zerobyte
v1.0.0
Published
TypeScript SDK for 0byte — the origin protocol for AI content
Maintainers
Readme
0byte TypeScript SDK
The official TypeScript SDK for 0byte — the origin protocol for AI content.
A thin, zero-dependency wrapper over the REST API (the OpenAPI contract is
served at GET /v1/openapi.yaml). Any language can integrate with plain
HTTP — this package is convenience, never a requirement.
Installation
npm install zerobyteQuickstart
import { writeFile } from "node:fs/promises";
import { Zerobyte } from "zerobyte";
const zb = new Zerobyte({ apiKey: "0b_key_..." });
// Stamp AI-generated content — with your brand on it
const result = await zb.stamp({
content: imageBytes,
contentType: "image/png",
provider: "acme-ai",
model: "imagen-x",
creator: { name: "Acme Studios", url: "https://acme.example" },
});
console.log(result.binding); // "manifest+registry" — always disclosed
// Publish the stamped file — IT carries the Content Credentials:
if (result.stampedBytes) await writeFile("out.png", result.stampedBytes);
// Verify any content — free, no API key needed
const check = await new Zerobyte().verify(someImageBytes);
console.log(check.verdict); // verified_origin | provenance_untrusted |
// provenance_invalid | no_provenance_found
console.log(check.originSources); // which signals prove it
console.log(check.evidence); // per-signal detail, statuses always disclosedFetch the proof material
Every proof is anchored in an RFC 6962-style transparency log, and the SDK fetches everything an independent verifier needs:
const head = await zb.getTreeHead(); // signed root (Ed25519)
const proof = await zb.getInclusionProof("0b_…"); // Merkle audit path
const keys = await zb.getSigningKeys(); // every key that ever signedFetching is not verifying: to check the math yourself, recompute the Merkle
inclusion path (RFC 9162 §2.1.3.2) against rootHash and verify the Ed25519
signature over sth:v1:{keyId}:{treeSize}:{rootHash} with the matching
public key. The SDK deliberately ships no crypto — these responses carry
everything an independent verifier needs, and the OpenAPI contract served
at GET /v1/openapi.yaml documents the exact shapes.
