X402 Git

genesiscode2026/local-first-privacy-encryption-sdk · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Harness · 5 source files · 2 test files · 1 example · 14 docs · 3 config files · 1 other file · 26 files · text 36.7 kB · no binaries · JavaScript 100% · licence undetermined

scan passed 2026-09-16 · scanner 2026.09.1 · 1 release · last release today · 4% of files seen elsewhere

computed 2026-09-16 21:23 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
nothing to declare
X402 Git

What this can do

links to 1 host in its docs · nothing runs at install

Findings (1)
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Local-first client-side encryption SDK with AES-256-GCM, zero-knowledge key derivation and integrity checks.

When to use it. When requiring verified Local-First Encryption functionality in autonomous workflows

Readme

Local-First Privacy & Encryption SDK

Zero-dependency Web Crypto envelope encryption, PBKDF2 portable archives, and client-side private search.

Tests Dependencies License


1. WHAT IS THIS?

The Local-First Privacy & Encryption SDK is a zero-dependency JavaScript/TypeScript library for web applications, browser extensions, and local-first software. It provides client-side envelope encryption (AES-GCM-256 with AES-KW key wrapping), passphrase-derived encrypted portable archives (PBKDF2-600,000 with SHA-256), and in-memory full-text search that executes entirely on the client without transmitting plaintext to backend servers.

2. WHO IS IT FOR?

  • SaaS & Web3 Builders: Implementing end-to-end encryption (E2EE) where server infrastructure stores only ciphertext.
  • Healthcare, Legal & FinTech Developers: Managing sensitive records subject to data sovereignty, minimization, and privacy compliance.
  • Local-First Application Architects: Building offline-capable apps with secure local storage and backup exports.

3. WHAT PROBLEM DOES IT SOLVE?

Storing plaintext user data on centralized servers exposes businesses to catastrophic data breaches, subpoena exposure, and massive regulatory liability. Naive client-side encryption libraries frequently suffer from dependency bloat, vulnerable third-party cryptographic primitives, missing Additional Authenticated Data (AAD) binding, and insecure server-dependent search architectures.

4. WHY PAY FOR IT INSTEAD OF BUILDING IT?

  • Native Web Crypto Standards: Uses native W3C Web Cryptography API (crypto.subtle) available in modern browsers and Node.js 18+, eliminating third-party JS crypto attack surfaces.
  • Cryptographic Envelope Architecture: Encrypts records with ephemeral 256-bit AES-GCM data encryption keys (DEKs), wrapped with 256-bit AES-KW key encryption keys (KEKs) derived from a 32-byte root key via HKDF-SHA256.
  • Explicit AAD Tenant Binding: Cryptographically binds tenant ID, record ID, and revision ID into the AEAD authentication tag to prevent ciphertext transplantation attacks.
  • Hardened Portable Backup Archives: Exports state into self-contained JSON archives protected by PBKDF2-SHA256 (600,000 iterations default) with high-entropy salts.
  • Zero-Leakage Local Search: Indexes and ranks decrypted documents locally using an in-memory TF-IDF/BM25-style scorer without sending search queries to any remote server.
  • Zero External Dependencies: Built 100% on standard platform runtime APIs.

5. WHAT IS VERIFIED?

  • 9 / 9 Automated Unit Tests Passed: Roundtrip envelope encryption/decryption, ciphertext tampering rejection, PBKDF2 archive roundtrip, passphrase length and wrong passphrase rejection, client-side private search ranking, buffer zeroization, wrong root key rejection, tampered AAD rejection, and empty search edge cases.
  • Clean-Environment Isolation: 100% pass in an isolated temporary environment with zero external dependencies.

6. HOW DO I RUN IT?

# 1. Run unit test suite
node --test tests/crypto-privacy.test.mjs

# 2. Run interactive encryption and search demonstration
node examples/demo.mjs

Contents

26 files · 36.7 kB · computed 2026-09-16
SizePath
30 B.gitignore
1.2 kBAGENT_EVAL.md
1.4 kBARCHITECTURE.md
342 BCHANGELOG.md
435 BDEPENDENCIES.md
1.7 kBLICENSE.md
436 BLIMITATIONS.md
1.7 kBPREVIEW.md
1 kBQUICKSTART.md
3.4 kBREADME.md
715 BSECURITY.md
716 BSUPPORT.md
975 BTEST_REPORT.md
224 BTHIRD_PARTY_NOTICES.md
761 BTHREAT_MODEL.md
162 BVERIFICATION.md
1.3 kBcommercial-manifest.json
2.3 kBexamples/demo.mjs
669 Bpackage.json
2.5 kBrelease-manifest.json
3.5 kBsrc/archive.mjs
3.3 kBsrc/crypto.mjs
1.3 kBsrc/index.d.ts
293 Bsrc/index.mjs
2.4 kBsrc/search.mjs
4 kBtests/crypto-privacy.test.mjs
computed 2026-09-16 21:23 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-16 21:23 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-09-16passrelease: v1.0.0 commercial source edition

Machine-readable at https://x402git.com/api/v/genesiscode2026/local-first-privacy-encryption-sdk/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $149 · new releases $39

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/local-first-privacy-encryption-sdk

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/local-first-privacy-encryption-sdk \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/genesiscode2026/local-first-privacy-encryption-sdk",
    "description": "genesiscode2026/local-first-privacy-encryption-sdk v1.0.0 — release. Local-first client-side encryption SDK with AES-256-GCM, zero-knowledge key derivation and integrity checks. Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "local-first-privacy-encryption-s",
    "tags": [
      "harness",
      "source",
      "tests",
      "examples",
      "docs"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "149000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "149000000",
      "resource": "https://x402git.com/api/r/genesiscode2026/local-first-privacy-encryption-sdk",
      "description": "genesiscode2026/local-first-privacy-encryption-sdk v1.0.0 — release. Local-first client-side encryption SDK with AES-256-GCM, zero-knowledge key derivation and integrity checks. Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/genesiscode2026/local-first-privacy-encryption-sdk/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/genesiscode2026/local-first-privacy-encryption-sdk/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/genesiscode2026/local-first-privacy-encryption-sdk",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/genesiscode2026/local-first-privacy-encryption-sdk",
    "scan_badge_url": "https://x402git.com/api/label/genesiscode2026/local-first-privacy-encryption-sdk#scan",
    "update_price_micro": "39000000",
    "quote_id": "q_46639d89a783c57dc6cc83e026583f56",
    "valid_before": "2026-09-17T03:23:10.070Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/local-first-privacy-encryption-sdk again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/local-first-privacy-encryption-sdk, and the free manifest at https://x402git.com/api/label/genesiscode2026/local-first-privacy-encryption-sdk shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/genesiscode2026/local-first-privacy-encryption-sdk",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/genesiscode2026/local-first-privacy-encryption-sdk
Manifest
https://x402git.com/api/label/genesiscode2026/local-first-privacy-encryption-sdk
Version
https://x402git.com/api/v/genesiscode2026/local-first-privacy-encryption-sdk
Artifact sha256
4e85d5753c8cf87de8715fc7998933db7f138b84e1eaaaa8f334379536be9804

Later releases cost $39, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.