@trust-assurance-protocol/sdk
v0.1.3
Published
Trust Agent Protocol (TAP) SDK — agent registration, policy evaluation, human review, TAP App passports, audit, and evidence
Readme
TAP SDK
TypeScript client for the Trust Agent Protocol (TAP). Use it to register agents, evaluate policy, wait for human review, and read TAP App passports.
Requires Node.js 20+.
NPM Registry URL
https://www.npmjs.com/package/@trust-assurance-protocol/sdk
Install
npm install @trust-assurance-protocol/sdkFrom source:
pnpm install && pnpm buildQuick start
import { TAPClient } from "@trust-assurance-protocol/sdk";
const tap = new TAPClient({
apiKey: process.env.TAP_API_KEY!,
companyId: "acme-corp",
// Omit baseUrl to use the in-process mock.
// baseUrl: "https://api.example.com/v1",
});
await tap.registerAgent({
agentName: "Procurement Agent",
agentUrl: "https://agent.example.com",
agentFramework: "CrewAI",
agentVersion: "1.0.0",
});
await tap.getAgent();
await tap.updateAgent(tap.currentAgentCode!, { agentVersion: "1.0.1" });
const decision = await tap.evaluate({
action: "purchase",
agentCode: tap.currentAgentCode,
context: { amount: 25_000, currency: "EUR" },
});
if (decision.decision === "REVIEW" && decision.reviewId) {
await tap.waitForReview(decision.reviewId);
}
const passport = await tap.getPassport(tap.currentAgentCode);
await tap.validatePassport(passport.id);
await tap.audit({ event: "Purchase Created", status: "SUCCESS" });
await tap.submitEvidence({
kind: "execution",
hashes: [{ algorithm: "sha256", value: "..." }],
});
await tap.health();getPassport reads the TAP App trust document after the agent is Verified. It is not required for evaluate. Mock: tap.getMockBackend()?.verifyAgent(agentCode) stands in for TAP App verification.
API
| Area | Methods |
| -------- | ------------------------------------------------------------------------------------- |
| Client | new TAPClient({ apiKey, companyId?, environment?, useMock?, baseUrl? }) |
| Agents | registerAgent, updateAgent(agentCode, patch), getAgent(agentCode?), heartbeat(agentCode?) |
| Passport | getPassport(agentCode?), validatePassport(passportId?), getTrustScore(passportId?) |
| Policy | evaluate({ action, agentCode?, context? }) returns ALLOW, BLOCK, or REVIEW |
| Review | getReview, waitForReview (use reviewId from evaluate) |
| Audit | audit |
| Evidence | submitEvidence |
| Health | health |
Configuration
apiKey is required. companyId is optional and sent as X-TAP-Company.
When baseUrl is omitted, the SDK uses an in-process mock. To call a real TAP service, set baseUrl (for example https://api.example.com/v1) and useMock: false.
Default mock policy for purchase amount:
| Amount | Decision |
| ---------------- | ---------------------------------- |
| <= 10,000 | ALLOW |
| 10,001 to 50,000 | REVIEW |
| > 50,000 | BLOCK (MANDATE_LIMIT_EXCEEDED) |
Thresholds can be changed via mockOptions or MockTAPBackend.
Errors
Failures throw TAPError with a stable code:
import { TAPError } from "@trust-assurance-protocol/sdk";
try {
await tap.evaluate({
action: "purchase",
context: { amount: 25_000, currency: "EUR" },
});
} catch (err) {
if (err instanceof TAPError) {
console.error(err.code, err.status, err.details);
}
throw err;
}Review-related codes include REVIEW_DENIED and REVIEW_TIMEOUT.
Development
pnpm install
pnpm typecheck
pnpm test
pnpm build
pnpm exampleLicense
MIT
