⬡ love-package/v1 · public static distribution

Packages without permission slips.

Discover an exact version, read its manifest, and install through ordinary HTTPS or the optional public npm mirror. LOVE packages are Locator-independent, Open, Verifiable, and Exchangeable. npm is a convenient entrance, not release authority or a prerequisite for access.

The package is a set of bytes, not an account relationship. Anyone can fetch it; verified mirrors can serve the same bytes.

No signup and no npm account. The catalog, manifests, and artifacts are public GET and HEAD resources. Pin an exact version in automation. The AgentTool catalog exposes no mutable latest artifact URL.

Install an exact version

Use an exact npm mirror when that registry carries it, or install the immutable LOVE tarball when you want an explicit locator and verification path. Either route keeps the declared scoped package name, so application imports stay unchanged.

PackageReleaseManifest
@agenttool/data0.3.1inspect JSON
@agenttool/data-sync0.1.2inspect JSON
@agenttool/credential-broker0.3.1inspect JSON
@agenttool/sdk0.18.0inspect JSON
@agenttool/wallet0.1.3inspect JSON
@agenttool/wallet-zerone0.1.2inspect JSON
@agenttool/telescope0.2.3inspect JSON
@agenttool/browser0.6.0inspect JSON
@agenttool/adds0.2.3inspect JSON

Optional npm convenience. Registry mirrors can lag or omit an exact LOVE release; query the requested version directly. Pin the complete version when it exists. npm search results and the mutable latest dist-tag are not AgentTool release authority. The LOVE manifest remains the release record and high-trust path because it names the expected byte size and SHA-256.

npm · exact registry mirrors (availability may lag)
npm install --save-exact @agenttool/adds@0.2.3
npm install --save-exact @agenttool/data@0.3.1
npm install --save-exact @agenttool/data-sync@0.1.2
npm install --save-exact @agenttool/credential-broker@0.3.1
npm install --save-exact @agenttool/sdk@0.18.0
npm install --save-exact @agenttool/wallet@0.1.3 @agenttool/wallet-zerone@0.1.2
npm install --save-exact @agenttool/telescope@0.2.3
npm install --save-exact @agenttool/browser@0.6.0
npm-only · exact reviewed releases
npm install --save-exact @agenttool/collab@0.4.0
npm install --save-exact @agenttool/kingdom@0.1.0
npm install --save-exact @agenttool/skills@0.3.0
npm install --save-exact @agenttool/alchemy@0.1.0-dev.0 @agenttool/credential-broker@0.3.1 @agenttool/alchemy-agentcred@0.1.0-dev.0

npm-only receipt boundary. Collab 0.4.0, KINGDOM 0.1.0, Agent Skills 0.3.0, and the Alchemy/AgentCred developer-preview pair have no LOVE inventory entry. Collab protected run 30906798360 published and read back byte-identical 303,376-byte GitHub/npm tarballs with SHA-256 1a9c1830ec9326351a475596820780ad7f93c7dfe16a6f1a9eb74bc08edbdb51; npm latest resolved to 0.4.0, and its exact SLSA provenance is recorded at Sigstore log index 2340231720. See the Collab receipt and the earlier release train for the canonical evidence. Alchemy and AgentCred requested npm next; npm also exposes each sole initial prerelease through latest, which is not a maturity signal. These packages provide local libraries, coordination, inspection, and explicit sidecar workflows; installation does not activate a skill, create a hidden model channel, issue a grant, reveal a credential, contact Alchemy or a chain, or deploy a hosted service.

Credential broker mirror boundary. The current checked-in exact LOVE release is @agenttool/credential-broker@0.3.1. Protected run 30492737828 published and read back byte-identical GitHub Release and npm mirrors of the 158,450-byte LOVE artifact with SHA-256 d05458b27b8832af7996c243abb22e3b400e5810fe5377ba58e1cb587d2461d8. npm latest resolved to 0.3.1 at that readback, but remains mutable and non-authoritative.

SDK mirror boundary. The current TypeScript LOVE line is @agenttool/sdk@0.18.0: 211,695 bytes with SHA-256 8e6bbe42f76decd1448dd07465840339e5b055abba0317b3d04f4f506e44616a, built from source revision bf708e4897f2bd509dfba9d559730a1e2dcb6698. It adds paired attestation-marketplace, memory-witness, and Syneidesis clients, shared URL/error boundaries, selected cross-language fixtures, and an explicit model-authored chronicle-write review hook. Annotated sdk-v0.18.0 peels to GitHub main merge 499cc5d7910b9fcf3507bd3599778dab83733009. Protected run 30909424114 published and independently read back byte-identical GitHub Release and npm mirrors; npm latest resolved to 0.18.0, with SLSA provenance at Sigstore log index 2340396627. PyPI 0.18.0 returned 404 at the 2026-08-04 readback, and deployment remains a separate observation. Exact 0.17.0 records remain immutable historical evidence.

Telescope mirror boundary. The current exact LOVE release is @agenttool/telescope@0.2.3. Its npm and GitHub 0.2.3 mirrors are public and independently byte-verified, so the command above names that exact version. Use the 0.2.3 LOVE URL below when you want the manifest-bound verification path.

ADDS/data-sync repair boundary. The checked-in catalog line @agenttool/adds@0.2.3 followed by @agenttool/data-sync@0.1.2 is public through the annotated ADDS and data-sync GitHub Releases and the exact npm versions. Protected runs 30495292940 and 30495589179 published and read back byte-identical mirrors: ADDS is 89,285 bytes with SHA-256 3fe42c4457e38f1fcdbc437c22c762ea7dabfe898714ec395287608a0480ea2b; data-sync is 59,774 bytes with SHA-256 37b69b13db60eafc4a0bae578faca14467c0844e4f4c32793808b3499bcd8fd6. npm latest currently resolves to those exact versions, but remains mutable and non-authoritative. ADDS now requires Noble Ed25519 ^2.3.0. Its immutable 0.2.2 predecessor could resolve Noble 2.2.3 and reject otherwise valid signatures because that dependency lacked the verifier's Point API; it did not accept invalid signatures. Data-sync peers on repaired ADDS ^0.2.3 plus data ^0.3.1, enforces exact sync manifest labels and matching event/payload times under the reference node's strict uppercase, non-leap-second RFC 3339 profile, and aligns its explicit maximum plaintext page with the default data-node 10 MiB record ceiling. Both current tarballs embed TypeScript text in JavaScript source maps and omit dangling declaration maps.

Wallet mirror boundary. The current catalog line is @agenttool/wallet@0.1.3 plus @agenttool/wallet-zerone@0.1.2. Protected runs 30491887230 and 30494659977 published and read back byte-identical GitHub/npm mirrors of their exact LOVE artifacts: Wallet is 52,837 bytes with SHA-256 33f3b81cfcc12882cb98dfd11b215fa4d3cbd963efc575e41ed54e05f132ae87; Zerone is 61,695 bytes with SHA-256 bc43b8be96dcc74a866926c9f5d98c00af9d8c4682cbb6f36ef77a7adbbaa8cc. Historical Wallet 0.1.1/0.1.2 and Zerone 0.1.0/0.1.1 LOVE artifacts remain hash-pinned and are not rewritten. Zerone run 30492436839 failed in credential-free preparation before any 0.1.1 GitHub/npm mutation; 0.1.2 is the new immutable release identity, not a moved tag. The adapter locks public Wallet 0.1.3 only for development while retaining the ^0.1.2 consumer peer.

Runtime boundary. npm is only the installer here; @agenttool/data and @agenttool/data-sync require Bun ≥1.3 at runtime. The credential broker, Agent Wallet, Wallet Zerone, Telescope, and Agent Browser support Node ≥20.19 or Bun ≥1.3.5. Wallet Zerone declares the compatible Wallet ^0.1.2 peer, which includes current Wallet 0.1.3, and uses injected host transports; it supplies no key custody, RPC endpoint, deployed bridge, or hosted chain service. Agent Browser additionally drives a compatible Chrome-family browser already installed on the operator's machine; installing the package does not download one.

An npm install uses registry integrity machinery but does not independently compare the downloaded bytes with the LOVE manifest's artifact.size and artifact.sha256. Use the verified workflow below when that boundary matters.

@agenttool/data · 0.3.1 · local node + conformance + replica seams
bun add https://docs.agenttool.dev/packages/v1/@agenttool/data/0.3.1/agenttool-data-0.3.1.tgz

import { DataNode } from "@agenttool/data";
@agenttool/sdk · 0.18.0 · paired evidence and witness clients
bun add https://docs.agenttool.dev/packages/v1/@agenttool/sdk/0.18.0/agenttool-sdk-0.18.0.tgz

import { AgentTool, KingdomFrameworkClient } from "@agenttool/sdk";

const card = await new KingdomFrameworkClient().card();
@agenttool/credential-broker · 0.3.1 · scoped local credential use + resumable managed handoff
bun add https://docs.agenttool.dev/packages/v1/@agenttool/credential-broker/0.3.1/agenttool-credential-broker-0.3.1.tgz

import { AgentCredClient } from "@agenttool/credential-broker";
@agenttool/adds · 0.2.3 · experimental adds/v0.1 package
bun add https://docs.agenttool.dev/packages/v1/@agenttool/adds/0.2.3/agenttool-adds-0.2.3.tgz

import { AgentData } from "@agenttool/adds";
@agenttool/data-sync · 0.1.2 · bounded encrypted pull bridge
bun add \
  https://docs.agenttool.dev/packages/v1/@agenttool/adds/0.2.3/agenttool-adds-0.2.3.tgz \
  https://docs.agenttool.dev/packages/v1/@agenttool/data/0.3.1/agenttool-data-0.3.1.tgz \
  https://docs.agenttool.dev/packages/v1/@agenttool/data-sync/0.1.2/agenttool-data-sync-0.1.2.tgz

import { DataSyncService } from "@agenttool/data-sync";
@agenttool/telescope · 0.2.3 · canonical discovery evidence + local MCP/Skill
bun add https://docs.agenttool.dev/packages/v1/@agenttool/telescope/0.2.3/agenttool-telescope-0.2.3.tgz

import { inspectTarget } from "@agenttool/telescope";

Telescope 0.2.3 accepts only three complete, positive exit phrases, rejects negated or incomplete wording, and accepts URI fragments on credential-free HTTPS catalog relation targets. Immutable 0.2.2 remains separately available with its historical permissive token-matching flaw. The current AgentTool producer remains compatible with immutable 0.2.1. No catalog member is followed, and the release adds no probe or automatic follow-up.

@agenttool/wallet · 0.1.3 · capability-bounded offline wallet records
bun add https://docs.agenttool.dev/packages/v1/@agenttool/wallet/0.1.3/agenttool-wallet-0.1.3.tgz

import { verifyWalletDescriptor } from "@agenttool/wallet";
@agenttool/wallet-zerone · 0.1.2 · exact offline Zerone profile
bun add \
  https://docs.agenttool.dev/packages/v1/@agenttool/wallet/0.1.3/agenttool-wallet-0.1.3.tgz \
  https://docs.agenttool.dev/packages/v1/@agenttool/wallet-zerone/0.1.2/agenttool-wallet-zerone-0.1.2.tgz

import { createZeroneDirectSignPlan } from "@agenttool/wallet-zerone";
@agenttool/browser · 0.6.0 · local control + direct understanding
bun add https://docs.agenttool.dev/packages/v1/@agenttool/browser/0.6.0/agenttool-browser-0.6.0.tgz

import { AgentBrowser } from "@agenttool/browser";
import { analyzeBrowserMaterial } from "@agenttool/browser/understanding";

Browser 0.6.0 understanding boundary. The nine-operation local runtime and package-root Codex plugin remain unchanged. A direct-only subpath binds exact observed text to Browser provenance, runs RhetorLint locally, and accepts one caller-injected, full-revision Hugging Face model observation behind literal remote disclosure. It adds no MCP tool, model, token, automatic network call, truth verdict, hosted service, or wider browser authority.

The same HTTPS tarballs remain directly consumable by package managers that support URL dependencies. For example, npm install https://…/agenttool-data-0.3.1.tgz uses the npm client without relying on registry publication.

This catalog contains the nine JavaScript packages above. Python is not mirrored through this catalog: independently verified annotated tag sdk-v0.18.0 is the current source locator and peels to merge 499cc5d7910b9fcf3507bd3599778dab83733009. PyPI 0.18.0 is optional and returned 404 at the 2026-08-04 public readback; use python -m pip install "agenttool-sdk==0.18.0" only after https://pypi.org/pypi/agenttool-sdk/0.18.0/json returns that exact release. The verified 0.17.0 source/PyPI receipts remain historical evidence.

!

Easy path versus verified path. An exact npm install or direct bun add https://…tgz is an explicit operator install, but LOVE does not claim that either package manager checks the sibling manifest's size and digest. For a conforming high-trust install, download to a temporary file, verify both values yourself, then give that verified local file to package machinery.

Dependency boundary. @agenttool/data and @agenttool/telescope have no third-party runtime dependencies. The SDK, Agent Wallet, Wallet Zerone, and ADDS artifacts declare upstream dependencies; Wallet Zerone additionally peers on Wallet ^0.1.2 and accepts current 0.1.3, while @agenttool/data-sync@0.1.2 peers on @agenttool/adds@^0.2.3 and @agenttool/data@^0.3.1. Agent Browser declares playwright-core, @modelcontextprotocol/server, zod, and exact RhetorLint 0.1.2 packages; it neither bundles nor downloads Chrome or a model. Install the paired peer artifacts explicitly when using Wallet Zerone or data-sync. A fresh install may otherwise resolve dependencies through your package manager's configured registry or cache. love-package/v1 distributes the named artifact—it does not vendor its dependency graph or promise an offline install.

Discover it as an agent

The well-known document is the stable entry point. It names the protocol and doctrine, points to the versioned catalog, and advertises optional registry locators. Its registry_role and every registry mirror's authority: false keep those convenience channels separate from package and release authority.

HTTP · no auth
# Stable discovery door
curl -fsS https://docs.agenttool.dev/.well-known/love-packages

# This origin's mirror catalog
curl -fsS https://docs.agenttool.dev/packages/v1/index.json

# One exact release
curl -fsS https://docs.agenttool.dev/packages/v1/@agenttool/data/0.3.1/manifest.json
discovery document · stable fields
{
  "protocol": "love-package/v1",
  "doctrine": "https://docs.agenttool.dev/LOVE-PACKAGE-PROTOCOL.md",
  "index_url": "https://docs.agenttool.dev/packages/v1/index.json",
  "access": "public_read",
  "registry_role": "mirror_index_not_authority",
  "registry_mirrors": [{
    "ecosystem": "npm",
    "registry_url": "https://registry.npmjs.org/",
    "authority": false
  }]
}
ResourceChanges?Job
/.well-known/love-packagesMay point at a newer catalogOrigin discovery plus optional non-authoritative registry locators. Start here when the origin is all you know.
/packages/v1/index.jsonRevalidatable locator indexLists package labels, available versions, and their manifest locations. It is not ownership authority.
…/{version}/manifest.jsonRevalidatable release recordBinds package labels and claimed source to an installable artifact, its mirrors, size, media type, and digest. Pin the fields you trust.
…/{version}/*.tgzImmutable for that versionThe installable package bytes.

What one release manifest carries

A manifest declares protocol, document_type: "package-manifest", name, version, description, nullable license, artifact, runtime, install, and source. Indexes use the distinct document_type: "package-index", so an agent can select the correct schema before reading either shape. The artifact record uses format: "npm-tarball" as a file-format label; that field alone does not prove registry publication. Read the optional well-known mirror metadata and query the exact registry version instead.

Verify before install

Read the sibling manifest over HTTPS, copy its size and SHA-256 value, download the artifact, and compare both locally before extraction or installation. This catches truncation, cache corruption, and artifact substitution that does not also replace the manifest.

macOS / Unix shell · exact bytes
base=https://docs.agenttool.dev/packages/v1/@agenttool/data/0.3.1
curl -fsS "$base/manifest.json"

expected_size='<artifact.size from manifest.json>'
expected_sha256='<artifact.sha256 from manifest.json>'
curl -fsSLo agenttool-data-0.3.1.tgz "$base/agenttool-data-0.3.1.tgz"
actual_size=$(wc -c < agenttool-data-0.3.1.tgz | tr -d '[:space:]')
actual_sha256=$(shasum -a 256 agenttool-data-0.3.1.tgz | awk '{print $1}')
test "$actual_size" = "$expected_size" &&
  test "$actual_sha256" = "$expected_sha256" &&
  bun add ./agenttool-data-0.3.1.tgz
!

What the digest proves. A matching SHA-256 proves that the downloaded bytes match the manifest you read. HTTPS authenticates the origin during that fetch. Version 1 manifests are not signed, so a digest does not prove maintainer identity if an attacker can replace both manifest and artifact. Installing any package still executes code under the package manager's rules. Review source and pin trusted manifest bytes where that threat matters.

Mirror without becoming a gatekeeper

An artifact mirror serves a byte-identical copy from another locator. A full catalog mirror can additionally copy the index and manifests. Consumers can choose another HTTPS origin while retaining the package name, version, size, and digest. This site is a convenient origin, not a protocol requirement.

love-package/v1 shape
/.well-known/love-packages
/packages/v1/index.json
/packages/v1/@agenttool/data/0.1.0/
  ├── manifest.json
  └── agenttool-data-0.1.0.tgz
/packages/v1/@agenttool/data/0.2.0/
  ├── manifest.json
  └── agenttool-data-0.2.0.tgz
/packages/v1/@agenttool/data/0.3.0/
  ├── manifest.json
  └── agenttool-data-0.3.0.tgz
/packages/v1/@agenttool/data/0.3.1/
  ├── manifest.json
  └── agenttool-data-0.3.1.tgz
/packages/v1/@agenttool/data-sync/0.1.0/
  ├── manifest.json
  └── agenttool-data-sync-0.1.0.tgz
/packages/v1/@agenttool/data-sync/0.1.1/
  ├── manifest.json
  └── agenttool-data-sync-0.1.1.tgz
/packages/v1/@agenttool/data-sync/0.1.2/
  ├── manifest.json
  └── agenttool-data-sync-0.1.2.tgz
/packages/v1/@agenttool/credential-broker/0.1.0/
  ├── manifest.json
  └── agenttool-credential-broker-0.1.0.tgz
/packages/v1/@agenttool/credential-broker/0.3.0/
  ├── manifest.json
  └── agenttool-credential-broker-0.3.0.tgz
/packages/v1/@agenttool/credential-broker/0.3.1/
  ├── manifest.json
  └── agenttool-credential-broker-0.3.1.tgz
/packages/v1/@agenttool/sdk/0.9.0/
  ├── manifest.json
  └── agenttool-sdk-0.9.0.tgz
/packages/v1/@agenttool/sdk/0.10.0/
  ├── manifest.json
  └── agenttool-sdk-0.10.0.tgz
/packages/v1/@agenttool/sdk/0.11.0/
  ├── manifest.json
  └── agenttool-sdk-0.11.0.tgz
/packages/v1/@agenttool/sdk/0.12.0/
  ├── manifest.json
  └── agenttool-sdk-0.12.0.tgz
/packages/v1/@agenttool/sdk/0.13.0/
  ├── manifest.json
  └── agenttool-sdk-0.13.0.tgz
/packages/v1/@agenttool/sdk/0.14.0/
  ├── manifest.json
  └── agenttool-sdk-0.14.0.tgz
/packages/v1/@agenttool/sdk/0.15.0/
  ├── manifest.json
  └── agenttool-sdk-0.15.0.tgz
/packages/v1/@agenttool/sdk/0.16.0/
  ├── manifest.json
  └── agenttool-sdk-0.16.0.tgz
/packages/v1/@agenttool/sdk/0.16.1/
  ├── manifest.json
  └── agenttool-sdk-0.16.1.tgz
/packages/v1/@agenttool/sdk/0.16.2/
  ├── manifest.json
  └── agenttool-sdk-0.16.2.tgz
/packages/v1/@agenttool/sdk/0.16.3/
  ├── manifest.json
  └── agenttool-sdk-0.16.3.tgz
/packages/v1/@agenttool/sdk/0.16.4/
  ├── manifest.json
  └── agenttool-sdk-0.16.4.tgz
/packages/v1/@agenttool/sdk/0.16.5/
  ├── manifest.json
  └── agenttool-sdk-0.16.5.tgz
/packages/v1/@agenttool/sdk/0.17.0/
  ├── manifest.json
  └── agenttool-sdk-0.17.0.tgz
/packages/v1/@agenttool/sdk/0.18.0/
  ├── manifest.json
  └── agenttool-sdk-0.18.0.tgz
/packages/v1/@agenttool/telescope/0.1.0/
  ├── manifest.json
  └── agenttool-telescope-0.1.0.tgz
/packages/v1/@agenttool/telescope/0.2.0/
  ├── manifest.json
  └── agenttool-telescope-0.2.0.tgz
/packages/v1/@agenttool/telescope/0.2.1/
  ├── manifest.json
  └── agenttool-telescope-0.2.1.tgz
/packages/v1/@agenttool/telescope/0.2.2/
  ├── manifest.json
  └── agenttool-telescope-0.2.2.tgz
/packages/v1/@agenttool/telescope/0.2.3/
  ├── manifest.json
  └── agenttool-telescope-0.2.3.tgz
/packages/v1/@agenttool/wallet/0.1.0/
  ├── manifest.json
  └── agenttool-wallet-0.1.0.tgz
/packages/v1/@agenttool/wallet/0.1.1/
  ├── manifest.json
  └── agenttool-wallet-0.1.1.tgz
/packages/v1/@agenttool/wallet/0.1.2/
  ├── manifest.json
  └── agenttool-wallet-0.1.2.tgz
/packages/v1/@agenttool/wallet/0.1.3/
  ├── manifest.json
  └── agenttool-wallet-0.1.3.tgz
/packages/v1/@agenttool/wallet-zerone/0.1.0/
  ├── manifest.json
  └── agenttool-wallet-zerone-0.1.0.tgz
/packages/v1/@agenttool/wallet-zerone/0.1.1/
  ├── manifest.json
  └── agenttool-wallet-zerone-0.1.1.tgz
/packages/v1/@agenttool/wallet-zerone/0.1.2/
  ├── manifest.json
  └── agenttool-wallet-zerone-0.1.2.tgz
/packages/v1/@agenttool/browser/0.1.0/
  ├── manifest.json
  └── agenttool-browser-0.1.0.tgz
/packages/v1/@agenttool/browser/0.2.0/
  ├── manifest.json
  └── agenttool-browser-0.2.0.tgz
/packages/v1/@agenttool/browser/0.3.0/
  ├── manifest.json
  └── agenttool-browser-0.3.0.tgz
/packages/v1/@agenttool/browser/0.5.0/
  ├── manifest.json
  └── agenttool-browser-0.5.0.tgz
/packages/v1/@agenttool/browser/0.5.1/
  ├── manifest.json
  └── agenttool-browser-0.5.1.tgz
/packages/v1/@agenttool/browser/0.6.0/
  ├── manifest.json
  └── agenttool-browser-0.6.0.tgz
/packages/v1/@agenttool/adds/0.1.0/
  ├── manifest.json
  └── agenttool-adds-0.1.0.tgz
/packages/v1/@agenttool/adds/0.2.0/
  ├── manifest.json
  └── agenttool-adds-0.2.0.tgz
/packages/v1/@agenttool/adds/0.2.1/
  ├── manifest.json
  └── agenttool-adds-0.2.1.tgz
/packages/v1/@agenttool/adds/0.2.2/
  ├── manifest.json
  └── agenttool-adds-0.2.2.tgz
/packages/v1/@agenttool/adds/0.2.3/
  ├── manifest.json
  └── agenttool-adds-0.2.3.tgz

Four standards, four jobs

StandardWhat it moves or describesWhat it does not imply
love-package/v1 Package discovery, exact release manifests, install artifact locations, and byte integrity. No code sandbox, dependency vendoring, runtime API, data replication, or durability guarantee.
agent-data/v1 Collections, immutable records, local query, collectors, blobs, and an append-only change feed. Installing its reference package does not create hosted storage or peer synchronization.
adds/v0.1
experimental
Encrypted content-addressed Blocks plus signed Manifests and direct read Grants. Package distribution is not encrypted-object distribution, and ADDS has no peer discovery in this profile.
agent-data-sync/v1 Bounded encrypted pull between explicit operator-configured peers, with private resumable checkpoints. No discovery, push, consensus, hosted sync service, or multi-master consistency.

In one line: love-package/v1 gets software onto a machine; agent-data/v1 lets an agent keep and query a corpus; adds/v0.1 lets exact encrypted objects move independently; agent-data-sync/v1 composes them into one explicit bounded pull path.

References