
Product
Microsoft Teams Notifications Are Now Available in Socket
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.
@provenonce/sdk
Advanced tools
Provenonce Beat SDK — Agent heartbeat client for sovereign time authentication
Cryptographic identity and accountability SDK for AI agents. Chain-agnostic (Solana + Ethereum).
npm install @provenonce/sdk
Before using the SDK, register your agent to get an API key:
import { register } from '@provenonce/sdk';
// No-wallet registration (default — identity only)
const creds = await register('my-agent-v1', {
registryUrl: 'https://provenonce.io',
registrationSecret: process.env.REGISTRATION_SECRET, // required in production
});
console.log(creds.hash); // unique agent identity
console.log(creds.api_key); // use this for BeatAgent
console.log(creds.secret); // save — shown only once
// Solana self-custody wallet (opt-in)
const withWallet = await register('my-org', {
registryUrl: 'https://provenonce.io',
walletModel: 'self-custody',
});
// withWallet.wallet.address = Solana address
// withWallet.wallet.secret_key = SAVE — cannot be recovered
// Child registration (requires parent credentials)
const child = await register('worker-1', {
registryUrl: 'https://provenonce.io',
parentHash: creds.hash,
parentApiKey: creds.api_key,
});
import { BeatAgent } from '@provenonce/sdk';
const agent = new BeatAgent({
apiKey: 'pvn_...',
registryUrl: 'https://provenonce.io',
verbose: true,
});
await agent.init(); // Birth in Beat time
// Purchase a SIGIL (cryptographic identity)
const sigil = await agent.purchaseSigil({
identityClass: 'autonomous',
paymentTx: 'solana-tx-signature...',
});
// Start heartbeating (paid liveness proofs)
agent.startHeartbeat();
// Get your Passport (latest lineage proof)
const passport = await agent.getPassport();
console.log(passport?.identity_class); // 'autonomous'
console.log(passport?.provenonce_signature); // Ed25519 signed
// Verify any proof offline — no API call needed
const valid = BeatAgent.verifyProofLocally(passport, authorityPubKeyHex);
agent.stopHeartbeat();
BeatAgent| Method | Description |
|---|---|
init() | Initialize the agent's Beat chain (birth in Logical Time) |
purchaseSigil(opts) | Purchase a SIGIL identity (required for heartbeating) |
heartbeat(opts?) | Submit a paid heartbeat and receive a signed lineage proof |
startHeartbeat() | Start autonomous heartbeat loop |
stopHeartbeat() | Stop heartbeat |
getPassport() | Get latest lineage proof (Passport) |
reissueProof(paymentTx?) | Reissue proof without extending lineage |
requestSpawn(name?) | Spawn a child agent (requires accumulated beats) |
getStatus() | Get full beat status from registry |
getLocalState() | Get local state (no network call) |
static verifyProofLocally(proof, pubKey) | Verify a lineage proof offline |
BeatAgentConfig| Option | Default | Description |
|---|---|---|
apiKey | required | API key from registration (pvn_...) |
registryUrl | required | Provenonce registry URL |
heartbeatIntervalSec | 300 | Seconds between automatic heartbeats |
onHeartbeat | — | Callback when heartbeat completes |
onError | — | Callback on error |
onStatusChange | — | Callback when status changes |
verbose | false | Enable console logging |
register(name, options)| Option | Description |
|---|---|
registryUrl | Registry URL (required) |
registrationSecret | Registration gate (mainnet) |
walletModel | 'self-custody' or 'operator' (opt-in wallet) |
walletChain | 'solana' or 'ethereum' |
walletAddress | Ethereum BYO address |
walletSignFn | Signing function for BYO wallets |
parentHash | Parent hash (child registration) |
parentApiKey | Parent's API key (child registration) |
Returns RegistrationResult with hash, api_key, secret, wallet?.
Note: Agent names should only contain [a-zA-Z0-9_\-. ]. Other characters are stripped by the server before signature verification.
import type { Passport, LineageProof, IdentityClass, SigilResult, HeartbeatResult } from '@provenonce/sdk';
// Passport = LineageProof (type alias)
// Contains: agent_hash, agent_public_key, identity_class, lineage_chain_hash,
// provenonce_signature, issued_at, valid_until, etc.
// IdentityClass = 'narrow_task' | 'autonomous' | 'orchestrator'
import { ProvenonceError, AuthError, RateLimitError, FrozenError, ErrorCode } from '@provenonce/sdk';
try {
await agent.heartbeat();
} catch (err) {
if (err instanceof RateLimitError) {
console.log(`Retry after ${err.retryAfterMs}ms`);
} else if (err instanceof FrozenError) {
console.log('Agent is frozen — heartbeat refused');
} else if (err instanceof AuthError) {
console.log('Invalid API key');
}
}
Ready-to-run examples for popular agent frameworks are in examples/:
| Framework | File | What it shows |
|---|---|---|
| CrewAI | crewai_example.py | Register a research crew with parent-child lineage |
| AutoGen | autogen_example.py | Coder + reviewer agents with post-run provenance audit |
| LangGraph | langgraph_example.py | Pipeline nodes with on-chain audit trail |
| Any (Node.js) | add-provenonce.ts | 20-line generic integration |
Python examples use the REST API directly — no Python SDK needed. See examples/README.md for details.
FAQs
Provenonce Beat SDK — Agent heartbeat client for sovereign time authentication
The npm package @provenonce/sdk receives a total of 5 weekly downloads. As such, @provenonce/sdk popularity was classified as not popular.
We found that @provenonce/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.