forge-agent402
Agent-native identity + payment middleware — wraps OpenAgent challenge-response, x402 micropayments, and Arsenal capability grants into agent402::serve() and agent402::connect()
Agent-native identity + payment middleware — wraps OpenAgent challenge-response, x402 micropayments, and Arsenal capability grants into agent402::serve() and agent402::connect()
Package contract
| Field | Value |
|---|---|
| Language | rust |
| Source version | 0.2.0 |
| Manifest | forge-rs/crates/forge-agent402/Cargo.toml |
| Source files | 4 |
| Evidence | Source reference; registry publication and runtime conformance are separate checks |
Import boundary
use forge_agent402;Use a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.
Crate boundary
The following entries are taken from src/lib.rs. Feature conditions in the exact source still apply.
pub mod client;
pub mod error;
pub mod server;
pub use client::{Agent, AgentConfig};
pub use server::{CapabilityConfig, GrantCondition, ServeConfig, ServeLayer};Source reference
Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.
client.rs
Read declaration text · 7 declaration entries
#[derive(Zeroize, ZeroizeOnDrop)]
pub struct AgentConfig {
/// Ed25519 secret key (32 bytes). The agent's identity key.
pub secret_key: [u8; 32]
}
pub struct Agent {
}
#[derive(Debug)]
pub struct FetchResponse {
/// HTTP status code.
pub status: u16,
/// Agent's DID as assigned by the server.
pub did: Option<String>,
/// Trust tier assigned by the server.
pub trust_tier: Option<u8>,
/// Response body bytes.
pub body: Vec<u8>
}
pub fn new(config: AgentConfig) -> Self;
pub fn public_key_bytes(&self) -> [u8; 32];
pub fn public_key_hex(&self) -> String;
pub async fn fetch(
&self,
url: &str,
body: Option<&[u8]>,
) -> Result<FetchResponse, Agent402Error>;error.rs
Read declaration text · 1 declaration entries
#[derive(Debug, Error)]
pub enum Agent402Error {
/// OpenAgent challenge-response authentication failed.
#[error("authentication failed: {reason}")]
AuthFailed { reason: String },
/// x402 payment required but not provided or invalid.
#[error("payment failed: {reason}")]
PaymentFailed { reason: String },
/// Session token expired or invalid.
#[error("session expired")]
SessionExpired,
/// Network or transport error.
#[error("network error: {0}")]
Network(String),
/// Configuration error.
#[error("configuration error: {0}")]
Config(String),
/// Internal error.
#[error("internal error: {0}")]
Internal(String),
}lib.rs
Read declaration text · 5 declaration entries
pub mod client;
pub mod error;
pub mod server;
pub use client::{Agent, AgentConfig};
pub use server::{CapabilityConfig, GrantCondition, ServeConfig, ServeLayer};server.rs
Read declaration text · 15 declaration entries
#[derive(Debug, Clone)]
pub struct ServeConfig {
/// Server origin (e.g., "https://api.example.com").
pub origin: String,
/// Optional realm for the OpenAgent challenge.
pub realm: Option<String>,
/// HMAC secret for session JWTs. Must be at least 32 bytes.
pub session_secret: Vec<u8>,
/// Session TTL in seconds (default: 900 = 15 minutes).
pub session_ttl_secs: i64,
/// Minimum trust tier (default: 0 = Anonymous).
pub min_trust_tier: u8,
/// Priced routes (empty = identity-only, no payment required).
pub priced_routes: Vec<RouteConfig>,
/// Wallet address for receiving payments.
pub recipient_address: Option<String>,
/// Facilitator URL for x402 settlement.
pub facilitator_url: Option<String>,
/// Capability requirements per route (Arsenal scopes).
pub capabilities: Vec<CapabilityConfig>
}
#[derive(Debug, Clone)]
pub struct RouteConfig {
/// Route path pattern (prefix match).
pub path: String,
/// HTTP method (None = all methods).
pub method: Option<String>,
/// Price per request as decimal string (e.g., "0.002").
pub price: String,
/// Currency (default: "USDC").
pub currency: String
}
pub fn new(origin: impl Into<String>, session_secret: impl AsRef<[u8]>) -> Self;
pub fn with_priced_route(
mut self,
path: impl Into<String>,
method: impl Into<String>,
price: impl Into<String>,
) -> Self;
pub fn with_recipient(mut self, address: impl Into<String>) -> Self;
pub fn with_facilitator(mut self, url: impl Into<String>) -> Self;
pub fn with_min_trust_tier(mut self, tier: u8) -> Self;
pub fn with_realm(mut self, realm: impl Into<String>) -> Self;
pub fn with_capability(
mut self,
path: impl Into<String>,
method: impl Into<String>,
scopes: &[&str],
condition: GrantCondition,
) -> Self;
#[derive(Debug, Clone)]
pub struct CapabilityConfig {
/// Route path pattern (prefix match).
pub path: String,
/// HTTP method (None = all methods).
pub method: Option<String>,
/// Required Arsenal scopes (format: `service:resource:action`).
pub scopes: Vec<String>,
/// Grant condition: "verified" or "verified_and_paid".
pub condition: GrantCondition
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum GrantCondition {
/// Grant after identity verification succeeds (any trust tier).
Verified,
/// Grant after identity verification AND x402 payment succeeds.
VerifiedAndPaid,
/// Grant only if trust tier meets minimum.
TrustMinimum(u8),
}
#[derive(Clone)]
pub struct ServeLayer {
}
pub fn new(config: ServeConfig) -> Self;
pub fn config(&self) -> &ServeConfig;
pub fn serve(config: ServeConfig) -> ServeLayer;