New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@spoolis/outcome

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@spoolis/outcome

Verify signed Spoolis Outcome Receipts offline.

latest
Source
npmnpm
Version
0.1.2
Version published
Weekly downloads
18
-88.96%
Maintainers
1
Weekly downloads
 
Created
Source

Outcome receipt verification

An Outcome Receipt is the signed record of what passed the agreed acceptance policy and what was earned.

Install

npm install @spoolis/outcome

Verify offline

Fetch the published keys once, select and pin the trust entry your application accepts, then store it with your application:

const keys = await fetch('https://spoolis.com/.well-known/spoolis-keys.json')
  .then((response) => response.json())

const trustEntry = keys.receipts.production.find(
  (entry) => entry.key_id === 'your-approved-key-id',
)

// Persist trustEntry in your application configuration before going offline.

After pinning the entry, verification makes no network calls:

import { readFile } from 'node:fs/promises'
import { verifyOutcome } from '@spoolis/outcome'

const receipt = JSON.parse(await readFile('outcome-receipt.json', 'utf8'))
const trustSet = [pinnedTrustEntry]

const result = await verifyOutcome(receipt, {
  trustSet,
  environment: 'production',
})

The caller supplies the trust set. This package does not fetch or broaden it.

Verification is offline by default. When a consumer must not act on a superseded receipt, fetch its current status and require that source:

// fetchReceiptStatus is re-exported from @spoolis/receipt-verifier and throws
// on a network or malformed response; an undefined status source makes
// require_current fail closed with status_source_required.
const status = await fetchReceiptStatus('https://spoolis.com', receipt.id).catch(() => undefined)
const gate = await requireOutcome(receipt, { minimum_status: 'pass', require_current: true }, { trustSet, statusSource: status })

CLI

npx -y @spoolis/cli outcome verify outcome-receipt.json

Read the Outcome Receipt documentation or inspect the Outcome Receipt schema.

FAQs

Package last updated on 16 Sep 2026

Related posts