@zanii/kya
v0.1.1
Published
Know Your Agent: screen a counterparty agent against a deny-list / injected sanctions provider before your agent transacts, and receipt the check (kya.screening). Rides @zanii/a2a-directory; the list is injected.
Readme
@zanii/kya
Know Your Agent. @zanii/a2a-directory tells you a counterparty's verified history;
nothing screens it against a sanctions / deny-list before your agent pays or delegates to
it. kya closes that pre-transaction gap and makes the check itself provable — a
kya.screening receipt records "before transacting, we screened X against list Y at T, clear."
The rails are here; the list is injected — like @zanii/x402 injects the chain RPC. Pass a
caller denyList (useful on day one, no external data) and/or an injected provider (OFAC SDN,
a UAE local list, a commercial KYB feed). The core is testable offline.
npm install @zanii/kya @zanii/a2a-directory @zanii/coreimport { screenAgent, buildScreeningReceipt } from '@zanii/kya';
const result = await screenAgent(counterpartyDid, {
denyList: ['did:key:zBlocked'],
provider: async ({ did }) => myOfacFeed.check(did), // injected — you supply the data
});
if (!result.ok) throw new Error('counterparty failed screening — do not transact');
const receipt = buildScreeningReceipt(result, { ts });
await agent.record(receipt.target, receipt.payload);Honest limit: screening a did:key is only as good as the DID to real-world-identity
mapping, which lives outside us. v1 screens what is disclosed (the owner via the directory) plus
caller lists; it does not de-anonymize a pseudonymous agent. Do not over-claim "sanctions-proof".
Changelog
- 0.1.0 — initial release:
screenAgent,resolveAndScreen,buildScreeningReceipt,verifyScreening.
License
Apache-2.0.
