TypeScript: @dnsid-ai/protocol — classes
Part of Protocol core (@dnsid-ai/protocol).
Classes
Section titled “Classes”ArgumentError
Section titled “ArgumentError”Defined in: packages/protocol/src/errors.ts:109
Thrown when a caller passes an invalid or unusable argument to a DNSid API.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new ArgumentError(message): ArgumentError;Defined in: packages/protocol/src/errors.ts:110
Parameters
Section titled “Parameters”message
Section titled “message”string
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructorProperties
Section titled “Properties”cause?
Section titled “cause?”optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24
Inherited from
Section titled “Inherited from”Error.causemessage
Section titled “message”message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075
Inherited from
Section titled “Inherited from”Error.messagename: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074
Inherited from
Section titled “Inherited from”Error.namestack?
Section titled “stack?”optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Section titled “Inherited from”Error.stackstackTraceLimit
Section titled “stackTraceLimit”static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:67
The Error.stackTraceLimit property specifies the number of stack frames
collected by a stack trace (whether generated by new Error().stack or
Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes
will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Section titled “Inherited from”Error.stackTraceLimitMethods
Section titled “Methods”captureStackTrace()
Section titled “captureStackTrace()”static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:51
Creates a .stack property on targetObject, which when accessed returns
a string representing the location in the code at which
Error.captureStackTrace() was called.
const myObject = {};Error.captureStackTrace(myObject);myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with
${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames
above constructorOpt, including constructorOpt, will be omitted from the
generated stack trace.
The constructorOpt argument is useful for hiding implementation
details of error generation from the user. For instance:
function a() { b();}
function b() { c();}
function c() { // Create an error without stack trace to avoid calculating the stack trace twice. const { stackTraceLimit } = Error; Error.stackTraceLimit = 0; const error = new Error(); Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace throw error;}
a();Parameters
Section titled “Parameters”targetObject
Section titled “targetObject”object
constructorOpt?
Section titled “constructorOpt?”Function
Returns
Section titled “Returns”void
Inherited from
Section titled “Inherited from”Error.captureStackTraceprepareStackTrace()
Section titled “prepareStackTrace()”static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:55
Parameters
Section titled “Parameters”Error
stackTraces
Section titled “stackTraces”CallSite[]
Returns
Section titled “Returns”any
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Section titled “Inherited from”Error.prepareStackTraceDnsIdTxtRecord
Section titled “DnsIdTxtRecord”Defined in: packages/protocol/src/txt-record.ts:21
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new DnsIdTxtRecord(): DnsIdTxtRecord;Returns
Section titled “Returns”Properties
Section titled “Properties”agentFQDN
Section titled “agentFQDN”agentFQDN: string = '';Defined in: packages/protocol/src/txt-record.ts:33
optional cu?: string;Defined in: packages/protocol/src/txt-record.ts:31
ek: string = '';Defined in: packages/protocol/src/txt-record.ts:24
optional fl?: string;Defined in: packages/protocol/src/txt-record.ts:29
gi: string = '';Defined in: packages/protocol/src/txt-record.ts:23
optional ka?: string;Defined in: packages/protocol/src/txt-record.ts:30
ku: string = '';Defined in: packages/protocol/src/txt-record.ts:25
lr: string = '';Defined in: packages/protocol/src/txt-record.ts:26
sg: string = '';Defined in: packages/protocol/src/txt-record.ts:28
su: string = '';Defined in: packages/protocol/src/txt-record.ts:27
unknownTags
Section titled “unknownTags”unknownTags: Map<string, string>;Defined in: packages/protocol/src/txt-record.ts:32
v: string = '';Defined in: packages/protocol/src/txt-record.ts:22
Accessors
Section titled “Accessors”isDnsid1
Section titled “isDnsid1”Get Signature
Section titled “Get Signature”get isDnsid1(): boolean;Defined in: packages/protocol/src/txt-record.ts:49
Returns
Section titled “Returns”boolean
isTwoKey
Section titled “isTwoKey”Get Signature
Section titled “Get Signature”get isTwoKey(): boolean;Defined in: packages/protocol/src/txt-record.ts:50
Returns
Section titled “Returns”boolean
usesEntityKey
Section titled “usesEntityKey”Get Signature
Section titled “Get Signature”get usesEntityKey(): boolean;Defined in: packages/protocol/src/txt-record.ts:51
Returns
Section titled “Returns”boolean
Methods
Section titled “Methods”canonical()
Section titled “canonical()”canonical(): string;Defined in: packages/protocol/src/txt-record.ts:135
Returns
Section titled “Returns”string
governanceId()
Section titled “governanceId()”governanceId(): string;Defined in: packages/protocol/src/txt-record.ts:54
Profile-selected accountable-entity identifier for relationship and acceptance checks; draft 01 uses gi as signed.
Returns
Section titled “Returns”string
hasStructuralGovernanceRelationship()
Section titled “hasStructuralGovernanceRelationship()”hasStructuralGovernanceRelationship(): boolean;Defined in: packages/protocol/src/txt-record.ts:65
Whether the agent FQDN is equal to or beneath the accountable entity’s governance domain. A false result is valid only for delegated identities, whose relationship MUST be established by verified ISSUANCE evidence.
Returns
Section titled “Returns”boolean
knownTagsCanonical()
Section titled “knownTagsCanonical()”knownTagsCanonical(): string;Defined in: packages/protocol/src/txt-record.ts:139
Returns
Section titled “Returns”string
policyFlags()
Section titled “policyFlags()”policyFlags(): Set<string>;Defined in: packages/protocol/src/txt-record.ts:172
Returns
Section titled “Returns”Set<string>
runtimeKeyAllowedHost()
Section titled “runtimeKeyAllowedHost()”runtimeKeyAllowedHost(): string;Defined in: packages/protocol/src/txt-record.ts:58
Returns
Section titled “Returns”string
runtimeKeyURI()
Section titled “runtimeKeyURI()”runtimeKeyURI(): string;Defined in: packages/protocol/src/txt-record.ts:57
Returns
Section titled “Returns”string
serialize()
Section titled “serialize()”serialize(): string;Defined in: packages/protocol/src/txt-record.ts:157
Returns
Section titled “Returns”string
signatureVerificationKeyAllowedHost()
Section titled “signatureVerificationKeyAllowedHost()”signatureVerificationKeyAllowedHost(): string;Defined in: packages/protocol/src/txt-record.ts:56
Returns
Section titled “Returns”string
signatureVerificationKeyURI()
Section titled “signatureVerificationKeyURI()”signatureVerificationKeyURI(): string;Defined in: packages/protocol/src/txt-record.ts:55
Returns
Section titled “Returns”string
validate()
Section titled “validate()”validate(): void;Defined in: packages/protocol/src/txt-record.ts:120
Returns
Section titled “Returns”void
parse()
Section titled “parse()”static parse(raw): DnsIdTxtRecord;Defined in: packages/protocol/src/txt-record.ts:35
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”parseUnsignedCanonical()
Section titled “parseUnsignedCanonical()”static parseUnsignedCanonical(raw, agentFQDN?): DnsIdTxtRecord;Defined in: packages/protocol/src/txt-record.ts:39
Parameters
Section titled “Parameters”string
agentFQDN?
Section titled “agentFQDN?”string
Returns
Section titled “Returns”DomainLog
Section titled “DomainLog”Defined in: packages/protocol/src/verified-domain.ts:116
The full verified event history for a domain, loaded from the lifecycle log.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new DomainLog(domain, events): DomainLog;Defined in: packages/protocol/src/verified-domain.ts:120
Parameters
Section titled “Parameters”domain
Section titled “domain”string
events
Section titled “events”LogEvent[]
Returns
Section titled “Returns”Properties
Section titled “Properties”domain
Section titled “domain”readonly domain: string;Defined in: packages/protocol/src/verified-domain.ts:117
events
Section titled “events”readonly events: LogEvent[];Defined in: packages/protocol/src/verified-domain.ts:118
Methods
Section titled “Methods”snapshotAt()
Section titled “snapshotAt()”snapshotAt(at): DomainSnapshot;Defined in: packages/protocol/src/verified-domain.ts:130
Materializes the domain state at a specific point in time. Pure computation — no I/O.
Parameters
Section titled “Parameters”Date
Returns
Section titled “Returns”Throws
Section titled “Throws”VerificationError if no events exist at or before at, or no ISSUANCE event found.
DomainSnapshot
Section titled “DomainSnapshot”Defined in: packages/protocol/src/verified-domain.ts:305
The materialized state of a domain at a specific point in time.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new DomainSnapshot(fields): DomainSnapshot;Defined in: packages/protocol/src/verified-domain.ts:316
Parameters
Section titled “Parameters”fields
Section titled “fields”activeKey
Section titled “activeKey”activeKeyThumbprint
Section titled “activeKeyThumbprint”string
domain
Section titled “domain”string
events
Section titled “events”LogEvent[]
governanceId
Section titled “governanceId”string
historicalState
Section titled “historicalState”keyBoundAt
Section titled “keyBoundAt”Date
snapshotAt
Section titled “snapshotAt”Date
Returns
Section titled “Returns”Properties
Section titled “Properties”activeKey
Section titled “activeKey”readonly activeKey: DnsIdJWK;Defined in: packages/protocol/src/verified-domain.ts:309
activeKeyThumbprint
Section titled “activeKeyThumbprint”readonly activeKeyThumbprint: string;Defined in: packages/protocol/src/verified-domain.ts:310
domain
Section titled “domain”readonly domain: string;Defined in: packages/protocol/src/verified-domain.ts:306
events
Section titled “events”readonly events: LogEvent[];Defined in: packages/protocol/src/verified-domain.ts:314
governanceId
Section titled “governanceId”readonly governanceId: string;Defined in: packages/protocol/src/verified-domain.ts:312
historicalState
Section titled “historicalState”readonly historicalState: AgentStatusState;Defined in: packages/protocol/src/verified-domain.ts:308
Lifecycle state materialized from the verified log history at snapshotAt.
keyBoundAt
Section titled “keyBoundAt”readonly keyBoundAt: Date;Defined in: packages/protocol/src/verified-domain.ts:311
snapshotAt
Section titled “snapshotAt”readonly snapshotAt: Date;Defined in: packages/protocol/src/verified-domain.ts:313
IdentityManager
Section titled “IdentityManager”Defined in: packages/protocol/src/identity-manager.ts:312
Core DNSid protocol facade.
This package-local version intentionally exposes only DNSid protocol-core methods. JWT/JWS, HTTP Message Signatures, transport, registry workflows, and concrete key storage live in sibling packages.
Implements
Section titled “Implements”Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new IdentityManager(config?, deps?): IdentityManager;Defined in: packages/protocol/src/identity-manager.ts:332
Parameters
Section titled “Parameters”config?
Section titled “config?”DnsidConfig = {}
Data-only configuration; omit identity for a verification-only manager.
IdentityManagerDependencies = {}
Injected runtime objects. The protocol core has no default DNS/HTTPS
implementations, so config.transport settings have no consumer here and are rejected;
runtime factories (for example @dnsid-ai/sdk/node) consume them before delegating.
Returns
Section titled “Returns”Properties
Section titled “Properties”config
Section titled “config”readonly config: DnsidConfig & object;Defined in: packages/protocol/src/identity-manager.ts:314
Validated immutable snapshot. identity is absent for verification-only managers.
Type Declaration
Section titled “Type Declaration”transport
Section titled “transport”transport: TransportConfig;verification
Section titled “verification”verification: VerificationConfig;Methods
Section titled “Methods”canonicalizeLogEvent()
Section titled “canonicalizeLogEvent()”canonicalizeLogEvent(event): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/protocol/src/identity-manager.ts:394
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
createTxtRecord()
Section titled “createTxtRecord()”createTxtRecord(): Promise<string>;Defined in: packages/protocol/src/identity-manager.ts:539
Builds and signs the _dnsid TXT record for DNS publication.
Returns
Section titled “Returns”Promise<string>
evictDomain()
Section titled “evictDomain()”evictDomain(domain): void;Defined in: packages/protocol/src/identity-manager.ts:1051
Removes a domain from the IdentityManager cache.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Returns
Section titled “Returns”void
getEntityKeySet()
Section titled “getEntityKeySet()”getEntityKeySet(): Promise<JWKS>;Defined in: packages/protocol/src/identity-manager.ts:501
Returns the accountable-entity public key set for ek JWKS publication.
Returns
Section titled “Returns”Promise<JWKS>
getKeyProvider()
Section titled “getKeyProvider()”getKeyProvider(): KeyProvider;Defined in: packages/protocol/src/identity-manager.ts:372
Returns
Section titled “Returns”getKeySet()
Section titled “getKeySet()”getKeySet(): Promise<JWKS>;Defined in: packages/protocol/src/identity-manager.ts:494
Returns the local identity’s operational public key set for ku JWKS publication.
Returns
Section titled “Returns”Promise<JWKS>
loadDomainLog()
Section titled “loadDomainLog()”loadDomainLog(vd): Promise<DomainLog>;Defined in: packages/protocol/src/identity-manager.ts:1037
Loads the full verified event history for a domain from its bound lifecycle log.
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<DomainLog>
requiredLogSignatures()
Section titled “requiredLogSignatures()”requiredLogSignatures(event): LogSignerRole[];Defined in: packages/protocol/src/identity-manager.ts:399
Parameters
Section titled “Parameters”Returns
Section titled “Returns”rotateOperationalKey()
Section titled “rotateOperationalKey()”rotateOperationalKey(options): Promise<OperationalKeyRotationResult>;Defined in: packages/protocol/src/identity-manager.ts:509
Runs the draft-01 operational-key rotation transaction.
Parameters
Section titled “Parameters”options
Section titled “options”Returns
Section titled “Returns”Promise<OperationalKeyRotationResult>
signAndWriteEvent()
Section titled “signAndWriteEvent()”signAndWriteEvent(event): Promise<string>;Defined in: packages/protocol/src/identity-manager.ts:387
Signs and appends a lifecycle event to the local identity log.
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<string>
signEvent()
Section titled “signEvent()”signEvent(event, role): Promise<LogEvent>;Defined in: packages/protocol/src/identity-manager.ts:412
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<LogEvent>
signEventWithProvider()
Section titled “signEventWithProvider()”signEventWithProvider( event, role, keyProvider, logBinding?): Promise<LogEvent>;Defined in: packages/protocol/src/identity-manager.ts:422
Parameters
Section titled “Parameters”keyProvider
Section titled “keyProvider”logBinding?
Section titled “logBinding?”Pick<LogReader, "canonical"> & object | null
Returns
Section titled “Returns”Promise<LogEvent>
verifyDomain()
Section titled “verifyDomain()”verifyDomain( domain, peerCert?, options?): Promise<VerifiedDomain>;Defined in: packages/protocol/src/identity-manager.ts:590
Verifies a DNSid identity according to the protocol, then enforces configured
trustedEntities acceptance. Acceptance runs per invocation, including cache hits,
and is never cached; a denial leaves valid protocol evidence cached.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
peerCert?
Section titled “peerCert?”options?
Section titled “options?”VerificationOptions = {}
Returns
Section titled “Returns”Promise<VerifiedDomain>
Implementation of
Section titled “Implementation of”writeSignedEvent()
Section titled “writeSignedEvent()”writeSignedEvent(event): Promise<string>;Defined in: packages/protocol/src/identity-manager.ts:467
Parameters
Section titled “Parameters”Returns
Section titled “Returns”Promise<string>
InMemoryIdentityCache
Section titled “InMemoryIdentityCache”Defined in: packages/protocol/src/identity-cache.ts:29
Default in-memory cache implementation.
Implements
Section titled “Implements”Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new InMemoryIdentityCache(): InMemoryIdentityCache;Returns
Section titled “Returns”Methods
Section titled “Methods”evict()
Section titled “evict()”evict(domain): void;Defined in: packages/protocol/src/identity-cache.ts:54
Removes a domain from the cache immediately.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Returns
Section titled “Returns”void
Implementation of
Section titled “Implementation of”get(domain): VerifiedDomain | null;Defined in: packages/protocol/src/identity-cache.ts:32
Returns the cached VerifiedDomain for a domain, or null if not cached or expired.
Parameters
Section titled “Parameters”domain
Section titled “domain”string
Returns
Section titled “Returns”VerifiedDomain | null
Implementation of
Section titled “Implementation of”put(domain, result): void;Defined in: packages/protocol/src/identity-cache.ts:42
Stores a verified domain result. Entry expires at result.expiry().
Parameters
Section titled “Parameters”domain
Section titled “domain”string
result
Section titled “result”Returns
Section titled “Returns”void
Implementation of
Section titled “Implementation of”Defined in: packages/protocol/src/jwks.ts:100
Wrapper around a JWK Set document.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new JWKS(keys): JWKS;Defined in: packages/protocol/src/jwks.ts:103
Parameters
Section titled “Parameters”DnsIdJWK[]
Returns
Section titled “Returns”Properties
Section titled “Properties”readonly keys: DnsIdJWK[];Defined in: packages/protocol/src/jwks.ts:101
Methods
Section titled “Methods”currentOperationalSigningKey()
Section titled “currentOperationalSigningKey()”currentOperationalSigningKey(): DnsIdJWK;Defined in: packages/protocol/src/jwks.ts:174
Returns
Section titled “Returns”currentRecordSigningKey()
Section titled “currentRecordSigningKey()”currentRecordSigningKey(): DnsIdJWK;Defined in: packages/protocol/src/jwks.ts:170
Returns
Section titled “Returns”draft01RecordSigningKeyById()
Section titled “draft01RecordSigningKeyById()”draft01RecordSigningKeyById(kid): DnsIdJWK | null;Defined in: packages/protocol/src/jwks.ts:136
Returns the draft-01-compatible record-signing key matching kid, or null if none.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”DnsIdJWK | null
keyById()
Section titled “keyById()”keyById(kid): DnsIdJWK | null;Defined in: packages/protocol/src/jwks.ts:131
Returns the key matching the given kid, or null if not found.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”DnsIdJWK | null
signingKeys()
Section titled “signingKeys()”signingKeys(): DnsIdJWK[];Defined in: packages/protocol/src/jwks.ts:112
Returns all keys suitable for signature verification. A key qualifies if use is absent/sig and it has a supported signature algorithm binding.
Returns
Section titled “Returns”DnsIdJWK[]
Throws
Section titled “Throws”ValidationError if no signing keys are present.
toJSON()
Section titled “toJSON()”toJSON(): object;Defined in: packages/protocol/src/jwks.ts:207
Returns the JWKS as a plain JSON-serializable object.
Returns
Section titled “Returns”object
keys: DnsIdJWK[];validate()
Section titled “validate()”validate(): void;Defined in: packages/protocol/src/jwks.ts:147
Validates the key set.
Returns
Section titled “Returns”void
Throws
Section titled “Throws”ValidationError if:
- no signing key has a kid field
- any present alg field is inconsistent with the key’s kty/crv binding
- no key is suitable for signing
validateOperational()
Section titled “validateOperational()”validateOperational(): void;Defined in: packages/protocol/src/jwks.ts:190
Returns
Section titled “Returns”void
validateRecordSigning()
Section titled “validateRecordSigning()”validateRecordSigning(): void;Defined in: packages/protocol/src/jwks.ts:178
Returns
Section titled “Returns”void
validateRecordSigningKeyset()
Section titled “validateRecordSigningKeyset()”validateRecordSigningKeyset(): Promise<void>;Defined in: packages/protocol/src/jwks.ts:184
Validates the single current draft-01 ek key and its importable public material.
Returns
Section titled “Returns”Promise<void>
LogRegistry
Section titled “LogRegistry”Defined in: packages/protocol/src/log-registry.ts:15
Single injection point for all log interaction. Holds one factory per log method.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new LogRegistry(): LogRegistry;Returns
Section titled “Returns”Methods
Section titled “Methods”newReader()
Section titled “newReader()”newReader(lr, options?): LogReader;Defined in: packages/protocol/src/log-registry.ts:41
Creates a LogReader bound to the given lr string. Returns a NoopLogReader if no factory is registered for the method.
Parameters
Section titled “Parameters”string
options?
Section titled “options?”signal?
Section titled “signal?”AbortSignal
Returns
Section titled “Returns”Throws
Section titled “Throws”ParseError if lr is malformed (no colon, empty method, or method violates pattern).
register()
Section titled “register()”register(method, factory): void;Defined in: packages/protocol/src/log-registry.ts:29
Registers a factory for the given method name (e.g. “algorand”, “ctlog”, “scitt”).
Parameters
Section titled “Parameters”method
Section titled “method”string
factory
Section titled “factory”LogReaderFactory
Returns
Section titled “Returns”void
Throws
Section titled “Throws”ArgumentError if method does not match [a-z][a-z0-9-]*
snapshot()
Section titled “snapshot()”snapshot(): LogRegistry;Defined in: packages/protocol/src/log-registry.ts:19
Copies method selection for an immutable manager verification context.
Returns
Section titled “Returns”NoopLogReader
Section titled “NoopLogReader”Defined in: packages/protocol/src/log-registry.ts:63
Returned by LogRegistry.newReader when no factory is registered for the method. Every method raises VerificationError{code: LogError}.
Implements
Section titled “Implements”Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new NoopLogReader(method): NoopLogReader;Defined in: packages/protocol/src/log-registry.ts:66
Parameters
Section titled “Parameters”method
Section titled “method”string
Returns
Section titled “Returns”Methods
Section titled “Methods”canonical()
Section titled “canonical()”canonical(_event): Promise<Uint8Array<ArrayBufferLike>>;Defined in: packages/protocol/src/log-registry.ts:77
Returns the canonical byte representation of the event for this log method. Used to verify the signatures required by the log method on events read from the log. MUST produce identical output to Log.canonical for the same supported event.
Parameters
Section titled “Parameters”_event
Section titled “_event”Returns
Section titled “Returns”Promise<Uint8Array<ArrayBufferLike>>
Implementation of
Section titled “Implementation of”keyTimestamp()
Section titled “keyTimestamp()”keyTimestamp(_domain, _keyThumbprint): Promise<Date>;Defined in: packages/protocol/src/log-registry.ts:78
Returns the timestamp at which the given key thumbprint was bound to the domain (ISSUANCE or KEY_ROTATION event). Used for ka validation.
Parameters
Section titled “Parameters”_domain
Section titled “_domain”string
_keyThumbprint
Section titled “_keyThumbprint”string
Returns
Section titled “Returns”Promise<Date>
Implementation of
Section titled “Implementation of”readEvent()
Section titled “readEvent()”readEvent(_ref): Promise<LogEvent>;Defined in: packages/protocol/src/log-registry.ts:82
Reads a single event by its log reference. MUST verify inclusion proof and timestamp proof before returning.
Parameters
Section titled “Parameters”string
Returns
Section titled “Returns”Promise<LogEvent>
Implementation of
Section titled “Implementation of”rebuildHistory()
Section titled “rebuildHistory()”rebuildHistory(_domain): Promise<LogEvent[]>;Defined in: packages/protocol/src/log-registry.ts:83
Rebuilds the full event history for the domain in authoritative log order. MUST verify inclusion proofs, timestamp proofs, append-only consistency, and required lifecycle signatures on every returned event. Event signature verification MUST use the public keys valid for that event in the reconstructed lifecycle history. Events with invalid signatures MUST NOT be returned.
Parameters
Section titled “Parameters”_domain
Section titled “_domain”string
Returns
Section titled “Returns”Promise<LogEvent[]>
Implementation of
Section titled “Implementation of”verifyBilateralBinding()
Section titled “verifyBilateralBinding()”verifyBilateralBinding( _record, _entityKey, _operationalKey): Promise<{ initialEntityThumbprint: string; initialOperationalThumbprint: string; timestamp: Date;}>;Defined in: packages/protocol/src/log-registry.ts:79
Verifies draft-01 bilateral ISSUANCE binding for the current TXT record.
Parameters
Section titled “Parameters”_record
Section titled “_record”unknown
_entityKey
Section titled “_entityKey”unknown
_operationalKey
Section titled “_operationalKey”unknown
Returns
Section titled “Returns”Promise<{
initialEntityThumbprint: string;
initialOperationalThumbprint: string;
timestamp: Date;
}>
Implementation of
Section titled “Implementation of”LogReader.verifyBilateralBinding
verifyNonRevocation()
Section titled “verifyNonRevocation()”verifyNonRevocation(_domain, _at): Promise<LoggedStateEvidence>;Defined in: packages/protocol/src/log-registry.ts:81
Verifies that the domain is neither REVOKED nor RETIRED at the given timestamp. Raises on a terminal state or if complete, fresh evidence cannot be established. Returns the accepted proof boundary.
Parameters
Section titled “Parameters”_domain
Section titled “_domain”string
Date
Returns
Section titled “Returns”Promise<LoggedStateEvidence>
Implementation of
Section titled “Implementation of”verifyOperationalContinuity()
Section titled “verifyOperationalContinuity()”verifyOperationalContinuity( _domain, _initialOperationalThumbprint, _currentOperationalThumbprint): Promise<void>;Defined in: packages/protocol/src/log-registry.ts:80
Verifies KEY_ROTATION continuity from ISSUANCE to the current operational key.
Parameters
Section titled “Parameters”_domain
Section titled “_domain”string
_initialOperationalThumbprint
Section titled “_initialOperationalThumbprint”string
_currentOperationalThumbprint
Section titled “_currentOperationalThumbprint”string
Returns
Section titled “Returns”Promise<void>
Implementation of
Section titled “Implementation of”LogReader.verifyOperationalContinuity
ParseError
Section titled “ParseError”Defined in: packages/protocol/src/errors.ts:43
Thrown when raw input (e.g. a TXT record or duration string) cannot be parsed into its structured form.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new ParseError(message): ParseError;Defined in: packages/protocol/src/errors.ts:44
Parameters
Section titled “Parameters”message
Section titled “message”string
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructorProperties
Section titled “Properties”cause?
Section titled “cause?”optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24
Inherited from
Section titled “Inherited from”Error.causemessage
Section titled “message”message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075
Inherited from
Section titled “Inherited from”Error.messagename: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074
Inherited from
Section titled “Inherited from”Error.namestack?
Section titled “stack?”optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Section titled “Inherited from”Error.stackstackTraceLimit
Section titled “stackTraceLimit”static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:67
The Error.stackTraceLimit property specifies the number of stack frames
collected by a stack trace (whether generated by new Error().stack or
Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes
will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Section titled “Inherited from”Error.stackTraceLimitMethods
Section titled “Methods”captureStackTrace()
Section titled “captureStackTrace()”static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:51
Creates a .stack property on targetObject, which when accessed returns
a string representing the location in the code at which
Error.captureStackTrace() was called.
const myObject = {};Error.captureStackTrace(myObject);myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with
${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames
above constructorOpt, including constructorOpt, will be omitted from the
generated stack trace.
The constructorOpt argument is useful for hiding implementation
details of error generation from the user. For instance:
function a() { b();}
function b() { c();}
function c() { // Create an error without stack trace to avoid calculating the stack trace twice. const { stackTraceLimit } = Error; Error.stackTraceLimit = 0; const error = new Error(); Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace throw error;}
a();Parameters
Section titled “Parameters”targetObject
Section titled “targetObject”object
constructorOpt?
Section titled “constructorOpt?”Function
Returns
Section titled “Returns”void
Inherited from
Section titled “Inherited from”Error.captureStackTraceprepareStackTrace()
Section titled “prepareStackTrace()”static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:55
Parameters
Section titled “Parameters”Error
stackTraces
Section titled “stackTraces”CallSite[]
Returns
Section titled “Returns”any
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Section titled “Inherited from”Error.prepareStackTraceValidationError
Section titled “ValidationError”Defined in: packages/protocol/src/errors.ts:51
Thrown when parsed data is structurally sound but violates a DNSid protocol constraint.
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new ValidationError(message): ValidationError;Defined in: packages/protocol/src/errors.ts:52
Parameters
Section titled “Parameters”message
Section titled “message”string
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructorProperties
Section titled “Properties”cause?
Section titled “cause?”optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24
Inherited from
Section titled “Inherited from”Error.causemessage
Section titled “message”message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075
Inherited from
Section titled “Inherited from”Error.messagename: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074
Inherited from
Section titled “Inherited from”Error.namestack?
Section titled “stack?”optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Section titled “Inherited from”Error.stackstackTraceLimit
Section titled “stackTraceLimit”static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:67
The Error.stackTraceLimit property specifies the number of stack frames
collected by a stack trace (whether generated by new Error().stack or
Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes
will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Section titled “Inherited from”Error.stackTraceLimitMethods
Section titled “Methods”captureStackTrace()
Section titled “captureStackTrace()”static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:51
Creates a .stack property on targetObject, which when accessed returns
a string representing the location in the code at which
Error.captureStackTrace() was called.
const myObject = {};Error.captureStackTrace(myObject);myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with
${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames
above constructorOpt, including constructorOpt, will be omitted from the
generated stack trace.
The constructorOpt argument is useful for hiding implementation
details of error generation from the user. For instance:
function a() { b();}
function b() { c();}
function c() { // Create an error without stack trace to avoid calculating the stack trace twice. const { stackTraceLimit } = Error; Error.stackTraceLimit = 0; const error = new Error(); Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace throw error;}
a();Parameters
Section titled “Parameters”targetObject
Section titled “targetObject”object
constructorOpt?
Section titled “constructorOpt?”Function
Returns
Section titled “Returns”void
Inherited from
Section titled “Inherited from”Error.captureStackTraceprepareStackTrace()
Section titled “prepareStackTrace()”static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:55
Parameters
Section titled “Parameters”Error
stackTraces
Section titled “stackTraces”CallSite[]
Returns
Section titled “Returns”any
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Section titled “Inherited from”Error.prepareStackTraceVerificationError
Section titled “VerificationError”Defined in: packages/protocol/src/errors.ts:82
Thrown when DNSid identity verification fails.
Carries a VerificationCode for programmatic handling and a transient
flag indicating whether a retry may succeed (see retryTransientVerification).
Extends
Section titled “Extends”Error
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new VerificationError(message, init): VerificationError;Defined in: packages/protocol/src/errors.ts:96
Parameters
Section titled “Parameters”message
Section titled “message”string
VerificationErrorInit
Returns
Section titled “Returns”Overrides
Section titled “Overrides”Error.constructorProperties
Section titled “Properties”agentState?
Section titled “agentState?”readonly optional agentState?: string;Defined in: packages/protocol/src/errors.ts:88
Agent state reported by the status document, when the failure is state-related.
cause?
Section titled “cause?”optional cause?: unknown;Defined in: node_modules/typescript/lib/lib.es2022.error.d.ts:24
Inherited from
Section titled “Inherited from”Error.causereadonly code: VerificationCode;Defined in: packages/protocol/src/errors.ts:84
Classification of the failure.
errorCategory?
Section titled “errorCategory?”readonly optional errorCategory?: LifecycleErrorCategory;Defined in: packages/protocol/src/errors.ts:90
Lifecycle conformance category, when the failure maps to a lifecycle state-machine rule.
message
Section titled “message”message: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1075
Inherited from
Section titled “Inherited from”Error.messagename: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1074
Inherited from
Section titled “Inherited from”Error.namestack?
Section titled “stack?”optional stack?: string;Defined in: node_modules/typescript/lib/lib.es5.d.ts:1076
Inherited from
Section titled “Inherited from”Error.stacktransient
Section titled “transient”readonly transient: boolean;Defined in: packages/protocol/src/errors.ts:86
True when retrying the verification may succeed.
verifiedEntityKeyThumbprint?
Section titled “verifiedEntityKeyThumbprint?”readonly optional verifiedEntityKeyThumbprint?: string;Defined in: packages/protocol/src/errors.ts:94
Observed verified record-signing key thumbprint (CounterpartyNotAccepted only). Never echoes configured pins.
verifiedGovernanceId?
Section titled “verifiedGovernanceId?”readonly optional verifiedGovernanceId?: string;Defined in: packages/protocol/src/errors.ts:92
Observed verified governance ID (CounterpartyNotAccepted only). Never echoes configured policy.
stackTraceLimit
Section titled “stackTraceLimit”static stackTraceLimit: number;Defined in: node_modules/@types/node/globals.d.ts:67
The Error.stackTraceLimit property specifies the number of stack frames
collected by a stack trace (whether generated by new Error().stack or
Error.captureStackTrace(obj)).
The default value is 10 but may be set to any valid JavaScript number. Changes
will affect any stack trace captured after the value has been changed.
If set to a non-number value, or set to a negative number, stack traces will not capture any frames.
Inherited from
Section titled “Inherited from”Error.stackTraceLimitMethods
Section titled “Methods”captureStackTrace()
Section titled “captureStackTrace()”static captureStackTrace(targetObject, constructorOpt?): void;Defined in: node_modules/@types/node/globals.d.ts:51
Creates a .stack property on targetObject, which when accessed returns
a string representing the location in the code at which
Error.captureStackTrace() was called.
const myObject = {};Error.captureStackTrace(myObject);myObject.stack; // Similar to `new Error().stack`The first line of the trace will be prefixed with
${myObject.name}: ${myObject.message}.
The optional constructorOpt argument accepts a function. If given, all frames
above constructorOpt, including constructorOpt, will be omitted from the
generated stack trace.
The constructorOpt argument is useful for hiding implementation
details of error generation from the user. For instance:
function a() { b();}
function b() { c();}
function c() { // Create an error without stack trace to avoid calculating the stack trace twice. const { stackTraceLimit } = Error; Error.stackTraceLimit = 0; const error = new Error(); Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace throw error;}
a();Parameters
Section titled “Parameters”targetObject
Section titled “targetObject”object
constructorOpt?
Section titled “constructorOpt?”Function
Returns
Section titled “Returns”void
Inherited from
Section titled “Inherited from”Error.captureStackTraceprepareStackTrace()
Section titled “prepareStackTrace()”static prepareStackTrace(err, stackTraces): any;Defined in: node_modules/@types/node/globals.d.ts:55
Parameters
Section titled “Parameters”Error
stackTraces
Section titled “stackTraces”CallSite[]
Returns
Section titled “Returns”any
https://v8.dev/docs/stack-trace-api#customizing-stack-traces
Inherited from
Section titled “Inherited from”Error.prepareStackTraceVerifiedDomain
Section titled “VerifiedDomain”Defined in: packages/protocol/src/verified-domain.ts:12
Result of a successful verifyDomain call. Contains all verified data for the domain.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new VerifiedDomain(fields): VerifiedDomain;Defined in: packages/protocol/src/verified-domain.ts:31
Parameters
Section titled “Parameters”fields
Section titled “fields”dnsExpiresAt?
Section titled “dnsExpiresAt?”Date
dnssecState
Section titled “dnssecState”dnsTTL
Section titled “dnsTTL”number
domain
Section titled “domain”string
keyBoundAt
Section titled “keyBoundAt”Date
lastStatusCheckAt
Section titled “lastStatusCheckAt”Date
logReader
Section titled “logReader”record
Section titled “record”recordSigningJwks?
Section titled “recordSigningJwks?”recordSigningTlsCert?
Section titled “recordSigningTlsCert?”registryStatus
Section titled “registryStatus”signingKey
Section titled “signingKey”signingKeyThumbprint
Section titled “signingKeyThumbprint”string
tlsCert
Section titled “tlsCert”verifiedAt
Section titled “verifiedAt”Date
Returns
Section titled “Returns”Properties
Section titled “Properties”dnsExpiresAt
Section titled “dnsExpiresAt”readonly dnsExpiresAt: Date;Defined in: packages/protocol/src/verified-domain.ts:25
dnssecState
Section titled “dnssecState”readonly dnssecState: DNSSECState;Defined in: packages/protocol/src/verified-domain.ts:28
dnsTTL
Section titled “dnsTTL”readonly dnsTTL: number;Defined in: packages/protocol/src/verified-domain.ts:24
domain
Section titled “domain”readonly domain: string;Defined in: packages/protocol/src/verified-domain.ts:13
readonly jwks: JWKS;Defined in: packages/protocol/src/verified-domain.ts:15
keyBoundAt
Section titled “keyBoundAt”readonly keyBoundAt: Date;Defined in: packages/protocol/src/verified-domain.ts:26
lastStatusCheckAt
Section titled “lastStatusCheckAt”lastStatusCheckAt: Date;Defined in: packages/protocol/src/verified-domain.ts:27
logReader
Section titled “logReader”readonly logReader: LogReader;Defined in: packages/protocol/src/verified-domain.ts:29
record
Section titled “record”readonly record: DnsIdTxtRecord;Defined in: packages/protocol/src/verified-domain.ts:14
recordSigningJwks
Section titled “recordSigningJwks”readonly recordSigningJwks: JWKS;Defined in: packages/protocol/src/verified-domain.ts:16
recordSigningTlsCert
Section titled “recordSigningTlsCert”readonly recordSigningTlsCert: TLSCertificate;Defined in: packages/protocol/src/verified-domain.ts:21
registryStatus
Section titled “registryStatus”registryStatus: AgentStatus;Defined in: packages/protocol/src/verified-domain.ts:22
signingKey
Section titled “signingKey”readonly signingKey: DnsIdJWK;Defined in: packages/protocol/src/verified-domain.ts:17
signingKeyThumbprint
Section titled “signingKeyThumbprint”readonly signingKeyThumbprint: string;Defined in: packages/protocol/src/verified-domain.ts:19
RFC 7638 SHA-256 thumbprint of signingKey, computed once at verification and reused by acceptance checks.
tlsCert
Section titled “tlsCert”readonly tlsCert: TLSCertificate;Defined in: packages/protocol/src/verified-domain.ts:20
verifiedAt
Section titled “verifiedAt”readonly verifiedAt: Date;Defined in: packages/protocol/src/verified-domain.ts:23
Methods
Section titled “Methods”cachedState()
Section titled “cachedState()”cachedState(): AgentStatusState;Defined in: packages/protocol/src/verified-domain.ts:71
Returns the agent state from the most recent su fetch. Reflects the state at lastStatusCheckAt, not necessarily right now.
Returns
Section titled “Returns”expiry()
Section titled “expiry()”expiry(): Date;Defined in: packages/protocol/src/verified-domain.ts:94
Returns the earliest time at which this verified result should be considered stale. Candidates: DNS TTL, TLS cert NotAfter, key age bound (ka).
Returns
Section titled “Returns”Date
requiresLogCheck()
Section titled “requiresLogCheck()”requiresLogCheck(): boolean;Defined in: packages/protocol/src/verified-domain.ts:76
Whether the record requests a current log check for high-value operations.
Returns
Section titled “Returns”boolean
verifyNonRevocation()
Section titled “verifyNonRevocation()”verifyNonRevocation(at?): Promise<LoggedStateEvidence>;Defined in: packages/protocol/src/verified-domain.ts:86
Performs the authoritative lifecycle-log non-revocation check used for a
high-value or irreversible operation. Callers decide which operations are
high value; local policy may also require this check when fl=logchk is
absent. Log unavailability and stale evidence fail closed.
Parameters
Section titled “Parameters”Date = ...
Returns
Section titled “Returns”Promise<LoggedStateEvidence>