npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@johnhenry/oat-protocol

v0.1.1

Published

OAT artifact envelope, canonical CBOR, digests, signatures, capabilities, UI proposal grammar

Downloads

341

Readme

@johnhenry/oat-protocol

npm version license

The wire and trust layer under every other OAT package: the artifact envelope, canonical CBOR encoding, SHA-256 digests, Ed25519 signatures, the capability model, the UI proposal grammar, M6 sandbox eligibility, and the ui.decision acknowledgment type. If two OAT endpoints agree on anything, it's defined here.

npm install @johnhenry/oat-protocol

Quick start

import {
  buildArtifact,
  verifyArtifact,
  extractPayload,
  generateSigningKey
} from '@johnhenry/oat-protocol';

const { publicKey, secretKey } = generateSigningKey();

const artifact = await buildArtifact({
  mediaType: 'text/plain',
  payload: new TextEncoder().encode('signed state, ready to travel'),
  sign: { secretKey, keyId: 'my-key' }
});

// On the other end:
const verification = verifyArtifact(artifact, { requireSignature: true });
if (verification.valid) {
  const bytes = await extractPayload(artifact); // decompresses if needed
}

verifyArtifact never throws — a malformed or tampered artifact fails with machine-readable reasons ('digest-mismatch', 'signature-invalid', 'signature-required', 'expired').

The traps

  • A valid signature is not identity. The signature carries the signer's public key inline, so there's no separate key-exchange step — but that also means anyone can produce a validly-signed artifact. signatureValid: true proves the bytes weren't tampered with, not that you should trust the sender. Trust lists live in @johnhenry/oat-receiver (trustedPublicKeys), not here.
  • valid: true does not imply a signature exists. An unsigned artifact with a good digest is "valid" unless you pass requireSignature: true — signatureValid is 'absent' in that case, not false. Anything security-sensitive should check signatureValid === true explicitly.
  • The signature covers the digest too. It's computed over the canonical CBOR encoding of every field except signature itself, so payload and digest can't be swapped together without invalidating it.
  • extractUiDecision refuses unsigned artifacts. A ui.decision claims capabilities were granted — an unsigned one is worthless as an audit record, so extraction requires an affirmatively verified signature.

API surface

| Area | Exports | | --- | --- | | Envelope | buildArtifact, verifyArtifact, extractPayload, isOatArtifact, OatArtifact, VerificationResult | | Encoding | encodeCanonical, decodeCanonical (canonical CBOR — deterministic bytes for signing) | | Crypto | generateSigningKey, signPayload, verifySignature, computeDigest, verifyDigest, constantTimeEqual | | Ids | randomId — a v4 UUID via crypto.randomUUID() where it exists, via crypto.getRandomValues() where it does not | | Compression | compress, decompress ('none' | 'gzip') | | Capabilities | WELL_KNOWN_CAPABILITIES, intersectCapabilities, createCapabilityPolicy, CapabilityPolicy, CapabilityGrant | | UI proposals | UiProposalEnvelope, UiViewDescriptor (text/form/media/safe-html/sandboxed-html), SanitizationProfile | | Decisions | buildUiDecisionArtifact, extractUiDecision, UiDecision, UI_DECISION_MEDIA_TYPE | | M6 gate | checkSandboxEligibility — requires a verified signature AND an explicitly trusted sender AND a receiver allowUnsafeHtml opt-in, or it reports ineligible |

Capability arithmetic is always the same intersection:

effective = sender requested ∩ receiver policy ∩ user-approved grants

Rendering is never authority — declarative actions carry typed, receiver-mediated requests, never remote code or DOM handles.

Docs

Full documentation: https://opensource.johnhenry.me/oat/ — the protocol page covers this package; the repo's docs/design.md is the full design doc.

License

MIT