Docs · integrationSource-available · verify path

From an assertion to a verified mandate in one call.

The examples below use the real surface of @flashyid/sdk — the verify path (verifyAssertion, authorize) and the grant kernel, source-available in the flashyid repo. An npm release is pending; roadmap APIs live on the spec.

Path A

Issue authority

You run agents. Mint a grant beneath your own, hand it to an agent, and let it present an assertion elsewhere.

issue.ts
import { issueRoot, attenuate } from '@flashyid/sdk'

// Pure functions — no network, no key. The root is issued from the
// accountable human named in your charter; children only narrow.
const root = issueRoot({ rootHuman, holder: 'org:flashy-academy', scp, res, lim, iat, exp, jti })

const grant = attenuate(root, {
  holder: 'agent:ceo-agent',
  scp:    ['proposal.draft'],
  lim:    { spend_max: 5000 },
  iat, exp, jti
})
Path B · the one every vendor buries

Verify authority

Someone else’s agent is talking to you. You hold no Flashy credential and need none — the key is public.

verify.ts
import { authorize } from '@flashyid/sdk'

// One call: verify the assertion, then verify its delegation permits this.
const out = await authorize(jws, { scope: 'payment.execute', amount: 1240 }, {
  issuer:   'https://id.flashyid.com',
  audience: clientId, nowSec
})

out              // null → 401 (assertion not genuine)
out.result.ok    // true
out.result.scp   // ['payment.execute']
out.result.code  // on refusal: 'expired' | 'revoked' | 'out_of_mandate'

Quickstart · verify a counterparty in four steps

No account, no key, no contact with us. Every step below runs against the public surface.

STEP 01

Add the SDK

The verify path is source-available in the flashyid repo (src/sdk); an npm release is coming. No account, no key.

// @flashyid/sdk — verifyAssertion, authorize
STEP 02

Point at the issuer

The public JWKS at id.flashyid.com is cacheable for an hour — the SDK fetches and caches it for you.

const opts = { issuer: 'https://id.flashyid.com', audience: yourClientId }
STEP 03

Verify + authorize

One call verifies the assertion and checks the delegation it carries against what the action needs.

await authorize(token, { scope: 'payment.execute', amount }, { ...opts, nowSec })
STEP 04

Read the result

On success you get the effective grant; on refusal a specific code (out_of_mandate, expired, revoked, chain_widened) — the code tells you what to do.

result.ok ? result.scp : result.code
Source surface · src/sdk
✓ verifyAssertion()✓ authorize()✓ issueRoot()✓ attenuate()✓ verifyChain()✓ permits()✓ grantFromCharterRole()

This list is the real export surface of src/sdk, and a test asserts it matches the package’s exports — a method that drifts from the code fails the build before it reaches a reader.