AIDR relying-party verifier for Node.js (0.1.0) — @aidr/verifier

Verify an AI agent's identity on your own server, offline: the agent's credential (signed by the
registry) and its RFC 9421 request signature. Zero dependencies — Node's built-in crypto only.
Node 18 or later.

  import { AgentVerifier, buildTrustStore, NonceCache, expressMiddleware } from './node/index.mjs';

  const trust = buildTrustStore(jwks, { deltaToken, expectedIssuer: 'https://api.evolivcore.com' });
  const verifier = new AgentVerifier(trust, { policy: { minAssurance: 1 }, nonceSeen: new NonceCache() });
  app.use(expressMiddleware(verifier, { optional: true }));   // req.agent, or null when unidentified

Refresh the registry's keys hourly and its revocation delta every 60 seconds, in the background;
nothing in the request path contacts the registry. Discovery: https://api.evolivcore.com/.well-known/aiaf-registry

Licensed under the Apache License, Version 2.0 (LICENSE).

Tests (they replay the shared cross-language vectors in testdata/):  cd node && npm test   (node --test test/*.test.mjs)
