{
  "name": "@forge-sdk/auth",
  "language": "typescript",
  "version": "0.1.0",
  "description": "Arsenal capability token integration and tool authorization for the Forge SDK",
  "manifest": "forge-ts/packages/forge-auth/package.json",
  "manifestSha256": "a782e02c223735d4c16f1fa90b6915a0df6622c12f73be3a392379d713bf34aa",
  "status": "source-reference",
  "registryPublicationVerified": false,
  "route": "/libraries/typescript/auth",
  "features": {},
  "files": [
    {
      "path": "forge-ts/packages/forge-auth/src/capability.ts",
      "sha256": "fa41d8819b1680b5fcae3f0ae4bab5353de32cfff73b1606cb10907b488012e7",
      "artifactSha256": "c25b2f44569d3f5cb598b3eb62cbf7afdd9c7c97a80b534783ee2f30515c1b0f",
      "url": "/reference/source/forge-ts/packages/forge-auth/src/capability.ts.txt",
      "declarations": [
        {
          "name": "AgentCapabilityToken",
          "line": 37,
          "signature": "export interface AgentCapabilityToken {\n  /** The unique token identifier. */\n  readonly id: string;\n  /** The agent DID this token is for. */\n  readonly subject: string;\n  /** The token issuer. */\n  readonly issuer: string;\n  /** The intended audience. */\n  readonly audience: string;\n  /** The granted scopes in 'service:resource:action' format. */\n  readonly scopes: readonly string[];\n  /** The ISO 8601 timestamp when the token was issued. */\n  readonly issuedAt: string;\n  /** The ISO 8601 timestamp after which the token is valid. */\n  readonly notBefore: string;\n  /** The ISO 8601 timestamp at which the token expires. */\n  readonly expiresAt: string;\n  /** Optional delegation constraints. */\n  readonly delegation?: DelegationConstraints;\n}",
          "documentation": "Represents an Arsenal Agent Capability Token.\n\nThis is the TypeScript representation of an Arsenal ACT. In production,\nthe actual token structure comes from the Arsenal SDK. This interface\ndefines the contract that the forge-auth package requires."
        },
        {
          "name": "DelegationConstraints",
          "line": 61,
          "signature": "export interface DelegationConstraints {\n  /** Whether delegation is allowed. */\n  readonly allowDelegation: boolean;\n  /** Optional list of allowed delegate agent IDs. Empty = any agent. */\n  readonly allowedDelegates: readonly string[];\n  /** Minimum TTL reduction in seconds when delegating. */\n  readonly minTtlReduction: number;\n  /** Maximum delegation depth. */\n  readonly maxDelegationDepth: number;\n}",
          "documentation": "Delegation constraints on an ACT."
        },
        {
          "name": "verifyAct",
          "line": 93,
          "signature": "export function verifyAct(act: AgentCapabilityToken): void;",
          "documentation": "Verifies that an Arsenal ACT is structurally valid and time-valid.\n\nPerforms two checks:\n1. Structural validation -- non-empty scopes, valid fields.\n2. Time validity -- not expired, not-before has passed.\n\nThis does NOT verify cryptographic signatures. Signature verification\nis the Arsenal crypto layer's responsibility."
        },
        {
          "name": "extractScopes",
          "line": 147,
          "signature": "export function extractScopes(act: AgentCapabilityToken): string[];",
          "documentation": "Extracts all granted scope strings from an Arsenal ACT.\n\nReturns the scopes as an array of strings in 'service:resource:action' format.\nDoes NOT validate the token; call `verifyAct` first."
        },
        {
          "name": "actAllowsScope",
          "line": 174,
          "signature": "export function actAllowsScope(act: AgentCapabilityToken, scope: string): boolean;",
          "documentation": "Checks whether an Arsenal ACT grants a specific scope.\n\nFirst verifies the token is valid, then checks if any of the token's\nscopes imply the requested scope. Wildcard scopes (e.g., 'forge:*:*')\nmatch specific scopes (e.g., 'forge:tool.search:execute')."
        },
        {
          "name": "scopeImplies",
          "line": 200,
          "signature": "export function scopeImplies(granted: string, requested: string): boolean;",
          "documentation": "Checks whether a granted scope implies a requested scope.\n\nSupports wildcard matching at each component position:\n- 'forge:*:*' implies 'forge:tool.search:execute'\n- '*:*:*' implies everything\n- 'forge:tool.search:execute' implies only itself"
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-auth/src/delegation.ts",
      "sha256": "850875172e52f836506516c11afa2d4b7dbeab1e657d75a8c232f1c029f53527",
      "artifactSha256": "a4d9b5d9ad28cdcd8b6b5814ae4dddfda3d8834525574a0a4ef934d2fb4d6eac",
      "url": "/reference/source/forge-ts/packages/forge-auth/src/delegation.ts.txt",
      "declarations": [
        {
          "name": "DelegationRequest",
          "line": 35,
          "signature": "export interface DelegationRequest {\n  /** The parent agent's Arsenal ACT. */\n  readonly parentAct: AgentCapabilityToken;\n  /** The parent agent's OAS DID. */\n  readonly parentDid: string;\n  /** The child agent's OAS DID. */\n  readonly childDid: string;\n  /** The scopes requested for the child agent. Must be a subset of the parent's. */\n  readonly requestedScopes: readonly string[];\n}",
          "documentation": "A request to delegate capabilities from a parent agent to a child agent.\n\nANVIL Spec section 11.3."
        },
        {
          "name": "DelegationResult",
          "line": 49,
          "signature": "export interface DelegationResult {\n  /** The child's scopes (verified subset of parent). */\n  readonly scopes: readonly string[];\n  /** The computed child TTL in seconds. */\n  readonly ttlSeconds: number;\n  /** The parent's DID for provenance. */\n  readonly parentDid: string;\n  /** The child's DID. */\n  readonly childDid: string;\n}",
          "documentation": "The result of a successful delegation."
        },
        {
          "name": "delegateCapabilities",
          "line": 88,
          "signature": "export function delegateCapabilities(request: DelegationRequest): DelegationResult;",
          "documentation": "Delegates capabilities from a parent agent to a child agent.\n\nEnforces all delegation constraints defined in ANVIL Spec section 11.3:\n\n1. Parent ACT validity -- not expired, structurally sound.\n2. Scope narrowing -- child scopes must be a subset of parent scopes.\n3. Delegation permission -- parent ACT must allow delegation.\n4. TTL reduction -- child's TTL is shorter than parent's remaining TTL."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-auth/src/error.ts",
      "sha256": "176c1b1ab4bcf83be292c873d98b7ca7ae9f61cc02fa5cf1b8cabd36467e212c",
      "artifactSha256": "4db2957274044d3c7b2c956fe78d1ebc3df7f03a15acbeee4c57ab87f4b87192",
      "url": "/reference/source/forge-ts/packages/forge-auth/src/error.ts.txt",
      "declarations": [
        {
          "name": "export const ForgeAuthErrorCode = {",
          "line": 17,
          "signature": "export const ForgeAuthErrorCode /* type inferred in source */;",
          "documentation": "Error types for the `@forge-sdk/auth` package.\n\nAll errors are actionable with full context: agent DIDs, scope names,\ntoken IDs, and specific reasons for denial. This enables operators and\ndevelopers to diagnose authorization failures without guessing.\n\nANVIL Spec section 8.7 -- Tool Authorization.\nANVIL Spec section 11.3 -- Capability Delegation.\nError code enumeration for `@forge-sdk/auth`."
        },
        {
          "name": "ForgeAuthErrorCodeType",
          "line": 26,
          "signature": "export type ForgeAuthErrorCodeType = (typeof ForgeAuthErrorCode)[keyof typeof ForgeAuthErrorCode];",
          "documentation": "Error code type."
        },
        {
          "name": "ForgeAuthError",
          "line": 46,
          "signature": "export class ForgeAuthError extends Error {\n  public readonly code: ForgeAuthErrorCodeType;\n  static tokenExpired(tokenId: string, agentDid: string, expiredAt: string): ForgeAuthError;\n  static insufficientScope(\n    agentDid: string,\n    requiredScope: string,\n    availableScopes: string[]\n  ): ForgeAuthError;\n  static capabilityEscalation(\n    parentDid: string,\n    childDid: string,\n    requested: string,\n    available: string[]\n  ): ForgeAuthError;\n  static delegationDenied(\n    parentDid: string,\n    childDid: string,\n    reason: string\n  ): ForgeAuthError;\n  static invalidToken(reason: string): ForgeAuthError;\n  isExpired(): boolean;\n  isInsufficientScope(): boolean;\n  isCapabilityEscalation(): boolean;\n  isDelegationDenied(): boolean;\n  isInvalidToken(): boolean;\n}",
          "documentation": "Error class for Forge authorization operations.\n\nEach variant carries enough context for operators to diagnose the issue\nwithout access to internal state. Error messages never include private\nkeys or raw token bytes."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-auth/src/index.ts",
      "sha256": "0b1870750696ee9c80238a2be95ef36cef19608269909b7a0f7066d5e140d463",
      "artifactSha256": "562e05d50662e2febb489786723a31e1aa9a541975b87f1ff13b46828b7915a8",
      "url": "/reference/source/forge-ts/packages/forge-auth/src/index.ts.txt",
      "declarations": [
        {
          "name": "export { ForgeAuthError, ForgeAuthErrorCode, type ForgeAuthErrorCodeType } from './error.js';",
          "line": 39,
          "signature": "export { ForgeAuthError, ForgeAuthErrorCode, type ForgeAuthErrorCodeType } from './error.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 42,
          "signature": "export {\n  type AgentCapabilityToken,\n  type DelegationConstraints,\n  verifyAct,\n  extractScopes,\n  actAllowsScope,\n  scopeImplies,\n} from './capability.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 52,
          "signature": "export {\n  type ToolAuthorizationRequest,\n  type ToolAuthorizationDecision,\n  ToolAuthorizationDecisionType,\n  authorizeToolInvocation,\n  isAllowed,\n  isDenied,\n  isLegacyMode,\n  buildToolScope,\n} from './tool-auth.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 64,
          "signature": "export {\n  type DelegationRequest,\n  type DelegationResult,\n  delegateCapabilities,\n} from './delegation.js';",
          "documentation": ""
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-auth/src/tool-auth.ts",
      "sha256": "0619c0c43191c4314ac126a89a70c281ee7e104ebf3afbd1b03cd5bd2775dc0c",
      "artifactSha256": "43704246cb95723f9d4fe0ebc0604ebd47ab98a02d025cf39e4751ee13288668",
      "url": "/reference/source/forge-ts/packages/forge-auth/src/tool-auth.ts.txt",
      "declarations": [
        {
          "name": "ToolAuthorizationRequest",
          "line": 37,
          "signature": "export interface ToolAuthorizationRequest {\n  /** The OAS DID of the agent requesting tool invocation. */\n  readonly agentDid: string;\n  /** The name of the tool being invoked. */\n  readonly toolName: string;\n  /** The tier classification of the tool. */\n  readonly toolTier: ToolTier;\n  /** The agent's Arsenal ACT, if available. Undefined for legacy mode. */\n  readonly act?: AgentCapabilityToken;\n}",
          "documentation": "A request to authorize a tool invocation.\n\nANVIL Spec section 8.7."
        },
        {
          "name": "export const ToolAuthorizationDecisionType = {",
          "line": 53,
          "signature": "export const ToolAuthorizationDecisionType /* type inferred in source */;",
          "documentation": "Tool authorization decision types.\n\nANVIL Spec section 8.7."
        },
        {
          "name": "ToolAuthorizationDecisionType",
          "line": 60,
          "signature": "export type ToolAuthorizationDecisionType =\n  (typeof ToolAuthorizationDecisionType)[keyof typeof ToolAuthorizationDecisionType];",
          "documentation": "Decision type."
        },
        {
          "name": "ToolAuthorizationDecision",
          "line": 68,
          "signature": "export interface ToolAuthorizationDecision {\n  /** The decision type. */\n  readonly decision: ToolAuthorizationDecisionType;\n  /** The denial reason, if denied. */\n  readonly reason?: string;\n}",
          "documentation": "The result of a tool authorization check.\n\nANVIL Spec section 8.7."
        },
        {
          "name": "isAllowed",
          "line": 83,
          "signature": "export function isAllowed(decision: ToolAuthorizationDecision): boolean;",
          "documentation": "Returns `true` if the decision allows tool invocation.\n\nBoth `Allowed` and `LegacyMode` permit execution."
        },
        {
          "name": "isDenied",
          "line": 96,
          "signature": "export function isDenied(decision: ToolAuthorizationDecision): boolean;",
          "documentation": "Returns `true` if the decision denies tool invocation."
        },
        {
          "name": "isLegacyMode",
          "line": 106,
          "signature": "export function isLegacyMode(decision: ToolAuthorizationDecision): boolean;",
          "documentation": "Returns `true` if operating in legacy mode (no ACT)."
        },
        {
          "name": "buildToolScope",
          "line": 118,
          "signature": "export function buildToolScope(toolName: string): string;",
          "documentation": "Builds the required scope string for a tool invocation.\n\nThe scope format is 'forge:tool.<tool_name>:execute'."
        },
        {
          "name": "authorizeToolInvocation",
          "line": 152,
          "signature": "export function authorizeToolInvocation(\n  request: ToolAuthorizationRequest\n): ToolAuthorizationDecision;",
          "documentation": "Authorizes a tool invocation per ANVIL Spec section 8.7.\n\nThis is the primary authorization gate for all tool invocations:\n\n- Tier 1 (Platform): Always returns Allowed.\n- Tier 2 (Host): Requires ACT scope check. Returns Denied if scope\n  is missing, LegacyMode if no ACT is provided.\n- Tier 3 (Embedded): Always returns Allowed."
        }
      ]
    }
  ]
}
