Skip to content

Add Agent Identity verifier SDK and examples - #415

Merged
raubrey-stripe merged 8 commits into
mainfrom
drapeau/agent-identity-sdk
Oct 7, 2026
Merged

raubrey-stripe merged 8 commits into
mainfrom
drapeau/agent-identity-sdk

Conversation

@drapeau-stripe

@drapeau-stripe drapeau-stripe commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Services receiving Link credentials need a verifier they can integrate alongside the wallet. Add @stripe/agent-identity to verify Link bearer attestations and holder-signed identity presentations, with ESM/CommonJS exports and Node 22+ support. Use Node built-ins and jose for byte and cryptography operations, retaining identity-specific validation and a small RSA key encoding adapter.

Includes issuer discovery and key caching, test fixtures, integration guides, and a runnable event-registration example: an attestation grants site access, and a verified-email presentation completes registration. The application owns sessions, interaction state, and replay policy. Guidance lives in READMEs and examples; no separate docs/ folder is added.

Validation:

  • 173 SDK tests and 22 HTTP example tests passed on Node 22 and 24, including independent Ed25519/P-256 signatures and malformed credentials. Typechecking, lint, and documentation checks passed.
  • Isolated package installation, ESM/CommonJS verification, and runnable examples passed on Node 22.0.0, current Node 22, and Node 24. CI checks the minimum supported runtime.
  • Built-wallet integration passed JSON issuance, private storage, pop, present, and event registration with session/retry behavior. Tests use a local synthetic issuer with real signatures.

r? @drapeau-stripe

-- Written by Codex

@drapeau-stripe drapeau-stripe self-assigned this Oct 6, 2026
Base automatically changed from drapeau/identity-namespaces to main October 7, 2026 14:23
Comment thread packages/agent-identity/src/__tests__/attestation-guidance.test.ts Dismissed
Comment thread packages/agent-identity/src/__tests__/attestation-guidance.test.ts Dismissed
Comment thread packages/agent-identity/src/__tests__/attestation-guidance.test.ts Dismissed
Comment thread packages/agent-identity/src/__tests__/attestation-guidance.test.ts Fixed
Comment thread packages/agent-identity/src/attestation.ts Fixed
Comment thread packages/agent-identity/src/internal/bytes.ts Fixed
Comment thread packages/agent-identity/src/issuer.ts Fixed
@drapeau-stripe
drapeau-stripe force-pushed the drapeau/agent-identity-sdk branch from cc4b489 to c0881d6 Compare October 7, 2026 16:38
@drapeau-stripe
drapeau-stripe marked this pull request as ready for review October 7, 2026 16:39
@drapeau-stripe
drapeau-stripe requested a review from a team as a code owner October 7, 2026 16:39
drapeau-stripe and others added 8 commits October 7, 2026 12:49
Give services a verifier for Link bearer attestations and selectively disclosed identity claims alongside the wallet. Keep application authorization and replay state separate from credential verification, and preserve independent ESM and CommonJS package exports.

Include executable examples, consumer guidance, and CI coverage for package installation and the complete wallet-to-verifier flow.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
* use base tsconfig and update license

* restructure test paths

* more test cleanup
Reject oversized credentials before parsing and replace backtracking suffix and auth-parameter parsing with linear scans. Invalid issuer and holder JWT shapes must return verification failures so malformed inputs cannot crash HTTP integrations.

Add parsing and HTTP recovery regressions, document input limits, and update the package development commands.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Compare complete expected error messages so the tests verify the documentation URL and recovery guidance without URL substring assertions that CodeQL mistakes for security validation.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Keep the original tests while evaluating CodeQL alert triage separately.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Avoid a statement-separating semicolon in the note and use a non-reserved participant identifier for Link. Validate the diagram with Mermaid's parser.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
Delegate byte encoding, hashing, RSA key validation and signature verification to Node, and JOSE operations to jose. Retain strict input and key-parameter checks and the SPKI adapter needed to preserve the public CryptoKey type.

Keep CommonJS consumers working on Node 22.0 through dynamic jose imports, and exercise the minimum runtime in CI. Add independent native-signature coverage for both supported credential algorithms and preserve the existing SDK and wallet integration tests.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
The identity command gate was removed in #377. Keep setup instructions and recovery guidance accurate after rebasing, and describe the verifier dependency choices consistently.

Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>
@drapeau-stripe
drapeau-stripe force-pushed the drapeau/agent-identity-sdk branch from 111d7ce to 662e171 Compare October 7, 2026 19:51
@raubrey-stripe
raubrey-stripe merged commit 985e8d9 into main Oct 7, 2026
12 checks passed
@raubrey-stripe
raubrey-stripe deleted the drapeau/agent-identity-sdk branch October 7, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants