Skip to content

Releases: cad07/parimit

Parimit v0.1.0-alpha.4 — AiNxt compatibility evidence and technical white paper

Choose a tag to compare

@cad07 cad07 released this 01 Oct 15:10
5f71ef0

Parimit v0.1.0-alpha.4 is a public research alpha for a proposal-only authorization boundary around agent-initiated payment intents.

Highlights

  • Source-reviewed AiNxt sidecar reference adapter with fixed synthetic fixtures and no approval or execution authority.
  • Local TLS/OIDC Keycloak pilot with separate agent, consumer, reviewer, and administrator identities.
  • Corrected AiNxt control-plane pin semantics and public live compatibility evidence.
  • Technical White Paper v0.2 covering architecture, evidence, limitations, reproducibility, and roadmap.
  • Keycloak five-minute token verification hardened for the 300/301-second timestamp-boundary encoding while actual remaining validity stays capped at five minutes.

Verified release gates

  • 95 core tests passed.
  • 6 TypeScript SDK tests passed.
  • Safety-boundary scan passed.
  • CI, CodeQL, secret scanning, dependency review, and Keycloak pilot guardrails passed on PR #12.
  • CI, CodeQL, secret scanning, and the Keycloak pilot guardrail also passed on the exact tagged main commit 5f71ef0759f09299858f5bdf9a2fa4ce15090035.
  • The 16-page white paper was rebuilt, text-validated, and visually checked.

Safety boundary

This release does not connect to NPCI, UPI, a bank, PSP, wallet, or live merchant. It cannot initiate, execute, debit, transfer, settle, refund, or retry a payment. Interactive two-person reviewer and administrator acceptance remains pending and is required before any external pilot.

Local pilot migration note

Fresh alpha.4 Keycloak pilot volumes use a 301-second maximum encoded exp - iat delta. Older local pilot volumes are integrity-bound to their original trust policy and will fail closed if started with the new default. Preserve the old volume and matching recovery set for audit or rollback, or begin with a fresh disposable Parimit volume; there is no silent in-place migration.

Public assets

  • Technical White Paper v0.2 PDF
  • Local AiNxt component manifest v0.2
  • Corrected live AiNxt-Keycloak smoke evidence summary

The source archive is generated automatically from the tagged commit.

Parimit v0.1.0-alpha.3 — OIDC pilot boundary and Authorization Envelope v1

Choose a tag to compare

@cad07 cad07 released this 20 Sep 18:04

What this prerelease contains

This release folds in the unpublished alpha.2 OIDC/pilot foundation from PR #4 and adds Authorization Envelope v1 from PR #5. There is intentionally no alpha.2 tag.

OIDC pilot foundation

  • Verifies OIDC bearer-token signature, issuer, audience, lifetime, algorithm, and JWKS rotation, with fail-closed role mapping.
  • Enforces separate agent, approver, consumer, and admin capabilities, including agent ownership scope and consumer isolation from proposal browsing.
  • Adds a dependency-free, role-shaped TypeScript SDK and a conservative single-tenant REST pilot profile with deployment, acceptance, backup, rollback, and stop procedures.
  • Includes a PostgreSQL 14+ schema and transaction contract for the future storage port; the running service remains SQLite-backed.

Authorization Envelope v1

  • Issues short-lived, audience-bound Ed25519 evidence only after the required human approvals.
  • Cryptographically binds the tenant, exact v3 intent, policy configuration, OIDC trust domain, ordered approver set, authorization-state version, and audit tip.
  • Signs explicit false values for payment dispatch, execution authority, provider instruction, and money movement.
  • Adds public JWKS, strict canonical verification, stable public vectors, idempotent issuance, signing-key rotation with historical verification, and atomic one-time consumption inside the current SQLite boundary.

Security-boundary changes

  • Every REST operation except safety metadata, public envelope JWKS, and preflight now requires authenticated identity.
  • Spoofable demo headers require explicit demo mode and loopback isolation.
  • Stdio MCP is disabled in OIDC mode because it cannot yet bind a verified actor; the hosted pilot is REST/SDK-only.
  • Trust-critical configuration is database-bound, lifecycle transitions are serialized, migrations and integrity-root creation are crash-atomic, and a full signing-key-registry checkpoint detects removed historical keys.

Verification

Verified on commit dcfb25201e8c4b9d68559f0b1358f302fd4624e9:

  • 63/63 core, HTTP, OIDC, migration, cryptographic, and storage-contract tests passed.
  • 6/6 TypeScript SDK tests passed.
  • A live loopback pilot passed with locally signed OIDC/JWKS authentication, agent proposal, distinct human approval, Ed25519 envelope issuance, independent and HTTP verification, one-time consumption, safe idempotent replay, conflicting-replay rejection, and replay-state persistence across restart.
  • The safety-boundary scan passed across all 11 runtime source files.
  • Hosted CI, container build, CodeQL, and full-history secret scanning passed on the final main commit.
  • Dependency review passed on both merged pull requests.

Known limitations

  • Parimit has no UPI, bank, PSP, wallet, or payment-provider connection and cannot move money. The envelope is governance evidence, not a payment command or bearer capability.
  • PostgreSQL is schema/contract work only; the runtime remains single-instance SQLite.
  • Envelope consumption is authoritative only within one SQLite service/database. Offline or distributed recipients need their own durable replay ledger.
  • The hosted pilot has no browser OIDC login, token acquisition or refresh, native step-up authentication, token-revocation lookup, or multi-tenant routing.
  • Compact JWS is signed, not encrypted. Managed/HSM signing, formal key revocation, and external transparency anchoring are not shipped.
  • An older internally consistent database/checkpoint rollback cannot be detected without an external monotonic anchor.
  • Alpha.3 permits exactly one relying-party audience and requires a fresh recovery set for trust-domain or receipt-key changes.

Safety boundary

This is an experimental prerelease for controlled, fictional-data pilots. It is not production payment infrastructure, a compliance certification, or an NPCI-affiliated implementation.

Parimit v0.1.0-alpha.1 — observation integrity hardening

Choose a tag to compare

@cad07 cad07 released this 19 Sep 15:12

Highlights

  • Reconciles mock observation rows with ordered, hash-linked audit evidence: identity for new rows, count, order, status, provider reference, source, timestamp, retry flag, and the no-money-movement invariant.
  • Fails ordinary intent, list, and audit reads closed when stored state diverges from its audit evidence.
  • Enforces strict approval and observation request bodies, returns a clean 400 for malformed observation paths, validates agent filters, and documents 413/500 responses in OpenAPI.

Verification

  • 17/17 repository tests passed.
  • A separate 16-check REST and MCP end-to-end run passed.
  • The runtime boundary scan passed across all 7 source files.
  • The browser flow passed: create, approve, attach a fictional observation, and verify the audit chain.
  • Hosted CI, CodeQL, and secret scanning passed on commit 72922d83f4e6b1d94e24fa2beced36c7e108ad98.

Compatibility note

Pre-alpha.1 observation events without an observation ID remain readable through exact legacy field, order, and count reconciliation. An exact delete-and-reinsert clone that preserves every legacy field and timestamp is inherently indistinguishable for those legacy rows.

Safety boundary

Parimit remains a proposal-only local demo. It has no UPI, bank, PSP, wallet, or payment-provider connector; exposes no execution route or MCP tool; and is not endorsed or certified by NPCI.

Parimit v0.1.0-alpha.0 — proposal-only safety demo

Choose a tag to compare

@cad07 cad07 released this 19 Sep 14:39

Parimit is a proposal-only payment-intent governance boundary for AI agents. It demonstrates constrained proposal creation, deterministic policy checks, demo human review, integrity evidence, and mock outcome recording without connecting to a live payment rail.

Highlights

  • Proposal-only REST and MCP interfaces with no approval or execution tool exposed to agents.
  • Deterministic limits, blocklists, optional allowlists, expiry, idempotency, and dual-control policy.
  • Demo human decisions backed by HMAC-authenticated records.
  • V2 intent digest binding and state-consistency verification, with legacy V1 rows restricted to archival reads.
  • Hash-linked local audit evidence and fail-closed IN_DOUBT handling.
  • Web demonstration, OpenAPI contract, Docker packaging, adapter boundary guidance, and technical design paper.

Verification

  • 16 of 16 automated tests passed on Node.js 24.
  • Safety-boundary scan passed across seven runtime source files.
  • Hosted CI, CodeQL, Gitleaks, container build, and dependency review passed.
  • No open CodeQL or GitHub secret-scanning alerts at release time.

Safety notice

This is an implementation-aligned alpha research prototype. It cannot move money and must not be connected directly to UPI, a bank, a PSP, a wallet, a blockchain facilitator, or any other live payment rail. It is independent and is not affiliated with or endorsed by NPCI or any payment provider.