@moesi/registry
v0.4.0
Published
Portable organization account, funding request, grant, revocation, and reconciliation artifacts for Moesi.
Maintainers
Readme
@moesi/registry
Portable WS6a artifacts and reconciliation for organization-owned Kernel accounts. This package has no server, database, manifest parser, or wallet keys. Files can live locally, in git, or behind the optional WS6b service.
The registry records organization accounts, purpose-bound funding requests, grants, revocations, closure accounting, and finalized receipts. It rejects authority-bearing fields such as private/session keys, enable signatures, bearer URLs, serialized permission accounts, and reusable approval artifacts.
Account and grant configuration is L3 account-authority state, not deployment
drift. An adapter observes the Kernel implementation, root validator, installed
permissions, and balances; reconcileRegistry reports typed blocked state and
revocation recommendations. It never revokes autonomously.
import {
parseRegistryArtifact,
observeRegistry,
reconcileRegistry,
} from "@moesi/registry";
const registry = parseRegistryArtifact(await readFile("moesi-registry.json", "utf8"));
const observations = await observeRegistry(registry, kernelObserver);
const result = reconcileRegistry(registry, observations);
if (result.status === "blocked") {
console.error(result.findings);
console.error(result.recommendations);
}WS6b is implemented separately and is optional to deploy or use. It is a projection over these same artifacts; it is never the source of authority.
