
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Typed client for Ausca metered agent infrastructure services: catalog-bound invocations paid per call under a hard USD cap, through pluggable payment authorities (x402 v2 today), with receipt-backed results.
The typed engine behind the ausca front door: catalog-bound invocations of Ausca metered agent infrastructure services, paid per call under a hard USD cap, with receipt-backed results.
Most consumers want the ausca package, which re-exports this entire
surface and adds the CLI and local MCP server. Depend on @ausca/sdk
directly when you only need the library.
import { AuscaClient } from "@ausca/sdk";
const client = AuscaClient.withLocalKey({
privateKey: process.env.AUSCA_PRIVATE_KEY,
maxPaymentUsd: 0.5,
});
const offer = await client.offer("document.ocr");
const price = await client.price("document.ocr");
const outcome = await client.invoke("document.ocr", { artifact });
const state = await client.invocation("inv_...");
The envelope carries the offer's immutable revision, schema digests, and
canonicalizer exactly as the catalog declares. Each invoke starts with a
fresh idempotency key. For recovery after an uncertain response, retry with
the same caller-owned idempotencyKey; use a new key for a new intentional
purchase, even when the input is identical.
The client pays through a PaymentAuthority, a small port any rail can
implement: wrap a fetch so 402 challenges are paid within policy, and decode
settlement evidence from the response. Built in:
localKeyAuthority({ privateKey, maxPaymentUsd, network? }): x402 v2 with
a local signing key via the official @x402/* libraries.x402Authority(config): the official x402 client configuration passed
through verbatim, so any registered scheme client works.inertAuthority(): pays nothing; reads and price discovery.Caps are enforced inside the authority before anything is signed.
Artifact-backed offers take an immutable input commitment.
client.commit(bytes, mediaType) uses Ausca's keyless temporary ingress and
creates a fresh temporary commitment on every call. Pass
{ idempotencyKey: "..." } only to recover the same uncertain upload. The
client verifies the returned digest-backed evidence and returns the commitment
the invocation input carries. No account or API token is needed.
ArtifactStore remains the narrow port for a custom storage policy.
Successful paid state includes receipt_ref.public_url, an immutable
hash-only proof of the Ausca service, public price, completion time, and
receipt digest. It contains no request or result bytes, content digests, or
access capabilities. Anyone holding the unguessable URL can read it.
A result larger than the offer's inline bound arrives as output_artifact
instead of output. client.artifactAccess(artifactRef) mints a 60-second
download URL for it; verify the bytes against contentDigest. A failed
invocation carries failure.code and failure.message.
@ausca/sdk/testkit ships an in-process x402 v2 resource and an
Ausca-shaped service fixture (catalog, schema, payable route, invocation
read) for offline test suites. No chain is involved.
MIT
FAQs
Typed client for Ausca metered agent infrastructure services: catalog-bound invocations paid per call under a hard USD cap, through pluggable payment authorities (x402 v2 today), with receipt-backed results.
The npm package @ausca/sdk receives a total of 383 weekly downloads. As such, @ausca/sdk popularity was classified as not popular.
We found that @ausca/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.