npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

agent-trust-card

v1.1.2

Published

ATC SDK v1.1.1 — issue, verify, and inspect Agent Trust Cards. Supports ATC/1.0 (single-sig Ed25519) and ATC v3.0 (multi-format multi-sig: Ed25519/JCS, EAT-CWT/CBOR, W3C VC JSON-LD). Includes CLI (`atc verify card.json`, `atc issue`, `atc inspect`), sync

Readme

ATC SDK

Issue and verify Agent Trust Cards in 5 minutes. A tiny (~5KB), framework-agnostic SDK for the ATC/1.0 specification. Works in any JavaScript runtime that supports node:crypto (Node.js >=18, Bun, Deno).

npm version License: AliceLabs Proprietary Spec: ATC/1.0


What is ATC?

ATC (Agent Trust Card) is SSL certificates for AI agents — a cryptographic credential that lets an agent prove its identity, declare its capabilities, and carry its security audit evidence. Any peer agent can verify it offline without calling home.

  • Spec: ATC/1.0 — 10 controls (8 required, 2 optional)
  • Crypto: Ed25519 (RFC 8032) signatures + RFC 8785 JCS canonical JSON + SHA-256
  • License: MNNC-1.0 (AliceLabs LLC Proprietary). The spec is open; the SDK is proprietary.

Install

npm install agent-trust-card
# or use without install:
npx agent-trust-card verify card.json

Quick start (5 minutes)

1. Generate keys

npx atc init > keys.json
{
  "ca": {
    "publicKey": "MCowBQYDK2VwAyEA...",
    "privateKey": "MC4CAQAwBQYDK2VwBCIEI..."
  },
  "agent": {
    "publicKey": "MCowBQYDK2VwAyEA...",
    "privateKey": "MC4CAQAwBQYDK2VwBCIEI..."
  }
}

2. Issue a card

import { generateKeyPair, issueATC } from 'agent-trust-card';

const ca = generateKeyPair();
const agent = generateKeyPair();

const atc = issueATC(ca, agent, {
  card_id: 'ATC-2026-0000001',
  identity: {
    agent_id: 'my-bot',
    agent_name: 'My Bot',
    agent_owner: 'My Org',
  },
  capabilities: {
    filesystem: { read: 'own_dir', write: 'own_dir' },
    network: { egress: 'allowlist', ingress: 'none' },
    shell: { exec: 'sandboxed', spawn: 'none' },
    credentials: { read_env: 'none', read_files: 'none' },
    process: { subprocess: 'none', signals: 'own' },
  },
  evidence: { /* ... see spec ... */ },
  risk: {
    trust_score: 9,
    risk_level: 'low',
    score_explanation: 'Clean audit',
    scored_at: new Date().toISOString(),
  },
});

console.log(JSON.stringify(atc, null, 2));

3. Verify a card

import { verifyATC } from 'agent-trust-card';

const result = verifyATC(atc);

if (!result.valid) {
  throw new Error(`Untrusted agent: ${result.errors.join(', ')}`);
}

console.log(`✓ ${atc.card_id} — ${result.controls_passed.length}/8 controls passed`);

4. CLI

# Generate keys
npx atc init > keys.json

# Issue
npx atc issue --ca ca.json --agent agent.json --payload payload.json --out card.json

# Verify
npx atc verify card.json

# Inspect
npx atc inspect card.json

API reference

generateKeyPair()

Returns { publicKey, privateKey, rawPublicKey, rawPrivateKey }. Uses node:crypto Ed25519 (RFC 8032).

loadKeyPairFromPrivate(base64PrivateKey)

Reconstructs a keypair from a saved private key. Useful for CAs that persist their key across sessions.

issueATC(caKeyPair, agentKeyPair, partialPayload)

Signs an ATC. Returns the complete, signed ATC document. See ATC-006 in the spec for the signature process.

verifyATC(atc, options?)

Verifies an ATC against ATC/1.0. Returns:

{
  valid: boolean,
  spec_version: string,
  controls_passed: string[],   // e.g. ['ATC-001', 'ATC-002', ..., 'ATC-008']
  controls_failed: string[],
  errors: string[],
  warnings: string[],
  card_id: string,
  issuer_ca_id: string,
  trust_score: number | null,
  risk_level: string | null,
  expires_at: string | null,
  agent_id: string | null,
  agent_name: string | null,
}

options.ca_public_key — Override the CA public key (base64 SPKI). Use this when you have an out-of-band trusted CA key and want to detect CA substitution attacks.

options.fetch_revocation — Not yet implemented. The verifier checks structural fields only. If revocation_check_required=true, the caller must fetch the revocation list at atc.revocation.revocation_check_url separately.

canonicalizeATC(atc)

Returns the RFC 8785 JCS canonical form of the ATC (with signature + hash blanked).

computePayloadHash(atc)

Returns the hex SHA-256 of the canonical payload.


The 8 required controls

| # | ID | What it checks | |---|----|----------------| | 1 | ATC-001 | Identity — agent_id, agent_name, agent_owner are present and well-formed | | 2 | ATC-002 | Attestation — subject_public_key, subject_algorithm=Ed25519, signature, signed_payload_hash are present and well-formed | | 3 | ATC-003 | Capabilities — 5 categories (filesystem, network, shell, credentials, process) × 2-3 sub-fields each, every value validated against an enum | | 4 | ATC-004 | Evidence — audit pipeline output, findings array with severity | | 5 | ATC-005 | Risk — trust_score 0-10, risk_level low/medium/high/critical, decision_authority=consumer | | 6 | ATC-006 | Signature — Ed25519 over RFC 8785 JCS canonical form, SHA-256 hash match | | 7 | ATC-007 | Revocation — revocation_check_url, revocation_check_method (ocsp/crl/simple_json), revocation_check_required | | 8 | ATC-008 | Expiration — issued_at, expires_at, max_ttl_days (1-365), ±5min clock skew tolerance |


CLI reference

atc init                                    Generate a CA + agent keypair (JSON to stdout)
atc issue --ca <key.json> \
          --agent <key.json> \
          --payload <payload.json> \
          [--out <card.json>]              Issue (sign) an ATC
atc verify <card.json>                      Verify an ATC — exits 0 if valid, 1 if invalid
atc inspect <card.json>                     Pretty-print an ATC summary
atc canonical <card.json>                   Print the RFC 8785 JCS canonical form
atc hash <card.json>                        Print the SHA-256 of the canonical payload
atc help                                    Show this message

Conformance

A conformant ATC/1.0 implementation MUST pass all 8 required controls. The conformance test suite is in test/conformance.mjs. Run it with:

git clone https://github.com/alicelabs-llc/marketnow.git
cd marketnow/atc-sdk
npm install
npm test

See CONFORMANCE.md for the full conformance matrix.


Badge

If your project implements ATC/1.0, you can add this badge to your README:

[![ATC Compatible](https://marketnow.site/badges/atc-compatible.svg)](https://github.com/alicelabs-llc/marketnow/blob/master/docs/atc-spec/SPEC.md)

ATC Compatible


Why ATC/1.0?

The market is converging on agent trust infrastructure from multiple directions — Microsoft AutoGen, OpenAI Cookbook, A2A Agent Cards, OpenA2A AIP, OATI, and others. ATC/1.0 is the first formal, versioned, testable specification for Agent Trust Cards.

See:


License

  • SDK source code (src/, bin/): MNNC-1.0 (AliceLabs LLC Proprietary)
  • Test vectors (test/): CC0 (public domain)
  • Specification (in docs/atc-spec/): W3C CG-FSA (open for community contribution)

For licensing: [email protected]

Built by AliceLabs LLC (Wyoming, USA) — founder Edison Flores.