[AVAILABLE] for every export below. [ROADMAP] for KMS/HSM key custody,
no provider class exists for it yet, see Deploy
patterns.
Purpose
Every hash and signature in Parmana goes through this package: trust record hashing, authorization signing and verification, receipt signing, and canonical JSON serialization so the signing side and verifying side always compute byte-identical input.Install
Not published to npm. This is an internal package of this repository, used from a clone of it:npm ci at the repository root links every workspace package. The packages published to npm are @parmana/sdk, @parmana/connector-sdk and @parmana/sign.
Key exports
Bootstrap, [AVAILABLE]
See Choose a signature provider for both, run live.
High-level services, [AVAILABLE]
Low-level primitives, [AVAILABLE]
Hybrid signing, [AVAILABLE]
Minimal example
verifyExecutionTrustRecordOffline instead:
A record over 4096 bytes of canonical content may have been signed by AWS KMS
as a fixed 97 byte commitment, because KMS refuses a longer raw Ed25519
message.
verifyExecutionTrustRecordOffline accepts a raw signature for any
record and additionally accepts the commitment form for a record over that
size. A commitment signature over a smaller record is rejected. The rule is
specified in ADR-0010, docs/adr/ADR-0010-Large-Message-Signing-Under-KMS.md.Next
Choose a signature provider
Ed25519, ML-DSA-65, and hybrid signing, all run live.
@parmana/envelope-verifier
Where
AuthorizationVerifier’s check fits into the fuller envelope
verification flow.