This source candidate declares SDK peer ^2.4.1 || ^3.0.0. SDK3 remains
a coordinated proposal; see the qualification and migration limits
before adopting it.
Browser- and Node-compatible BRC-167 reference implementation for progressively publishing and resiliently resolving large UHRP-addressed byte streams.
npm install @bsv/chirp @bsv/sdkimport { CHIRPUploader, CHIRPDownloader } from '@bsv/chirp'
const publication = await new CHIRPUploader({
wallet,
storageURLs: ['https://storage-a.example', 'https://storage-b.example'],
resilienceLevel: 2
}).publish({
source: file.stream(),
logicalLength: file.size,
retentionSeconds: 2_592_000,
mediaType: file.type || undefined
})
const downloader = new CHIRPDownloader({ concurrency: 4 })
for await (const chunk of downloader.stream(publication.chirpURL)) {
consume(chunk.data)
}ls_uhrp servicecontentHash verification for complete streamschirp CLIBlob and ReadableStream plus Node AsyncIterable byte-source adaptersCHIRP is additive. It does not change StorageUploader, StorageDownloader,
StorageUtils, uhrp: identifiers, tm_uhrp, ls_uhrp, or existing storage-
server routes. The maintained filesystem and cloud-bucket servers expose CHIRP
under /chirp/v1 and publish roots as ordinary BRC-26 advertisements only
after validating the complete transitive closure.
The package reports profileCanonical: false when it safely resolves a future
chunking profile whose profile-specific construction it cannot yet validate.
Unknown critical extensions and unsupported node or child kinds fail closed.
Authenticated uploads send Content-Type: application/octet-stream; the HTTP
transport supplies content length and an absent content encoding means identity.
This keeps SDK AuthFetch signing within its supported header contract.
download() or another atomic sink when early consumption is unsafe.mediaType is untrusted advisory metadata and does not authorize rendering
or execution.urlPolicy; the CLI rejects non-public DNS by default.Set resilienceLevel to the number of complete hosts required before
publication succeeds, protect and retain resumable upload checkpoints, and
monitor root retention and renewal. Bound readers by logical and object bytes,
object count, depth, redirects, retries, concurrency, and cache use. A
server-side urlPolicy must constrain DNS and pin the connected address; a
preflight lookup alone does not prevent rebinding.
For licensed media, CHIRP should store LCH ciphertext, not plaintext or keys.
CHIRPContentSink bridges the uploader and LCH representation while
UniversalContentSource bridges the downloader and LCH reader. See the
production CHIRP and LCH guide for the
combined code path, ownership model, failure matrix, rollout gate, and agent
checklist.
chirp publish ./large.bin --host https://storage.example \
--wallet-module ./wallet.mjs --retention-seconds 2592000
chirp retrieve chirp://... --output ./large.bin --range 0:4194304
chirp verify chirp://...