
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@agtnames/resolver
Advanced tools
Resolve and verify .agt agent names against AGT Registry v2 (raw JSON-RPC, no wallet library needed)
Resolve and verify .agt agent names against the AGT Registry (Polygon). Reads the registry over raw JSON-RPC — no wallet library — and verifies the agent manifest three ways: the signer, the manifest's declared owner, and the on-chain owner must all agree. Works in Node.js, Deno, Bun, and browsers.
npm install @agtnames/resolver
import { AgtResolver } from "@agtnames/resolver";
const agt = new AgtResolver({ chain: "polygon" }); // or { rpcUrl, registry }
const r = await agt.resolveAgent("exampleagent.agt");
r.owner // '0x…' — current on-chain owner
r.active // registered and not expired
r.verified // manifest passed all checks
r.records.endpoints.mcp // 'https://…/mcp'
r.records.addr // primary address record
r.manifest // the full signed manifest (or null)
new AgtResolver(options)| Option | Description |
|---|---|
chain | Named chain: "polygon" (mainnet; the CLI/MCP default), "amoy", "localhost". Fills rpcUrl, registry, resolver, fns defaults |
rpcUrl | Override the JSON-RPC endpoint |
registry | Override the registry contract address (needed only for localhost or a custom deployment) |
ipfsGateway | Gateway for ipfs:// manifests |
timeoutMs | Per-request timeout |
maxManifestBytes | Cap on manifest size (default 256 KiB) |
legacyDns, dohUrl | Opt-in DNS-over-HTTPS fallback for names that predate the registry (off by default) |
resolveAgent(name) → AgentResolutionReturns owner, registered / active / perpetual, records (addr, manifestUri, wallet, endpoints, texts), manifest (+ manifestSource), verified / reasons / signer, and source.
manifest is typed as AgtManifest (spec v3): description, icon, website, endpoints[], capabilities[], pricing (AgtPricing — model is free / freemium / paid / contact), payments[], keys[], delegation, registrations[]. Only trust these fields when verified is true.
isAgent(name) → booleanResolves a name and returns whether it has a valid, verified manifest.
CHAINS exports the deployed Registry v2 addresses, so new AgtResolver({ chain: "polygon" }) is a complete configuration:
| Chain | Registry | Resolver | Migration claim |
|---|---|---|---|
polygon (137) | 0x5B9386C47395B0551c814cC03b69cbD20eb0C87A | 0x66Ae037d2A6a770B4772b889b6cA1704504399f2 | 0x4276d03AcbcA433D257FBd90c53F090F4B16d38E |
amoy (80002) | 0xd08E0d9BCB26572Eaa22fe27Df53a5D2721D3BCD | 0xE02f88b9BC0394742bBBe5c590E043B647B83419 | 0xC79A3fb86BcC3637BB58cDcd1f6E12Cf3fFDCBc8 |
localhost has no defaults; pass { rpcUrl, registry }.
ipfs://, https://, or data:) and verify it — signer, declared owner, and on-chain owner must agree, and ipfs:// bytes must hash to the CID.npx agt-resolve exampleagent.agt
Prints a name's resolution as JSON.
No wallet library, no framework — resolution is raw JSON-RPC plus fetch. The only dependencies are the audited @noble/curves and @noble/hashes primitives (signature recovery and hashing). Runs in Node.js, Deno, Bun, and browsers.
MIT
FAQs
Resolve and verify .agt agent names against AGT Registry v2 (raw JSON-RPC, no wallet library needed)
The npm package @agtnames/resolver receives a total of 99 weekly downloads. As such, @agtnames/resolver popularity was classified as not popular.
We found that @agtnames/resolver demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.