ALMAby AdaSouls

DEVELOPERS / START LOCALLY

Build with ALMA

The protocol libraries are open source (MIT), run in Node and browsers, make no network calls and need no account.

Draft spec alma/v1 · alma-core v0.7.0 · MIT

QUICKSTART / #QUICKSTART

An identity in a few lines

INSTALL / NPM

npm install @adasouls/alma-core

Create an accountable principal, give an agent a persistent identity, delegate narrowly and record evidence.

IDENTITY + AUTHORITY / TYPESCRIPT

import { createIdentity, createDelegation, createRelationship, recordEvidence } from "@adasouls/alma-core";

const org = createIdentity({ subjectType: "organization", displayName: "Acme Labs" });
const agent = createIdentity({ subjectType: "agent", displayName: "Treasury Agent", principal: org.id, controllers: [{ type: "wallet", value: "0x8F12…21C" }] });
const delegation = createDelegation({ issuer: org.id, subject: agent.id, scope: { capabilities: ["pay"], constraints: { maxTransaction: { USDC: "1000" } } }, expiresAt: "2027-01-01T00:00:00Z" });
createRelationship({ from: org.id, to: agent.id, type: "delegates", sourceRef: delegation.id });
recordEvidence({ subject: agent.id, role: "agent", source: { type: "economic-action", reference: "eco_123" }, outcome: "success" });
console.log(org.id); // alma:main:organization:acme-labs
console.log(agent.id); // alma:main:agent:treasury-agent

Sign and verify a receipt

Generate a local test key, bind the issuer’s signature to the exact statement digest, then verify it against an explicitly trusted keyset.

LOCAL TEST / TYPESCRIPT

import { LocalSigner, buildReceiptStatement, receiptDigest, toBaseUnits, signReceiptMint, signReceiptAttestation, createIssuerKeyset, verifyReceipt } from "@adasouls/alma-core";

const issuer = await LocalSigner.generate(); // a local test key; a production key belongs in a KMS
const statement = buildReceiptStatement({
  issuer: "demo-issuer",
  env: "testnet",
  action: "eco_123",
  payer: "alma:main:agent:buyer",
  payee: "alma:main:agent:vendor",
  capability: "pay",
  chain: "eip155:84532",
  asset: "eip155:84532/erc20:0x036cbd53842c5426634e7929541ec2318f3dcf7e",
  amount: toBaseUnits("12.5", 6),
  to: "0x000000000000000000000000000000000000dEaD",
  txHash: "0x" + "ab".repeat(32),
});
const digest = await receiptDigest(statement);
const mint = await signReceiptMint(issuer, { iss: "demo-issuer", receipt: "rcpt_1", digest, independent: true });
const delivery = await signReceiptAttestation(issuer, { iss: "demo-issuer", receipt: "rcpt_1", digest, kind: "delivery", decision: "confirmed", decidedBy: "member", decidedAt: new Date() });
const keyset = await createIssuerKeyset([{ iss: "demo-issuer", publicKey: Buffer.from(issuer.publicKey).toString("base64url") }]);
const result = await verifyReceipt({ id: "rcpt_1", statement, mint, delivery }, keyset);
console.log(result.ok); // true; change any field of the statement and it is false

Small packages, explicit responsibilities

@adasouls/alma-core
Protocol identifiers, identities, delegation, credentials, relationships, evidence, receipts, signatures, reports, deliveries and log.
npm ↗ · GitHub ↗ · v0.7.0
@adasouls/alma-credentials
The interface a credential verifier implements. The verifier it ships is a stub with no cryptography: its “verified” is not a verification claim.
npm ↗ · GitHub ↗ · v0.1.2
@adasouls/alma-manifest
YAML schema, parser and compiler.
npm ↗ · GitHub ↗ · v0.2.1
@adasouls/alma-cli
A local command line, in the repository only. It is not on npm, so there is no npx quickstart yet.
GitHub ↗ · not on npm
@adasouls/protocol
Solidity AlmaAnchorRegistry: optional on-chain anchors for ALMA identifiers. No deployment addresses are published yet.
npm ↗ · GitHub ↗ · v0.1.0, separate repository

The command line runs from a clone of the repository:

CLI / FROM A CLONE

git clone https://github.com/AdaSouls/alma.git
cd alma
npm install
npm run build -w @adasouls/alma-core -w @adasouls/alma-manifest -w @adasouls/alma-cli
node packages/cli/dist/bin.js --help

Put policy beside your agent

The manifest package parses and compiles YAML. Keep identity, capabilities and counterparty requirements readable and versioned.

ALMA.YAML / AGENT MANIFEST

kind: Agent
version: alma/v1
metadata:
  name: treasury-agent
identity:
  type: agent
capabilities:
  - pay
authority:
  maxTransaction:
    USDC: "1000"
counterpartyPolicy:
  minCompletedTransactions: 20
  minReputationEvidence:
    disputeRate: 0.02
  requiredCredentials:
    - kyb_verified

PARSE + COMPILE / TYPESCRIPT

import { readFileSync } from "node:fs";
import { parseManifestYaml, compileManifest } from "@adasouls/alma-manifest";

const manifest = parseManifestYaml(readFileSync("alma.yaml", "utf8")); // throws AlmaValidationError on a bad manifest
const compiled = compileManifest(manifest);
console.log(compiled.delegation.scope); // { capabilities: [ 'pay' ] }
console.log(compiled.counterpartyPolicy.rules.minCompletedTransactions); // 20

The thresholds are one application’s choice, not protocol defaults. Compiling produces plain objects and makes no network calls: applying them is the caller’s job. The schema is in packages/alma-manifest ↗.

Reference, without false readiness

Going further

NO ACCOUNT

Local protocol

Use alma-core to model identity, check delegations and verify evidence. Rank agents with your own rules.

OPTIONAL / ADASOULS

Hosted enforcement

Payments, policies, issued receipts and marketplace access through the SDK and the MCP server. @adasouls/sdk v0.5 and @adasouls/mcp v0.4 are on npm. The hosted API is not open yet.

AdaSouls Developers ↗

Contribute to the protocol

Open issues ↗, propose spec changes and include changesets for versioned releases. The code is MIT licensed. Discuss interoperability and evidence semantics in the open.