Package

@flashyos/signer

The isolated signer for the wallet authorization plane: verifies an Ed25519-signed SpendAuthorization, re-derives the operation from the real call, refuses on any mismatch, executes through Tether WDK, and reports settlement.

version 0.1.0 · audit of 2026-10-04 · source: flashyos/packages/signer

npm i @flashyos/signer

The only process that holds a seed, and it never holds the plane’s private key. For every request it does five things in a fixed order — verify the signature, re-derive the operation, compare, execute, report — and a mismatch at any step is a refusal with a reason, never a best effort.

Edge cases — each one paid for once

Re-derive the operation from the real call; never trust the one in the envelope

An authorization names an operation. The signer recomputes what the call would actually do and refuses when the two differ, because a signed envelope that describes a different transfer than the one about to execute is exactly the attack a signer exists to stop.

The deploy image needs the manifest, not just the import

npm links a workspace into an image only when its manifest was copied before npm ci. The api imported this package and the Dockerfile’s copy list stayed at four, so Deploy prod died on Module not found one step after an earlier fix got it that far. A test now reads imports with the TypeScript scanner and refuses the omission.

← Full catalog · The doctrine behind the tools · Adopt one