Skip to main content
[AVAILABLE] for every export below. [ROADMAP] for KMS/HSM key custody, no provider class exists for it yet, see Deploy patterns.

Purpose

Every hash and signature in Parmana goes through this package: trust record hashing, authorization signing and verification, receipt signing, and canonical JSON serialization so the signing side and verifying side always compute byte-identical input.

Install

Not published to npm. This is an internal package of this repository, used from a clone of it: npm ci at the repository root links every workspace package. The packages published to npm are @parmana/sdk, @parmana/connector-sdk and @parmana/sign.

Key exports

Bootstrap, [AVAILABLE]

See Choose a signature provider for both, run live.

High-level services, [AVAILABLE]

Low-level primitives, [AVAILABLE]

Hybrid signing, [AVAILABLE]

Minimal example

For a check with zero disk/env-var dependency at all — the shape an actual third party holding only a record and a fetched public key needs — use verifyExecutionTrustRecordOffline instead:
A record over 4096 bytes of canonical content may have been signed by AWS KMS as a fixed 97 byte commitment, because KMS refuses a longer raw Ed25519 message. verifyExecutionTrustRecordOffline accepts a raw signature for any record and additionally accepts the commitment form for a record over that size. A commitment signature over a smaller record is rejected. The rule is specified in ADR-0010, docs/adr/ADR-0010-Large-Message-Signing-Under-KMS.md.
Full runnable version: Verify a trust record independently.

Next

Choose a signature provider

Ed25519, ML-DSA-65, and hybrid signing, all run live.

@parmana/envelope-verifier

Where AuthorizationVerifier’s check fits into the fuller envelope verification flow.