npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@fidacy/langchain

v0.3.0

Published

Gate LangChain tool calls behind a signed Fidacy verdict. Wraps the tool itself, so a denied payment never executes: callbacks can only observe, this can stop.

Readme

@fidacy/langchain

Gate LangChain tool calls behind a signed Fidacy verdict. A denied payment never executes.

npm i @fidacy/langchain @langchain/core
import { guardTools } from "@fidacy/langchain";

// No key, no signup: the offline judge decides your first 20 calls.
const tools = guardTools([payTool, searchTool]);
// payTool is now assessed before every call. searchTool is returned untouched.

Two ways it decides

Offline, out of the box. With no credential the deterministic local judge runs: deny-by-default, your own limits, a hash-chained log on your machine. The first 20 decisions on an install are free and need no account, so you can watch a payment get blocked before deciding whether you want any of this.

Set the limits that fit your case:

const tools = guardTools([payTool], {
  mandate: { payees: ["acme-inc"], perTxMax: 5_000, maxTotal: 50_000 },
});

A blocked call tells you what was stopped, in money terms, and prints the exact edit that would allow it.

Hosted, with an account. Pass apiKey and the engine decides instead, returning a verdict signed with a stable key that anyone can verify against the public JWKS, plus a Bitcoin-anchored audit chain that outlives your process.

Free key, no card: https://fidacy.com/claim

Why not a callback handler

LangChain callbacks (handleToolStart and friends) are observational. They fire around the call and cannot cancel it, so a guardrail built on them watches the money leave. This replaces the tool's own execution path, which is the only place that can actually stop a payment.

Fail-closed

If the engine is unreachable, the key is wrong, or the request times out, the call is denied. A payment firewall that opens when it breaks is not a firewall.

review also blocks by default. Set reviewIsDeny: false to let it through.

What a denial looks like

guardTool throws FidacyDenied with the signed proof attached:

try {
  await tools[0].invoke({ payee: "acme", amount: 5000 });
} catch (e) {
  if (e instanceof FidacyDenied) {
    e.decision;                // "deny" | "review" | "unavailable"
    e.verdict?.riskPayloadJws; // detached JWS, verify offline with @fidacy/verify
    e.verdict?.assessmentId;
  }
}

Options

| Option | Default | What it does | | --- | --- | --- | | apiKey | FIDACY_ENGINE_API_KEY | Engine credential. Omit it to stay offline | | mandate | none | Offline limits: payees, perTxMax, maxTotal, currency | | engineUrl | https://api.fidacy.com | Engine base URL | | client | built from apiKey | Bring your own @fidacy/sdk client | | isPayment | name heuristic | Which tools guardTools gates | | toMandate | payee/amount/currency + raw args | Build the mandate the engine assesses | | reviewIsDeny | true | Whether review blocks | | onDecision | none | Observe every decision, including approvals |

guardTool(tool, opts) gates one tool unconditionally. guardTools(list, opts) gates only the ones isPayment matches and returns the rest by identity, so non-payment tools carry no cost.

The wrapped tool keeps its name, description and schema, so the model sees no difference.

Anonymous telemetry

The adapter reports anonymous usage so we can tell which surfaces are alive: an install marker, an "agent active" ping, the result class of local decisions (allow, deny_payee, deny_cap and so on) and the moment the free-trial wall is shown. Every field is a closed enum. It never carries payees, amounts, currencies, tool arguments or any content, and it never sits on the path of a decision: failures are swallowed and nothing blocks.

Disable it entirely with:

export FIDACY_DISABLE_TELEMETRY=1

The anonymous id lives in ~/.fidacy/config.json, shared with @fidacy/mcp, so the free-decision counter and a later account claim stay consistent across Fidacy tools on the same machine.

Apache-2.0 · https://fidacy.com