Forge documentation
Library referenceRust

forge-agent402

Agent-native identity + payment middleware — wraps OpenAgent challenge-response, x402 micropayments, and Arsenal capability grants into agent402::serve() and agent402::connect()

Agent-native identity + payment middleware — wraps OpenAgent challenge-response, x402 micropayments, and Arsenal capability grants into agent402::serve() and agent402::connect()

Package contract

FieldValue
Languagerust
Source version0.2.0
Manifestforge-rs/crates/forge-agent402/Cargo.toml
Source files4
EvidenceSource reference; registry publication and runtime conformance are separate checks

Import boundary

use forge_agent402;

Use a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.

Crate boundary

The following entries are taken from src/lib.rs. Feature conditions in the exact source still apply.

pub mod client;

pub mod error;

pub mod server;

pub use client::{Agent, AgentConfig};

pub use server::{CapabilityConfig, GrantCondition, ServeConfig, ServeLayer};

Source reference

Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.

client.rs

Read declaration text · 7 declaration entries

#[derive(Zeroize, ZeroizeOnDrop)]
pub struct AgentConfig {
/// Ed25519 secret key (32 bytes). The agent's identity key.

pub secret_key: [u8; 32]
}

pub struct Agent {

}

#[derive(Debug)]
pub struct FetchResponse {
/// HTTP status code.

pub status: u16,
/// Agent's DID as assigned by the server.

pub did: Option<String>,
/// Trust tier assigned by the server.

pub trust_tier: Option<u8>,
/// Response body bytes.

pub body: Vec<u8>
}

pub fn new(config: AgentConfig) -> Self;

pub fn public_key_bytes(&self) -> [u8; 32];

pub fn public_key_hex(&self) -> String;

pub async fn fetch(
        &self,
        url: &str,
        body: Option<&[u8]>,
    ) -> Result<FetchResponse, Agent402Error>;

error.rs

Read declaration text · 1 declaration entries

#[derive(Debug, Error)]
pub enum Agent402Error {
    /// OpenAgent challenge-response authentication failed.
    #[error("authentication failed: {reason}")]
    AuthFailed { reason: String },

    /// x402 payment required but not provided or invalid.
    #[error("payment failed: {reason}")]
    PaymentFailed { reason: String },

    /// Session token expired or invalid.
    #[error("session expired")]
    SessionExpired,

    /// Network or transport error.
    #[error("network error: {0}")]
    Network(String),

    /// Configuration error.
    #[error("configuration error: {0}")]
    Config(String),

    /// Internal error.
    #[error("internal error: {0}")]
    Internal(String),
}

lib.rs

Read declaration text · 5 declaration entries

pub mod client;

pub mod error;

pub mod server;

pub use client::{Agent, AgentConfig};

pub use server::{CapabilityConfig, GrantCondition, ServeConfig, ServeLayer};

server.rs

Read declaration text · 15 declaration entries

#[derive(Debug, Clone)]
pub struct ServeConfig {
/// Server origin (e.g., "https://api.example.com").

pub origin: String,
/// Optional realm for the OpenAgent challenge.

pub realm: Option<String>,
/// HMAC secret for session JWTs. Must be at least 32 bytes.

pub session_secret: Vec<u8>,
/// Session TTL in seconds (default: 900 = 15 minutes).

pub session_ttl_secs: i64,
/// Minimum trust tier (default: 0 = Anonymous).

pub min_trust_tier: u8,
/// Priced routes (empty = identity-only, no payment required).

pub priced_routes: Vec<RouteConfig>,
/// Wallet address for receiving payments.

pub recipient_address: Option<String>,
/// Facilitator URL for x402 settlement.

pub facilitator_url: Option<String>,
/// Capability requirements per route (Arsenal scopes).

pub capabilities: Vec<CapabilityConfig>
}

#[derive(Debug, Clone)]
pub struct RouteConfig {
/// Route path pattern (prefix match).

pub path: String,
/// HTTP method (None = all methods).

pub method: Option<String>,
/// Price per request as decimal string (e.g., "0.002").

pub price: String,
/// Currency (default: "USDC").

pub currency: String
}

pub fn new(origin: impl Into<String>, session_secret: impl AsRef<[u8]>) -> Self;

pub fn with_priced_route(
        mut self,
        path: impl Into<String>,
        method: impl Into<String>,
        price: impl Into<String>,
    ) -> Self;

pub fn with_recipient(mut self, address: impl Into<String>) -> Self;

pub fn with_facilitator(mut self, url: impl Into<String>) -> Self;

pub fn with_min_trust_tier(mut self, tier: u8) -> Self;

pub fn with_realm(mut self, realm: impl Into<String>) -> Self;

pub fn with_capability(
        mut self,
        path: impl Into<String>,
        method: impl Into<String>,
        scopes: &[&str],
        condition: GrantCondition,
    ) -> Self;

#[derive(Debug, Clone)]
pub struct CapabilityConfig {
/// Route path pattern (prefix match).

pub path: String,
/// HTTP method (None = all methods).

pub method: Option<String>,
/// Required Arsenal scopes (format: `service:resource:action`).

pub scopes: Vec<String>,
/// Grant condition: "verified" or "verified_and_paid".

pub condition: GrantCondition
}

#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum GrantCondition {
    /// Grant after identity verification succeeds (any trust tier).
    Verified,
    /// Grant after identity verification AND x402 payment succeeds.
    VerifiedAndPaid,
    /// Grant only if trust tier meets minimum.
    TrustMinimum(u8),
}

#[derive(Clone)]
pub struct ServeLayer {

}

pub fn new(config: ServeConfig) -> Self;

pub fn config(&self) -> &ServeConfig;

pub fn serve(config: ServeConfig) -> ServeLayer;

Continue

On this page