Open source · @armalo/extension-sdk
Sign what you publish. Verify what you're handed.
The authoring boundary for immutable publisher claims: exact dependency locks, RFC 8785 canonical manifests, Ed25519 or low-S P-256 signatures, and fail-closed verification receipts. Every call is a plain value or a throw — no hidden I/O, no network calls, and signing never reads or prints private key material.
Install
npm install @armalo/extension-sdkNot yet published to the npm registry — the package is built, tested, and reviewed against its packed form; this guide's code is copied from that check.
The default export is browser-safe and contains no Node APIs. Filesystem scaffolding is isolated behind the /scaffold subpath.
Scaffold a new extension
import { planExtensionScaffold } from "@armalo/extension-sdk/scaffold";
const scaffold = planExtensionScaffold({
baseDirectory: "/absolute/new-extension",
outputDirectory: "/absolute/new-extension",
publisher: "your-publisher-id",
name: "your-extension",
moduleKinds: ["skill"],
});
// scaffold.files, scaffold.contents — write them out yourselfSign a manifest
Turn manifest claims into a publisher-attributable, signed bundle.
import { signPublisherBundle, derivePublisherPublicKey } from "@armalo/extension-sdk/sign";
const bundle = signPublisherBundle(claims, {
algorithm: "ed25519",
namespace: "your-publisher-id",
keyId: "your-key-id",
privateKey,
signedAt: new Date().toISOString(),
});Verify a bundle
A local key can prove only that a signature is valid and untrusted — it can never produce an Armalo admission or trust verdict on its own. That requires the separate Armalo API plus a verifier rooted in Armalo-controlled attestation keys. Artifact URIs and dependency references are content-addressed; mutable tags and caller-asserted proof are invalid.
import { verifyPublisherBundleCryptographically } from "@armalo/extension-sdk/verify";
const result = await verifyPublisherBundleCryptographically(bundle, {
now: new Date().toISOString(),
expectedNamespace: "your-publisher-id",
keyResolver,
});
// result.signatureValidLicense
Apache-2.0. Back to open source.