.toml vars +
wrangler secret put ASTRASYNC_API_KEY):
[vars]
ASTRASYNC_COUNTERPARTY_ID = "ASTRAE-…"
ASTRASYNC_COUNTERPARTY_URL = "https://example.shop"Deploy the worker on the routes you want covered. Pass traffic is forwarded
to your origin with fetch(); telemetry runs in ctx.waitUntil, off the
latency path.
Vercel Edge Middleware
This package does not import next, so the middleware returns either a
Response (return it as-is) or a pass signal you apply with the
provided helper — a two-line wrapper:
// middleware.ts
import { NextResponse, type NextRequest } from 'next/server';
import { createGatewayMiddleware, applyGatewayPass } from '@astrasyncai/adapter-edge/vercel';
const gateway = createGatewayMiddleware();
export async function middleware(request: NextRequest) {
const result = await gateway(request);
if (result instanceof Response) return result;
return NextResponse.next({ request: { headers: applyGatewayPass(request.headers, result) } });
}Configuration comes from process.env (ASTRASYNC_COUNTERPARTY_ID,
ASTRASYNC_COUNTERPARTY_URL, ASTRASYNC_API_KEY) or explicit options.
Alternatively pass a next factory option to get back a plain
Response | undefined middleware.
Fastly Compute (JavaScript)
Fastly requires every fetch to name a configured backend, so
originBackend is required — create a backend for your origin (and one
for astrasync.ai so verification calls can leave the service):
// src/index.ts
import { createGatewayHandler } from '@astrasyncai/adapter-edge/fastly';
const gateway = createGatewayHandler({
originBackend: 'origin',
counterpartyId: 'ASTRAE-…',
counterpartyUrl: 'https://example.shop',
apiKey: '…', // e.g. from a Fastly secret store lookup at startup
});
addEventListener('fetch', (event) => event.respondWith(gateway(event)));Optional geolocation enrichment (country/city/ASN) via the Fastly runtime
is behind the geo: true flag; the fastly:geolocation import is dynamic,
so the base build stays runtime-neutral.
Configuration
| Option | Env var | Default | Notes |
| ----------------- | ---------------------------- | -------------------------- | ------------------------------------------------------------------------- |
| counterpartyId | ASTRASYNC_COUNTERPARTY_ID | — | Your property's ASTRAE-… endpoint id. Missing ⇒ fail-open pass-through. |
| counterpartyUrl | ASTRASYNC_COUNTERPARTY_URL | — | Canonical public URL of the property. |
| apiKey | ASTRASYNC_API_KEY | — | Merchant kya_* key. Observe mode degrades gracefully without it. |
| apiBaseUrl | ASTRASYNC_API_BASE_URL | https://astrasync.ai/api | |
| configTtlMs | — | 60 000 | Dashboard edge-config refresh interval. |
| budgets | — | 300 / 1500 / 3000 ms | Beacon / observe-verify / enforce-verify time budgets. |
| maxBodyBytes | — | 1 MiB | Body read cap for commerce-protocol detection. |
| fallbackConfig | — | observe/classify | Used before the first config fetch succeeds. |
| originBackend | — | — | Fastly only, required. Named backend for origin traffic. |
| geo | — | false | Fastly only. Opt-in fastly:geolocation enrichment. |
| next | — | — | Vercel only. Continue-factory for pass outcomes. |
Mode (observe/enforce), check depth (classify/authenticate/
authorize), per-path rules, and bot-telemetry sampling are configured on
the endpoint's Edge verification panel in the AstraSync dashboard — no
redeploys. The gateway refreshes its config every ~60s, and configs stale
for more than 24h automatically degrade enforce back to observe.
Capture matrix
Beyond the sanitized header capture (identical on every platform — secrets stripped, credential headers reduced to a safe format prefix), each platform contributes the connection-layer signals it can see:
| Signal | Cloudflare Workers | Vercel Edge | Fastly Compute | (Lambda@Edge) |
| ------------------ | ------------------------------------------------------ | --------------------------------------- | ----------------------- | --------------------------------- |
| Client IP | CF-Connecting-IP | x-real-ip | Fastly-Client-IP | viewer address |
| Country | request.cf.country | x-vercel-ip-country | geo flag | viewer headers |
| Region/City | request.cf.regionCode / .city | x-vercel-ip-country-region / -city | geo flag | viewer headers |
| Continent | request.cf.continent | x-vercel-ip-continent | — | — |
| Time zone | request.cf.timezone | x-vercel-ip-timezone | geo flag (UTC offset) | viewer headers |
| ASN / AS org | request.cf.asn / .asOrganization | — | geo flag | viewer headers (ASN only) |
| TLS version/cipher | request.cf.tlsVersion / .tlsCipher | — | — | viewer headers (ver+cipher) |
| HTTP version | request.cf.httpProtocol | — | — | viewer headers |
| JA3 / JA4 | request.cf.botManagement (Bot Management zones only) | x-vercel-ja4-digest (BotID; JA4 only) | — | viewer headers (both, 2.2.0+) |
| Header structure | — | — | — | viewer header-order/-count |
| PoP/colo, TCP RTT | request.cf.colo / .clientTcpRtt | — | — | — |
Everything captured surfaces on the endpoint's traffic feed in the
AstraSync dashboard. For the cross-integration view (edge vs SDK-behind-CDN
vs platform-managed CDN) see the canonical capture matrix in the
@astrasyncai/verification-gateway README.
CloudFront (adapter-lambda) is currently the only platform yielding both
JA3 and JA4 unconditionally — if fingerprint-based spoof resistance is the
deciding factor for your CDN choice, that's the row to read.
Enforce mode
Requests that fail verification on enforced paths get a machine-readable
403 with registration guidance; human-approval flows return 202 with
step-up polling info. Allowed agent requests reach your origin with trust
attestation headers (X-AstraSync-Trust-Score, X-AstraSync-Agent-Id,
X-AstraSync-Developer-Id, X-AstraSync-Permissions) — inbound spoofs of
x-astrasync-* headers are stripped in both modes.
License
MIT © AstraSync
