{
  "name": "com.l1fe.forge:forge-auth",
  "language": "kotlin",
  "version": "0.1.0",
  "description": "Kotlin/JVM forge-auth module.",
  "manifest": "forge-kt/forge-auth/build.gradle.kts",
  "manifestSha256": "b7c77618e92fbdeb5530efa2a338987d579828199ed598b8aeeb903817b610a6",
  "status": "source-reference",
  "registryPublicationVerified": false,
  "route": "/libraries/kotlin/forge-auth",
  "features": {},
  "files": [
    {
      "path": "forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/AuthError.kt",
      "sha256": "a87395a829a7793de75d6a9af176225b75ca64a1ffea0bce7a4204196d2e2382",
      "artifactSha256": "a7c27340fece60f066a2816fcb83e1d60d2529958064472d341849ab8955cf2d",
      "url": "/reference/source/forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/AuthError.kt.txt",
      "declarations": [
        {
          "name": "public sealed class ForgeAuthError(",
          "line": 16,
          "signature": "public sealed class ForgeAuthError(\nmessage: String,\ncause: Throwable?;",
          "documentation": ""
        },
        {
          "name": "public class TokenExpired(",
          "line": 27,
          "signature": "public class TokenExpired(\npublic val actId: String,\npublic val expiredAt: String,\n) : ForgeAuthError(\n\"Arsenal ACT '$actId' expired at $expiredAt\"\n)\n\n/**\n* The agent does not have sufficient scope in its ACT.\n*\n* @property agentDid The agent's DID.\n* @property actId The ACT identifier.\n* @property requiredScope The scope that was required.\n* @property availableScopes The scopes available in the ACT.\n*/\npublic class InsufficientScope(\npublic val agentDid: String,\npublic val actId: String,\npublic val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public val actId: String,",
          "line": 28,
          "signature": "public val actId: String,\npublic val expiredAt: String,\n) : ForgeAuthError(\n\"Arsenal ACT '$actId' expired at $expiredAt\"\n)\n\n/**\n* The agent does not have sufficient scope in its ACT.\n*\n* @property agentDid The agent's DID.\n* @property actId The ACT identifier.\n* @property requiredScope The scope that was required.\n* @property availableScopes The scopes available in the ACT.\n*/\npublic class InsufficientScope(\npublic val agentDid: String,\npublic val actId: String,\npublic val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public val expiredAt: String,",
          "line": 29,
          "signature": "public val expiredAt: String,\n) : ForgeAuthError(\n\"Arsenal ACT '$actId' expired at $expiredAt\"\n)\n\n/**\n* The agent does not have sufficient scope in its ACT.\n*\n* @property agentDid The agent's DID.\n* @property actId The ACT identifier.\n* @property requiredScope The scope that was required.\n* @property availableScopes The scopes available in the ACT.\n*/\npublic class InsufficientScope(\npublic val agentDid: String,\npublic val actId: String,\npublic val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public class InsufficientScope(",
          "line": 42,
          "signature": "public class InsufficientScope(\npublic val agentDid: String,\npublic val actId: String,\npublic val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public val agentDid: String,",
          "line": 43,
          "signature": "public val agentDid: String,\npublic val actId: String,\npublic val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public val actId: String,",
          "line": 44,
          "signature": "public val actId: String,\npublic val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public val requiredScope: String,",
          "line": 45,
          "signature": "public val requiredScope: String,\npublic val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public val availableScopes: List<String>,",
          "line": 46,
          "signature": "public val availableScopes: List<String>,\n) : ForgeAuthError(\n\"agent $agentDid lacks scope '$requiredScope' in Arsenal ACT '$actId'; \" +",
          "documentation": ""
        },
        {
          "name": "public class CapabilityEscalation(",
          "line": 62,
          "signature": "public class CapabilityEscalation(\npublic val parentDid: String,\npublic val actId: String,\npublic val requestedScope: String,\npublic val parentScopes: List<String>,\n) : ForgeAuthError(\n\"capability escalation denied: child requested scope '$requestedScope' but \" +\n\"parent $parentDid ACT '$actId' only grants: \" +\nparentScopes.joinToString(\", \").ifEmpty",
          "documentation": ""
        },
        {
          "name": "public val parentDid: String,",
          "line": 63,
          "signature": "public val parentDid: String,\npublic val actId: String,\npublic val requestedScope: String,\npublic val parentScopes: List<String>,\n) : ForgeAuthError(\n\"capability escalation denied: child requested scope '$requestedScope' but \" +\n\"parent $parentDid ACT '$actId' only grants: \" +\nparentScopes.joinToString(\", \").ifEmpty",
          "documentation": ""
        },
        {
          "name": "public val actId: String,",
          "line": 64,
          "signature": "public val actId: String,\npublic val requestedScope: String,\npublic val parentScopes: List<String>,\n) : ForgeAuthError(\n\"capability escalation denied: child requested scope '$requestedScope' but \" +\n\"parent $parentDid ACT '$actId' only grants: \" +\nparentScopes.joinToString(\", \").ifEmpty",
          "documentation": ""
        },
        {
          "name": "public val requestedScope: String,",
          "line": 65,
          "signature": "public val requestedScope: String,\npublic val parentScopes: List<String>,\n) : ForgeAuthError(\n\"capability escalation denied: child requested scope '$requestedScope' but \" +\n\"parent $parentDid ACT '$actId' only grants: \" +\nparentScopes.joinToString(\", \").ifEmpty",
          "documentation": ""
        },
        {
          "name": "public val parentScopes: List<String>,",
          "line": 66,
          "signature": "public val parentScopes: List<String>,\n) : ForgeAuthError(\n\"capability escalation denied: child requested scope '$requestedScope' but \" +\n\"parent $parentDid ACT '$actId' only grants: \" +\nparentScopes.joinToString(\", \").ifEmpty",
          "documentation": ""
        },
        {
          "name": "public class DelegationDenied(",
          "line": 78,
          "signature": "public class DelegationDenied(\npublic val reason: String,\n) : ForgeAuthError(\"delegation denied: $reason\")\n\n/**\n* An ACT is structurally invalid.\n*\n* @property actId The ACT identifier.\n* @property reason The validation failure reason.\n*/\npublic class InvalidAct(\npublic val actId: String,\npublic val reason: String,\n) : ForgeAuthError(\"Arsenal ACT '$actId' is invalid: $reason\")\n}",
          "documentation": ""
        },
        {
          "name": "public val reason: String,",
          "line": 79,
          "signature": "public val reason: String,\n) : ForgeAuthError(\"delegation denied: $reason\")\n\n/**\n* An ACT is structurally invalid.\n*\n* @property actId The ACT identifier.\n* @property reason The validation failure reason.\n*/\npublic class InvalidAct(\npublic val actId: String,\npublic val reason: String,\n) : ForgeAuthError(\"Arsenal ACT '$actId' is invalid: $reason\")\n}",
          "documentation": ""
        },
        {
          "name": "public class InvalidAct(",
          "line": 88,
          "signature": "public class InvalidAct(\npublic val actId: String,\npublic val reason: String,\n) : ForgeAuthError(\"Arsenal ACT '$actId' is invalid: $reason\")\n}",
          "documentation": ""
        },
        {
          "name": "public val actId: String,",
          "line": 89,
          "signature": "public val actId: String,\npublic val reason: String,\n) : ForgeAuthError(\"Arsenal ACT '$actId' is invalid: $reason\")\n}",
          "documentation": ""
        },
        {
          "name": "public val reason: String,",
          "line": 90,
          "signature": "public val reason: String,\n) : ForgeAuthError(\"Arsenal ACT '$actId' is invalid: $reason\")\n}",
          "documentation": ""
        }
      ]
    },
    {
      "path": "forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/Capability.kt",
      "sha256": "11089e02fd0d74841bfa5055c573d99440431e66d3fa7f2c6a62cc7e14aeb2dd",
      "artifactSha256": "3d986a0fd33f6b6071aa3f562fb29ecb7bfc17ffc8e103a8f0afee7b67535547",
      "url": "/reference/source/forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/Capability.kt.txt",
      "declarations": [
        {
          "name": "public data class DelegationConstraints(",
          "line": 24,
          "signature": "public data class DelegationConstraints(\n@SerialName(\"allow_delegation\")\nval allowDelegation: Boolean;",
          "documentation": ""
        },
        {
          "name": "public data class AgentCapabilityToken(",
          "line": 51,
          "signature": "public data class AgentCapabilityToken(\nval id: String,\n@SerialName(\"agent_did\")\nval agentDid: String,\n@SerialName(\"issuer_did\")\nval issuerDid: String,\nval scopes: List<String>,\n@SerialName(\"issued_at\")\nval issuedAt: Timestamp,\n@SerialName(\"expires_at\")\nval expiresAt: Timestamp,\n@SerialName(\"delegation_constraints\")\nval delegationConstraints: DelegationConstraints;",
          "documentation": ""
        },
        {
          "name": "public fun verifyAct(act: AgentCapabilityToken)",
          "line": 75,
          "signature": "public fun verifyAct(act: AgentCapabilityToken)",
          "documentation": ""
        },
        {
          "name": "public fun extractScopes(act: AgentCapabilityToken): List<String>;",
          "line": 101,
          "signature": "public fun extractScopes(act: AgentCapabilityToken): List<String>;",
          "documentation": ""
        },
        {
          "name": "public fun actAllowsScope(act: AgentCapabilityToken, requiredScope: String): Boolean",
          "line": 113,
          "signature": "public fun actAllowsScope(act: AgentCapabilityToken, requiredScope: String): Boolean",
          "documentation": ""
        },
        {
          "name": "public fun scopeImplies(granted: String, required: String): Boolean",
          "line": 129,
          "signature": "public fun scopeImplies(granted: String, required: String): Boolean",
          "documentation": ""
        }
      ]
    },
    {
      "path": "forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/Delegation.kt",
      "sha256": "603526c52eaab00e28650ef6e1826a8a6931710562751e776d1db721b0a84faf",
      "artifactSha256": "d8093d7fb1cced5f1cbe8d43704a207a4c9cd43e02a540f7478ad5440f89359b",
      "url": "/reference/source/forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/Delegation.kt.txt",
      "declarations": [
        {
          "name": "public data class DelegationRequest(",
          "line": 26,
          "signature": "public data class DelegationRequest(\n@SerialName(\"parent_act\")\nval parentAct: AgentCapabilityToken,\n@SerialName(\"child_did\")\nval childDid: String,\n@SerialName(\"requested_scopes\")\nval requestedScopes: List<String>,\n)\n\n/**\n* The result of a delegation operation.\n*\n* @property childAct The delegated ACT for the child agent.\n* @property narrowedScopes The scopes that were actually granted (may be a subset of requested).\n*/\n@Serializable\npublic data class DelegationResult(\n@SerialName(\"child_act\")\nval childAct: AgentCapabilityToken,\n@SerialName(\"narrowed_scopes\")\nval narrowedScopes: List<String>,\n)\n\n/**\n* Delegate capabilities from a parent to a child agent.\n*",
          "documentation": ""
        },
        {
          "name": "public data class DelegationResult(",
          "line": 42,
          "signature": "public data class DelegationResult(\n@SerialName(\"child_act\")\nval childAct: AgentCapabilityToken,\n@SerialName(\"narrowed_scopes\")\nval narrowedScopes: List<String>,\n)\n\n/**\n* Delegate capabilities from a parent to a child agent.\n*\n* Enforces the ANVIL rule that child capabilities must be a strict\n* subset of parent capabilities. The child's TTL is reduced by\n* the delegation constraints.\n*\n* ANVIL Spec Section 11.2\n*\n* @param request The delegation request.\n* @return The delegation result with the child's ACT.\n* @throws ForgeAuthError.DelegationDenied if delegation is not allowed.\n* @throws ForgeAuthError.CapabilityEscalation if requested scopes exceed parent's.\n* @throws ForgeAuthError.TokenExpired if the parent's ACT has expired.\n*/\npublic fun delegateCapabilities(request: DelegationRequest): DelegationResult",
          "documentation": ""
        },
        {
          "name": "public fun delegateCapabilities(request: DelegationRequest): DelegationResult",
          "line": 64,
          "signature": "public fun delegateCapabilities(request: DelegationRequest): DelegationResult",
          "documentation": ""
        }
      ]
    },
    {
      "path": "forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/ToolAuth.kt",
      "sha256": "e211ec6ee04a724b1a12f698dff6b208b52a362a06a4e4d2816080c41a417c18",
      "artifactSha256": "13421f74b219abff4b97b9586b861a794d1be564e4f44bcac70d256355efc29c",
      "url": "/reference/source/forge-kt/forge-auth/src/main/kotlin/com/l1fe/forge/auth/ToolAuth.kt.txt",
      "declarations": [
        {
          "name": "public data class ToolAuthorizationRequest(",
          "line": 25,
          "signature": "public data class ToolAuthorizationRequest(\n@SerialName(\"tool_name\")\nval toolName: String,\n@SerialName(\"tool_tier\")\nval toolTier: ToolTier,\n@SerialName(\"agent_did\")\nval agentDid: String?;",
          "documentation": ""
        },
        {
          "name": "public sealed class ToolAuthorizationDecision",
          "line": 41,
          "signature": "public sealed class ToolAuthorizationDecision",
          "documentation": ""
        },
        {
          "name": "public data class Allowed(val scope: String) : ToolAuthorizationDecision()",
          "line": 50,
          "signature": "public data class Allowed(val scope: String) : ToolAuthorizationDecision()\n\n/**\n* The tool invocation is denied.\n*\n* @property reason The denial reason.\n*/\n@Serializable\n@SerialName(\"denied\")\npublic data class Denied(val reason: String) : ToolAuthorizationDecision()\n\n/**\n* The tool invocation is in legacy mode (no identity/auth configured).\n*\n* Legacy mode allows all tools but logs a warning.\n*/\n@Serializable\n@SerialName(\"legacy_mode\")\npublic data object LegacyMode : ToolAuthorizationDecision()\n}\n\n/**\n* Authorize a tool invocation against an Arsenal ACT.\n*\n* Authorization rules per ANVIL 3-tier model:\n* - **Platform (Tier 1)**: Always allowed, no ACT check needed.",
          "documentation": ""
        },
        {
          "name": "public data class Denied(val reason: String) : ToolAuthorizationDecision()",
          "line": 59,
          "signature": "public data class Denied(val reason: String) : ToolAuthorizationDecision()\n\n/**\n* The tool invocation is in legacy mode (no identity/auth configured).\n*\n* Legacy mode allows all tools but logs a warning.\n*/\n@Serializable\n@SerialName(\"legacy_mode\")\npublic data object LegacyMode : ToolAuthorizationDecision()\n}\n\n/**\n* Authorize a tool invocation against an Arsenal ACT.\n*\n* Authorization rules per ANVIL 3-tier model:\n* - **Platform (Tier 1)**: Always allowed, no ACT check needed.\n* - **External (Tier 2)**: Requires ACT with matching scope.\n* - **Embedded (Tier 3)**: Always allowed (module-scoped).\n*\n* If no ACT is provided, returns [ToolAuthorizationDecision.LegacyMode].\n*\n* ANVIL Spec Section 8.7\n*\n* @param request The authorization request.\n* @return The authorization decision.",
          "documentation": ""
        },
        {
          "name": "public data object LegacyMode : ToolAuthorizationDecision()",
          "line": 68,
          "signature": "public data object LegacyMode : ToolAuthorizationDecision()\n}\n\n/**\n* Authorize a tool invocation against an Arsenal ACT.\n*\n* Authorization rules per ANVIL 3-tier model:\n* - **Platform (Tier 1)**: Always allowed, no ACT check needed.\n* - **External (Tier 2)**: Requires ACT with matching scope.\n* - **Embedded (Tier 3)**: Always allowed (module-scoped).\n*\n* If no ACT is provided, returns [ToolAuthorizationDecision.LegacyMode].\n*\n* ANVIL Spec Section 8.7\n*\n* @param request The authorization request.\n* @return The authorization decision.\n*/\npublic fun authorizeToolInvocation(request: ToolAuthorizationRequest): ToolAuthorizationDecision",
          "documentation": ""
        },
        {
          "name": "public fun authorizeToolInvocation(request: ToolAuthorizationRequest): ToolAuthorizationDecision",
          "line": 86,
          "signature": "public fun authorizeToolInvocation(request: ToolAuthorizationRequest): ToolAuthorizationDecision",
          "documentation": ""
        },
        {
          "name": "public fun buildToolScope(toolName: String): String;",
          "line": 131,
          "signature": "public fun buildToolScope(toolName: String): String;",
          "documentation": ""
        }
      ]
    }
  ]
}
