Skip to content

TypeScript: @dnsid-ai/protocol — classes

Part of Protocol core (@dnsid-ai/protocol).

Defined in: packages/protocol/src/errors.ts:109

Thrown when a caller passes an invalid or unusable argument to a DNSid API.

  • Error

new ArgumentError(message): ArgumentError;

Defined in: packages/protocol/src/errors.ts:110

string

ArgumentError

Error.constructor

optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24

Error.cause

message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075

Error.message

name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074

Error.name

optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Error.stack

static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Error.stackTraceLimit

static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();

object

Function

void

Error.captureStackTrace

static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:55

Error

CallSite[]

any

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Error.prepareStackTrace

Defined in: packages/protocol/src/txt-record.ts:21

new DnsIdTxtRecord(): DnsIdTxtRecord;

DnsIdTxtRecord

agentFQDN: string = '';

Defined in: packages/protocol/src/txt-record.ts:33

optional cu?: string;

Defined in: packages/protocol/src/txt-record.ts:31

ek: string = '';

Defined in: packages/protocol/src/txt-record.ts:24

optional fl?: string;

Defined in: packages/protocol/src/txt-record.ts:29

gi: string = '';

Defined in: packages/protocol/src/txt-record.ts:23

optional ka?: string;

Defined in: packages/protocol/src/txt-record.ts:30

ku: string = '';

Defined in: packages/protocol/src/txt-record.ts:25

lr: string = '';

Defined in: packages/protocol/src/txt-record.ts:26

sg: string = '';

Defined in: packages/protocol/src/txt-record.ts:28

su: string = '';

Defined in: packages/protocol/src/txt-record.ts:27

unknownTags: Map<string, string>;

Defined in: packages/protocol/src/txt-record.ts:32

v: string = '';

Defined in: packages/protocol/src/txt-record.ts:22

get isDnsid1(): boolean;

Defined in: packages/protocol/src/txt-record.ts:49

boolean

get isTwoKey(): boolean;

Defined in: packages/protocol/src/txt-record.ts:50

boolean

get usesEntityKey(): boolean;

Defined in: packages/protocol/src/txt-record.ts:51

boolean

canonical(): string;

Defined in: packages/protocol/src/txt-record.ts:135

string

governanceId(): string;

Defined in: packages/protocol/src/txt-record.ts:54

Profile-selected accountable-entity identifier for relationship and acceptance checks; draft 01 uses gi as signed.

string

hasStructuralGovernanceRelationship(): boolean;

Defined in: packages/protocol/src/txt-record.ts:65

Whether the agent FQDN is equal to or beneath the accountable entity’s governance domain. A false result is valid only for delegated identities, whose relationship MUST be established by verified ISSUANCE evidence.

boolean

knownTagsCanonical(): string;

Defined in: packages/protocol/src/txt-record.ts:139

string

policyFlags(): Set<string>;

Defined in: packages/protocol/src/txt-record.ts:172

Set<string>

runtimeKeyAllowedHost(): string;

Defined in: packages/protocol/src/txt-record.ts:58

string

runtimeKeyURI(): string;

Defined in: packages/protocol/src/txt-record.ts:57

string

serialize(): string;

Defined in: packages/protocol/src/txt-record.ts:157

string

signatureVerificationKeyAllowedHost(): string;

Defined in: packages/protocol/src/txt-record.ts:56

string

signatureVerificationKeyURI(): string;

Defined in: packages/protocol/src/txt-record.ts:55

string

validate(): void;

Defined in: packages/protocol/src/txt-record.ts:120

void

static parse(raw): DnsIdTxtRecord;

Defined in: packages/protocol/src/txt-record.ts:35

string

DnsIdTxtRecord

static parseUnsignedCanonical(raw, agentFQDN?): DnsIdTxtRecord;

Defined in: packages/protocol/src/txt-record.ts:39

string

string

DnsIdTxtRecord


Defined in: packages/protocol/src/verified-domain.ts:116

The full verified event history for a domain, loaded from the lifecycle log.

new DomainLog(domain, events): DomainLog;

Defined in: packages/protocol/src/verified-domain.ts:120

string

LogEvent[]

DomainLog

readonly domain: string;

Defined in: packages/protocol/src/verified-domain.ts:117

readonly events: LogEvent[];

Defined in: packages/protocol/src/verified-domain.ts:118

snapshotAt(at): DomainSnapshot;

Defined in: packages/protocol/src/verified-domain.ts:130

Materializes the domain state at a specific point in time. Pure computation — no I/O.

Date

DomainSnapshot

VerificationError if no events exist at or before at, or no ISSUANCE event found.


Defined in: packages/protocol/src/verified-domain.ts:305

The materialized state of a domain at a specific point in time.

new DomainSnapshot(fields): DomainSnapshot;

Defined in: packages/protocol/src/verified-domain.ts:316

DnsIdJWK

string

string

LogEvent[]

string

AgentStatusState

Date

Date

DomainSnapshot

readonly activeKey: DnsIdJWK;

Defined in: packages/protocol/src/verified-domain.ts:309

readonly activeKeyThumbprint: string;

Defined in: packages/protocol/src/verified-domain.ts:310

readonly domain: string;

Defined in: packages/protocol/src/verified-domain.ts:306

readonly events: LogEvent[];

Defined in: packages/protocol/src/verified-domain.ts:314

readonly governanceId: string;

Defined in: packages/protocol/src/verified-domain.ts:312

readonly historicalState: AgentStatusState;

Defined in: packages/protocol/src/verified-domain.ts:308

Lifecycle state materialized from the verified log history at snapshotAt.

readonly keyBoundAt: Date;

Defined in: packages/protocol/src/verified-domain.ts:311

readonly snapshotAt: Date;

Defined in: packages/protocol/src/verified-domain.ts:313


Defined in: packages/protocol/src/identity-manager.ts:312

Core DNSid protocol facade.

This package-local version intentionally exposes only DNSid protocol-core methods. JWT/JWS, HTTP Message Signatures, transport, registry workflows, and concrete key storage live in sibling packages.

new IdentityManager(config?, deps?): IdentityManager;

Defined in: packages/protocol/src/identity-manager.ts:332

DnsidConfig = {}

Data-only configuration; omit identity for a verification-only manager.

IdentityManagerDependencies = {}

Injected runtime objects. The protocol core has no default DNS/HTTPS implementations, so config.transport settings have no consumer here and are rejected; runtime factories (for example @dnsid-ai/sdk/node) consume them before delegating.

IdentityManager

readonly config: DnsidConfig & object;

Defined in: packages/protocol/src/identity-manager.ts:314

Validated immutable snapshot. identity is absent for verification-only managers.

transport: TransportConfig;
verification: VerificationConfig;

canonicalizeLogEvent(event): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: packages/protocol/src/identity-manager.ts:394

LogEvent

Promise<Uint8Array<ArrayBufferLike>>

createTxtRecord(): Promise<string>;

Defined in: packages/protocol/src/identity-manager.ts:539

Builds and signs the _dnsid TXT record for DNS publication.

Promise<string>

evictDomain(domain): void;

Defined in: packages/protocol/src/identity-manager.ts:1051

Removes a domain from the IdentityManager cache.

string

void

getEntityKeySet(): Promise<JWKS>;

Defined in: packages/protocol/src/identity-manager.ts:501

Returns the accountable-entity public key set for ek JWKS publication.

Promise<JWKS>

getKeyProvider(): KeyProvider;

Defined in: packages/protocol/src/identity-manager.ts:372

KeyProvider

getKeySet(): Promise<JWKS>;

Defined in: packages/protocol/src/identity-manager.ts:494

Returns the local identity’s operational public key set for ku JWKS publication.

Promise<JWKS>

loadDomainLog(vd): Promise<DomainLog>;

Defined in: packages/protocol/src/identity-manager.ts:1037

Loads the full verified event history for a domain from its bound lifecycle log.

VerifiedDomain

Promise<DomainLog>

requiredLogSignatures(event): LogSignerRole[];

Defined in: packages/protocol/src/identity-manager.ts:399

LogEvent

LogSignerRole[]

rotateOperationalKey(options): Promise<OperationalKeyRotationResult>;

Defined in: packages/protocol/src/identity-manager.ts:509

Runs the draft-01 operational-key rotation transaction.

OperationalKeyRotationOptions

Promise<OperationalKeyRotationResult>

signAndWriteEvent(event): Promise<string>;

Defined in: packages/protocol/src/identity-manager.ts:387

Signs and appends a lifecycle event to the local identity log.

LogEvent

Promise<string>

signEvent(event, role): Promise<LogEvent>;

Defined in: packages/protocol/src/identity-manager.ts:412

LogEvent

LogSignerRole

Promise<LogEvent>

signEventWithProvider(
event,
role,
keyProvider,
logBinding?
): Promise<LogEvent>;

Defined in: packages/protocol/src/identity-manager.ts:422

LogEvent

LogSignerRole

KeyProvider

Pick<LogReader, "canonical"> & object | null

Promise<LogEvent>

verifyDomain(
domain,
peerCert?,
options?
): Promise<VerifiedDomain>;

Defined in: packages/protocol/src/identity-manager.ts:590

Verifies a DNSid identity according to the protocol, then enforces configured trustedEntities acceptance. Acceptance runs per invocation, including cache hits, and is never cached; a denial leaves valid protocol evidence cached.

string

TLSCertificate

VerificationOptions = {}

Promise<VerifiedDomain>

IdentityResolver.verifyDomain

writeSignedEvent(event): Promise<string>;

Defined in: packages/protocol/src/identity-manager.ts:467

LogEvent

Promise<string>


Defined in: packages/protocol/src/identity-cache.ts:29

Default in-memory cache implementation.

new InMemoryIdentityCache(): InMemoryIdentityCache;

InMemoryIdentityCache

evict(domain): void;

Defined in: packages/protocol/src/identity-cache.ts:54

Removes a domain from the cache immediately.

string

void

IdentityCache.evict

get(domain): VerifiedDomain | null;

Defined in: packages/protocol/src/identity-cache.ts:32

Returns the cached VerifiedDomain for a domain, or null if not cached or expired.

string

VerifiedDomain | null

IdentityCache.get

put(domain, result): void;

Defined in: packages/protocol/src/identity-cache.ts:42

Stores a verified domain result. Entry expires at result.expiry().

string

VerifiedDomain

void

IdentityCache.put


Defined in: packages/protocol/src/jwks.ts:100

Wrapper around a JWK Set document.

new JWKS(keys): JWKS;

Defined in: packages/protocol/src/jwks.ts:103

DnsIdJWK[]

JWKS

readonly keys: DnsIdJWK[];

Defined in: packages/protocol/src/jwks.ts:101

currentOperationalSigningKey(): DnsIdJWK;

Defined in: packages/protocol/src/jwks.ts:174

DnsIdJWK

currentRecordSigningKey(): DnsIdJWK;

Defined in: packages/protocol/src/jwks.ts:170

DnsIdJWK

draft01RecordSigningKeyById(kid): DnsIdJWK | null;

Defined in: packages/protocol/src/jwks.ts:136

Returns the draft-01-compatible record-signing key matching kid, or null if none.

string

DnsIdJWK | null

keyById(kid): DnsIdJWK | null;

Defined in: packages/protocol/src/jwks.ts:131

Returns the key matching the given kid, or null if not found.

string

DnsIdJWK | null

signingKeys(): DnsIdJWK[];

Defined in: packages/protocol/src/jwks.ts:112

Returns all keys suitable for signature verification. A key qualifies if use is absent/sig and it has a supported signature algorithm binding.

DnsIdJWK[]

ValidationError if no signing keys are present.

toJSON(): object;

Defined in: packages/protocol/src/jwks.ts:207

Returns the JWKS as a plain JSON-serializable object.

object

keys: DnsIdJWK[];

validate(): void;

Defined in: packages/protocol/src/jwks.ts:147

Validates the key set.

void

ValidationError if:

  • no signing key has a kid field
  • any present alg field is inconsistent with the key’s kty/crv binding
  • no key is suitable for signing

validateOperational(): void;

Defined in: packages/protocol/src/jwks.ts:190

void

validateRecordSigning(): void;

Defined in: packages/protocol/src/jwks.ts:178

void

validateRecordSigningKeyset(): Promise<void>;

Defined in: packages/protocol/src/jwks.ts:184

Validates the single current draft-01 ek key and its importable public material.

Promise<void>


Defined in: packages/protocol/src/log-registry.ts:15

Single injection point for all log interaction. Holds one factory per log method.

new LogRegistry(): LogRegistry;

LogRegistry

newReader(lr, options?): LogReader;

Defined in: packages/protocol/src/log-registry.ts:41

Creates a LogReader bound to the given lr string. Returns a NoopLogReader if no factory is registered for the method.

string

AbortSignal

LogReader

ParseError if lr is malformed (no colon, empty method, or method violates pattern).

register(method, factory): void;

Defined in: packages/protocol/src/log-registry.ts:29

Registers a factory for the given method name (e.g. “algorand”, “ctlog”, “scitt”).

string

LogReaderFactory

void

ArgumentError if method does not match [a-z][a-z0-9-]*

snapshot(): LogRegistry;

Defined in: packages/protocol/src/log-registry.ts:19

Copies method selection for an immutable manager verification context.

LogRegistry


Defined in: packages/protocol/src/log-registry.ts:63

Returned by LogRegistry.newReader when no factory is registered for the method. Every method raises VerificationError{code: LogError}.

new NoopLogReader(method): NoopLogReader;

Defined in: packages/protocol/src/log-registry.ts:66

string

NoopLogReader

canonical(_event): Promise<Uint8Array<ArrayBufferLike>>;

Defined in: packages/protocol/src/log-registry.ts:77

Returns the canonical byte representation of the event for this log method. Used to verify the signatures required by the log method on events read from the log. MUST produce identical output to Log.canonical for the same supported event.

LogEvent

Promise<Uint8Array<ArrayBufferLike>>

LogReader.canonical

keyTimestamp(_domain, _keyThumbprint): Promise<Date>;

Defined in: packages/protocol/src/log-registry.ts:78

Returns the timestamp at which the given key thumbprint was bound to the domain (ISSUANCE or KEY_ROTATION event). Used for ka validation.

string

string

Promise<Date>

LogReader.keyTimestamp

readEvent(_ref): Promise<LogEvent>;

Defined in: packages/protocol/src/log-registry.ts:82

Reads a single event by its log reference. MUST verify inclusion proof and timestamp proof before returning.

string

Promise<LogEvent>

LogReader.readEvent

rebuildHistory(_domain): Promise<LogEvent[]>;

Defined in: packages/protocol/src/log-registry.ts:83

Rebuilds the full event history for the domain in authoritative log order. MUST verify inclusion proofs, timestamp proofs, append-only consistency, and required lifecycle signatures on every returned event. Event signature verification MUST use the public keys valid for that event in the reconstructed lifecycle history. Events with invalid signatures MUST NOT be returned.

string

Promise<LogEvent[]>

LogReader.rebuildHistory

verifyBilateralBinding(
_record,
_entityKey,
_operationalKey
): Promise<{
initialEntityThumbprint: string;
initialOperationalThumbprint: string;
timestamp: Date;
}>;

Defined in: packages/protocol/src/log-registry.ts:79

Verifies draft-01 bilateral ISSUANCE binding for the current TXT record.

unknown

unknown

unknown

Promise<{ initialEntityThumbprint: string; initialOperationalThumbprint: string; timestamp: Date; }>

LogReader.verifyBilateralBinding

verifyNonRevocation(_domain, _at): Promise<LoggedStateEvidence>;

Defined in: packages/protocol/src/log-registry.ts:81

Verifies that the domain is neither REVOKED nor RETIRED at the given timestamp. Raises on a terminal state or if complete, fresh evidence cannot be established. Returns the accepted proof boundary.

string

Date

Promise<LoggedStateEvidence>

LogReader.verifyNonRevocation

verifyOperationalContinuity(
_domain,
_initialOperationalThumbprint,
_currentOperationalThumbprint
): Promise<void>;

Defined in: packages/protocol/src/log-registry.ts:80

Verifies KEY_ROTATION continuity from ISSUANCE to the current operational key.

string

string

string

Promise<void>

LogReader.verifyOperationalContinuity


Defined in: packages/protocol/src/errors.ts:43

Thrown when raw input (e.g. a TXT record or duration string) cannot be parsed into its structured form.

  • Error

new ParseError(message): ParseError;

Defined in: packages/protocol/src/errors.ts:44

string

ParseError

Error.constructor

optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24

Error.cause

message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075

Error.message

name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074

Error.name

optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Error.stack

static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Error.stackTraceLimit

static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();

object

Function

void

Error.captureStackTrace

static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:55

Error

CallSite[]

any

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Error.prepareStackTrace

Defined in: packages/protocol/src/errors.ts:51

Thrown when parsed data is structurally sound but violates a DNSid protocol constraint.

  • Error

new ValidationError(message): ValidationError;

Defined in: packages/protocol/src/errors.ts:52

string

ValidationError

Error.constructor

optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24

Error.cause

message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075

Error.message

name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074

Error.name

optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Error.stack

static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Error.stackTraceLimit

static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();

object

Function

void

Error.captureStackTrace

static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:55

Error

CallSite[]

any

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Error.prepareStackTrace

Defined in: packages/protocol/src/errors.ts:82

Thrown when DNSid identity verification fails.

Carries a VerificationCode for programmatic handling and a transient flag indicating whether a retry may succeed (see retryTransientVerification).

  • Error

new VerificationError(message, init): VerificationError;

Defined in: packages/protocol/src/errors.ts:96

string

VerificationErrorInit

VerificationError

Error.constructor

readonly optional agentState?: string;

Defined in: packages/protocol/src/errors.ts:88

Agent state reported by the status document, when the failure is state-related.

optional cause?: unknown;

Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24

Error.cause

readonly code: VerificationCode;

Defined in: packages/protocol/src/errors.ts:84

Classification of the failure.

readonly optional errorCategory?: LifecycleErrorCategory;

Defined in: packages/protocol/src/errors.ts:90

Lifecycle conformance category, when the failure maps to a lifecycle state-machine rule.

message: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075

Error.message

name: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074

Error.name

optional stack?: string;

Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076

Error.stack

readonly transient: boolean;

Defined in: packages/protocol/src/errors.ts:86

True when retrying the verification may succeed.

readonly optional verifiedEntityKeyThumbprint?: string;

Defined in: packages/protocol/src/errors.ts:94

Observed verified record-signing key thumbprint (CounterpartyNotAccepted only). Never echoes configured pins.

readonly optional verifiedGovernanceId?: string;

Defined in: packages/protocol/src/errors.ts:92

Observed verified governance ID (CounterpartyNotAccepted only). Never echoes configured policy.

static stackTraceLimit: number;

Defined in: node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

Error.stackTraceLimit

static captureStackTrace(targetObject, constructorOpt?): void;

Defined in: node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();

object

Function

void

Error.captureStackTrace

static prepareStackTrace(err, stackTraces): any;

Defined in: node_modules/@types/node/globals.d.ts:55

Error

CallSite[]

any

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Error.prepareStackTrace

Defined in: packages/protocol/src/verified-domain.ts:12

Result of a successful verifyDomain call. Contains all verified data for the domain.

new VerifiedDomain(fields): VerifiedDomain;

Defined in: packages/protocol/src/verified-domain.ts:31

Date

DNSSECState

number

string

JWKS

Date

Date

LogReader

DnsIdTxtRecord

JWKS

TLSCertificate

AgentStatus

DnsIdJWK

string

TLSCertificate

Date

VerifiedDomain

readonly dnsExpiresAt: Date;

Defined in: packages/protocol/src/verified-domain.ts:25

readonly dnssecState: DNSSECState;

Defined in: packages/protocol/src/verified-domain.ts:28

readonly dnsTTL: number;

Defined in: packages/protocol/src/verified-domain.ts:24

readonly domain: string;

Defined in: packages/protocol/src/verified-domain.ts:13

readonly jwks: JWKS;

Defined in: packages/protocol/src/verified-domain.ts:15

readonly keyBoundAt: Date;

Defined in: packages/protocol/src/verified-domain.ts:26

lastStatusCheckAt: Date;

Defined in: packages/protocol/src/verified-domain.ts:27

readonly logReader: LogReader;

Defined in: packages/protocol/src/verified-domain.ts:29

readonly record: DnsIdTxtRecord;

Defined in: packages/protocol/src/verified-domain.ts:14

readonly recordSigningJwks: JWKS;

Defined in: packages/protocol/src/verified-domain.ts:16

readonly recordSigningTlsCert: TLSCertificate;

Defined in: packages/protocol/src/verified-domain.ts:21

registryStatus: AgentStatus;

Defined in: packages/protocol/src/verified-domain.ts:22

readonly signingKey: DnsIdJWK;

Defined in: packages/protocol/src/verified-domain.ts:17

readonly signingKeyThumbprint: string;

Defined in: packages/protocol/src/verified-domain.ts:19

RFC 7638 SHA-256 thumbprint of signingKey, computed once at verification and reused by acceptance checks.

readonly tlsCert: TLSCertificate;

Defined in: packages/protocol/src/verified-domain.ts:20

readonly verifiedAt: Date;

Defined in: packages/protocol/src/verified-domain.ts:23

cachedState(): AgentStatusState;

Defined in: packages/protocol/src/verified-domain.ts:71

Returns the agent state from the most recent su fetch. Reflects the state at lastStatusCheckAt, not necessarily right now.

AgentStatusState

expiry(): Date;

Defined in: packages/protocol/src/verified-domain.ts:94

Returns the earliest time at which this verified result should be considered stale. Candidates: DNS TTL, TLS cert NotAfter, key age bound (ka).

Date

requiresLogCheck(): boolean;

Defined in: packages/protocol/src/verified-domain.ts:76

Whether the record requests a current log check for high-value operations.

boolean

verifyNonRevocation(at?): Promise<LoggedStateEvidence>;

Defined in: packages/protocol/src/verified-domain.ts:86

Performs the authoritative lifecycle-log non-revocation check used for a high-value or irreversible operation. Callers decide which operations are high value; local policy may also require this check when fl=logchk is absent. Log unavailability and stale evidence fail closed.

Date = ...

Promise<LoggedStateEvidence>