npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@emilia-protocol/langchain

v0.4.1

Published

Guard LangChain.js tools with EMILIA Protocol — require an offline-verifiable authorization receipt (EP-RECEIPT-v1) before an irreversible tool runs: missing -> refused, valid -> runs, replay -> refused, forged -> refused (RR-1). The approval becomes port

Readme

@emilia-protocol/langchain

Guard LangChain.js tools with the EMILIA Protocol — require an offline-verifiable authorization receipt (EP-RECEIPT-v1) before an irreversible tool runs.

missing receipt  -> refused
valid receipt    -> runs
replayed receipt -> refused   (one-time consumption)
forged receipt   -> refused

Verification is offline Ed25519 over canonical JSON via @emilia-protocol/require-receipt's canonical makeReceiptGate — zero network, no vendor in the loop. The receipt becomes portable evidence an auditor can check without trusting the runtime. Necessary, not sufficient: it composes with — never replaces — the tool's own checks.

The base gate proves an accepted issuer signed the exact action. To claim a named human was present, also require class_a and verify a WebAuthn ceremony against your pinned approver directory, RP ID, and origin allowlist.

Install

npm install @emilia-protocol/langchain   # brings in @emilia-protocol/require-receipt

Recommended: offline receipt gate

import { requireReceiptForLangChainTool } from '@emilia-protocol/langchain';

const guarded = requireReceiptForLangChainTool(wireTransferTool, {
  action: 'payment.release',           // semantic base action
  trustedKeys: [ISSUER_SPKI_B64URL],   // pin the issuer keys you trust
  assuranceClass: 'class_a',
  approverKeys: ENROLLED_APPROVER_KEYS,
  rpId: 'approvals.example.com',
  allowedOrigins: ['https://approvals.example.com'],
  store: durableAtomicReceiptStore,    // { reserve, commit, release }
});

// The human-approved receipt travels as out-of-band call metadata:
await guarded.invoke(
  { to: 'acct_1', amount: 100 },
  { configurable: { emiliaReceipt: receipt } },
);
// missing/invalid/replayed/forged -> throws; valid + action-bound -> runs.

Per-call binding is automatic: the wrapper hashes the tool name and complete actual input into the final action, so a receipt minted for one call cannot drive a different one. actionFor may choose a semantic base action but cannot disable the exact binding. Once the underlying tool is invoked, an exception is an indeterminate effect: the approval is consumed and automatic retry with the same receipt is refused. Only release a reservation when you can prove the external effect never began.

The default store is process-local. Production fleets must provide a shared, ownership-fenced store whose reserve is an atomic insert-if-absent and whose commit/release can be called only by the reservation owner.

Legacy: hosted policy gate

guardAction calls a hosted gate for a precheck-only allow/deny/signoff decision. withGuard is retained for compatibility but now always refuses execution: neither a hosted boolean nor an application callback is portable exact-action authority. Use requireReceiptForLangChainTool for execution.

What it is / isn't

  • Is: an offline gate for exact-action issuer evidence, with optional pinned Class-A or quorum verification for named-human authorization.
  • Isn't: authentication, access control, or a hosted runtime. It composes on top.

Apache-2.0. Reference implementation, experimental. Part of the EMILIA Protocol — an open IETF-track authorization-receipt standard (draft-schrock-ep-authorization-receipts).