The examples below use the real surface of @flashyid/sdk — the verify path (verifyAssertion, authorize) and the grant kernel, source-available in the flashyid repo. An npm release is pending; roadmap APIs live on the spec.
You run agents. Mint a grant beneath your own, hand it to an agent, and let it present an assertion elsewhere.
Someone else’s agent is talking to you. You hold no Flashy credential and need none — the key is public.
No account, no key, no contact with us. Every step below runs against the public surface.
The verify path is source-available in the flashyid repo (src/sdk); an npm release is coming. No account, no key.
The public JWKS at id.flashyid.com is cacheable for an hour — the SDK fetches and caches it for you.
One call verifies the assertion and checks the delegation it carries against what the action needs.
On success you get the effective grant; on refusal a specific code (out_of_mandate, expired, revoked, chain_widened) — the code tells you what to do.
This list is the real export surface of src/sdk, and a test asserts it matches the package’s exports — a method that drifts from the code fails the build before it reaches a reader.