aitp 0.3.0

Agent Identity & Trust Protocol — facade crate re-exporting the protocol crates
Documentation

Agent Identity & Trust Protocol (AITP) — facade crate.

This crate re-exports the AITP protocol crates so most users can depend on a single crate:

[dependencies]
aitp = "0.1"

Consumers that need only TCT verification (e.g. integrating into an existing service) should depend on aitp-tct and aitp-crypto directly to avoid pulling in the handshake state machine and HTTP transport.

Example: issue and verify a TCT (compact JWS)

use aitp::core::Timestamp;
use aitp::prelude::*;
use aitp::tct::{verify_tct, TctBuilder, TctVerifyContext};

# fn main() -> Result<(), Box<dyn std::error::Error>> {
let alice = AitpSigningKey::from_seed(&[0x11; 32]);
let bob = AitpSigningKey::from_seed(&[0x22; 32]);
let now = Timestamp(1_700_000_000);

// `issued.token` is the opaque compact JWS that goes on the wire;
// `issued.voucher` is the companion grant voucher bob can later
// delegate with.
let issued = TctBuilder::new(&alice)
    .subject(bob.aid().clone())
    .audience(bob.aid().clone())  // v0.2: audience == subject
    .grants(["demo.echo"])
    .ttl_secs(3600)
    .subject_pubkey(bob.verifying_key())
    .issued_at(now)
    .build()?;

let ctx = TctVerifyContext {
    expected_audience: bob.aid(),
    issuer: alice.aid(),
    now,
    issuer_manifest_expires_at: None,
    revocation_check: None,
};
let verified = verify_tct(&issued.token, &ctx)?;
assert_eq!(verified.claims.grants, vec!["demo.echo".to_string()]);
# Ok(())
# }