Skip to main content
[AVAILABLE] for credential isolation, wired into the default server.

Purpose

Authenticates a calling gateway, issues single-use session credentials, and routes a verified release to a connector, auditing every step. See Credential isolation and Gateway attestation for the concepts.

Install

Not published to npm. This is an internal package of this repository, used from a clone of it: npm ci at the repository root links every workspace package. The packages published to npm are @parmana/sdk, @parmana/connector-sdk and @parmana/sign.

Key exports: the wired credential-isolation path

Signed caller-capability check. DefaultConnectorPolicy.assertAllowed() checks the connector’s own declared capabilities and three pre-verified verifiedTransaction booleans, then — when the authorization’s grantedCapability (see Execution authorization) is present — additionally requires it to equal the action actually being executed, before the connector’s credential is ever resolved. This is defense-in-depth, not a second signature re-verification: ExecutionGateway already independently re-verifies the authorization’s signature before the one production call site that reaches this check is ever invoked. Its value is against a future code path that might reach assertAllowed() without going through that already-verified route — see docs/CLAIMS.md §2.31 for the full, honestly-scoped writeup.

Minimal example

Full runnable version: Issue and verify session credentials.

Next

Issue and verify session credentials

Issue, consume, expire, reuse-reject, and revoke, run live.

@parmana/execution-gateway

The boundary that verifies an authorization before anything here runs.