[AVAILABLE] for credential isolation, wired into the default server.
Purpose
Authenticates a calling gateway, issues single-use session credentials, and routes a verified release to a connector, auditing every step. See Credential isolation and Gateway attestation for the concepts.Install
Not published to npm. This is an internal package of this repository, used from a clone of it:npm ci at the repository root links every workspace package. The packages published to npm are @parmana/sdk, @parmana/connector-sdk and @parmana/sign.
Key exports: the wired credential-isolation path
Signed caller-capability check.
DefaultConnectorPolicy.assertAllowed()
checks the connector’s own declared capabilities and three pre-verified
verifiedTransaction booleans, then — when the authorization’s
grantedCapability (see Execution
authorization) is present — additionally
requires it to equal the action actually being executed, before the
connector’s credential is ever resolved. This is defense-in-depth, not a
second signature re-verification: ExecutionGateway already independently
re-verifies the authorization’s signature before the one production call site
that reaches this check is ever invoked. Its value is against a future code
path that might reach assertAllowed() without going through that
already-verified route — see docs/CLAIMS.md §2.31 for the full,
honestly-scoped writeup.Minimal example
Next
Issue and verify session credentials
Issue, consume, expire, reuse-reject, and revoke, run live.
@parmana/execution-gateway
The boundary that verifies an authorization before anything here runs.