<>ts-stack
Get StartedArchitecturePackagesSpecsGuides
⌘K
Reference
Home
Get StartedOverviewInstallChoose your stackKey concepts
ArchitectureOverviewStack layersBEEF (BRC-62)BRC-100 Wallet InterfaceIdentity & AuthConformance pipeline
PackagesOverviewSDKWalletNetworkOverlaysMessagingMiddlewareHelpers
InfrastructureOverviewmessage-box-serveroverlay-serveruhrp-server-basicuhrp-server-cloud-bucketwabwallet-infrachaintracks-server
SpecsOverviewBRC-100 Wallet InterfaceOverlay HTTPMessage-box HTTPAuthsocket (WebSocket)BRC-31 Auth HandshakeBRC-29 Peer PaymentBRC-121 / HTTP 402ARC BroadcastMerkle ServiceStorage AdapterGASP SyncUHRPAir-Gap Optical (BRC-141)
ConformanceOverviewVector catalogTS runnerContributing vectors
GuidesOverviewIdentity, DIDs and credentialsIdentity migrationBuild a wallet-aware appRun an overlay nodePeer-to-peer messagingHTTP 402 payments
ReferenceOverviewBRC indexRepository health
AboutVersioningContributingDoc agentDocumentation sources
Loading…
Edit this page on GitHub
© 2026 BSV Blockchain. ts-stack is open-source.
GitHubContributingVersioning

Package API, Declarations, and Migration Ledger

This page is generated from all 33 public manifests, package documentation, and governance/package-release-notes.json. It records source candidates without publishing them. CI rejects a version change unless its release classification, summary, and migration guidance are updated at the same time.

The declaration targets below describe the packed manifest contract. The package pages remain the human API and usage authority; generated declarations and clean-consumer tests remain the executable type authority.

Current release boundary

Packagenpm baselineSourceCandidateAPIMigration
@bsv/402-pay0.3.20.3.3patchAPI and usageCustom clients must send a strictly framed BRC-95 Atomic BEEF envelope whose subject is the payment transaction; plain BEEF is no longer accepted. Legacy Atomic BEEF containing unrelated branches remains compatible because the server reduces it to the declared subject and dependency closure. The default replay store is bounded and process-local; production services with more than one serving process or node must inject the same durable atomic PaymentReplayStore everywhere. Low-level validators should retain one wallet object or pass an explicit store. Applications that relied on implicit console diagnostics must supply the optional structured logger. Treat an unchallenged 503 after payment submission as ambiguous and reconcile the transaction before requesting another payment. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/air-gap0.1.30.1.3noneAPI and usageNo migration is required for valid BRC-141 v1 senders or decoders. Malformed, oversized, duplicate-heavy, or adversarial high-degree sessions now fail closed or are evicted within the documented limits instead of consuming unbounded resources.
@bsv/amountinator2.1.62.1.7patchAPI and usageValid finite inputs retain the public API. Currency identifiers are trimmed and normalized to uppercase; callers that passed non-finite values, empty currencies, coercive options, invalid decimal precision, or non-finite converter results must normalize or reject them before calling because those values now fail closed. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/auth0.1.50.1.6patchAPI and usageNo valid proof bytes or public API shape changes. Client and server must use the same protocol tuple; security levels 0, 1, and 2 remain supported and select wallet consent policy while the explicit counterparty scopes derivation at every level. Proof and wallet adapters must supply plain own data fields and dense byte arrays; inherited, accessor-backed, sparse, or malformed runtime shapes fail closed. Structured bodies containing non-finite numbers or negative zero must be normalized to an unambiguous wire representation before signing. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/auth-express-middleware2.2.82.2.9patchAPI and usageNo BRC100 call, wire or wallet-data migration. Configure and validate transport header limits at the HTTP server, CDN, proxy or WAF; maxRequestBytes no longer caps received headers. Clients needing larger signed responses require corresponding client capacity, including SDK 2.8.5. Published 2.2.8 is verified against protected release 36052862859 and its immutable source artifacts. Upgrade the required SDK peer to 2.8.5; custom ExpressTransport/Peer setups should pass maxGeneralPayloadBytes=null when the HTTP layer owns payload capacity. SDK consumers may retain ^2.8.5 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/authsocket2.1.82.1.9patchAPI and usageNo API or wire migration is required for valid JSON events. Existing numeric-key objects under byte-like names are unchanged; typed payment protocols recover historical byte objects at their explicit fields. Outbound non-JSON or ambiguous runtime values, including negative zero, nested undefined, sparse arrays, accessors, hidden/extra properties, and serialization hooks, now fail closed before signing. requestedCertificates is an SDK allowlist, not an application authorization verdict. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/authsocket-client2.1.72.1.8patchAPI and usageNo API or wire migration is required for valid JSON events. Existing numeric-key objects under byte-like names are unchanged; typed payment protocols recover historical byte objects at their explicit fields. Outbound non-JSON or ambiguous runtime values, including negative zero, nested undefined, sparse arrays, accessors, hidden/extra properties, and serialization hooks, now fail closed before signing. The connect event/connected property report Socket.IO transport state, not completed BRC-103 authentication; wait for verified application traffic when local behavior requires a known unpinned server. Distributors who copy the UMD file must keep THIRD_PARTY_NOTICES.md and LICENSES/ with it. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/btms1.2.31.2.4patchAPI and usageExisting local, mainnet, testnet, and number-array behavior is unchanged. TTN consumers select networkPreset teratestnet; all consumers should upgrade to @bsv/sdk 2.4.1 or later for byte-boundary compatibility. Valid canonical token amounts remain compatible. Audit historical tokens for signed, exponent, leading-zero, non-positive, or greater-than-9007199254740991 amount fields before rebuilding wallet state; public number-based operations now fail closed when an aggregate cannot be represented exactly. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/btms-permission-module1.2.11.2.2patchAPI and usageValid canonical BTMS flows remain compatible. Custom prompts must return literal true, authorization maps may contain at most 1,024 entries, and callers must provide dense signatures, safe exact totals, and canonical preimages; coercive or trailing-byte forms now fail closed. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/chirp0.1.30.1.4patchAPI and usageNo API, codec, object identifier, service schema, or wire-format migration. Use @bsv/chirp 0.1.3 with SDK 2.8.9 or later and Cloud Bucket 0.2.48 or Lite 0.1.45 for authenticated binary uploads, including full 4 MiB chunks. Custom authenticated transports must send the supplied owned byte body unchanged and supply ordinary HTTP framing; Content-Type remains signed through AuthFetch. Earlier service entrypoints do not parse staged binary bytes before authentication and require this service patch. Existing stored objects, sessions, advertisements and leases remain unchanged. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/did0.2.60.3.0minorAPI and usageDID0.3 is a breaking pre-1.0 candidate: compressed identity-key input only; remote document/lifecycle options rejected. Use original signed BRC52 binary for envelopes, or explicitly verified compatible structured core. Wire authenticated BRC103/104 payload/control, durable atomic replay, consent, issuer/schema/purpose reliance and local status policy; callbacks alone are not full transport conformance. See docs/guides/identity-did-vc-migration.md. Proposed custom W3C mechanisms remain unregistered. Import BRC52 APIs/types from @bsv/did/brc52; identity-key DID and independent SD-JWT helpers stay at @bsv/did.
@bsv/ecpm-permission-module0.1.10.1.2patchAPI and usageValid ecpm requests remain compatible. Authorization callbacks must return literal true; inherited, accessor-backed, malformed, or oversized inputs now fail closed. Hosts must keep grants below 1,024 entries and avoid more than 64 concurrently pending new authorization prompts per module instance. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/fund-wallet1.5.21.5.3patchAPI and usageNo public API migration is required for conforming wallets. Custom WalletInterface adapters must return the literal accepted: true verdict after successful internalization; refusals and malformed or coercive results now throw instead of being reported as success. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/gasp1.3.71.3.8patchAPI and usageNo API or wire migration is required. In bidirectional mode, the receiver must already have the parent of a pushed child, request it during a subsequent synchronization round, or reject the graph because GASP v1 submitNode does not transmit the spentBy parent outpoint. Pull-only operation avoids that assumption. Custom storage and remote adapters must preserve exact request/node binding and bounded responses. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/lch0.2.00.2.1patchAPI and usageReplace buyer.quote(endpoint, request, issuer, keyGrants) with buyer.quote(verifiedSignedOffer, request, expectedSeller, keyGrants). JavaScript callers that still pass an endpoint string fail before transport I/O. Persist the returned plan and every partial settlement proof, retry with the same funded transaction, and configure a profile-aware agreementEvaluator before completion or recovery. Low-level unverified recovery results must not authorize key storage or content access. DNS endpoints require an address-pinning connector outside trusted browser environments. Distributors must retain THIRD_PARTY_NOTICES.md with the package; published BRC-170 remains authoritative if the implementation and standard differ. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/message-box-client2.5.42.6.0minorAPI and usageNo migration required for the new fields: the PeerMessage paymentOutcome and retained payment are optional, and messages without a payment are unchanged. To avoid losing payments, store any returned payment (validate it first; it is the raw envelope value) before acknowledging its message. Install @bsv/sdk 2.8.6 or later alongside this package; payments refused on earlier SDKs remain pending in the message box and can be accepted after upgrading. No BRC100 wire or wallet-data change. SDK consumers may retain ^2.8.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/overlay2.6.32.6.4patchAPI and usageNo wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative. For UMP lineage, deploy this engine patch together with overlay-topics 2.0.1 or an equivalent custom UMP history decider. Existing selector decisions and resource bounds remain unchanged.
@bsv/overlay-discovery-services2.2.62.2.7patchAPI and usageNo wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. SDK consumers may retain ^2.4.0 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/overlay-express2.7.32.7.4patchAPI and usageNo wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. SDK consumers may retain ^2.4.0 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/overlay-topics2.0.02.0.1patchAPI and usageTopics2 is a breaking retirement candidate. Remove DIDTopicManager/createDIDLookupService/DIDRecord/DIDQuery and tm_did/ls_did usage. Resolve immutable identity-key DIDs offline; explicitly configured tm_identity/ls_identity supplies certificate discovery, not DID-document mutation or automatic trust. Preserve existing database/history and plan service rollout without automatic replacement installation. See docs/guides/identity-did-vc-migration.md. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative. Mandala is a clean break with no data migration: the old MandalaToken/MandalaAdmin wire format is no longer admitted and 1.x Mandala rows are not read or converted, so start Mandala on a new database with new deploys (existing on-chain outputs are not spent or deleted). MandalaTopicManager drops adminWallet, adminProtocolID and stateStore.isAdminOutpoint and requires trustedIssuers (non-empty compressed lowercase public keys) and engineOutputs, with optional membership, membershipExempt and onOwnerRepair; pass the same MandalaStorageManager (a MandalaStateStore) to admission and lookup. Refusals are MandalaReject { code, reason } from the Reasons catalog; do not match on old error text. MandalaLinkagePayload is replaced by MandalaEnvelope with encodeEnvelope/decodeEnvelope; the register action is replaced by a deploy at output 0 with a deploySig. foldAction, defaultAssetState, AssetAdminState, FoldContext and MandalaTokenRecord use tokenId (_0) instead of assetId, drop issuerIdentityKey and add feeRatePerKb. Persisted schema (section 6.6): new mandalaOwners and mandalaAuthorities collections; mandalaTokens, mandalaMetadata, mandalaAssetStates and mandalaAdminHistory are keyed by tokenId, metadata holds the decoded deploy payload, and history rows store kind, detailsHex, commitment and delta (plus optional frozenAmount/frozenOwner on freezes). De-trusting an issuer key revokes the authority coins it holds; rotate keys by moving authority coins first. Operators register tm_mandala_registry/ls_mandala_registry explicitly. The infra/overlay-server wiring follows after publication (P1b). The prior 2.0.0 contracts above are the published baseline. This 2.0.1 UMP patch has no API, wire or schema migration; deploy with overlay 2.6.4 to retain history past confirmation.
@bsv/paymail2.4.92.4.10patchAPI and usageNone. ESM consumers are unaffected. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/payment-express-middleware2.1.82.1.9patchAPI and usageNo BRC100 call, wire or wallet-data migration. maxPaymentHeaderBytes is now ignored, including existing explicit values: move transport policy to the HTTP server, CDN, proxy or WAF and remove the deprecated option. Validate the complete HTTP route for supported payment proofs. Published 2.1.8 is verified against protected release 36052862859 and its immutable source artifacts. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/sdk3.2.03.2.1patchAPI and usageSDK3 is a separate breaking retirement candidate: remove identity/DIDTokenValidation imports and use @bsv/did BRC202 identity-key resolution plus optional @bsv/did/brc52 original-signature envelopes. Retain historical data and recover authenticated identity bindings; do not relabel serial DIDs. Existing acquisition-result validation fixes remain. First-party SDK3 peer alternatives require complete packed qualification and owner coordination; preserved SDK2 ranges are not silently narrowed. See docs/guides/identity-did-vc-migration.md. The additive authorization callback requires independently verified local policy; wallet-returned labels or fields are not authority. The completeBoundAction.outputAuthorizationVersion function property allows compatible consumers to detect support without importing a missing named export from older ESM peers. No BRC100 wire or persistence migration is introduced by this addition. Identity search recovery is opt-in: useContacts true with contactErrorMode fallback bounds contact enrichment at 2000ms by default, or an explicit integer deadline from1 to60000ms. Use onContactError for partial-result warnings and handle public lookup errors separately from empty results. Legacy booleans and defaults remain compatible. A contact deadline does not cancel wallet requests or permission prompts. Applications must update their bundled SDK and search component; this source candidate does not update deployed apps. The splice-operand change is a consensus alignment with SV Node v1.2.3 and needs no API change; spends whose OP_SUBSTR, OP_LEFT or OP_RIGHT operands are longer than nine bytes, or whose ninth byte carries magnitude bits, were accepted by node v1.2.2 and are now rejected by both the node and the SDK.
@bsv/simple0.6.00.7.0minorAPI and usageSimple0.7 is a breaking pre-1.0 candidate. Remove mutable DID/resolver/provider configuration, proxy handlers and DIDError/types; use DID.fromIdentityKey/resolve and wallet.getDID. CredentialIssuer.issue returns {credential,keyringForSubject}; verify accepts exact JSON or UTF8 bytes and returns structured cryptographic results. The HTTP verify route now requires {credential: originalEnvelopeJson} with original text as a string; parsed objects return HTTP400. Web request decoding rejects duplicate members and invalid UTF8, and custom parsed-body adapters must establish equivalent strict decoding. Preserve received text and inspect verification.verified, not HTTP success. Local revocation record status is retained/unknown, not inferred chain revocation. See docs/guides/identity-did-vc-migration.md. Replace createServerWalletHandler() deployments with createServerWalletHandler({ authorize: async ({ action, headers }) => authenticatedSessionCanUseAction(headers, action) }). The callback must return literal true for each status, create, request, receive, balance, outputs, or reset action; omission now returns HTTP 403 for every action. Roll out the authentication layer and callback with the package, update anonymous probes or automation, and apply the same policy to every replica. Do not emulate the old public behavior with an unconditional authorize: () => true callback. Valid recipient derivations and authenticated Message Box peers remain supported; malformed, wrong-owner, or transaction-mutated flows now fail closed. New CredentialSchema and Certifier records use canonical 32-byte types. Current SDK wallet methods reject historical short types, so do not put migration aliases in wallet list, acquire, prove, or relinquish calls. Export affected records through the storage version that created them, authenticate them offline against the exact locally configured identifier, and reissue/import canonical replacements; no legacy certificate is rewritten automatically. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/. Persisted local field ordering requires no migration; transport adapters preserve original certificate signing bytes.
@bsv/templates1.10.22.0.0majorAPI and usageBreaking. Removed exports: MandalaToken, MandalaTokenDecoded, MandalaAdmin, ADMIN_PROTOCOL, MandalaAdminDecoded, MandalaActionDetails, MandalaActionKind, MandalaAdminLockParams, MandalaAdminUnlockParams and AssetMetadata. Removed subpath @bsv/templates/mandala-signing.ts. The @bsv/templates/mandala-encoding.ts subpath keeps only createMinimallyEncodedScriptChunk, decodeScriptNum and decodeScriptNumChunk; encodeScriptNum, encodeAssetId and decodeAssetId are removed. Replace MandalaToken/MandalaAdmin with Bsv21Binary: deploy, authority and value outputs are lock(tokenId | null, amount, pubKeyHash, payload?) with bigint amounts and _0 token ids (tokenIdFromString/tokenIdToString), decoded with Bsv21Binary.decode. Mandala admin actions are committed by sha256 of strict-CBOR details in the authority output payload, not by a commitment-derived key. This is a clean break with no data migration: tokens and admin chains in the old format are not readable by 2.0.0. @bsv/overlay-topics 2.0.0 consumes this format; the infra/overlay-server wiring follows after publication. SDK consumers may retain ^2.1.6 or install the SDK3 candidate; SDK3 removes the obsolete DID token API (see docs/guides/identity-did-vc-migration.md).
@bsv/teranode-listener1.1.61.1.7patchAPI and usageNo API migration is required for valid consumers: raw callbacks remain the default and decoding is opt-in with decodeMessages: true. Configuration arrays and callbacks are snapshotted at construction, boolean controls must be literal booleans, and malformed or duplicate topics, addresses, keys, and unsupported properties now fail closed. usePrivateDHT: false now actually omits the DHT service. The published mainnet PNET value is transport compatibility data, not a publisher credential; decoded sender and payload fields remain untrusted and security-critical claims require independent validation. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/verifast0.3.60.3.7patchAPI and usageValid typed verification calls and worker protocols remain compatible. Custom module factories and WASM adapters must return the exact documented binary and boolean shapes; coercive network, height, flag, byte, batch, verdict, lifecycle, or disposed-instance values now fail closed. Keep THIRD_PARTY_NOTICES.md and LICENSES/ with every JavaScript and WebAssembly distribution. SDK consumers may retain ^2.1.8 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/wallet-helper0.1.80.1.9patchAPI and usagegetAddress now derives with forSelf: true and returns the caller-owned side of the bilateral relationship. Applications that stored or coordinated the previous peer-owned result must regenerate and exchange the corrected address before sending value. Amount must be an integer from 1 through 1,000 and counterparties must be valid public keys. Valid canonical transaction-builder flows remain supported; malformed, ambiguous, or wallet-mutated results now fail closed. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/wallet-relay0.5.10.5.2patchAPI and usageEnable signed QR codes and distribute only HTTPS pairing origins and relay API URLs. Root-relative API paths and loopback HTTP remain supported. Configure onApprovalRequired for every method not deliberately listed in autoApproveMethods; unsigned pairing URIs and implicit approval are no longer accepted. Existing relay sessions, custom RPC method names, and supported wallet RPC byte encodings remain valid, and host applications continue to provide their matching Express runtime and type graph. Version 0.5 defaults to two missed pongs; set maxMissedHeartbeats to 1 to retain the prior heartbeat policy. Heartbeat intervals must fit the Node timer range. Preserve Cache-Control: no-store at proxies, prefer the stable bsv-wallet-relay plus token WebSocket subprotocols over the legacy token query parameter, and configure edge rate limiting in addition to the bounded in-process defaults. The 24-hour connected-session lifetime no longer renews on reconnect, malformed wallet calls fail with code 400, and WalletRelayClient retains at most 100 log entries unless maxLogEntries is configured. The QR remains a short-lived bearer invitation: keep it private and require explicit operation approval. Relay envelopes, cryptographic framing, and wallet RPC encodings remain unchanged. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
@bsv/wallet-toolbox2.14.52.14.7patchAPI and usageNo public API, wire, database, or consumer migration is required. Pending no-send actions and retryable failures retain the same originator-bound abort behavior; positively queued or broadcast actions no longer retain session ownership records. Upgrade the SDK to a release exposing completeBoundAction.outputAuthorizationVersion=1 alongside wallet-toolbox 2.14.6. SDK2 peers keep their existing strict behavior; they do not obtain this fee-bearing faucet fix. The main SDK3.1 candidate retains the separate SDK3 retirement migration; SDK2 hosts require a coordinated additive backport or that migration. Serialized or cross-package-instance result adapters discard local authority and fail closed. Signup interruption/retry persistence is unchanged; reconcile any previous faucet transaction before repeating a failed signup. No API or schema migration is required for pin continuity. Retire a support pin only after unpinned lookup independently returns the verified current token. Deploy overlay 2.6.4 plus overlay-topics 2.0.1 or an equivalent history decider for confirmed ancestry. Stored WAB pins remain lineage anchors; the client follows verified descendants without needing an administrative pin rewrite. No API, wire or database migration is required for the BRC-177 funding fix. A protected action can pay the difference between its delivery need and the reclaim floor as miner fee. Funding/reclaim fees remain the wallet owner's responsibility; upgrade the active storage implementation as well as client packages. No API, database or peer migration is required for compact BEEF transport. Upgrade clients and active storage to obtain both request and response savings; older peers retain ordinary JSON. Existing payload ceilings still apply. No API, wire or schema migration is required for the IndexedDB filter fix. Empty optional arrays now behave like omitted filters. Applications still receive only records allowed by their user and partial predicates; nonempty arrays retain their restrictions. No public API, wire or database migration is required for internalization broadcast. Upgrade the active storage implementation. Recipients receive a review-actions error when broadcast is rejected and must inspect that result before retrying; no recipient outputs are stored on rejection. Existing proven transactions retain their no-rebroadcast path.
@bsv/wallet-toolbox-client2.14.52.14.7patchAPI and usageNo public API, wire, database, or consumer migration is required. Pending no-send actions and retryable failures retain the same originator-bound abort behavior; positively queued or broadcast actions no longer retain session ownership records. Upgrade the SDK to a release exposing completeBoundAction.outputAuthorizationVersion=1 alongside wallet-toolbox 2.14.6. SDK2 peers keep their existing strict behavior; they do not obtain this fee-bearing faucet fix. The main SDK3.1 candidate retains the separate SDK3 retirement migration; SDK2 hosts require a coordinated additive backport or that migration. Serialized or cross-package-instance result adapters discard local authority and fail closed. Signup interruption/retry persistence is unchanged; reconcile any previous faucet transaction before repeating a failed signup. No API or schema migration is required for pin continuity. Retire a support pin only after unpinned lookup independently returns the verified current token. Deploy overlay 2.6.4 plus overlay-topics 2.0.1 or an equivalent history decider for confirmed ancestry. Stored WAB pins remain lineage anchors; the client follows verified descendants without needing an administrative pin rewrite. No API, wire or database migration is required for the BRC-177 funding fix. A protected action can pay the difference between its delivery need and the reclaim floor as miner fee. Funding/reclaim fees remain the wallet owner's responsibility; upgrade the active storage implementation as well as client packages. No API, database or peer migration is required for compact BEEF transport. Upgrade clients and active storage to obtain both request and response savings; older peers retain ordinary JSON. Existing payload ceilings still apply. No API, wire or schema migration is required for the IndexedDB filter fix. Empty optional arrays now behave like omitted filters. Applications still receive only records allowed by their user and partial predicates; nonempty arrays retain their restrictions. No public API, wire or database migration is required for internalization broadcast. Upgrade the active storage implementation. Recipients receive a review-actions error when broadcast is rejected and must inspect that result before retrying; no recipient outputs are stored on rejection. Existing proven transactions retain their no-rebroadcast path.
@bsv/wallet-toolbox-mobile2.14.52.14.7patchAPI and usageNo public API, wire, database, or consumer migration is required. Pending no-send actions and retryable failures retain the same originator-bound abort behavior; positively queued or broadcast actions no longer retain session ownership records. Upgrade the SDK to a release exposing completeBoundAction.outputAuthorizationVersion=1 alongside wallet-toolbox 2.14.6. SDK2 peers keep their existing strict behavior; they do not obtain this fee-bearing faucet fix. The main SDK3.1 candidate retains the separate SDK3 retirement migration; SDK2 hosts require a coordinated additive backport or that migration. Serialized or cross-package-instance result adapters discard local authority and fail closed. Signup interruption/retry persistence is unchanged; reconcile any previous faucet transaction before repeating a failed signup. No API or schema migration is required for pin continuity. Retire a support pin only after unpinned lookup independently returns the verified current token. Deploy overlay 2.6.4 plus overlay-topics 2.0.1 or an equivalent history decider for confirmed ancestry. Stored WAB pins remain lineage anchors; the client follows verified descendants without needing an administrative pin rewrite. No API, wire or database migration is required for the BRC-177 funding fix. A protected action can pay the difference between its delivery need and the reclaim floor as miner fee. Funding/reclaim fees remain the wallet owner's responsibility; upgrade the active storage implementation as well as client packages. No API, database or peer migration is required for compact BEEF transport. Upgrade clients and active storage to obtain both request and response savings; older peers retain ordinary JSON. Existing payload ceilings still apply. No public API, wire or database migration is required for internalization broadcast. Upgrade the active storage implementation. Recipients receive a review-actions error when broadcast is rejected and must inspect that result before retrying; no recipient outputs are stored on rejection. Existing proven transactions retain their no-rebroadcast path.
create-bsv-app1.1.21.1.2noneAPI and usageExisting CLI flags, network choices, and generated project structure are unchanged. Regenerate or update dependencies after the patched packages are published. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package.

none means the source manifest matches the recorded npm baseline. Any other value records source ahead of that baseline; it does not establish the current registry state. Publication, tags, releases, registry reconciliation, and infrastructure dependency synchronization remain separate, explicitly authorized operations.

Package entry points

@bsv/402-pay

  • Package documentation: docs/packages/middleware/402-pay.md
  • Source: packages/middleware/402-pay
  • Release note: Adds an exact-tarball Vite and esbuild contract for the browser-safe client entry point, including a bundle-size ratchet and an assertion that server exports never leak into browser consumers. Retains the hash-pinned pre-uniformization Open BSV License version 4 grant as a scoped continuity notice. Standardizes first-party author metadata on the current BSV Association name. Binds BRC-121 pricing and internalization to the transaction declared by the BRC-95 Atomic BEEF subject, removes unrelated included branches, rejects trailing bytes and non-atomic envelopes, and requires affirmative wallet acceptance before serving paid content. Adds independent bounded atomic transaction replay claims so conforming BRC-100 wallets that omit the non-public isMerge detail cannot authorize duplicate access, preserves actual overpayments in middleware receipts, uses fixed bounded wallet descriptions, makes diagnostics opt-in, and returns an unchallenged 503 after ambiguous wallet or replay-store failures to avoid inducing a second spend. Aligns the development-only Vitest runner and V8 coverage provider at 4.1.11. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Custom clients must send a strictly framed BRC-95 Atomic BEEF envelope whose subject is the payment transaction; plain BEEF is no longer accepted. Legacy Atomic BEEF containing unrelated branches remains compatible because the server reduces it to the declared subject and dependency closure. The default replay store is bounded and process-local; production services with more than one serving process or node must inject the same durable atomic PaymentReplayStore everywhere. Low-level validators should retain one wallet object or pass an explicit store. Applications that relied on implicit console diagnostics must supply the optional structured logger. Treat an unchallenged 503 after payment submission as ambiguous and reconcile the transaction before requesting another payment. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts
./server./dist/server.mjs./dist/server.cjs./dist/server.d.mts./dist/server.d.cts
./client./dist/client.mjs./dist/client.cjs./dist/client.d.mts./dist/client.d.cts

@bsv/air-gap

  • Package documentation: docs/packages/helpers/air-gap.md
  • Source: packages/helpers/air-gap
  • Release note: Bounds BRC-141 decoder state, scanned strings, duplicate tracking, pending mixes, fountain indices, and high-degree work while replacing sparse O(K) index materialization with bounded mapping. Systematic and degree-one frames remain available under pressure and valid wire-v1 payloads retain their bytes.
  • Migration: No migration is required for valid BRC-141 v1 senders or decoders. Malformed, oversized, duplicate-heavy, or adversarial high-degree sessions now fail closed or are evicted within the documented limits instead of consuming unbounded resources.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts

@bsv/amountinator

  • Package documentation: docs/packages/helpers/amountinator.md
  • Source: packages/helpers/amountinator
  • Release note: Validates finite monetary values, normalized nonempty currency codes, integer decimal precision, grouping flags, converter rates, and conversion results, and formats negative sub-unit amounts from their absolute magnitude without losing the sign. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Valid finite inputs retain the public API. Currency identifiers are trimmed and normalized to uppercase; callers that passed non-finite values, empty currencies, coercive options, invalid decimal precision, or non-finite converter results must normalize or reject them before calling because those values now fail closed. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts

@bsv/auth

  • Package documentation: docs/packages/middleware/auth.md
  • Source: packages/middleware/auth
  • Release note: Adopts the governed strict TypeScript profile and repository-wide zero-warning lint and formatting contract. Snapshots canonical own-data proof fields, dense signature bytes, bodies, protocols, wallet identities, and exact wallet verdicts before asynchronous work; rejects accessor/inherited authority and ambiguous JSON numbers; and retains exact nonce-consumption replay claims. Standardizes first-party author metadata on the current BSV Association name. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No valid proof bytes or public API shape changes. Client and server must use the same protocol tuple; security levels 0, 1, and 2 remain supported and select wallet consent policy while the explicit counterparty scopes derivation at every level. Proof and wallet adapters must supply plain own data fields and dense byte arrays; inherited, accessor-backed, sparse, or malformed runtime shapes fail closed. Structured bodies containing non-finite numbers or negative zero must be normalized to an unambiguous wire representation before signing. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts

@bsv/auth-express-middleware

  • Package documentation: docs/packages/middleware/auth-express-middleware.md
  • Source: packages/middleware/auth-express-middleware
  • Release note: Removes middleware header byte/count ceilings and excludes received HTTP headers from authenticated request-body budgets, preserving signed header bytes. HTTP server and edge layers own transport capacity. Canonical framing, authentication, invalid-header rejection, body budgets and response signing remain. Requires SDK 2.8.5 and delegates its Peer general-payload capacity to the HTTP layer, avoiding an indirect SDK envelope ceiling for received headers. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No BRC100 call, wire or wallet-data migration. Configure and validate transport header limits at the HTTP server, CDN, proxy or WAF; maxRequestBytes no longer caps received headers. Clients needing larger signed responses require corresponding client capacity, including SDK 2.8.5. Published 2.2.8 is verified against protected release 36052862859 and its immutable source artifacts. Upgrade the required SDK peer to 2.8.5; custom ExpressTransport/Peer setups should pass maxGeneralPayloadBytes=null when the HTTP layer owns payload capacity. SDK consumers may retain ^2.8.5 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.mjs./dist/mod.cjs./dist/mod.d.mts./dist/mod.d.cts
./package.json./package.json—

@bsv/authsocket

  • Package documentation: docs/packages/messaging/authsocket.md
  • Source: packages/messaging/authsocket
  • Release note: Contains authentication and application callback failures, caps per-socket authentication concurrency, gates every concurrently received first-session event and routing decision on one completed authenticated-connection activation, snapshots strict JSON before signing, serializes real typed arrays portably, and preserves supported signed event JSON exactly. Retains the hash-pinned pre-uniformization Open BSV License version 4 grant as a scoped continuity notice. Standardizes first-party author metadata on the current BSV Association name. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No API or wire migration is required for valid JSON events. Existing numeric-key objects under byte-like names are unchanged; typed payment protocols recover historical byte objects at their explicit fields. Outbound non-JSON or ambiguous runtime values, including negative zero, nested undefined, sparse arrays, accessors, hidden/extra properties, and serialization hooks, now fail closed before signing. requestedCertificates is an SDK allowlist, not an application authorization verdict. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.mjs./dist/mod.cjs./dist/mod.d.mts./dist/mod.d.cts
./package.json./package.json—

@bsv/authsocket-client

  • Package documentation: docs/packages/messaging/authsocket-client.md
  • Source: packages/messaging/authsocket-client
  • Release note: Contains authentication and application callback failures, caps authentication concurrency, snapshots strict JSON before signing, serializes real typed arrays portably, preserves supported signed event JSON exactly, and ships the complete SDK incorporated-material notice archive with a retained UMD notice banner. Standardizes first-party author metadata on the current BSV Association name. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No API or wire migration is required for valid JSON events. Existing numeric-key objects under byte-like names are unchanged; typed payment protocols recover historical byte objects at their explicit fields. Outbound non-JSON or ambiguous runtime values, including negative zero, nested undefined, sparse arrays, accessors, hidden/extra properties, and serialization hooks, now fail closed before signing. The connect event/connected property report Socket.IO transport state, not completed BRC-103 authentication; wait for verified application traffic when local behavior requires a known unpinned server. Distributors who copy the UMD file must keep THIRD_PARTY_NOTICES.md and LICENSES/ with it. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.js./dist/mod.cjs./dist/mod.d.ts./dist/mod.d.cts
./package.json./package.json—

@bsv/btms

  • Package documentation: docs/packages/wallet/btms.md
  • Source: packages/wallet/btms
  • Release note: Adds TerraTestNet and preserves token settlement and refund transaction bytes across number-array, Uint8Array, and historical numeric-key JSON wallet runtimes. Standardizes first-party author metadata on the current BSV Association name. Rejects non-canonical or unsafe token amounts, applies exact checked arithmetic to financial aggregates, and enforces value conservation for custom change strategies. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Existing local, mainnet, testnet, and number-array behavior is unchanged. TTN consumers select networkPreset teratestnet; all consumers should upgrade to @bsv/sdk 2.4.1 or later for byte-boundary compatibility. Valid canonical token amounts remain compatible. Audit historical tokens for signed, exponent, leading-zero, non-positive, or greater-than-9007199254740991 amount fields before rebuilding wallet state; public number-based operations now fail closed when an aggregate cannot be represented exactly. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts

@bsv/btms-permission-module

  • Package documentation: docs/packages/wallet/btms-permission-module.md
  • Source: packages/wallet/btms-permission-module
  • Release note: Requires literal authorization verdicts, bounds authorization state, validates dense signature bytes and safe-integer totals, and binds BTMS signing to an exact canonical BIP143 preimage with no trailing data. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Valid canonical BTMS flows remain compatible. Custom prompts must return literal true, authorization maps may contain at most 1,024 entries, and callers must provide dense signatures, safe exact totals, and canonical preimages; coercive or trailing-byte forms now fail closed. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.d.mts

@bsv/chirp

  • Package documentation: docs/packages/network/chirp.md
  • Source: packages/network/chirp
  • Release note: Fixes authenticated CHIRP object uploads: omit explicit Content-Length and Content-Encoding application headers that AuthFetch rejects, while HTTP transport generates the correct length and absent encoding preserves identity bytes. Adds a real mutually authenticated client/server regression that verifies raw object bytes, automatic HTTP framing, object identifiers, caller identity, and successful commit. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No API, codec, object identifier, service schema, or wire-format migration. Use @bsv/chirp 0.1.3 with SDK 2.8.9 or later and Cloud Bucket 0.2.48 or Lite 0.1.45 for authenticated binary uploads, including full 4 MiB chunks. Custom authenticated transports must send the supplied owned byte body unchanged and supply ordinary HTTP framing; Content-Type remains signed through AuthFetch. Earlier service entrypoints do not parse staged binary bytes before authentication and require this service patch. Existing stored objects, sessions, advertisements and leases remain unchanged. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.

CLI entry points: {"chirp":"./dist/cli.js"}.

Public subpathRuntime target(s)Declaration target(s)
../dist/index.js./dist/index.js./dist/index.d.ts
./openapi./dist/openapi.js./dist/openapi.js./dist/openapi.d.ts
./package.json./package.json—

@bsv/did

  • Package documentation: docs/packages/helpers/did.md
  • Source: packages/helpers/did
  • Release note: Fixes the CommonJS build of the DID key, signature and multibase helpers. The CommonJS build imported @bsv/sdk classes through bundler Node-mode interop, which bound each default import to the whole SDK module, so require() consumers failed at first use with ".default is not a constructor". SDK classes are now imported by name from the SDK barrels; the ESM build, public API and browser bundle size are unchanged. Adds proposed BRC202 exact compressed identity-key DID resolution and BRC203 original-byte verified envelopes, authorized recipient-bound selected disclosure and explicit status/privacy adapters. Preserves the independently named SD-JWT format. BRC52 adapters use an explicit optional @bsv/did/brc52 entry, preserving the original DID-only browser budget.
  • Migration: DID0.3 is a breaking pre-1.0 candidate: compressed identity-key input only; remote document/lifecycle options rejected. Use original signed BRC52 binary for envelopes, or explicitly verified compatible structured core. Wire authenticated BRC103/104 payload/control, durable atomic replay, consent, issuer/schema/purpose reliance and local status policy; callbacks alone are not full transport conformance. See docs/guides/identity-did-vc-migration.md. Proposed custom W3C mechanisms remain unregistered. Import BRC52 APIs/types from @bsv/did/brc52; identity-key DID and independent SD-JWT helpers stay at @bsv/did.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.js./dist/mod.cjs./dist/mod.d.ts./dist/mod.d.cts
./*.ts./dist/src/*.js./dist/src/*.cjs./dist/src/*.d.ts./dist/src/*.d.cts
./brc52./dist/brc52.js./dist/brc52.cjs./dist/brc52.d.ts./dist/brc52.d.cts

@bsv/ecpm-permission-module

  • Package documentation: docs/packages/wallet/ecpm-permission-module.md
  • Source: packages/wallet/ecpm-permission-module
  • Release note: Hardens the BRC-98 ecpm boundary with plain-own-data arguments, exact key, point, protocol, and counterparty validation, immutable configuration snapshots, originator binding, and bounded grant and pending-authorization state. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Valid ecpm requests remain compatible. Authorization callbacks must return literal true; inherited, accessor-backed, malformed, or oversized inputs now fail closed. Hosts must keep grants below 1,024 entries and avoid more than 64 concurrently pending new authorization prompts per module instance. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.d.mts

@bsv/fund-wallet

  • Package documentation: docs/packages/helpers/fund-wallet.md
  • Source: packages/helpers/fund-wallet
  • Release note: Requires the funding wallet's internalizeAction result to contain accepted: true before reporting a funded transaction as successfully internalized. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No public API migration is required for conforming wallets. Custom WalletInterface adapters must return the literal accepted: true verdict after successful internalization; refusals and malformed or coercive results now throw instead of being reported as success. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.

CLI entry points: {"fund-metanet":"./dist/index.mjs"}.

Public subpathRuntime target(s)Declaration target(s)
.——

@bsv/gasp

  • Package documentation: docs/packages/overlays/gasp.md
  • Source: packages/overlays/gasp-core
  • Release note: Validates and correlates every GASP page, outpoint, node, raw transaction, metadata field, requested-input map, and completion result; caps page, graph, metadata and concurrency work; prevents prototype-sensitive records, quadratic replies, stale-watermark advancement, and non-progressing pagination. Retains the positional constructor and v1 wire contract while documenting the parent-availability assumption of the bidirectional push half. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No API or wire migration is required. In bidirectional mode, the receiver must already have the parent of a pushed child, request it during a subsequent synchronization round, or reject the graph because GASP v1 submitNode does not transmit the spentBy parent outpoint. Pull-only operation avoids that assumption. Custom storage and remote adapters must preserve exact request/node binding and bounded responses. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/esm/mod.js./dist/cjs/mod.js./dist/types/mod.d.ts./dist/cjs/mod.d.ts
./*.ts./dist/esm/src/*.js./dist/cjs/src/*.js./dist/types/src/*.d.ts./dist/cjs/src/*.d.ts

@bsv/lch

  • Package documentation: docs/packages/content/lch.md
  • Source: packages/content/lch
  • Release note: Hardens the BRC-170 Licensed Content Header implementation with deterministic malformed-input handling, URL-canonical SSRF protection including IPv4-mapped IPv6 literals, bounded DAG composition, authenticated settlement evidence, replay-safe receipts, recovery-safe multipay state, and signed-Offer agreement binding. Removes the endpoint-only quote overload because it cannot authenticate the Asset, Policy, Agreement, seller, or key-delivery terms. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Replace buyer.quote(endpoint, request, issuer, keyGrants) with buyer.quote(verifiedSignedOffer, request, expectedSeller, keyGrants). JavaScript callers that still pass an endpoint string fail before transport I/O. Persist the returned plan and every partial settlement proof, retry with the same funded transaction, and configure a profile-aware agreementEvaluator before completion or recovery. Low-level unverified recovery results must not authorize key storage or content access. DNS endpoints require an address-pinning connector outside trusted browser environments. Distributors must retain THIRD_PARTY_NOTICES.md with the package; published BRC-170 remains authoritative if the implementation and standard differ. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.

CLI entry points: {"lch":"./dist/cli.js"}.

Public subpathRuntime target(s)Declaration target(s)
../dist/index.js./dist/index.js./dist/index.d.ts
./package.json./package.json—

@bsv/message-box-client

  • Package documentation: docs/packages/messaging/message-box-client.md
  • Source: packages/messaging/message-box-client
  • Release note: listMessages() and listMessagesLite() report paymentOutcome ('internalized', 'failed', 'skipped' or 'no-wallet-outputs') on each message that carried a payment, and keep that payment on the returned message unless the wallet accepted it (issue #503). Previously the payment envelope was always removed and a failed internalization was only logged, so acknowledging a listed message could delete the only copy of a payment. Both PeerMessage fields are optional and absent on messages without a payment. This release also carries the @bsv/sdk peer-floor raise from ^2.8.0 to ^2.8.6: SDK 2.8.0 through 2.8.5 derive the recipient key in Brc29RemittanceModule.acceptSettlement without forSelf, so PeerPayClient.acceptPayment() and rejectPayment() fail with brc29.internalize_failed for every valid incoming payment, and SDK 2.8.6 fixes acceptance. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No migration required for the new fields: the PeerMessage paymentOutcome and retained payment are optional, and messages without a payment are unchanged. To avoid losing payments, store any returned payment (validate it first; it is the raw envelope value) before acknowledging its message. Install @bsv/sdk 2.8.6 or later alongside this package; payments refused on earlier SDKs remain pending in the message box and can be accepted after upgrading. No BRC100 wire or wallet-data change. SDK consumers may retain ^2.8.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.js./dist/mod.cjs./dist/mod.d.ts./dist/mod.d.cts
./package.json./package.json—

@bsv/overlay

  • Package documentation: docs/packages/overlays/overlay.md
  • Source: packages/overlays/overlay
  • Release note: Maps SQL NULL output block heights to absent confirmation metadata without inventing a height or changing stored state. Strict engine height validation remains unchanged. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide. Explicit lookup history retains selected confirmed predecessors instead of truncating them at a Merkle proof; unrequested history and ordinary proof serialization are unchanged.
  • Migration: No wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative. For UMP lineage, deploy this engine patch together with overlay-topics 2.0.1 or an equivalent custom UMP history decider. Existing selector decisions and resource bounds remain unchanged.
Public subpathRuntime target(s)Declaration target(s)
../dist/esm/mod.js./dist/cjs/mod.js./dist/types/mod.d.ts./dist/cjs/mod.d.ts
./*.ts./dist/esm/src/*.js./dist/cjs/src/*.js./dist/types/src/*.d.ts./dist/cjs/src/*.d.ts
./storage./dist/esm/src/storage/Storage.js./dist/cjs/src/storage/Storage.js./dist/types/src/storage/Storage.d.ts./dist/cjs/src/storage/Storage.d.ts
./storage/*.ts./dist/esm/src/storage/*.js./dist/cjs/src/storage/*.js./dist/types/src/storage/*.d.ts./dist/cjs/src/storage/*.d.ts
./storage/*./dist/esm/src/storage/*.js./dist/cjs/src/storage/*.js./dist/types/src/storage/*.d.ts./dist/cjs/src/storage/*.d.ts

@bsv/overlay-discovery-services

  • Package documentation: docs/packages/overlays/overlay-discovery-services.md
  • Source: packages/overlays/overlay-discovery-services
  • Release note: Adds the unique MongoDB _id tie breaker to discovery pagination so bounded overflow probes preserve stable ordering. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. SDK consumers may retain ^2.4.0 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/esm/mod.js./dist/cjs/mod.js./dist/types/mod.d.ts./dist/cjs/mod.d.ts
./*.ts./dist/esm/src/*.js./dist/cjs/src/*.js./dist/types/src/*.d.ts./dist/cjs/src/*.d.ts

@bsv/overlay-express

  • Package documentation: docs/packages/overlays/overlay-express.md
  • Source: packages/overlays/overlay-express
  • Release note: Pages built-in discovery overflow probes within the discovery service 1000-row query bound, retaining the configured engine ceiling and explicit overflow failure. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. SDK consumers may retain ^2.4.0 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/esm/mod.js./dist/cjs/mod.js./dist/types/mod.d.ts./dist/cjs/mod.d.ts
./*.ts./dist/esm/src/*.js./dist/cjs/src/*.js./dist/types/src/*.d.ts./dist/cjs/src/*.d.ts

@bsv/overlay-topics

  • Package documentation: docs/packages/overlays/overlay-topics.md
  • Source: packages/overlays/topics
  • Release note: Accepts SDK StorageDownloader UHRP pages up to 200 rows with deterministic outpoint ordering. Retains selector allowlists and authenticated advertisement admission. Removes serial-DID topic/lookup/storage exports and tm_did/ls_did registrations. Existing BRC189 identity discovery, UORA and all other legitimate topics remain. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide. Replaces the tm_mandala/ls_mandala admission, lookup and storage API with Mandala on BRC-162 (BSV-21 binary tokens with authority supply, consuming the @bsv/templates 2.0.0 Bsv21Binary codec): typed MandalaReject refusals with ERR_* codes, the v3 envelope, strict-CBOR admin details committed by the authority output, a trusted-issuer set, an append-only owner journal with inline owner-index repair, and the eviction API. Adds the tm_mandala_registry/ls_mandala_registry identity registry topic (RegistryTopicManager, RegistryLookupService). Changes the persisted Mandala schema (spec section 6.6). UMP lookup requests the retained token-update lineage for presentation, recovery and outpoint queries, within the engine traversal budgets.
  • Migration: Topics2 is a breaking retirement candidate. Remove DIDTopicManager/createDIDLookupService/DIDRecord/DIDQuery and tm_did/ls_did usage. Resolve immutable identity-key DIDs offline; explicitly configured tm_identity/ls_identity supplies certificate discovery, not DID-document mutation or automatic trust. Preserve existing database/history and plan service rollout without automatic replacement installation. See docs/guides/identity-did-vc-migration.md. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative. Mandala is a clean break with no data migration: the old MandalaToken/MandalaAdmin wire format is no longer admitted and 1.x Mandala rows are not read or converted, so start Mandala on a new database with new deploys (existing on-chain outputs are not spent or deleted). MandalaTopicManager drops adminWallet, adminProtocolID and stateStore.isAdminOutpoint and requires trustedIssuers (non-empty compressed lowercase public keys) and engineOutputs, with optional membership, membershipExempt and onOwnerRepair; pass the same MandalaStorageManager (a MandalaStateStore) to admission and lookup. Refusals are MandalaReject { code, reason } from the Reasons catalog; do not match on old error text. MandalaLinkagePayload is replaced by MandalaEnvelope with encodeEnvelope/decodeEnvelope; the register action is replaced by a deploy at output 0 with a deploySig. foldAction, defaultAssetState, AssetAdminState, FoldContext and MandalaTokenRecord use tokenId (_0) instead of assetId, drop issuerIdentityKey and add feeRatePerKb. Persisted schema (section 6.6): new mandalaOwners and mandalaAuthorities collections; mandalaTokens, mandalaMetadata, mandalaAssetStates and mandalaAdminHistory are keyed by tokenId, metadata holds the decoded deploy payload, and history rows store kind, detailsHex, commitment and delta (plus optional frozenAmount/frozenOwner on freezes). De-trusting an issuer key revokes the authority coins it holds; rotate keys by moving authority coins first. Operators register tm_mandala_registry/ls_mandala_registry explicitly. The infra/overlay-server wiring follows after publication (P1b). The prior 2.0.0 contracts above are the published baseline. This 2.0.1 UMP patch has no API, wire or schema migration; deploy with overlay 2.6.4 to retain history past confirmation.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.js./dist/index.js./dist/index.d.ts

@bsv/paymail

  • Package documentation: docs/packages/messaging/paymail.md
  • Source: packages/messaging/ts-paymail
  • Release note: Fixes the CommonJS build of the P2P signature and PaymailClient key helpers. The CommonJS build imported @bsv/sdk classes through bundler Node-mode interop, which bound each default import to the whole SDK module, so require() consumers failed at first use with ".default is not a constructor". SDK classes are now imported by name from the SDK barrels; the ESM build, public API and browser bundle size are unchanged. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: None. ESM consumers are unaffected. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.browser.js./dist/mod.js./dist/mod.cjs./dist/mod.browser.d.ts./dist/mod.d.ts./dist/mod.d.cts
./client./dist/src/paymailClient/index.js./dist/src/paymailClient/index.cjs./dist/src/paymailClient/index.d.ts./dist/src/paymailClient/index.d.cts
./client/*./dist/src/paymailClient/*.js./dist/src/paymailClient/*.cjs./dist/src/paymailClient/*.d.ts./dist/src/paymailClient/*.d.cts
./capability./dist/src/capability/index.js./dist/src/capability/index.cjs./dist/src/capability/index.d.ts./dist/src/capability/index.d.cts
./capability/*./dist/src/capability/*.js./dist/src/capability/*.cjs./dist/src/capability/*.d.ts./dist/src/capability/*.d.cts
./router./dist/src/paymailRouter/index.js./dist/src/paymailRouter/index.cjs./dist/src/paymailRouter/index.d.ts./dist/src/paymailRouter/index.d.cts
./router/*./dist/src/paymailRouter/*.js./dist/src/paymailRouter/*.cjs./dist/src/paymailRouter/*.d.ts./dist/src/paymailRouter/*.d.cts
./errors./dist/src/errors/index.js./dist/src/errors/index.cjs./dist/src/errors/index.d.ts./dist/src/errors/index.d.cts
./errors/*./dist/src/errors/*.js./dist/src/errors/*.cjs./dist/src/errors/*.d.ts./dist/src/errors/*.d.cts
./package.json./package.json—

@bsv/payment-express-middleware

  • Package documentation: docs/packages/middleware/payment-express-middleware.md
  • Source: packages/middleware/payment-express-middleware
  • Release note: Removes middleware payment-header size rejection so received payments are validated regardless of header size. Retains the deprecated maxPaymentHeaderBytes option as an ignored source-compatibility field. Atomic BEEF framing, canonical base64, derivation verification, pricing, wallet acceptance and atomic replay protection remain. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No BRC100 call, wire or wallet-data migration. maxPaymentHeaderBytes is now ignored, including existing explicit values: move transport policy to the HTTP server, CDN, proxy or WAF and remove the deprecated option. Validate the complete HTTP route for supported payment proofs. Published 2.1.8 is verified against protected release 36052862859 and its immutable source artifacts. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.mjs./dist/mod.cjs./dist/mod.d.mts./dist/mod.d.cts
./package.json./package.json—

@bsv/sdk

  • Package documentation: docs/packages/sdk/bsv-sdk.md
  • Source: packages/sdk
  • Release note: WalletClient and the binary BRC-100 wire no longer reject every acquireCertificate issuance: result validation required the returned fields to equal the request's, but issuance sends plaintext values and the certificate comes back with each value encrypted. An issuance result is now bound to exactly the requested field names; a direct acquisition is still bound to its requested encrypted values exactly. Removes the obsolete serial-DID token validation module and deep import. Native identity/certificate, wallet, transaction and authentication behavior is retained. Repairs cold BasePoint/JacobianPoint leaf exports with original-class initialization wrappers and exact declarations. The ESM UMD facade retains the established global effect and canonical class identities; the standalone classic bundle is preserved. Adds caller-installed completeBoundAction additional-output authorization with exact index, script and amount binding; the default external-input restriction and signed-template verification remain unchanged. Adds any-field saved-contact substring matching and contact-only results in parallel identity searches, plus explicit contactErrorMode, contactTimeoutMs and onContactError options for bounded optional-contact recovery. Existing callers retain strict contact errors; public discovery, certificate verification and permission checks remain unchanged. Aligns the Script interpreter with SV Node v1.2.3: OP_SUBSTR, OP_LEFT and OP_RIGHT operands are decoded through the checked int64 script-number path, so an operand longer than nine bytes or outside the signed 64-bit range is a script number overflow instead of being read from its first eight bytes, and OP_SPLIT also rejects a position above INT32_MAX.
  • Migration: SDK3 is a separate breaking retirement candidate: remove identity/DIDTokenValidation imports and use @bsv/did BRC202 identity-key resolution plus optional @bsv/did/brc52 original-signature envelopes. Retain historical data and recover authenticated identity bindings; do not relabel serial DIDs. Existing acquisition-result validation fixes remain. First-party SDK3 peer alternatives require complete packed qualification and owner coordination; preserved SDK2 ranges are not silently narrowed. See docs/guides/identity-did-vc-migration.md. The additive authorization callback requires independently verified local policy; wallet-returned labels or fields are not authority. The completeBoundAction.outputAuthorizationVersion function property allows compatible consumers to detect support without importing a missing named export from older ESM peers. No BRC100 wire or persistence migration is introduced by this addition. Identity search recovery is opt-in: useContacts true with contactErrorMode fallback bounds contact enrichment at 2000ms by default, or an explicit integer deadline from1 to60000ms. Use onContactError for partial-result warnings and handle public lookup errors separately from empty results. Legacy booleans and defaults remain compatible. A contact deadline does not cancel wallet requests or permission prompts. Applications must update their bundled SDK and search component; this source candidate does not update deployed apps. The splice-operand change is a consensus alignment with SV Node v1.2.3 and needs no API change; spends whose OP_SUBSTR, OP_LEFT or OP_RIGHT operands are longer than nine bytes, or whose ninth byte carries magnitude bits, were accepted by node v1.2.2 and are now rejected by both the node and the SDK.
Public subpathRuntime target(s)Declaration target(s)
../dist/esm/mod.js./dist/cjs/mod.js./dist/types/mod.d.ts./dist/cjs/mod.d.ts
./*.ts./dist/esm/src/*.js./dist/cjs/src/*.js./dist/types/src/*.d.ts./dist/cjs/src/*.d.ts
./primitives./dist/esm/src/primitives/index.js./dist/cjs/src/primitives/index.js./dist/types/src/primitives/index.d.ts./dist/cjs/src/primitives/index.d.ts
./primitives/BasePoint./dist/esm/src/primitives/entries/BasePoint.js./dist/cjs/src/primitives/entries/BasePoint.js./dist/types/src/primitives/entries/BasePoint.d.ts./dist/cjs/src/primitives/entries/BasePoint.d.ts
./primitives/BasePoint.ts./dist/esm/src/primitives/entries/BasePoint.js./dist/cjs/src/primitives/entries/BasePoint.js./dist/types/src/primitives/entries/BasePoint.d.ts./dist/cjs/src/primitives/entries/BasePoint.d.ts
./primitives/JacobianPoint./dist/esm/src/primitives/entries/JacobianPoint.js./dist/cjs/src/primitives/entries/JacobianPoint.js./dist/types/src/primitives/entries/JacobianPoint.d.ts./dist/cjs/src/primitives/entries/JacobianPoint.d.ts
./primitives/JacobianPoint.ts./dist/esm/src/primitives/entries/JacobianPoint.js./dist/cjs/src/primitives/entries/JacobianPoint.js./dist/types/src/primitives/entries/JacobianPoint.d.ts./dist/cjs/src/primitives/entries/JacobianPoint.d.ts
./primitives/*.ts./dist/esm/src/primitives/*.js./dist/cjs/src/primitives/*.js./dist/types/src/primitives/*.d.ts./dist/cjs/src/primitives/*.d.ts
./primitives/*./dist/esm/src/primitives/*.js./dist/cjs/src/primitives/*.js./dist/types/src/primitives/*.d.ts./dist/cjs/src/primitives/*.d.ts
./script./dist/esm/src/script/index.js./dist/cjs/src/script/index.js./dist/types/src/script/index.d.ts./dist/cjs/src/script/index.d.ts
./script/*.ts./dist/esm/src/script/*.js./dist/cjs/src/script/*.js./dist/types/src/script/*.d.ts./dist/cjs/src/script/*.d.ts
./script/*./dist/esm/src/script/*.js./dist/cjs/src/script/*.js./dist/types/src/script/*.d.ts./dist/cjs/src/script/*.d.ts
./script/templates./dist/esm/src/script/templates/index.js./dist/cjs/src/script/templates/index.js./dist/types/src/script/templates/index.d.ts./dist/cjs/src/script/templates/index.d.ts
./script/templates/*.ts./dist/esm/src/script/templates/*.js./dist/cjs/src/script/templates/*.js./dist/types/src/script/templates/*.d.ts./dist/cjs/src/script/templates/*.d.ts
./script/templates/*./dist/esm/src/script/templates/*.js./dist/cjs/src/script/templates/*.js./dist/types/src/script/templates/*.d.ts./dist/cjs/src/script/templates/*.d.ts
./transaction./dist/esm/src/transaction/index.js./dist/cjs/src/transaction/index.js./dist/types/src/transaction/index.d.ts./dist/cjs/src/transaction/index.d.ts
./transaction/*.ts./dist/esm/src/transaction/*.js./dist/cjs/src/transaction/*.js./dist/types/src/transaction/*.d.ts./dist/cjs/src/transaction/*.d.ts
./transaction/*./dist/esm/src/transaction/*.js./dist/cjs/src/transaction/*.js./dist/types/src/transaction/*.d.ts./dist/cjs/src/transaction/*.d.ts
./transaction/broadcaster./dist/esm/src/transaction/broadcasters/index.js./dist/cjs/src/transaction/broadcasters/index.js./dist/types/src/transaction/broadcasters/index.d.ts./dist/cjs/src/transaction/broadcasters/index.d.ts
./transaction/broadcaster/*.ts./dist/esm/src/transaction/broadcasters/*.js./dist/cjs/src/transaction/broadcasters/*.js./dist/types/src/transaction/broadcasters/*.d.ts./dist/cjs/src/transaction/broadcasters/*.d.ts
./transaction/broadcaster/*./dist/esm/src/transaction/broadcasters/*.js./dist/cjs/src/transaction/broadcasters/*.js./dist/types/src/transaction/broadcasters/*.d.ts./dist/cjs/src/transaction/broadcasters/*.d.ts
./transaction/broadcasters./dist/esm/src/transaction/broadcasters/index.js./dist/cjs/src/transaction/broadcasters/index.js./dist/types/src/transaction/broadcasters/index.d.ts./dist/cjs/src/transaction/broadcasters/index.d.ts
./transaction/broadcasters/*.ts./dist/esm/src/transaction/broadcasters/*.js./dist/cjs/src/transaction/broadcasters/*.js./dist/types/src/transaction/broadcasters/*.d.ts./dist/cjs/src/transaction/broadcasters/*.d.ts
./transaction/broadcasters/*./dist/esm/src/transaction/broadcasters/*.js./dist/cjs/src/transaction/broadcasters/*.js./dist/types/src/transaction/broadcasters/*.d.ts./dist/cjs/src/transaction/broadcasters/*.d.ts
./transaction/chaintrackers./dist/esm/src/transaction/chaintrackers/index.js./dist/cjs/src/transaction/chaintrackers/index.js./dist/types/src/transaction/chaintrackers/index.d.ts./dist/cjs/src/transaction/chaintrackers/index.d.ts
./transaction/chaintrackers/*.ts./dist/esm/src/transaction/chaintrackers/*.js./dist/cjs/src/transaction/chaintrackers/*.js./dist/types/src/transaction/chaintrackers/*.d.ts./dist/cjs/src/transaction/chaintrackers/*.d.ts
./transaction/chaintrackers/*./dist/esm/src/transaction/chaintrackers/*.js./dist/cjs/src/transaction/chaintrackers/*.js./dist/types/src/transaction/chaintrackers/*.d.ts./dist/cjs/src/transaction/chaintrackers/*.d.ts
./transaction/http./dist/esm/src/transaction/http/index.js./dist/cjs/src/transaction/http/index.js./dist/types/src/transaction/http/index.d.ts./dist/cjs/src/transaction/http/index.d.ts
./transaction/http/*.ts./dist/esm/src/transaction/http/*.js./dist/cjs/src/transaction/http/*.js./dist/types/src/transaction/http/*.d.ts./dist/cjs/src/transaction/http/*.d.ts
./transaction/http/*./dist/esm/src/transaction/http/*.js./dist/cjs/src/transaction/http/*.js./dist/types/src/transaction/http/*.d.ts./dist/cjs/src/transaction/http/*.d.ts
./transaction/fee-model./dist/esm/src/transaction/fee-models/index.js./dist/cjs/src/transaction/fee-models/index.js./dist/types/src/transaction/fee-models/index.d.ts./dist/cjs/src/transaction/fee-models/index.d.ts
./transaction/fee-model/*.ts./dist/esm/src/transaction/fee-models/*.js./dist/cjs/src/transaction/fee-models/*.js./dist/types/src/transaction/fee-models/*.d.ts./dist/cjs/src/transaction/fee-models/*.d.ts
./transaction/fee-model/*./dist/esm/src/transaction/fee-models/*.js./dist/cjs/src/transaction/fee-models/*.js./dist/types/src/transaction/fee-models/*.d.ts./dist/cjs/src/transaction/fee-models/*.d.ts
./transaction/fee-models./dist/esm/src/transaction/fee-models/index.js./dist/cjs/src/transaction/fee-models/index.js./dist/types/src/transaction/fee-models/index.d.ts./dist/cjs/src/transaction/fee-models/index.d.ts
./transaction/fee-models/*.ts./dist/esm/src/transaction/fee-models/*.js./dist/cjs/src/transaction/fee-models/*.js./dist/types/src/transaction/fee-models/*.d.ts./dist/cjs/src/transaction/fee-models/*.d.ts
./transaction/fee-models/*./dist/esm/src/transaction/fee-models/*.js./dist/cjs/src/transaction/fee-models/*.js./dist/types/src/transaction/fee-models/*.d.ts./dist/cjs/src/transaction/fee-models/*.d.ts
./messages./dist/esm/src/messages/index.js./dist/cjs/src/messages/index.js./dist/types/src/messages/index.d.ts./dist/cjs/src/messages/index.d.ts
./messages/*.ts./dist/esm/src/messages/*.js./dist/cjs/src/messages/*.js./dist/types/src/messages/*.d.ts./dist/cjs/src/messages/*.d.ts
./messages/*./dist/esm/src/messages/*.js./dist/cjs/src/messages/*.js./dist/types/src/messages/*.d.ts./dist/cjs/src/messages/*.d.ts
./compat./dist/esm/src/compat/index.js./dist/cjs/src/compat/index.js./dist/types/src/compat/index.d.ts./dist/cjs/src/compat/index.d.ts
./compat/*.ts./dist/esm/src/compat/*.js./dist/cjs/src/compat/*.js./dist/types/src/compat/*.d.ts./dist/cjs/src/compat/*.d.ts
./compat/*./dist/esm/src/compat/*.js./dist/cjs/src/compat/*.js./dist/types/src/compat/*.d.ts./dist/cjs/src/compat/*.d.ts
./totp./dist/esm/src/totp/index.js./dist/cjs/src/totp/index.js./dist/types/src/totp/index.d.ts./dist/cjs/src/totp/index.d.ts
./totp/*.ts./dist/esm/src/totp/*.js./dist/cjs/src/totp/*.js./dist/types/src/totp/*.d.ts./dist/cjs/src/totp/*.d.ts
./totp/*./dist/esm/src/totp/*.js./dist/cjs/src/totp/*.js./dist/types/src/totp/*.d.ts./dist/cjs/src/totp/*.d.ts
./wallet./dist/esm/src/wallet/index.js./dist/cjs/src/wallet/index.js./dist/types/src/wallet/index.d.ts./dist/cjs/src/wallet/index.d.ts
./wallet/*.ts./dist/esm/src/wallet/*.js./dist/cjs/src/wallet/*.js./dist/types/src/wallet/*.d.ts./dist/cjs/src/wallet/*.d.ts
./wallet/*./dist/esm/src/wallet/*.js./dist/cjs/src/wallet/*.js./dist/types/src/wallet/*.d.ts./dist/cjs/src/wallet/*.d.ts
./wallet/substrates./dist/esm/src/wallet/substrates/index.js./dist/cjs/src/wallet/substrates/index.js./dist/types/src/wallet/substrates/index.d.ts./dist/cjs/src/wallet/substrates/index.d.ts
./wallet/substrates/*.ts./dist/esm/src/wallet/substrates/*.js./dist/cjs/src/wallet/substrates/*.js./dist/types/src/wallet/substrates/*.d.ts./dist/cjs/src/wallet/substrates/*.d.ts
./wallet/substrates/*./dist/esm/src/wallet/substrates/*.js./dist/cjs/src/wallet/substrates/*.js./dist/types/src/wallet/substrates/*.d.ts./dist/cjs/src/wallet/substrates/*.d.ts
./auth./dist/esm/src/auth/index.js./dist/cjs/src/auth/index.js./dist/types/src/auth/index.d.ts./dist/cjs/src/auth/index.d.ts
./auth/*.ts./dist/esm/src/auth/*.js./dist/cjs/src/auth/*.js./dist/types/src/auth/*.d.ts./dist/cjs/src/auth/*.d.ts
./auth/*./dist/esm/src/auth/*.js./dist/cjs/src/auth/*.js./dist/types/src/auth/*.d.ts./dist/cjs/src/auth/*.d.ts
./auth/certificate./dist/esm/src/auth/certificates/index.js./dist/cjs/src/auth/certificates/index.js./dist/types/src/auth/certificates/index.d.ts./dist/cjs/src/auth/certificates/index.d.ts
./auth/certificate/*.ts./dist/esm/src/auth/certificates/*.js./dist/cjs/src/auth/certificates/*.js./dist/types/src/auth/certificates/*.d.ts./dist/cjs/src/auth/certificates/*.d.ts
./auth/certificate/*./dist/esm/src/auth/certificates/*.js./dist/cjs/src/auth/certificates/*.js./dist/types/src/auth/certificates/*.d.ts./dist/cjs/src/auth/certificates/*.d.ts
./auth/certificates./dist/esm/src/auth/certificates/index.js./dist/cjs/src/auth/certificates/index.js./dist/types/src/auth/certificates/index.d.ts./dist/cjs/src/auth/certificates/index.d.ts
./auth/certificates/*.ts./dist/esm/src/auth/certificates/*.js./dist/cjs/src/auth/certificates/*.js./dist/types/src/auth/certificates/*.d.ts./dist/cjs/src/auth/certificates/*.d.ts
./auth/certificates/*./dist/esm/src/auth/certificates/*.js./dist/cjs/src/auth/certificates/*.js./dist/types/src/auth/certificates/*.d.ts./dist/cjs/src/auth/certificates/*.d.ts
./identity./dist/esm/src/identity/index.js./dist/cjs/src/identity/index.js./dist/types/src/identity/index.d.ts./dist/cjs/src/identity/index.d.ts
./identity/*.ts./dist/esm/src/identity/*.js./dist/cjs/src/identity/*.js./dist/types/src/identity/*.d.ts./dist/cjs/src/identity/*.d.ts
./identity/*./dist/esm/src/identity/*.js./dist/cjs/src/identity/*.js./dist/types/src/identity/*.d.ts./dist/cjs/src/identity/*.d.ts
./overlay-tools./dist/esm/src/overlay-tools/index.js./dist/cjs/src/overlay-tools/index.js./dist/types/src/overlay-tools/index.d.ts./dist/cjs/src/overlay-tools/index.d.ts
./overlay-tools/*.ts./dist/esm/src/overlay-tools/*.js./dist/cjs/src/overlay-tools/*.js./dist/types/src/overlay-tools/*.d.ts./dist/cjs/src/overlay-tools/*.d.ts
./overlay-tools/*./dist/esm/src/overlay-tools/*.js./dist/cjs/src/overlay-tools/*.js./dist/types/src/overlay-tools/*.d.ts./dist/cjs/src/overlay-tools/*.d.ts
./telemetry./dist/esm/src/telemetry/index.js./dist/cjs/src/telemetry/index.js./dist/types/src/telemetry/index.d.ts./dist/cjs/src/telemetry/index.d.ts
./telemetry/*.ts./dist/esm/src/telemetry/*.js./dist/cjs/src/telemetry/*.js./dist/types/src/telemetry/*.d.ts./dist/cjs/src/telemetry/*.d.ts
./telemetry/*./dist/esm/src/telemetry/*.js./dist/cjs/src/telemetry/*.js./dist/types/src/telemetry/*.d.ts./dist/cjs/src/telemetry/*.d.ts
./storage./dist/esm/src/storage/index.js./dist/cjs/src/storage/index.js./dist/types/src/storage/index.d.ts./dist/cjs/src/storage/index.d.ts
./storage/*.ts./dist/esm/src/storage/*.js./dist/cjs/src/storage/*.js./dist/types/src/storage/*.d.ts./dist/cjs/src/storage/*.d.ts
./storage/*./dist/esm/src/storage/*.js./dist/cjs/src/storage/*.js./dist/types/src/storage/*.d.ts./dist/cjs/src/storage/*.d.ts
./kvstore./dist/esm/src/kvstore/index.js./dist/cjs/src/kvstore/index.js./dist/types/src/kvstore/index.d.ts./dist/cjs/src/kvstore/index.d.ts
./kvstore/*.ts./dist/esm/src/kvstore/*.js./dist/cjs/src/kvstore/*.js./dist/types/src/kvstore/*.d.ts./dist/cjs/src/kvstore/*.d.ts
./kvstore/*./dist/esm/src/kvstore/*.js./dist/cjs/src/kvstore/*.js./dist/types/src/kvstore/*.d.ts./dist/cjs/src/kvstore/*.d.ts
./remittance./dist/esm/src/remittance/index.js./dist/cjs/src/remittance/index.js./dist/types/src/remittance/index.d.ts./dist/cjs/src/remittance/index.d.ts
./remittance/*.ts./dist/esm/src/remittance/*.js./dist/cjs/src/remittance/*.js./dist/types/src/remittance/*.d.ts./dist/cjs/src/remittance/*.d.ts
./remittance/*./dist/esm/src/remittance/*.js./dist/cjs/src/remittance/*.js./dist/types/src/remittance/*.d.ts./dist/cjs/src/remittance/*.d.ts
./umd./dist/esm/src/umd.js./dist/types/src/umd.d.ts

@bsv/simple

  • Package documentation: docs/packages/helpers/simple.md
  • Source: packages/helpers/simple
  • Release note: Corrects PushDrop self-derivation ownership, pins Message Box responses to the authenticated peer, hardens wallet, credential, DID, persistence, and transaction boundaries, preserves explicit offline migration identifiers and historical signature verification for pre-0.6 short certificate types while keeping new issuance, remote metadata, and wallet operations canonical 32-byte, and changes the generated server-wallet handler to require explicit authenticated action-level authorization. Preserves original BRC52 signed bytes, including the SDK certificate serializer's existing field order; persisted local field ordering remains a separate concern. Replaces mutable serial DID tooling with offline identity-key DID adapters and copied VC/VP proof wrappers with original-signature-preserving BRC52 envelopes. Retains certificate issuance/acquisition/revocation and persisted data.
  • Migration: Simple0.7 is a breaking pre-1.0 candidate. Remove mutable DID/resolver/provider configuration, proxy handlers and DIDError/types; use DID.fromIdentityKey/resolve and wallet.getDID. CredentialIssuer.issue returns {credential,keyringForSubject}; verify accepts exact JSON or UTF8 bytes and returns structured cryptographic results. The HTTP verify route now requires {credential: originalEnvelopeJson} with original text as a string; parsed objects return HTTP400. Web request decoding rejects duplicate members and invalid UTF8, and custom parsed-body adapters must establish equivalent strict decoding. Preserve received text and inspect verification.verified, not HTTP success. Local revocation record status is retained/unknown, not inferred chain revocation. See docs/guides/identity-did-vc-migration.md. Replace createServerWalletHandler() deployments with createServerWalletHandler({ authorize: async ({ action, headers }) => authenticatedSessionCanUseAction(headers, action) }). The callback must return literal true for each status, create, request, receive, balance, outputs, or reset action; omission now returns HTTP 403 for every action. Roll out the authentication layer and callback with the package, update anonymous probes or automation, and apply the same policy to every replica. Do not emulate the old public behavior with an unconditional authorize: () => true callback. Valid recipient derivations and authenticated Message Box peers remain supported; malformed, wrong-owner, or transaction-mutated flows now fail closed. New CredentialSchema and Certifier records use canonical 32-byte types. Current SDK wallet methods reject historical short types, so do not put migration aliases in wallet list, acquire, prove, or relinquish calls. Export affected records through the storage version that created them, authenticate them offline against the exact locally configured identifier, and reissue/import canonical replacements; no legacy certificate is rewritten automatically. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/. Persisted local field ordering requires no migration; transport adapters preserve original certificate signing bytes.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts
./browser./dist/browser.mjs./dist/browser.cjs./dist/browser.d.mts./dist/browser.d.cts
./server./dist/server.mjs./dist/server.cjs./dist/server.d.mts./dist/server.d.cts

@bsv/templates

  • Package documentation: docs/packages/helpers/templates.md
  • Source: packages/helpers/ts-templates
  • Release note: Templates 2.0.0 replaces the Mandala token format with BRC-162 (BSV-21 binary) token outputs. Adds Bsv21Binary: an encoder and decoder for the BRC-162 prefix (token id, amount, optional payload) in front of any locking script, with exactly one accepted encoding per value (32-byte id as a direct push; amount OP_0, OP_1..OP_16 or a minimal direct push; amounts as bigint up to 2^64-1), role helpers, _0 token-id strings, lock/lockBRC29 and a P2PKH unlock. Adds a hand-rolled strict DAG-CBOR subset codec (encodeStrictCbor/decodeStrictCbor) with no new runtime dependency, safe in CommonJS and ESM. Includes the 1.10.3 CommonJS interop fix (issue #571): SDK classes are imported by name from the SDK barrels. Removes MandalaToken, MandalaAdmin and ADMIN_PROTOCOL. Also publishes the SDK 3 peer alternative already declared in source (superseded 1.10.4 candidate, PR #729): @bsv/sdk ^2.1.6 || ^3.0.0.
  • Migration: Breaking. Removed exports: MandalaToken, MandalaTokenDecoded, MandalaAdmin, ADMIN_PROTOCOL, MandalaAdminDecoded, MandalaActionDetails, MandalaActionKind, MandalaAdminLockParams, MandalaAdminUnlockParams and AssetMetadata. Removed subpath @bsv/templates/mandala-signing.ts. The @bsv/templates/mandala-encoding.ts subpath keeps only createMinimallyEncodedScriptChunk, decodeScriptNum and decodeScriptNumChunk; encodeScriptNum, encodeAssetId and decodeAssetId are removed. Replace MandalaToken/MandalaAdmin with Bsv21Binary: deploy, authority and value outputs are lock(tokenId | null, amount, pubKeyHash, payload?) with bigint amounts and _0 token ids (tokenIdFromString/tokenIdToString), decoded with Bsv21Binary.decode. Mandala admin actions are committed by sha256 of strict-CBOR details in the authority output payload, not by a commitment-derived key. This is a clean break with no data migration: tokens and admin chains in the old format are not readable by 2.0.0. @bsv/overlay-topics 2.0.0 consumes this format; the infra/overlay-server wiring follows after publication. SDK consumers may retain ^2.1.6 or install the SDK3 candidate; SDK3 removes the obsolete DID token API (see docs/guides/identity-did-vc-migration.md).
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.js./dist/mod.cjs./dist/mod.d.ts./dist/mod.d.cts
./*.ts./dist/src/*.js./dist/src/*.cjs./dist/src/*.d.ts./dist/src/*.d.cts

@bsv/teranode-listener

  • Package documentation: docs/packages/network/teranode-listener.md
  • Source: packages/network/ts-p2p
  • Release note: Adds optional bounded decoding for Teranode's two-layer JSON message envelope and typed topic payload interfaces. Hardens the network boundary with canonical PNET, multiaddr, topic, configuration, callback, and numeric validation; immutable caller-owned inputs; exact runtime controls; coalesced retry-safe lifecycle transitions; and a working DHT-disable control. Replaces the internal placeholder subtree hash with the canonical Bitcoin Merkle root and verifies exact uint64 values, dimensions, totals, conflicts, framing, and resource ceilings before accepting serialized subtree state. Refreshes the compatible libp2p dependency set while retaining the imported source's hash-pinned MIT provenance and notices. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: No API migration is required for valid consumers: raw callbacks remain the default and decoding is opt-in with decodeMessages: true. Configuration arrays and callbacks are snapshotted at construction, boolean controls must be literal booleans, and malformed or duplicate topics, addresses, keys, and unsupported properties now fail closed. usePrivateDHT: false now actually omits the DHT service. The published mainnet PNET value is transport compatibility data, not a publisher credential; decoded sender and payload fields remain untrusted and security-critical claims require independent validation. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.js./dist/index.js./dist/index.d.ts
./package.json./package.json—

@bsv/verifast

  • Package documentation: docs/packages/sdk/verifast.md
  • Source: packages/verifast
  • Release note: Hardens JavaScript, worker, and WebAssembly verification boundaries with exact network and height validation, literal consensus verdicts, uint32 flags, dense bounded byte and signature inputs, bounded batches, exact verdict shapes, and deterministic preload and disposal lifecycle handling. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Valid typed verification calls and worker protocols remain compatible. Custom module factories and WASM adapters must return the exact documented binary and boolean shapes; coercive network, height, flag, byte, batch, verdict, lifecycle, or disposed-instance values now fail closed. Keep THIRD_PARTY_NOTICES.md and LICENSES/ with every JavaScript and WebAssembly distribution. SDK consumers may retain ^2.1.8 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/mod.browser.js./dist/mod.js./dist/cjs/mod.cjs./dist/mod.js./dist/mod.browser.d.ts./dist/mod.d.ts./dist/mod.d.cts
./umd./dist/umd/verifast.js./dist/umd.js./dist/umd/verifast.cjs./dist/umd.js./dist/umd.d.ts./dist/umd.d.cts
./wasm/bdk-core.umd.js./dist/src/wasm/bdk-core.umd.js—
./wasm/bdk-core.umd.wasm./dist/src/wasm/bdk-core.umd.wasm—
./wasm/bdk-core.wasm./dist/src/wasm/bdk-core.wasm—

@bsv/wallet-helper

  • Package documentation: docs/packages/helpers/wallet-helper.md
  • Source: packages/helpers/bsv-wallet-helper
  • Release note: Corrects caller-owned bilateral address derivation and hardens address generation, transaction building, prevout binding, P2PKH, Ordinal, OrdLock, preimage, sighash, OP_RETURN, script, amount, output, and final-wallet-transaction validation. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: getAddress now derives with forSelf: true and returns the caller-owned side of the bilateral relationship. Applications that stored or coordinated the previous peer-owned result must regenerate and exchange the corrected address before sending value. Amount must be an integer from 1 through 1,000 and counterparties must be valid public keys. Valid canonical transaction-builder flows remain supported; malformed, ambiguous, or wallet-mutated results now fail closed. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. SDK consumers may retain ^2.1.6 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.
Public subpathRuntime target(s)Declaration target(s)
../dist/index.mjs./dist/index.cjs./dist/index.d.mts./dist/index.d.cts

@bsv/wallet-relay

  • Package documentation: docs/packages/wallet/wallet-relay.md
  • Source: packages/wallet/ts-wallet-relay
  • Release note: Adds the strict package contract and preserves wallet RPC, encrypted relay payloads, signatures, and transaction bytes across number-array, Uint8Array, Buffer, and historical numeric-key JSON runtimes. Standardizes first-party author metadata on the current BSV Association name. Enforces signed pairing metadata before relay resolution, requires HTTPS outside loopback development for pairing origins and directly configured relay APIs, and rejects privileged wallet methods when no explicit approval callback is configured. Retains portable wallet RPC byte handling and the strict package contract. Tolerates two missed heartbeat pongs by default and adds close diagnostics whose callback failures cannot interrupt disconnect cleanup. Hardens both wallet-RPC trust boundaries with exact argument and security-sensitive result validation; serializes sequence acceptance and outbound encryption; prevents stale mobile lifecycle work, reconnect identity squatting, active-socket authorization after expiry, and shutdown races; makes session lifetime absolute; and bounds concurrent wallet requests, log retention, response bodies, session capacity, and creation rate. Restricts active QR artifacts, pairing-URI structure, and scaffold output paths; adds no-store bearer-response policy, constant-time desktop-token checks, safe browser WebSocket subprotocol authentication, deterministic relay teardown, fail-closed callback containment, strict scaffold request parsing, and corrected wallet-authentication UI semantics. Adds an SDK3 peer alternative while preserving the existing SDK2 lower bound; clean packed SDK2.8.11 and SDK3 candidate consumers are documented in the identity/DID/VC migration guide.
  • Migration: Enable signed QR codes and distribute only HTTPS pairing origins and relay API URLs. Root-relative API paths and loopback HTTP remain supported. Configure onApprovalRequired for every method not deliberately listed in autoApproveMethods; unsigned pairing URIs and implicit approval are no longer accepted. Existing relay sessions, custom RPC method names, and supported wallet RPC byte encodings remain valid, and host applications continue to provide their matching Express runtime and type graph. Version 0.5 defaults to two missed pongs; set maxMissedHeartbeats to 1 to retain the prior heartbeat policy. Heartbeat intervals must fit the Node timer range. Preserve Cache-Control: no-store at proxies, prefer the stable bsv-wallet-relay plus token WebSocket subprotocols over the legacy token query parameter, and configure edge rate limiting in addition to the bounded in-process defaults. The 24-hour connected-session lifetime no longer renews on reconnect, malformed wallet calls fail with code 400, and WalletRelayClient retains at most 100 log entries unless maxLogEntries is configured. The QR remains a short-lived bearer invitation: keep it private and require explicit operation approval. Relay envelopes, cryptographic framing, and wallet RPC encodings remain unchanged. SDK consumers may retain ^2.4.1 or install the proposed SDK3 candidate. The immutable SDK2.8.11 reference has nine pre-existing SDK cold-leaf/UMD import defects; all historical floor versions are not qualified by this matrix. SDK3 removes the obsolete DID token API; use the identity-key DID and optional BRC52 adapters described in docs/guides/identity-did-vc-migration.md. No other public API or wire migration is introduced by the peer alternative.

CLI entry points: {"wallet-relay":"./bin/init.mjs"}.

Public subpathRuntime target(s)Declaration target(s)
../dist/index.js./dist/index.cjs./dist/index.d.ts./dist/index.d.cts
./client./dist/client.js./dist/client.cjs./dist/client.d.ts./dist/client.d.cts
./react./dist/react.js./dist/react.cjs./dist/react.d.ts./dist/react.d.cts
./package.json./package.json—

@bsv/wallet-toolbox

  • Package documentation: docs/packages/wallet/wallet-toolbox.md
  • Source: packages/wallet/wallet-toolbox
  • Release note: WalletPermissionsManager retires signed no-send ownership and reference aliases after createAction or signAction reports sending or unproven, including sendWith-only calls and successful members of an undelayed review error. Failed or unreported actions retain their originator binding for retry or abort. Cleanup visits only the retired transaction's references and preserves aliases reused by newer actions. Adds an SDK3 peer alternative while retaining the existing SDK2.8.0 floor. Public Argon2id declarations reference the typed hash-wasm package while retaining the same generic binary/string contract and emitted runtime bytes. Fixes WAB faucet redemption for an empty wallet when storage adds a service charge. Local signer decisions for independently validated commission and derived change are retained privately through the permissions wrapper and bound by the SDK before signing. UMP pins anchor verified token-update lineage: password and token updates supersede their pinned predecessor, while unrelated historical continuations cannot override the anchor. Explicit overlay history is linked past confirmed Merkle anchors. Updates with missing pin ancestry remain indeterminate instead of selecting an unrelated continuation. Every retained token spend proves control through its unlocking script, including confirmed updates and hash rotation; funding paths do not establish token lineage. BRC-177 anchors fund both the protected action and an economic reclaim. Protected actions pay the bounded reclaim allowance surplus as fee and produce no automatically generated wallet change; ordinary change planning and its positive output cap remain unchanged. BEEF request data and schema-declared storage response bytes use the existing negotiated compact binary JSON encoding. Legacy peers retain numeric-array JSON, existing authentication and payload bounds, and byte-for-byte transaction/proof content. IndexedDB treats empty certificate certifier/type, transaction status and output-tag ID arrays as unrestricted optional filters, matching Knex. Nonempty filters, partial predicates and user ownership remain enforced. Internalizing an unproven transaction new to a user attempts broadcast before storing recipient outputs, including a sender's no-send transaction already known to shared storage. A failed broadcast rejects the internalization; transactions backed by a mining proof are not rebroadcast.
  • Migration: No public API, wire, database, or consumer migration is required. Pending no-send actions and retryable failures retain the same originator-bound abort behavior; positively queued or broadcast actions no longer retain session ownership records. Upgrade the SDK to a release exposing completeBoundAction.outputAuthorizationVersion=1 alongside wallet-toolbox 2.14.6. SDK2 peers keep their existing strict behavior; they do not obtain this fee-bearing faucet fix. The main SDK3.1 candidate retains the separate SDK3 retirement migration; SDK2 hosts require a coordinated additive backport or that migration. Serialized or cross-package-instance result adapters discard local authority and fail closed. Signup interruption/retry persistence is unchanged; reconcile any previous faucet transaction before repeating a failed signup. No API or schema migration is required for pin continuity. Retire a support pin only after unpinned lookup independently returns the verified current token. Deploy overlay 2.6.4 plus overlay-topics 2.0.1 or an equivalent history decider for confirmed ancestry. Stored WAB pins remain lineage anchors; the client follows verified descendants without needing an administrative pin rewrite. No API, wire or database migration is required for the BRC-177 funding fix. A protected action can pay the difference between its delivery need and the reclaim floor as miner fee. Funding/reclaim fees remain the wallet owner's responsibility; upgrade the active storage implementation as well as client packages. No API, database or peer migration is required for compact BEEF transport. Upgrade clients and active storage to obtain both request and response savings; older peers retain ordinary JSON. Existing payload ceilings still apply. No API, wire or schema migration is required for the IndexedDB filter fix. Empty optional arrays now behave like omitted filters. Applications still receive only records allowed by their user and partial predicates; nonempty arrays retain their restrictions. No public API, wire or database migration is required for internalization broadcast. Upgrade the active storage implementation. Recipients receive a review-actions error when broadcast is rejected and must inspect that result before retrying; no recipient outputs are stored on rejection. Existing proven transactions retain their no-rebroadcast path.
Public subpathRuntime target(s)Declaration target(s)
../out/src/index.js./out/src/index.js./out/src/index.d.ts
./out/src/sdk./out/src/sdk/index.js./out/src/sdk/index.js./out/src/sdk/index.d.ts
./out/src/*./out/src/*.js./out/src/*.d.ts
./package.json./package.json—

@bsv/wallet-toolbox-client

  • Package documentation: docs/packages/wallet/wallet-toolbox-client.md
  • Source: packages/wallet/wallet-toolbox/client
  • Release note: WalletPermissionsManager retires signed no-send ownership and reference aliases after createAction or signAction reports sending or unproven, including sendWith-only calls and successful members of an undelayed review error. Failed or unreported actions retain their originator binding for retry or abort. Cleanup visits only the retired transaction's references and preserves aliases reused by newer actions. Fixes WAB faucet redemption for an empty wallet when storage adds a service charge. Local signer decisions for independently validated commission and derived change are retained privately through the permissions wrapper and bound by the SDK before signing. UMP pins anchor verified token-update lineage: password and token updates supersede their pinned predecessor, while unrelated historical continuations cannot override the anchor. Explicit overlay history is linked past confirmed Merkle anchors. Updates with missing pin ancestry remain indeterminate instead of selecting an unrelated continuation. Every retained token spend proves control through its unlocking script, including confirmed updates and hash rotation; funding paths do not establish token lineage. BRC-177 anchors fund both the protected action and an economic reclaim. Protected actions pay the bounded reclaim allowance surplus as fee and produce no automatically generated wallet change; ordinary change planning and its positive output cap remain unchanged. BEEF request data and schema-declared storage response bytes use the existing negotiated compact binary JSON encoding. Legacy peers retain numeric-array JSON, existing authentication and payload bounds, and byte-for-byte transaction/proof content. IndexedDB treats empty certificate certifier/type, transaction status and output-tag ID arrays as unrestricted optional filters, matching Knex. Nonempty filters, partial predicates and user ownership remain enforced. Internalizing an unproven transaction new to a user attempts broadcast before storing recipient outputs, including a sender's no-send transaction already known to shared storage. A failed broadcast rejects the internalization; transactions backed by a mining proof are not rebroadcast.
  • Migration: No public API, wire, database, or consumer migration is required. Pending no-send actions and retryable failures retain the same originator-bound abort behavior; positively queued or broadcast actions no longer retain session ownership records. Upgrade the SDK to a release exposing completeBoundAction.outputAuthorizationVersion=1 alongside wallet-toolbox 2.14.6. SDK2 peers keep their existing strict behavior; they do not obtain this fee-bearing faucet fix. The main SDK3.1 candidate retains the separate SDK3 retirement migration; SDK2 hosts require a coordinated additive backport or that migration. Serialized or cross-package-instance result adapters discard local authority and fail closed. Signup interruption/retry persistence is unchanged; reconcile any previous faucet transaction before repeating a failed signup. No API or schema migration is required for pin continuity. Retire a support pin only after unpinned lookup independently returns the verified current token. Deploy overlay 2.6.4 plus overlay-topics 2.0.1 or an equivalent history decider for confirmed ancestry. Stored WAB pins remain lineage anchors; the client follows verified descendants without needing an administrative pin rewrite. No API, wire or database migration is required for the BRC-177 funding fix. A protected action can pay the difference between its delivery need and the reclaim floor as miner fee. Funding/reclaim fees remain the wallet owner's responsibility; upgrade the active storage implementation as well as client packages. No API, database or peer migration is required for compact BEEF transport. Upgrade clients and active storage to obtain both request and response savings; older peers retain ordinary JSON. Existing payload ceilings still apply. No API, wire or schema migration is required for the IndexedDB filter fix. Empty optional arrays now behave like omitted filters. Applications still receive only records allowed by their user and partial predicates; nonempty arrays retain their restrictions. No public API, wire or database migration is required for internalization broadcast. Upgrade the active storage implementation. Recipients receive a review-actions error when broadcast is rejected and must inspect that result before retrying; no recipient outputs are stored on rejection. Existing proven transactions retain their no-rebroadcast path.
Public subpathRuntime target(s)Declaration target(s)
../out/index.client.mjs./out/index.client.mjs./out/index.client.cjs./out/index.client.d.mts./out/index.client.d.mts./out/index.client.d.cts
./package.json./package.json—

@bsv/wallet-toolbox-mobile

  • Package documentation: docs/packages/wallet/wallet-toolbox-mobile.md
  • Source: packages/wallet/wallet-toolbox/mobile
  • Release note: WalletPermissionsManager retires signed no-send ownership and reference aliases after createAction or signAction reports sending or unproven, including sendWith-only calls and successful members of an undelayed review error. Failed or unreported actions retain their originator binding for retry or abort. Cleanup visits only the retired transaction's references and preserves aliases reused by newer actions. Adds an SDK3 peer alternative while retaining the existing SDK2.8.0 floor. Fixes WAB faucet redemption for an empty wallet when storage adds a service charge. Local signer decisions for independently validated commission and derived change are retained privately through the permissions wrapper and bound by the SDK before signing. UMP pins anchor verified token-update lineage: password and token updates supersede their pinned predecessor, while unrelated historical continuations cannot override the anchor. Explicit overlay history is linked past confirmed Merkle anchors. Updates with missing pin ancestry remain indeterminate instead of selecting an unrelated continuation. Every retained token spend proves control through its unlocking script, including confirmed updates and hash rotation; funding paths do not establish token lineage. BRC-177 anchors fund both the protected action and an economic reclaim. Protected actions pay the bounded reclaim allowance surplus as fee and produce no automatically generated wallet change; ordinary change planning and its positive output cap remain unchanged. BEEF request data and schema-declared storage response bytes use the existing negotiated compact binary JSON encoding. Legacy peers retain numeric-array JSON, existing authentication and payload bounds, and byte-for-byte transaction/proof content. Internalizing an unproven transaction new to a user attempts broadcast before storing recipient outputs, including a sender's no-send transaction already known to shared storage. A failed broadcast rejects the internalization; transactions backed by a mining proof are not rebroadcast.
  • Migration: No public API, wire, database, or consumer migration is required. Pending no-send actions and retryable failures retain the same originator-bound abort behavior; positively queued or broadcast actions no longer retain session ownership records. Upgrade the SDK to a release exposing completeBoundAction.outputAuthorizationVersion=1 alongside wallet-toolbox 2.14.6. SDK2 peers keep their existing strict behavior; they do not obtain this fee-bearing faucet fix. The main SDK3.1 candidate retains the separate SDK3 retirement migration; SDK2 hosts require a coordinated additive backport or that migration. Serialized or cross-package-instance result adapters discard local authority and fail closed. Signup interruption/retry persistence is unchanged; reconcile any previous faucet transaction before repeating a failed signup. No API or schema migration is required for pin continuity. Retire a support pin only after unpinned lookup independently returns the verified current token. Deploy overlay 2.6.4 plus overlay-topics 2.0.1 or an equivalent history decider for confirmed ancestry. Stored WAB pins remain lineage anchors; the client follows verified descendants without needing an administrative pin rewrite. No API, wire or database migration is required for the BRC-177 funding fix. A protected action can pay the difference between its delivery need and the reclaim floor as miner fee. Funding/reclaim fees remain the wallet owner's responsibility; upgrade the active storage implementation as well as client packages. No API, database or peer migration is required for compact BEEF transport. Upgrade clients and active storage to obtain both request and response savings; older peers retain ordinary JSON. Existing payload ceilings still apply. No public API, wire or database migration is required for internalization broadcast. Upgrade the active storage implementation. Recipients receive a review-actions error when broadcast is rejected and must inspect that result before retrying; no recipient outputs are stored on rejection. Existing proven transactions retain their no-rebroadcast path.
Public subpathRuntime target(s)Declaration target(s)
../out/index.mobile.mjs./out/index.mobile.mjs./out/index.mobile.cjs./out/index.mobile.d.mts./out/index.mobile.d.mts./out/index.mobile.d.cts
./package.json./package.json—

create-bsv-app

  • Package documentation: docs/packages/helpers/create-bsv-app.md
  • Source: packages/helpers/create-bsv-app
  • Release note: Advances the scaffold release metadata so generated applications consume the compatibility-preserving security hardening in this release train.
  • Migration: Existing CLI flags, network choices, and generated project structure are unchanged. Regenerate or update dependencies after the patched packages are published. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package.

CLI entry points: {"create-bsv-app":"dist/index.js"}.

Public subpathRuntime target(s)Declaration target(s)
../dist/index.js./dist/index.d.ts

Change procedure

  1. Change the public package and select the SemVer impact from its packed API, runtime, wire, persistence, and declaration changes.
  2. Bump only affected package manifests and first-party dependents whose packed contract changes.
  3. Update the matching entry in governance/package-release-notes.json, including explicit migration guidance even when no consumer action is required.
  4. Run pnpm docs:packages, pnpm docs:packages:check, pnpm check-versions, packed-consumer checks, and the full release gates.
  5. After an authorized publication, update publishedVersion to the registry result and set releaseType to none only when source and npm match.