@dnsid-ai/web-bot-auth
v0.24.1
Published
DNSid Web Bot Auth profile helpers.
Readme
@dnsid-ai/web-bot-auth
DNSid Web Bot Auth profile helpers.
This package signs outbound HTTP requests per the Web Bot Auth draft (RFC 9421 HTTP Message Signatures with the web-bot-auth tag) and serves the /.well-known/http-message-signatures-directory document so origins can discover and verify an agent's keys.
It builds on @dnsid-ai/http-signatures and @dnsid-ai/protocol contracts and performs no DNS or HTTPS transport itself. Signing requires an Ed25519 operational key; the profile throws ArgumentError for other key types.
Install
npm install @dnsid-ai/web-bot-auth @dnsid-ai/protocolExample
Sign an outbound request:
import { createWebBotAuthProfile } from '@dnsid-ai/web-bot-auth';
const profile = createWebBotAuthProfile({
domain: 'agent.example.com',
keyProvider, // Ed25519 operational key
});
const signed = await profile.createWebBotAuthSignedRequest(
new Request('https://origin.example/api'),
);
await fetch(signed);Serve the key directory (mount at /.well-known/http-message-signatures-directory):
const response = await profile.serveHttpMessageSignaturesDirectory(request);The directory response is itself signed with the http-message-signatures-directory tag and served as application/http-message-signatures-directory+json.
Options
signatureAgent— the discovery URI and type advertised inSignature-Agent. It defaults to the domain's HTTPS origin withtype=directory; usetype=jwks_urifor a direct JWKS endpoint.directoryURL— deprecated compatibility option interpreted as a directjwks_uriendpoint. UsesignatureAgent.uriinstead.signatureTTL/directorySignatureTTL— signature lifetimes in seconds (defaults: 60 for requests, 300 for the directory).includeSignatureAgent— setfalseto omit theSignature-Agentheader.
You can also build the profile from a signing identity manager with WebBotAuthProfile.fromIdentityManager(idm).
