Repository navigation
RTQ Release v0.1.1 — Updated READMEs, npm keywords, and mobile enhancements
RTQ continues its zero‑third‑party‑dependency approach, now with fully‑documented READMEs and curated npm keywords for every @rtq/* package. The mobile package has been renamed to Rtq, now includes native OS screen‑lock (Android biometric verification with device‑credential fallback, iOS Face/Touch ID support), and ships a placeholder unsigned .ipa asset.
📦 Published npm Monorepo Packages (@rtq/* v0.1.1)
| Package | Version | Link | Role |
|---|---|---|---|
@rtq/security |
0.1.1 | npm | Unified pipeline façade (createRTQ) |
@rtq/cli |
0.1.1 | npm | Security CLI (capabilities, policy, sandbox, audit) |
@rtq/mcp |
0.1.1 | npm | Business‑grade MCP gateway |
@rtq/core |
0.1.1 | npm | Capability registry, ticket store, schema validation |
@rtq/crypto |
0.1.1 | npm | Canonical JSON, SHA‑256, Ed25519 signing |
@rtq/sandbox |
0.1.1 | npm | macOS Seatbelt, Linux bubblewrap, Windows AppContainer |
@rtq/approval |
0.1.1 | npm | QR‑based approval strategies |
@rtq/mobile |
0.1.1 | npm | Rtq – mobile approval host transport & pairing server |
@rtq/risk |
0.1.1 | npm | Authoritative risk engine (raise‑only) |
@rtq/policy |
0.1.1 | npm | Declarative default‑deny rule evaluator |
@rtq/clarification |
0.1.1 | npm | Ambiguity resolution |
@rtq/audit |
0.1.1 | npm | Structured, redacted audit logging |
📱 Mobile Package Enhancements (Rtq)
- Renamed to Rtq (README header updated,
APP_NAME = "Rtq"). - Native OS screen‑lock:
- Android: uses
react-native-biometricswithBiometricPromptand falls back toDEVICE_CREDENTIAL(PIN/pattern/password). - iOS: supports Face ID / Touch ID via the same library.
- Added
ensureBiometricAuth()helper (src/biometric.ts) andSimulatedDevice.approveWithBiometric()method that requires successful biometric verification before signing an approval.
- Android: uses
- Placeholder unsigned
.ipaadded to the package (included infiles).
🚀 Quick Start
npm install @rtq/security # core runtime
# or install the CLI globally
npm install -g @rtq/cliimport { createRTQ } from "@rtq/security";
const rtq = createRTQ({ signingKey: process.env.RTQ_SIGNING_KEY! });
// ...register capabilities, policies, authorize, executeFor mobile approval with biometric verification:
import { createMobileApprovalServer, SimulatedDevice } from "@rtq/mobile";
const server = await createMobileApprovalServer({ /* … */ });
const device = new SimulatedDevice({ name: "my‑device", keyPair: myKeyPair, pinnedHostPublicKey: hostPubKey });
await device.approveWithBiometric(challengePayload);🔬 Verification
- All 12 packages pass the CI suite (
npm run ci). - New biometric flow is covered by unit tests (
tests/mobile/biometric.test.ts).
💡 Why RTQ Was Created
While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS‑level sandboxing, capability scoping, fine‑grained permission gating, and challenge‑response authorization from scratch. RTQ was created to solve this problem for developers everywhere — packaging a security‑focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ enables developers to integrate capability security, OS‑enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge‑response approvals into their applications without having to build security infrastructure from scratch.