Node.js @aidr/verifier 0.1.0
Zero dependencies — Node's built-in crypto only. Node 18+. Includes Express/Connect middleware.
30 KB · SHA-256 77a1af4f4e7165ab20d78aecf571ed134de60066ab95f811c2ef4351db90bf84
Download for Node.jsResources
Everything needed to understand AIAF, verify agents on your own site, and run agents with Project AIDR.
Standard
The trust model, the three assurance axes, and how a request is verified.
Specification
The normative text, including conformance requirements for registries, relying parties and operators.
Guide · Relying parties
Add the verifier to a Node.js or Python service and decide what assurance each action needs.
Guide · Operators
How the Evoliv Core app signs your agent's requests without the agent ever holding its key.
Guide · Operators
Sign up, verify your account, prove your domain, and add agents in the console.
Reference · Live
What the AIDR registry actually enforces — levels, algorithms, lifetimes — as JSON.
Quick start · Relying parties
The verifier checks the agent's credential and its request signature locally. It needs the registry's public keys (refresh hourly) and its signed revocation feed (refresh every 60 seconds), fetched in the background — nothing in the request path contacts the registry. Endpoints are in the registry's discovery document.
import { AgentVerifier, buildTrustStore, NonceCache,
expressMiddleware } from './node/index.mjs';
// jwks and the revocation delta, refreshed in the background
const trust = buildTrustStore(jwks, {
deltaToken, expectedIssuer: 'https://api.evolivcore.com' });
const verifier = new AgentVerifier(trust, {
policy: { minAssurance: 1 }, nonceSeen: new NonceCache() });
// req.agent: the verified agent, or null when unidentified
app.use(expressMiddleware(verifier, { optional: true }));
from aidr_verifier import AidrMiddleware, RelyingPartyConfig
# keeps keys and revocation state in sync by itself
app.add_middleware(AidrMiddleware, config=RelyingPartyConfig(
issuer="https://api.evolivcore.com",
min_agal=1,
))
@app.get("/whoami")
async def whoami(request):
identity = request.state.aidr # .is_agent, .aid, .agal, .org_domains
...
Each file is listed with its SHA-256, so you can check what you received. Every verifier includes the shared cross-language test vectors and passes them.
Zero dependencies — Node's built-in crypto only. Node 18+. Includes Express/Connect middleware.
30 KB · SHA-256 77a1af4f4e7165ab20d78aecf571ed134de60066ab95f811c2ef4351db90bf84
Download for Node.jsASGI and FastAPI middleware with background sync and shared replay protection. Python 3.10+; needs
cryptography and httpx.
107 KB · SHA-256 f70beadf902ac6272db780be96b7a621206da3d77e068282f3b651d9d1b858ef
Download for PythonStandard library only. Go 1.21+.
30 KB · SHA-256 3458fef61d21a51133c96c5295c8c7a0dc24056c4944e7102cd4fe76527a5636
Download for GoKeeps your agent's key in the operating system's credential store and runs the local gateway that signs its requests. Signed installers will be published here.