npm ci.
Auditors should continue with the Audit guide after step 2.
Requirements
- Node.js 24.6 or later. The hybrid Ed25519 and ML-DSA-65 signatures use
node:crypto, which supports ML-DSA from 24.6. - npm, as bundled with Node.js.
- Git, and Bash for two tests that syntax check shell scripts. On Windows, Git for Windows provides it.
- Docker, only for the optional offline check in step 4.
1. Install, build and test
npm run build comes first because tests import the workspace packages from their built
dist/ output; npm test refuses to run against stale output.
No .env is needed. The test setup uses the same local defaults as CI: the committed
./policies, in memory storage, and local Ed25519 keys generated for the run. Suites that
need live services (HubSpot, Supabase) skip. Expect about 2,880 passing tests and about 54
skipped.
2. Run every example
FAILED or ✗ on purpose: they show a forged, replayed or tampered request being refused.
The run ends with All Parmana examples completed successfully. and exit code 0.
To see the whole chain in one walkthrough (policy evaluation, signed authorization, envelope
verification, credential isolation, connector execution and the signed Trust Record):
npm run preflight runs everything a contributor runs before a change: typecheck, lint,
format check, the Python model check, every test, the build and every example.
3. Try the hosted sandbox (optional)
A public sandbox runs the same API with demo policies and a published demo approver key. Use the Playground, or the scripts in examples/sandbox-playground/ from cURL, PowerShell, TypeScript or Python. See Live API and demos.4. Run the full stack with no internet route (optional, Docker)
5. Verify a record without Parmana
Every approved action produces a signed Execution Trust Record. It can be checked with only the record and the public keys, using@parmana/sign (Apache 2.0,
a separate repository) or this repository’s scripts/verify-trust-record.ts: