@sealkeeper/schema
v0.4.3
Published
Zod schemas, event taxonomy and signing helpers for SealKeeper.
Readme
@sealkeeper/schema
Shared schemas and helpers for SealKeeper, the reputation layer for AI agents.
@sealkeeper/schemaexports the Zod schemas, the event taxonomy, the JWS signing helpers, credential verification and the agent id helper. No database dependency. ThesealkeeperCLI bundles this entrypoint.@sealkeeper/schema/dbexports the Drizzle tables the SealKeeper API uses. It needsdrizzle-ormandpostgres, which are optional peer dependencies, so installing the package for verification pulls neither. Install both yourself to use this entrypoint.
npm install @sealkeeper/schemaIssuer and keys path
From 0.4.0 a SEAL carries iss sealkeeper.run (CREDENTIAL_ISSUER) and the keys document lives at /.well-known/seal.json (WELL_KNOWN_PATH, full URL WELL_KNOWN_URL). The path is product neutral, so another issuer can serve its own keys at the same path on its own domain. The old path /.well-known/vouched.json (LEGACY_WELL_KNOWN_PATH) is served beside it for one release. SEALs issued as vouched.run before the cutover stay valid until they expire, at most 24 hours. acceptedIssuer(iss, nowSeconds) accepts sealkeeper.run always and a LEGACY_ISSUERS entry only before LEGACY_ISSUER_UNTIL, 2 October 2026 00:00 UTC, and parseSealPayload calls it first. CredentialPayload and LegacyCredentialPayload are the issuer shapes and take sealkeeper.run only, so an issuer never writes or re-serves a legacy issuer. Verifiers read through parseSealPayload, which uses VerifiedCredentialPayload and VerifiedLegacyCredentialPayload after the clock check. Cards carry the SEAL under https://sealkeeper.run/ext/seal/v1 (SEAL_EXTENSION_URI) with the two old URIs in LEGACY_SEAL_EXTENSION_URIS beside it for one release.
Licensed under Apache-2.0. See LICENSE and NOTICE.
