{
  "name": "@forge-sdk/identity",
  "language": "typescript",
  "version": "0.1.0",
  "description": "OAS identity binding for Forge agents with an explicit production crypto bridge",
  "manifest": "forge-ts/packages/forge-identity/package.json",
  "manifestSha256": "6e0fd4348b60c08aa3b6686a6342eddd51a8cca9d3b63ca11584f7525726880a",
  "status": "source-reference",
  "registryPublicationVerified": false,
  "route": "/libraries/typescript/identity",
  "features": {},
  "files": [
    {
      "path": "forge-ts/packages/forge-identity/src/agent-identity.ts",
      "sha256": "0af434de2b7e560b26c8f6935a719a855a35a5058e3eb9ac7cb6cf2e66e847b0",
      "artifactSha256": "af83740d09a389eec3f80bfae32a773afc35ac0025a1df693c0c9e0a640291f8",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/agent-identity.ts.txt",
      "declarations": [
        {
          "name": "OasDocument",
          "line": 25,
          "signature": "export interface OasDocument {\n  /** The DID identifier. */\n  readonly id: string;\n  /** The DID document context. */\n  readonly context: readonly string[];\n  /** Verification methods. */\n  readonly verificationMethod: readonly VerificationMethod[];\n  /** Authentication references. */\n  readonly authentication: readonly string[];\n  /** Optional lineage section for derived identities. */\n  readonly lineage?: LineageSection;\n  /** Optional document proof. */\n  readonly proof?: DocumentProof;\n}",
          "documentation": "Represents an OAS Identity Document.\n\nThis is a simplified representation of the OAS document for the TypeScript\nSDK. The full document structure is defined by the OAS specification."
        },
        {
          "name": "VerificationMethod",
          "line": 43,
          "signature": "export interface VerificationMethod {\n  /** The method identifier. */\n  readonly id: string;\n  /** The method type. */\n  readonly type: string;\n  /** The controller DID. */\n  readonly controller: string;\n  /** The public key in multibase encoding. */\n  readonly publicKeyMultibase: string;\n}",
          "documentation": "A verification method in an OAS document."
        },
        {
          "name": "LineageSection",
          "line": 57,
          "signature": "export interface LineageSection {\n  /** The generation (derivation depth) of this entity. */\n  readonly generation: number;\n  /** The DID of the human root in the lineage chain. */\n  readonly humanRootDid: string;\n  /** The DID of the immediate parent. */\n  readonly parentDid: string;\n  /** The derivation path used. */\n  readonly derivationPath: string;\n  /** The lineage proof. */\n  readonly proof: LineageProof;\n}",
          "documentation": "The lineage section of a derived OAS document."
        },
        {
          "name": "LineageProof",
          "line": 73,
          "signature": "export interface LineageProof {\n  /** The proof type (e.g., 'AgentLineageProof2025'). */\n  readonly type: string;\n  /** The ISO 8601 creation timestamp. */\n  readonly created: string;\n  /** The verification method used to create the proof. */\n  readonly verificationMethod: string;\n  /** The proof value (base64url-encoded signature). */\n  readonly proofValue: string;\n}",
          "documentation": "A lineage proof linking a child to its parent."
        },
        {
          "name": "DocumentProof",
          "line": 87,
          "signature": "export interface DocumentProof {\n  /** The proof type. */\n  readonly type: string;\n  /** The ISO 8601 creation timestamp. */\n  readonly created: string;\n  /** The verification method used to create the proof. */\n  readonly verificationMethod: string;\n  /** The proof value (base64url-encoded signature). */\n  readonly proofValue: string;\n}",
          "documentation": "A document proof."
        },
        {
          "name": "CryptoBridge",
          "line": 107,
          "signature": "export interface CryptoBridge {\n  /** Generates a new Ed25519 keypair. Returns [privateKey, publicKey]. */\n  generateKeypair(): [Uint8Array, Uint8Array];\n  /** Signs a message with the given private key. Returns a 64-byte signature. */\n  sign(privateKey: Uint8Array, message: Uint8Array): Uint8Array;\n  /** Verifies a signature. Returns true if valid. */\n  verify(publicKey: Uint8Array, message: Uint8Array, signature: Uint8Array): boolean;\n  /** Derives a child key via HKDF-SHA256. Returns [childPrivateKey, childPublicKey]. */\n  deriveChild(parentPrivateKey: Uint8Array, path: string): [Uint8Array, Uint8Array];\n}",
          "documentation": "The WASM crypto bridge interface for Ed25519 operations.\n\nIn production, all crypto operations are delegated to the Rust WASM module\nto guarantee cross-language parity. This interface defines the bridge contract.\n\nIMPORTANT: TypeScript MUST NOT reimplement Ed25519, HKDF, or BLAKE3.\nAll crypto operations go through this bridge. See Forge CLAUDE.md section 2.4."
        },
        {
          "name": "ForgeAgentIdentity",
          "line": 140,
          "signature": "export class ForgeAgentIdentity {\n  constructor(\n    did: string,\n    kind: string,\n    privateKey: Uint8Array,\n    publicKey: Uint8Array,\n    document: OasDocument,\n    lineageDepth: number,\n    bridge: CryptoBridge\n  );\n  did(): string;\n  kind(): string;\n  document(): OasDocument;\n  lineageDepth(): number;\n  sign(message: Uint8Array): Uint8Array;\n  verify(message: Uint8Array, signature: Uint8Array): void;\n  verifyingKeyBytes(): Uint8Array;\n  toString(): string;\n  _privateKeyBytes(): Uint8Array;\n  _cryptoBridge(): CryptoBridge;\n}",
          "documentation": "A Forge agent's cryptographic identity, binding an OAS DID, keypair, and lineage.\n\nEvery Forge agent has a `ForgeAgentIdentity` from creation. The identity\nincludes the agent's Ed25519 keypair (derived via HKDF-SHA256 from its parent),\nthe OAS DID document, and the lineage proof chain.\n\nSee ANVIL Specification section 11.1 -- OAS Identity Binding.\n\nSECURITY:\n- `toString()` never exposes the private key (`[REDACTED]`).\n- The signing key should be zeroized when no longer needed.\n- Private key bytes are never logged, serialized in plain text, or transmitted."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-identity/src/error.ts",
      "sha256": "cef37ce9291d8fd027a1dfe96471df04bedd7e67594bf69e8843f49ea6d9b9c6",
      "artifactSha256": "d2fb507ade435eca682c911b56322b5c4ee459e02a923542841526f9f9e4fd5f",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/error.ts.txt",
      "declarations": [
        {
          "name": "export const ForgeIdentityErrorCode = {",
          "line": 17,
          "signature": "export const ForgeIdentityErrorCode /* type inferred in source */;",
          "documentation": "Error types for the `@forge-sdk/identity` package.\n\nAll errors are typed, actionable, and reference the relevant ANVIL spec\nsection. Error messages include enough context for the developer to\ndiagnose the issue without reading source code.\n\nANVIL Spec section 11.1 -- OAS Identity Binding.\nANVIL Spec section 11.2 -- Lineage Propagation.\nError code enumeration for `@forge-sdk/identity`."
        },
        {
          "name": "ForgeIdentityErrorCodeType",
          "line": 27,
          "signature": "export type ForgeIdentityErrorCodeType =\n  (typeof ForgeIdentityErrorCode)[keyof typeof ForgeIdentityErrorCode];",
          "documentation": "Error code type."
        },
        {
          "name": "ForgeIdentityError",
          "line": 50,
          "signature": "export class ForgeIdentityError extends Error {\n  public readonly code: ForgeIdentityErrorCodeType;\n  static derivationFailed(parentDid: string, path: string, reason: string): ForgeIdentityError;\n  static lineageVerificationFailed(did: string, reason: string): ForgeIdentityError;\n  static chainTooDeep(depth: number, maxDepth: number): ForgeIdentityError;\n  static invalidIdentity(reason: string): ForgeIdentityError;\n  static persistenceFailed(reason: string): ForgeIdentityError;\n  static wasmBridgeError(reason: string): ForgeIdentityError;\n}",
          "documentation": "Error class for identity operations.\n\nCovers identity derivation failures, lineage verification failures,\nchain depth violations, structural validation, and persistence errors.\n\nEvery variant includes actionable context: what failed, why, and the\nrelevant ANVIL specification section."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-identity/src/glyph.ts",
      "sha256": "62728b9e8735f5b4c30a9751f0e6a835ad733f5b56f8606b4f13b35326dac02c",
      "artifactSha256": "1390ed926b4caf1dea884485115cf52fbea4da059a06b7b92c47f5088b2aa319",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/glyph.ts.txt",
      "declarations": [
        {
          "name": "GlyphColor",
          "line": 28,
          "signature": "export interface GlyphColor {\n  /** Red channel (0-255). */\n  readonly r: number;\n  /** Green channel (0-255). */\n  readonly g: number;\n  /** Blue channel (0-255). */\n  readonly b: number;\n}",
          "documentation": "Glyph -- Visual Identity for Forge Agents.\n\nDeterministic visual identity glyphs for OAS agents. A glyph is a\nscannable, aesthetically unique avatar that encodes an agent's `did:oas`\nidentity into a colored block grid.\n\nDeterminism Guarantee: Same DID + same options = identical output bytes.\nAn RGB color triple.\n\nAll channels are 8-bit unsigned (0-255)."
        },
        {
          "name": "glyphColorRgb",
          "line": 45,
          "signature": "export function glyphColorRgb(r: number, g: number, b: number): GlyphColor;",
          "documentation": "Create a GlyphColor from RGB components."
        },
        {
          "name": "glyphColorToHex",
          "line": 55,
          "signature": "export function glyphColorToHex(c: GlyphColor): string;",
          "documentation": "Format a GlyphColor as a CSS hex color string."
        },
        {
          "name": "glyphColorLerp",
          "line": 70,
          "signature": "export function glyphColorLerp(\n  a: GlyphColor,\n  b: GlyphColor,\n  t: number,\n): GlyphColor;",
          "documentation": "Linearly interpolate between two colors."
        },
        {
          "name": "GlyphPalette",
          "line": 101,
          "signature": "export interface GlyphPalette {\n  /** Primary identity color. */\n  readonly primary: GlyphColor;\n  /** Secondary identity color (hue-offset from primary). */\n  readonly secondary: GlyphColor;\n  /** Accent color for kind region and highlights. */\n  readonly accent: GlyphColor;\n  /** Background color (dark, desaturated primary). */\n  readonly background: GlyphColor;\n}",
          "documentation": "A complete glyph color palette derived from an agent's identity.\n\nThe palette is deterministically computed from the hash of the\nDID string. Every field is fully determined by the input; no\nrandomness is involved.\n\n| Field | Derivation |\n|-------|-----------|\n| `primary` | HSL from hash bytes 0-3 (hue), byte 8 (saturation), byte 9 (lightness) |\n| `secondary` | HSL offset 60-180 degrees from primary hue, via hash bytes 4-7 |\n| `accent` | Bright, saturated version of secondary hue |\n| `background` | Dark, desaturated version of primary hue |"
        },
        {
          "name": "export const GlyphEntityKind = {",
          "line": 127,
          "signature": "export const GlyphEntityKind /* type inferred in source */;",
          "documentation": "Entity kinds supported by the glyph system.\n\n| Kind | Value | Visual Motif |\n|------|-------|-------------|\n| `Hmr` | 0 | Shield (human root) |\n| `Mhr` | 1 | Multi-shield (machine root) |\n| `Enr` | 2 | Grid (entity root) |\n| `Agent` | 3 | Diamond (agent) |\n| `Org` | 4 | Hexagon (organization) |"
        },
        {
          "name": "GlyphEntityKind",
          "line": 136,
          "signature": "export type GlyphEntityKind = (typeof GlyphEntityKind)[keyof typeof GlyphEntityKind];",
          "documentation": "Entity kind type."
        },
        {
          "name": "parseGlyphEntityKind",
          "line": 144,
          "signature": "export function parseGlyphEntityKind(s: string): GlyphEntityKind | undefined;",
          "documentation": "Parse a kind string into a `GlyphEntityKind`."
        },
        {
          "name": "glyphEntityKindAsU8",
          "line": 160,
          "signature": "export function glyphEntityKindAsU8(kind: GlyphEntityKind): number;",
          "documentation": "Return the numeric value for a GlyphEntityKind.\n\nValues 0-4 match the upstream `oas-glyph` EntityKind discriminants."
        },
        {
          "name": "glyphEntityKindFromU8",
          "line": 177,
          "signature": "export function glyphEntityKindFromU8(v: number): GlyphEntityKind | undefined;",
          "documentation": "Reconstruct a `GlyphEntityKind` from its numeric value."
        },
        {
          "name": "GlyphDescriptor",
          "line": 195,
          "signature": "export interface GlyphDescriptor {\n  /** The agent's DID string (e.g. `did:oas:l1fe:agent:data-analyst`). */\n  readonly did: string;\n  /** The entity kind that determines the kind-region visual motif. */\n  readonly kind: GlyphEntityKind;\n  /** Optional human-readable label rendered below the glyph. */\n  readonly label?: string;\n}",
          "documentation": "The glyph input contract: describes what to render."
        },
        {
          "name": "export const GlyphRenderTarget = {",
          "line": 207,
          "signature": "export const GlyphRenderTarget /* type inferred in source */;",
          "documentation": "Render target selection."
        },
        {
          "name": "GlyphRenderTarget",
          "line": 215,
          "signature": "export type GlyphRenderTarget =\n  (typeof GlyphRenderTarget)[keyof typeof GlyphRenderTarget];",
          "documentation": "Render target type."
        },
        {
          "name": "GlyphRenderOptions",
          "line": 221,
          "signature": "export interface GlyphRenderOptions {\n  /** The render target (Web or Terminal). */\n  readonly target: GlyphRenderTarget;\n  /** Desired width in pixels (Web) or columns (Terminal). */\n  readonly width?: number;\n  /** Desired height in pixels (Web) or rows (Terminal). */\n  readonly height?: number;\n  /** Optional background color override. */\n  readonly colorOverride?: GlyphColor;\n}",
          "documentation": "Render options controlling the glyph output."
        },
        {
          "name": "export const GlyphRenderFormat = {",
          "line": 235,
          "signature": "export const GlyphRenderFormat /* type inferred in source */;",
          "documentation": "Output format tag for render results."
        },
        {
          "name": "GlyphRenderFormat",
          "line": 244,
          "signature": "export type GlyphRenderFormat =\n  (typeof GlyphRenderFormat)[keyof typeof GlyphRenderFormat];",
          "documentation": "Render format type."
        },
        {
          "name": "GlyphRenderResult",
          "line": 250,
          "signature": "export interface GlyphRenderResult {\n  /** The output format. */\n  readonly format: GlyphRenderFormat;\n  /** The rendered data as a string (SVG, ANSI, etc.). */\n  readonly data: string;\n  /** Width of the rendered output. */\n  readonly width: number;\n  /** Height of the rendered output. */\n  readonly height: number;\n}",
          "documentation": "The output of a glyph render operation."
        },
        {
          "name": "derivePaletteFromDid",
          "line": 283,
          "signature": "export async function derivePaletteFromDid(\n  did: string,\n  kind: GlyphEntityKind,\n): Promise<GlyphPalette>;",
          "documentation": "Derive a deterministic color palette from a DID string and entity kind.\n\nUses SHA-256 to hash the DID bytes, then maps the resulting bytes to HSL\ncolor space. The algorithm is designed to match the Rust implementation's\npalette derivation logic."
        },
        {
          "name": "derivePaletteFromDidSync",
          "line": 304,
          "signature": "export function derivePaletteFromDidSync(\n  did: string,\n  kind: GlyphEntityKind,\n): GlyphPalette;",
          "documentation": "Synchronous palette derivation using a simple hash.\n\nFor environments where `crypto.subtle` is not available or when\nsynchronous execution is required. Uses FNV-1a-based hashing for\ndeterministic output (not cryptographic)."
        },
        {
          "name": "renderGlyph",
          "line": 374,
          "signature": "export function renderGlyph(\n  descriptor: GlyphDescriptor,\n  options: GlyphRenderOptions,\n): GlyphRenderResult;",
          "documentation": "Renders a glyph for the given descriptor and options.\n\nProduces an SVG string for Web targets and ANSI half-block characters\nfor Terminal targets."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-identity/src/index.ts",
      "sha256": "a88cbce5d2b5539a28506110554bde10f3bd35bc708d27d655a6f40fa1c92519",
      "artifactSha256": "69f24e9a356221e30da7461ee3df034b381f6c9952d0a20af19728f291d90d2b",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/index.ts.txt",
      "declarations": [
        {
          "name": "export {",
          "line": 34,
          "signature": "export {\n  ForgeIdentityError,\n  ForgeIdentityErrorCode,\n  type ForgeIdentityErrorCodeType,\n} from './error.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 41,
          "signature": "export {\n  ForgeAgentIdentity,\n  type CryptoBridge,\n  type OasDocument,\n  type VerificationMethod,\n  type LineageSection,\n  type LineageProof,\n  type DocumentProof,\n} from './agent-identity.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 52,
          "signature": "export {\n  createHmrIdentity,\n  createMhrIdentity,\n  deriveAgentIdentity,\n  setCryptoBridge,\n  getCryptoBridge,\n  DEFAULT_MAX_LINEAGE_DEPTH,\n} from './lineage.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 62,
          "signature": "export {\n  saveIdentity,\n  loadIdentity,\n  type ProtectedSigningKey,\n  type IdentityKeyProtector,\n} from './persistence.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 70,
          "signature": "export {\n  type GlyphColor,\n  glyphColorRgb,\n  glyphColorToHex,\n  glyphColorLerp,\n  type GlyphPalette,\n  GlyphEntityKind,\n  parseGlyphEntityKind,\n  glyphEntityKindAsU8,\n  glyphEntityKindFromU8,\n  type GlyphDescriptor,\n  GlyphRenderTarget,\n  type GlyphRenderOptions,\n  GlyphRenderFormat,\n  type GlyphRenderResult,\n  derivePaletteFromDid,\n  derivePaletteFromDidSync,\n  renderGlyph,\n} from './glyph.js';",
          "documentation": ""
        },
        {
          "name": "export {",
          "line": 91,
          "signature": "export {\n  FORGE_DEV_METHOD,\n  forgeDevDid,\n  deriveMachineId,\n  deriveMachineIdSync,\n  validateForgeDevDid,\n  type LocalOrg,\n  createLocalOrg,\n  type ForgeDevIdentity,\n  type LocalDevProfile,\n  PROFILE_SCHEMA_VERSION,\n  createLocalDevProfile,\n  deriveAgent,\n  profileToJSON,\n  profileFromJSON,\n} from './local-dev.js';",
          "documentation": ""
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-identity/src/lineage.ts",
      "sha256": "b7a0ea54d868588643050b0ecf7789a7e8fa654e4642802270e5a35e7c4871cc",
      "artifactSha256": "99661aa670e0e4a288335a8e4f45af8707348c326557c846f44cef9ae9b8d8e4",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/lineage.ts.txt",
      "declarations": [
        {
          "name": "export const DEFAULT_MAX_LINEAGE_DEPTH = 16;",
          "line": 30,
          "signature": "export const DEFAULT_MAX_LINEAGE_DEPTH /* type inferred in source */;",
          "documentation": "The default maximum lineage chain depth per ANVIL Spec section 11.2.\n\nThe ANVIL specification recommends a maximum of 16 derivation steps\nfrom a human root entity. Chains exceeding this depth are rejected."
        },
        {
          "name": "setCryptoBridge",
          "line": 54,
          "signature": "export function setCryptoBridge(bridge: CryptoBridge): void;",
          "documentation": "Sets the global crypto bridge implementation.\n\nCall this once at application startup to inject the production crypto bridge."
        },
        {
          "name": "getCryptoBridge",
          "line": 63,
          "signature": "export function getCryptoBridge(): CryptoBridge;",
          "documentation": "Returns the configured global crypto bridge."
        },
        {
          "name": "createHmrIdentity",
          "line": 94,
          "signature": "export function createHmrIdentity(\n  namespace: string,\n  identifier: string,\n  bridge?: CryptoBridge\n): ForgeAgentIdentity;",
          "documentation": "Creates a new Human Root (HMR) identity.\n\nGenerates a fresh Ed25519 keypair, constructs an OAS Identity Document\nfor a `did:oas:<namespace>:hmr:<identifier>` DID, and signs it.\n\nHMR identities are the ultimate trust anchors in the lineage chain.\nEvery derived agent traces back to an HMR.\n\nSee ANVIL Spec section 11.1 -- OAS Identity Binding."
        },
        {
          "name": "createMhrIdentity",
          "line": 125,
          "signature": "export function createMhrIdentity(\n  namespace: string,\n  identifier: string,\n  bridge?: CryptoBridge\n): ForgeAgentIdentity;",
          "documentation": "Creates a new Multi-Human Root (MHR) identity.\n\nSimilar to `createHmrIdentity` but for machine-originated root entities.\nMHR identities use `did:oas:<namespace>:mhr:<identifier>`.\n\nSee ANVIL Spec section 11.1 -- OAS Identity Binding."
        },
        {
          "name": "deriveAgentIdentity",
          "line": 163,
          "signature": "export function deriveAgentIdentity(\n  parent: ForgeAgentIdentity,\n  name: string,\n  namespace: string,\n  bridge?: CryptoBridge\n): ForgeAgentIdentity;",
          "documentation": "Derives a child agent identity from a parent identity.\n\nPerforms the complete agent derivation workflow per ANVIL Spec section 11.2:\n\n1. Validates the parent's lineage depth does not exceed the maximum.\n2. Derives a child Ed25519 keypair using HKDF-SHA256.\n3. Generates an AgentLineageProof2025 linking child to parent.\n4. Constructs a signed OAS Identity Document with a complete lineage section.\n\nThe child's lineage depth is `parent.lineageDepth() + 1`."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-identity/src/local-dev.ts",
      "sha256": "61a584ede2936d1f404270b6dcd71eab51e87711903ad43b5d52e3bb7b768369",
      "artifactSha256": "3085829eb8d6b02276096bf0de2669bd9a4bf26d81e21f00fdf28b4876054d3a",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/local-dev.ts.txt",
      "declarations": [
        {
          "name": "export const FORGE_DEV_METHOD = 'forge-dev';",
          "line": 28,
          "signature": "export const FORGE_DEV_METHOD /* type inferred in source */;",
          "documentation": "Local development identity layer for Forge agents.\n\nProvides a lightweight, self-contained identity and authorization\nlayer that works entirely offline without external services. Uses\nthe distinct DID method `did:forge-dev` that is rejected by all\nproduction systems.\n\nArchitecture:\n- `LocalDevProfile` -- top-level profile managing root identity, org, agent cache.\n- `ForgeDevIdentity` -- a dev identity with development metadata.\n- `LocalOrg` -- a local organization container for grouping dev identities.\n- `forgeDevDid()` -- DID construction for the `forge-dev` method.\n- `deriveMachineId()` -- deterministic machine identifier derivation.\n\nSecurity:\n- The `forge-dev` method is not recognized by any production DID resolver.\n- Profile is stored at `~/.forge/dev-profile.json`.\nThe DID method prefix for local development identities."
        },
        {
          "name": "forgeDevDid",
          "line": 53,
          "signature": "export function forgeDevDid(\n  machineId: string,\n  kind: string,\n  identifier: string,\n): string;",
          "documentation": "Constructs a local dev DID string.\n\nFormat: `did:forge-dev:<machine-id>:<kind>:<identifier>`"
        },
        {
          "name": "deriveMachineId",
          "line": 81,
          "signature": "export async function deriveMachineId(\n  hostname: string,\n  username: string,\n  profileName: string,\n): Promise<string>;",
          "documentation": "Derives a deterministic machine identifier from hostname, username,\nand profile name.\n\nAlgorithm: `SHA-256(\"forge-dev-root:\" + hostname + \":\" + username + \":\" + profile_name)`\ntruncated to the first 8 bytes, hex-encoded to 16 characters.\n\nThis is the async variant using Web Crypto API."
        },
        {
          "name": "deriveMachineIdSync",
          "line": 108,
          "signature": "export function deriveMachineIdSync(\n  hostname: string,\n  username: string,\n  profileName: string,\n): string;",
          "documentation": ""
        },
        {
          "name": "validateForgeDevDid",
          "line": 130,
          "signature": "export function validateForgeDevDid(did: string): boolean;",
          "documentation": "Validates that a string is a valid forge-dev DID."
        },
        {
          "name": "LocalOrg",
          "line": 180,
          "signature": "export interface LocalOrg {\n  /** Deterministic org ID. Format: `forge-dev-org:<name>`. */\n  readonly id: string;\n  /** Human-readable org name. */\n  readonly name: string;\n}",
          "documentation": "A local organization for grouping dev identities.\n\nIn production, orgs are managed by external services. In local dev,\nan org is a named container with a deterministic ID."
        },
        {
          "name": "createLocalOrg",
          "line": 195,
          "signature": "export function createLocalOrg(name: string): LocalOrg;",
          "documentation": "Creates a new local org with the given name.\n\nThe org ID is deterministically derived as `\"forge-dev-org:<name>\"`."
        },
        {
          "name": "ForgeDevIdentity",
          "line": 209,
          "signature": "export interface ForgeDevIdentity {\n  /** The `did:forge-dev` identifier string. */\n  readonly did: string;\n  /** The entity kind (e.g., \"mhr\", \"agent\"). */\n  readonly kind: string;\n  /** The lineage depth from the root. */\n  readonly lineageDepth: number;\n  /** The org ID this identity belongs to. */\n  readonly orgId: string;\n  /** ISO 8601 creation timestamp. */\n  readonly createdAt: string;\n  /** Schema version for forward compatibility. */\n  readonly schemaVersion: number;\n}",
          "documentation": "A local development identity with development metadata."
        },
        {
          "name": "LocalDevProfile",
          "line": 228,
          "signature": "export interface LocalDevProfile {\n  /** The local developer's root identity. */\n  readonly root: ForgeDevIdentity;\n  /** The local organization context. */\n  readonly org: LocalOrg;\n  /** Registry of derived agent identities, keyed by agent name. */\n  readonly agents: Readonly<Record<string, ForgeDevIdentity>>;\n  /** The 16-character hex machine identifier. */\n  readonly machineId: string;\n  /** The profile name (e.g., \"default\", \"alice\"). */\n  readonly profileName: string;\n}",
          "documentation": "A local development profile providing identity and authorization\nwithout external services."
        },
        {
          "name": "export const PROFILE_SCHEMA_VERSION = 1;",
          "line": 242,
          "signature": "export const PROFILE_SCHEMA_VERSION /* type inferred in source */;",
          "documentation": "Current schema version for profile persistence."
        },
        {
          "name": "createLocalDevProfile",
          "line": 251,
          "signature": "export function createLocalDevProfile(\n  machineId: string,\n  profileName: string,\n): LocalDevProfile;",
          "documentation": "Creates a new local dev profile."
        },
        {
          "name": "deriveAgent",
          "line": 282,
          "signature": "export function deriveAgent(\n  profile: LocalDevProfile,\n  agentName: string,\n): LocalDevProfile;",
          "documentation": "Derives an agent identity within a local dev profile."
        },
        {
          "name": "profileToJSON",
          "line": 313,
          "signature": "export function profileToJSON(\n  profile: LocalDevProfile,\n): Record<string, unknown>;",
          "documentation": "Serializes a profile to a JSON-compatible object for persistence."
        },
        {
          "name": "profileFromJSON",
          "line": 352,
          "signature": "export function profileFromJSON(\n  data: Record<string, unknown>,\n): LocalDevProfile;",
          "documentation": "Deserializes a profile from a JSON-compatible object."
        }
      ]
    },
    {
      "path": "forge-ts/packages/forge-identity/src/persistence.ts",
      "sha256": "dd3d9ba2a3e09fa3e5f0abb6c22a7f6e78d1dd094021b4e23fcb756a70dc6797",
      "artifactSha256": "37ae3752f9ef7eb3f241c549e39e53643dd2ffe3ad3e768a2b0338d7217183e7",
      "url": "/reference/source/forge-ts/packages/forge-identity/src/persistence.ts.txt",
      "declarations": [
        {
          "name": "ProtectedSigningKey",
          "line": 28,
          "signature": "export interface ProtectedSigningKey {\n  /** Protection scheme identifier (for example `aws-kms-envelope`). */\n  scheme: string;\n  /** Opaque serialized payload for the selected scheme. */\n  payload: string;\n  /** Optional key reference for KMS or secure-store lookups. */\n  keyId?: string;\n}",
          "documentation": "Protected key payload returned by a production key protector.\n\nThe payload shape is intentionally minimal so SDK consumers can back it\nwith a KMS envelope, HSM reference, platform keychain entry, or another\napproved secure storage mechanism."
        },
        {
          "name": "IdentityKeyProtector",
          "line": 40,
          "signature": "export interface IdentityKeyProtector {\n  /**\n   * Protects a signing key before persistence.\n   *\n   * Implementations should encrypt, seal, or securely externalize the key.\n   */\n  protect(signingKey: Uint8Array): Promise<ProtectedSigningKey>;\n  /**\n   * Restores a protected signing key from persisted storage.\n   *\n   * Implementations must return the raw Ed25519 signing key bytes.\n   */\n  unprotect(protectedSigningKey: ProtectedSigningKey): Promise<Uint8Array>;\n}",
          "documentation": "Contract for protecting and restoring signing keys during persistence."
        },
        {
          "name": "saveIdentity",
          "line": 87,
          "signature": "export async function saveIdentity(\n  identity: ForgeAgentIdentity,\n  protector?: IdentityKeyProtector\n): Promise<string>;",
          "documentation": "Serializes an agent identity to a JSON string.\n\nThe identity is serialized as a PersistedIdentity containing the DID,\nkind, protected signing key payload, public key (hex-encoded), full\ndocument JSON, and lineage depth."
        },
        {
          "name": "loadIdentity",
          "line": 134,
          "signature": "export async function loadIdentity(\n  json: string,\n  protector?: IdentityKeyProtector,\n  bridge?: CryptoBridge\n): Promise<ForgeAgentIdentity>;",
          "documentation": "Deserializes an agent identity from a JSON string.\n\nReads and deserializes a PersistedIdentity, reconstructs the keypair\nfrom the stored key bytes, parses the OAS document, and returns a\nfully functional ForgeAgentIdentity."
        }
      ]
    }
  ]
}
