Package
@flashyos/wallet-wdk
Governed economic agency for FlashyOS agents on Tether WDK: the AAO WalletCapability, an authorizer client, an MCP elicitation handler, and a WDK policy rule that defers every spend to the authorization plane.
version 0.1.0 · audit of 2026-10-04 · source: flashyos/packages/wallet-wdk
npm i @flashyos/wallet-wdkThe package an agent runtime, a signer or a stranger verifying our records installs. It carries no dependency on the FlashyOS API: an agent asks the authorization plane for a SpendAuthorization and the plane answers with a signed decision, so the thing that moves money and the thing that decides never share a process.
Tether WDK is an optional dependency, and the package must build without it. The build is the part that bit.
Edge cases — each one paid for once
An optional dependency must also be one the package BUILDS without
esbuild resolves and bundles a string literal inside import() however carefully the try/catch around it is written, so a present @tetherto/wdk subtree inlined the lazy import, the try/catch went dead, and nothing was red. Externals are now derived from optionalDependencies in the tsup config and a test is the alarm for the silent half (flashyos, docs/record/one-lockfile-two-trees.md).
One lockfile, two Node versions, two trees
npm drops an optional subtree whose engines the running Node cannot satisfy silently. CI ran Node 22 and the deploy ran Node 20, so the same commit built green on CI and red in production at a step named after a package neither commit had touched. The versions agree now and a test refuses the divergence.
Published to a registry is committing, not serving
This package and its two siblings went live on npm on 2026-09-22 and reached no catalog, no case study and no thesis — zero references anywhere a stranger deciding to depend on it would read. The distribution floor in flashyos measures that; the coverage gate on this site refuses it.