atsign-foundation/at_client_sdk
66.6
Adequate · 19 September 2026
120.7k
lines of production code
Dart
primary language
1
measurement over time
What this system is
This system is a comprehensive Dart SDK for the Atsign Protocol, providing the foundational libraries for decentralized, end-to-end encrypted data management and secure device authentication. It implements a full cryptographic stack with post-quantum readiness, managing key lifecycle, enrollment workflows, and secure storage across native and WebAssembly environments. The SDK exposes high-level APIs for reactive data collections, real-time notifications, and RPC communication, supported by specialized Flutter plugins for building cross-platform mobile and desktop applications.
How it got here
2021–2022 — Flutter plugin expansion and client refactoring
95 changes.
This period focused on releasing a suite of new Flutter platform plugins, including chat, events, location, login, and theme services, while establishing their native scaffolding and example applications. Simultaneously, the core at\_client SDK underwent significant refactoring to introduce explicit lifecycle management, reactive KeyStream APIs, and a structured post-quantum cryptography posture, supported by comprehensive unit and end-to-end test coverage.
2023–2025 — APKAM onboarding and post-quantum support
54 changes.
This period focused on implementing the Advanced Public Key Authentication Method (APKAM) and post-quantum cryptography support across the atProtocol ecosystem. It introduced the at\_auth package for centralized onboarding and enrollment, expanded at\_commons with new verb builders and key models, and added comprehensive CLI tools and Flutter UI components to manage the new authentication lifecycle.
2026 — Post-quantum cryptography and AtCollection integration
36 changes.
This period focused on integrating post-quantum cryptographic algorithms into the SDK's core infrastructure, including key exchange, signing, and enrollment workflows, while introducing the new AtCollection API for typed, reactive data management. Significant architectural improvements included refactoring storage backends for isolation, enhancing network timeout policies, and strengthening keyfile security with atomic updates and typed serialization. The work was supported by comprehensive testing, benchmarking, and new Flutter UI components for device authorization.
Features
Add AtBuffer interface and implementations for string and byte data
The \at\_commons\ package now includes a new \AtBuffer\ abstract class along with concrete \StringBuffer\ and \ByteBuffer\ implementations in the \buffer\ source directory. This provides a standardized way to manage message buffers with configurable capacity and terminating characters, throwing \AtBufferOverFlowException\ when limits are exceeded. The \StringBuffer\ handles string concatenation while \ByteBuffer\ manages raw byte data using Dart's \BytesBuilder\.
_packages/at\commons/lib/src/buffer · high confidence
Add ChatScreen widget for displaying chat history and messages
The ChatScreen widget has been added to the at\_chat\_flutter package, providing a UI component that displays chat history via a stream builder and supports both full-screen and bottom-sheet modes. Users can now view incoming and outgoing messages with customizable colors, delete specific messages through a service integration, and see loading or empty states while the chat history is being fetched.
_packages/at\_chat\flutter/lib/screens · high confidence
Add Message model for chat data representation
Introduced the Message model class within the chat package to define the structure of chat messages. This model supports both text and image content types, tracks message direction (incoming or outgoing), and includes serialization methods (JSON/map conversion) and equality checks to facilitate data handling within the chat interface.
_packages/at\_chat\flutter/lib/models · high confidence
Add Zariot IoT Safe example for secure element signing
The \packages/at\_chops/example/zariot\ directory now includes example code demonstrating how to use AT Chops with a Zariot IoT Safe secure element. This includes an \ExternalSigner\ class that handles serial port communication (via \dart\_periphery\) to perform cryptographic operations like key pair generation, signing, and public key retrieval on the SIM card, as well as an \AtChopsSecureElement\ implementation that integrates this external signer with the AT Chops signing interface.
_packages/at\chops/example/zariot · high confidence
Add at\_key\_regex\_utils and string\_utils to at\_commons
The at\_commons package now includes new utility files for key validation and string handling. The at\_key\_regex\_utils.dart file introduces a Regexes abstract class and implementations (RegexesWithMandatoryNamespace, RegexesNonMandatoryNamespace) that define regular expressions for validating at-sign keys, including public, private, self, shared, cached, local, and reserved keys. It also provides a RegexUtil class with a keyType method to determine the type of an at-key. Additionally, string\_utils.dart adds an extension on String? to check for null or empty values.
_packages/at\commons/lib/src/utils · high confidence
Add at\_theme\_flutter example app with onboarding and profile UI
The example application for the at\_theme\_flutter package has been added, providing a complete demo of the theme library in action. The app includes an onboarding flow that initializes the AtClient and allows users to onboard an atSign, followed by a profile page that demonstrates dynamic theming using the AppTheme service. The implementation features a tabbed interface, user details display, and settings access, all styled according to the current theme configuration.
_packages/at\_theme\flutter/example/lib · high confidence
Add base2e15 and dart\_utf7 encoding packages
The repository now includes the \base2e15\ and \dart\_utf7\ packages, providing binary-to-text encoding capabilities. The \base2e15\ package encodes binary data into Unicode strings using CJK and Hangul characters (15 bits per character), while the \dart\_utf7\ package provides UTF-7 encoding and decoding functionality. Both packages include their respective source code, tests, and documentation.
packages/base2e15 · high confidence
Add example app for at\_location\_flutter
The example application for the at\_location\_flutter package has been added, providing a complete demo of the library's capabilities. The app includes an onboarding flow using at\_onboarding\_flutter, a main screen for managing atSign authentication, and a second screen that demonstrates key features such as sending and requesting location updates, tracking location via the AtLocationFlutterPlugin, and displaying multiple location points on a map. It also handles incoming location notifications through a stream builder.
_packages/at\_location\flutter/example/lib · high confidence
Added AES-CTR performance and memory-leak benchmark probes
The \packages/at\_chops/benchmark\ directory now includes two new Dart scripts for manual performance and stability analysis. \aes\_ctr\_throughput.dart\ measures and compares the throughput of the \at\_chops\ FFI implementation against pure-Dart \cryptography\ implementations across various chunk sizes, helping users understand performance characteristics and potential crossover points. \aes\_ctr\_ctx\_leak.dart\ provides a manual probe to detect native memory leaks in \AesCtrFfiCipher\ by monitoring RSS changes when cipher contexts are disposed versus held, addressing a known risk of leaked \EVP\_CIPHER\_CTX\ structures.
_packages/at\chops/benchmark · high confidence
Added CLI example programs for at\_cli\_commons
New example programs have been added to the at\_cli\_commons package to demonstrate usage. The scan\_example.dart script shows how to list all data keys stored on the atServer, while put\_and\_get\_example.dart demonstrates storing and retrieving private data, including fetching it via the remote atServer and decrypting it. These examples utilize the CLIBase class for argument parsing and atClient for data operations.
_packages/at\_cli\commons/example · high confidence
Added CLI examples for APKAM enrollment and onboarding
The \packages/at\_onboarding\_cli/example\ directory now includes runnable Dart scripts (\onboard.dart\, \get\_cram\_key.dart\) and a comprehensive README that guide users through the full APKAM enrollment lifecycle. These examples demonstrate how to onboard an atsign, retrieve CRAM secrets, authenticate, and manage enrollment approvals using the \args\ package for command-line argument parsing.
_packages/at\_onboarding\cli/example · high confidence
Added ChatService for managing chat history and notifications
Introduced a new ChatService singleton in the at\_chat\_flutter package to handle chat message storage, retrieval, and real-time updates. The service initializes with an AtClientManager instance and manages local chat history by fetching messages from the At Protocol store, interleaving sent and received messages by timestamp, and subscribing to notifications to update the UI when new messages arrive. It supports both one-to-one and group chats, handling key generation and decryption for chat content.
_packages/at\_chat\flutter/lib/services · high confidence
Added ThemeService for persistent theme storage
Introduced a new ThemeService singleton that manages the persistence of application theme data using the AtProtocol. This service handles initializing the connection parameters, storing theme configurations via the AtClient's put method, and retrieving them via get, ensuring theme preferences are synced and available across sessions.
_packages/at\_theme\flutter/lib/services · high confidence
Added at\_policy example application demonstrating policy enforcement workflow
The example directory now includes a runnable demonstration of the at\_policy package, featuring three Dart scripts (client.dart, service.dart, and policy.dart) that simulate a request flow where a client sends requests to a service, which then queries a policy service for authorization decisions. The example includes configuration files such as .gitignore, CHANGELOG.md, README.md, and analysis\_options.yaml to support development and usage of the sample application.
_packages/at\policy/example · high confidence
Added authorization exception models for enrollment workflows
The models directory now includes a new \AuthorisationException\ class and several specific subclasses (such as \InvalidSppException\, \OtpGenerationException\, and exceptions for failing to approve, deny, or revoke enrollment requests). These are exported via \models.dart\, providing structured error handling for authorization and enrollment operations within the Flutter client.
_packages/at\_client\flutter/lib/src/models · high confidence
Added cryptographic benchmarking harness for at\_chips primitives
A new benchmark script (\crypto\_bench.dart\) has been added to the \at\_client\ package to measure the performance of cryptographic operations provided by \at\_chips\. The harness benchmarks symmetric encryption (AES-256-GCM vs legacy AES-256-CTR) across various payload sizes, as well as post-quantum key conveyance using X-Wing and legacy RSA-2048 wrapping. This allows developers to track the computational cost of these primitives in microseconds.
_packages/at\client/benchmark · high confidence
Added legacy example scripts for activation and authentication
New example files have been added to the \at\_onboarding\_cli\ package to demonstrate legacy usage patterns. \activate.dart\ shows how to activate an atSign using a CRAM secret and store keys in the home directory, while \authenticate.dart\ demonstrates authenticating via an existing keyfile with command-line argument support. These examples serve as reference implementations for programs that need to interact with the atClient lifecycle using older onboarding methods.
_packages/at\_onboarding\_cli/example/legacy\examples · high confidence
Added macOS example app scaffolding
The at\_chat\_flutter example now includes a complete macOS platform implementation, enabling users to run and test the chat application on macOS. This addition provides the necessary Xcode project structure, including the main application entry point, window management, and a generated plugin registrant that initializes key dependencies like biometric storage, file picker, and path provider. It also configures the app bundle with specific entitlements for keychain access and network capabilities, and registers the .atkeys file type to support cryptographic key file handling on the desktop.
_packages/at\_chat\flutter/example/macos · high confidence
Added macOS platform support for the example app
The \at\_events\_flutter\ example application now includes a complete macOS implementation, allowing users to build and run the app on macOS. This change adds the necessary Xcode project structure, including the \Runner\ target, \AppDelegate\, and \MainFlutterWindow\, along with a \GeneratedPluginRegistrant\ that registers macOS-compatible versions of plugins such as \at\_file\_saver\, \at\_login\_flutter\, \biometric\_storage\, \device\_info\_plus\, \file\_picker\, \flutter\_local\_notifications\, \geolocator\_apple\, \path\_provider\_foundation\, \share\_plus\, \shared\_preferences\_foundation\, \sqflite\_darwin\, \url\_launcher\_macos\, and \webview\_flutter\_wkwebview\. The configuration also defines the app bundle identifier, entitlements for sandboxing and file access, and declares support for the \.atkeys\ file type.
_packages/at\_events\_flutter/example/macos, packages/at\_sync\_ui\_flutter/example/macos, packages/at\_theme\flutter/example/macos · high confidence
Added post-quantum and classical key-exchange examples
The \packages/at\_chops/example/pq\ directory now includes runnable Dart examples demonstrating key generation, encapsulation, and signature verification for X-Wing, ML-KEM-768, ML-DSA-65, and X25519. Each algorithm is provided in two variants: one using the native FFI backend (requiring OpenSSL) and one using the pure-Dart implementation, allowing users to see how to integrate these cryptographic primitives into their applications.
_packages/at\chops/example/pq · high confidence
Added utility helpers for CLI argument parsing and AtSign configuration
The example CLI now includes two new utility classes to improve usability and configuration management. CustomArgParser enforces required command-line arguments (--atsign and --atKeysPath) and provides immediate help output, ensuring users receive clear error messages if inputs are missing. AtSignPreference provides static methods to configure the AtClient environment, specifically setting the root domain to 'vip.ve.atsign.zone' and managing Hive storage paths for user enrollment.
_packages/at\_onboarding\cli/example/util · high confidence
CLI onboarding now supports skipping sync and uses a dedicated service interface
The onboarding CLI now allows users to opt out of background synchronization via a new \skipSync\ preference, which configures the underlying \AtClient\ to use a \NoOpSyncService\ instead of the default sync implementation. This capability is exposed through a new \AtOnboardingService\ interface and its \AtOnboardingServiceImpl\ implementation, which centralize the logic for opening an \AtClient\ from a keyfile, managing the client lifecycle (stopping existing clients before opening new ones), and reporting connection status. This change provides a cleaner abstraction for CLI applications to manage atSign authentication and client state without directly handling \AtClient\ instantiation details.
_packages/at\_onboarding\cli/lib/src/onboard · high confidence
Example app iOS project scaffolded for Flutter v2 embedding and iOS 12+
The iOS native project for the at\_events\_flutter example app has been added, providing a complete Xcode workspace configured for the Flutter v2 embedding. This includes the standard Runner target, CocoaPods integration, and asset configurations. The app now targets a minimum iOS version of 12.0 and declares location permissions (when in use and always) in its Info.plist, enabling location-based features in the example.
_packages/at\_events\flutter/example/ios · high confidence
Example app now includes onboarding and event management screens
The example application for at\_events\_flutter has been updated to include a main entry point (main.dart) and a secondary screen (second\_screen.dart). Users can now run the example to perform AtSign onboarding via the AtOnboarding widget, reset authentication state, and view/manage events using the HomeEventService. The app handles theme switching and displays event tiles with retry capabilities.
_packages/at\_events\flutter/example/lib · high confidence
Initial release of Flutter platform plugins and theme service
This change introduces the foundational structure for several new Flutter packages: \at\_chat\_flutter\, \at\_events\_flutter\, \at\_location\_flutter\, and \at\_theme\_flutter\. For the platform-specific plugins (chat, events, location), the diff adds the necessary Android (Kotlin plugins, Gradle wrapper, manifests) and iOS (Swift/Objective-C plugins, headers) boilerplate to enable native method channel communication, alongside standard \.gitignore\ files. The \at\_theme\_flutter\ package adds the core Dart library for managing application themes, including exports for the theme service, inherited widget, and settings page, as well as utility constants for domain and API configuration. Additionally, example web applications for \at\_sync\_ui\_flutter\ are initialized with standard Flutter web entry points and PWA manifests.
(repo-wide) · high confidence
Initial release of at\_client\_skills AI agent documentation
The new \at\_client\_skills\ package provides AI coding agents with structured documentation for the \at\_client\ and \at\_client\_flutter\ SDKs. It covers core features like \AtCollection\<T\>\ CRUD operations, authentication flows, and querying, as well as advanced topics such as RPC, headless agents, and remote/local server operations. The package is installed via the \skills\ CLI and includes a changelog, license, and configuration files to support its integration into development environments.
_packages/at\_client\skills · high confidence
Initial release of at\_events\_flutter package
The at\_events\_flutter package is now available for Flutter developers to integrate event management features into their applications. This new package enables users to create and update events with location and participants, leveraging the atPlatform's decentralized, edge computing model for cryptographic data access control and end-to-end encryption without requiring a backend. The package includes an example application, comprehensive documentation, and standard project configuration files (such as .gitignore and analysis\_options.yaml) to facilitate integration.
(repo-wide) · high confidence
Initial release of at\_location\_flutter package with deprecation notice
The at\_location\_flutter package is introduced to allow Flutter developers to share and receive location data between atsigns using the atPlatform's decentralized model. The package includes a CHANGELOG indicating version 3.2.1, which carries a deprecation notice stating the package is no longer recommended for new apps, directing users to the location\_sharing example in at\_client\_flutter instead. The release also establishes standard project files including a BSD 3-Clause license, .gitignore rules for build artifacts, and analysis options based on flutter\_lints.
_packages/at\_location\flutter · high confidence
Initial release of at\_notify\_flutter package and example app
The at\_notify\_flutter package is introduced to help Flutter developers handle notifications within Atsign Protocol apps, supporting the platform's decentralized, edge-computing model with end-to-end encryption. This release includes the core library, a working sample application in the example directory, and comprehensive documentation (README, CHANGELOG, LICENSE) to guide integration and usage.
_packages/at\_notify\flutter · high confidence
Initial release of the at\_login\_flutter plugin
This change introduces the at\_login\_flutter package, a Flutter plugin for implementing zero-trust logins using the Atsign Protocol. The package provides an AtLogin screen for scanning QR codes to capture and approve login requests, and an AtLoginDashboard screen for viewing request history. It includes native Android and iOS implementations, configuration for required permissions (camera, storage), and an example application demonstrating integration with the Atsign onboarding system.
_packages/at\_login\flutter · high confidence
Introduce AtCollection for typed, reactive, and shareable data management
The \at\_client\ library now includes a new \AtCollection\<T\>\ API that provides a structured way to manage typed records with built-in support for CRUD operations, hierarchical sub-collections, and reactive event streams. Users can now create collections scoped to specific namespaces, perform queries with filtering and sorting, and subscribe to live updates via \Query.watch\. A key feature is the configurable \EventSource\ enum, allowing applications to choose whether to receive events from local data changes, remote notifications, or both, facilitating real-time synchronization across atSigns. The API also includes a built-in read-receipt framework to track which users have viewed shared items, and supports nested collections for complex hierarchical data models.
_packages/at\client/lib/src/collections · high confidence
Introduce AtRpc for request-response communication via notifications
Added a new \AtRpc\ API in \packages/at\_client/lib/src/rpc\ that enables simple request-response interactions using atProtocol notifications under the hood. This includes the \AtRpc\ class for managing the RPC lifecycle and an \AtRpcClient\ helper for a cleaner client-side developer experience. The implementation defines \AtRpcReq\ and \AtRpcResp\ types (in \at\_rpc\_types.dart\) to structure requests and responses, supporting features like namespace isolation, allow-listing of atSigns, and JSON serialization. Users can now send requests to a server atSign and receive responses, with the client handling completer-based async flows and stopping logic.
_packages/at\client/lib/src/rpc · high confidence
Introduce AtStatus model and AtServerStatus interface for server status checks
The at\_server\_status package now exposes a new public API for checking server health. The AtServerStatus abstract class defines methods to retrieve detailed status information (get) and raw HTTP status codes (httpStatus) for a given @sign. The underlying AtStatus model provides structured data including atSign, server location, and specific status enums for root, server, and atSign states, along with convenience methods to map these to standard HTTP status codes (e.g., 200 OK, 404 Not Found, 418 I'm a teapot) and JSON serialization. This change removes the dependency on dart:io by defining HTTP status constants locally, enabling the package to be used in web environments.
_packages/at\_server\status/lib/src · high confidence
Introduce AtSync UI library for sync progress and dialogs
This change adds the \at\_sync\_ui\_flutter\ package, providing a unified UI layer for synchronization states. It includes platform-specific progress indicators (\AtSyncIndicator\) for both Material and Cupertino styles, a reusable \AtSyncButton\ that overlays a spinner during loading, and an \AtSyncUI\ singleton for managing global sync overlays (dialogs and snackbars) via an overlay entry system. The library also exposes an \AtSyncUIController\ to manage a loading queue, ensuring the UI correctly reflects active sync operations.
_packages/at\_sync\_ui\flutter/lib · high confidence
Introduce at\_auth package for activation and onboarding
The new at\_auth package centralizes the atSign activation workflow, providing an AtAuth interface that manages CRAM and PKAM authentication, key minting, and the first enrollment. It exposes an onboard method to initialize a new atSign (handling key generation and server validation) and a completeActivation method to finalize the process by updating the encryption public key and removing the CRAM secret. The implementation supports configurable authenticators and key stores, including post-activation control via autoCompleteActivation, and introduces constants for APKAM key schemas to support both legacy RSA and post-quantum key material.
_packages/at\auth/lib/src · high confidence
Introduce at\_cli\_commons library for CLI application scaffolding
The new \at\_cli\_commons\ package provides a foundational library for building command-line applications on the AtSign platform. It introduces the \CLIBase\ class, which standardizes argument parsing (including support for hidden developer flags, legacy \-d\ root domain aliases, and pass-phrase handling for encrypted atKeys files) and initializes the AtClient with configurable connection attempts and sync behavior. The package also includes utility functions for resolving standard storage paths and usernames across different operating systems, as well as helper classes for managing sync progress and disabling sync services when needed.
_packages/at\_cli\commons/lib · high confidence
Introduce at\_policy package for centralized policy management
The new at\_policy package provides a structured way to manage policies via the atProtocol. It introduces a PolicyService interface and implementation that listens for policy requests over RPC, logs events, and delegates to a handler for policy details. The package includes data models for policy intents, requests, responses, and log events, along with a factory for creating PolicyService instances with configurable namespaces and access controls.
_packages/at\policy/lib · high confidence
Introduce post-quantum secret sharing substrate with X-Wing and ML-KEM-1024 support
This change adds a new secret-sharing substrate to the at\_client library, enabling per-enrollment key exchange using post-quantum key encapsulation mechanisms. The implementation introduces a registry of algorithm identifiers supporting X-Wing (a hybrid X25519/ML-KEM-768 suite) and pure ML-KEM-1024 (CNSA 2.0 compliant), along with corresponding RFC 9180 HPKE sealing suites. It provides the infrastructure for minting, signing, and advertising encapsulation key packages via enrollment records, handling the secure conveyance of symmetric keys to new enrollments, and managing the lifecycle of key packages (minting new algorithms, retiring obsolete ones) to maintain alignment with the client's configured key establishment preferences.
_packages/at\_client/lib/src/secret\sharing · high confidence
Introduces core event management services for the Flutter package
The \packages/at\_events\_flutter/lib/services\ directory now contains the foundational service layer for handling event lifecycle and data. This includes \AtEventNotificationListener\ for monitoring and processing incoming encrypted event notifications, \EventKeyStreamService\ for managing the stream of event data and syncing with the AtProtocol, \EventService\ for creating and editing events, \HomeEventService\ for determining user actions and status on events, \ContactService\ for retrieving AtContact details, and \VenuesServices\ for persisting and retrieving venue location data.
_packages/at\_events\flutter/lib/services · high confidence
Introduces new encryption and encoding converter implementations
The \packages/at\_client/lib/src/converters\ directory now includes new implementations for data transformation: \byte\_splitter.dart\ provides a utility to split byte streams, \encoder/at\_encoder.dart\ and \decoder/at\_decoder.dart\ introduce factory-based base64 encoding and decoding, and \encryption/aes\_converter.dart\ adds AES encryption and decryption capabilities using the \encrypt\ package. These files establish the foundational converter classes used by the client for handling data serialization and security.
_packages/at\client/lib/src/converters · high confidence
Introduces new foundational classes and constants for the atProtocol library
This change adds several new source files to the at\_commons package to support core protocol functionality. It introduces the AtConstants class, which centralizes string literals for keys, verbs, and metadata fields (such as appMetadata, immutable, and force flags). It also adds the AtRootDomain class for parsing root domain and proxy address configurations, the AtMessage enum with extensions for standardized error messages, the SharedKeyStatus enum for tracking key synchronization states, and the AtTelemetryService interface along with its event and sample data classes for software telemetry.
_packages/at\commons/lib/src · high confidence
Introduction of the at\_theme\_flutter package for dynamic theme management
The \at\_theme\_flutter\ package is now available, providing a comprehensive system for managing and applying dynamic app themes. It introduces an \AppTheme\ model that encapsulates brightness and color settings, supported by an \InheritedAppTheme\ widget for context-aware theme access. The package includes a \ThemeSettingPage\ UI component that allows users to select primary colors and toggle between light and dark modes, with preview and apply functionality. Additionally, it provides utility widgets like \ColorCard\ and \ThemeModeCard\ for consistent UI representation, and a \CustomToast\ service that automatically adapts its background color to the current app theme.
_packages/at\_theme\flutter/lib/src · high confidence
New APKAM example scripts for enrollment and authentication
Added three new Dart example scripts in the \packages/at\_onboarding\_cli/example/apkam\_examples\ directory to demonstrate Advanced Public Key Authentication Method (APKAM) workflows. \apkam\_enroll.dart\ shows how to initiate a device enrollment using an OTP and wait for approval, \apkam\_authenticate.dart\ demonstrates opening a client session using an existing keyfile, and \enroll\_app\_listen.dart\ provides a terminal-based listener for approving or denying incoming enrollment requests.
_packages/at\_onboarding\_cli/example/apkam\examples · high confidence
New AtBytes class for efficient base64 key management
A new AtBytes class has been introduced in the at\_commons package to manage base64-encoded byte data. This class provides a more efficient way to handle keys by comparing raw bytes directly via the == operator and hashCode, rather than relying on string comparisons, which reduces overhead. It includes a factory constructor to create instances from strings and a helper method for string equality checks.
_packages/at\commons/lib/src/key · high confidence
New AtServerEvent interface and AtSignPKChangedEvent class
The at\_commons library now includes a new \AtServerEvent\ interface and a concrete \AtSignPKChangedEvent\ class in \atserver\_events.dart\. This introduces a structured way to represent server-generated events, specifically for tracking when an atSign's public key changes. The event includes the atSign's identifier and supports serialization to and from JSON, enabling consistent handling of this specific protocol event by consumers.
_packages/at\commons/lib/src/atserver · high confidence
New CLI command to register a free atSign via email
The \register\_cli\ package now includes a \register.dart\ entry point that allows users to obtain a free atSign by providing an email address. The command validates the email input, initiates a multi-step registration flow (generating an atSign, sending a verification code, and validating the OTP), and upon successful registration, automatically authenticates the user by invoking the auth CLI with the retrieved credentials.
_packages/at\_onboarding\_cli/lib/src/register\cli · high confidence
New CLI examples for AtCollection, custom crypto, and dockerstats
The example application now includes several new command-line programs in the \bin\ directory. \collections\_binary.dart\, \collections\_domain\_objects.dart\, \collections\_generic.dart\, \collections\_primitives.dart\, and \collections\_subcollections.dart\ demonstrate the new \AtCollection\ API for storing and sharing binary data, domain objects, generic types, primitives, and hierarchical sub-collections. \custom\_crypto\_provider.dart\ shows how to implement and wire a custom \CryptoProvider\ (using a simple XOR example) via \AtClientPreference\. Additionally, \dockerstats\_publish.dart\ and \dockerstats\_subscribe.dart\ provide a CLI-based closed-loop verification for publishing and receiving live Docker statistics via notifications, supporting both real and simulated modes.
_packages/at\client/example/bin · high confidence
New Flutter example app for at\_client\_flutter
A new minimal Flutter example application has been added to the at\_client\_flutter package to demonstrate usage of the library. The app includes a main entry point, a dedicated APKAM enrollment demo page, and a collection of copy/paste code snippets for features like invitations and key backups. It also provides the complete native project scaffolding for Android and iOS, including manifest configurations, launch themes, and asset definitions, to serve as a ready-to-run reference for developers.
_packages/at\_client\flutter/example · high confidence
New Flutter reference app for AtCollection
Added a multi-platform Flutter example app (\todos\) that demonstrates the idiomatic use of the \AtCollection\<T\>\ API. The app provides a shared, end-to-end-encrypted todo list across atSigns, showcasing features like typed collections, sub-collections, live reactive queries, sharing controls, and read receipts. It serves as a reference implementation for building real Flutter applications on the atPlatform, with data shapes compatible with the existing CLI sibling app.
_packages/at\_client\flutter/examples/todos · high confidence
New KeyStream API for reactive AtKey observation
The at\_client library now includes a new KeyStream API that allows applications to observe changes to AtKeys in real-time via Dart streams. This feature introduces an abstract KeyStream class along with concrete implementations for standard collections (IterableKeyStream, ListKeyStream, SetKeyStream, and MapKeyStream), enabling developers to subscribe to notifications for specific keys filtered by regex, sharedBy, or sharedWith attributes. The implementation handles key pre-loading, notification dispatching, and automatic disposal on atSign switches, providing a seamless way to integrate atProtocol data into reactive UI frameworks like Flutter.
_packages/at\_client/lib/src/key\stream · high confidence
New RSA, ECDSA, and Ed25519 signing implementations alongside ML-DSA-65 backends
The signing algorithm module now includes dedicated implementations for RSA (RsaSignatureAlgo), ECDSA (EccSigningAlgo), and Ed25519 (Ed25519SigningAlgo), in addition to the existing ML-DSA-65 FFI and pure-Dart backends. RsaSignatureAlgo supports 2048-bit and 4096-bit keys with SHA-256 or SHA-512 hashing, enforcing modulus size consistency to prevent wire-label mismatches. EccSigningAlgo provides ECDSA signing using SHA-256, while Ed25519SigningAlgo handles asynchronous Ed25519 operations. These new classes implement the AtSignatureAlgorithm interface, allowing explicit key material passing, while retaining deprecated stateful AtSigningAlgorithm surfaces for backward compatibility with the 3.3.0 API.
_packages/at\chops/lib/src/algorithm/signing · high confidence
New UI components for the device authorization interface
The authorization page now includes a set of new Flutter widgets to render enrollment requests and manage device status. Users will see enrollment requests displayed as cards that show the app name, device name, affected namespaces, and provide Approve, Reject, and Revoke actions. A feedback overlay displays the current status (Pending, Approved, Denied, Revoked, Expired) of requests, while section headers and list tiles organize the interface. Additional components include a tip card for user guidance, a namespace chip for visualizing permissions, and a manager device card indicating the device's authenticator role.
_packages/at\_client\flutter/lib/src/widgets/authorisation/components · high confidence
New WASM compatibility gates and acceptance ledger tooling
This change introduces two new internal tooling capabilities in the \tools\ directory. First, the \wasm\_shakedown\ tool adds automated regression tests and compile gates to ensure packages like \at\_chops\ and \at\_auth\ remain compatible with WebAssembly (Wasm) by detecting forbidden platform imports (such as \dart:io\) that the Dart compiler allows but which fail at runtime in browsers. Second, the new \acceptance\_ledger.sh\ script provides a unified view of test coverage by rendering a ledger that maps catalogue citations to actual test results, distinguishing between unit sources and live integration packs.
tools · high confidence
New acceptance ledger and JWS vector verification tools
Added three new tooling scripts to the at\_client package to improve testing transparency and interoperability. The \acceptance\_ledger.dart\ script now renders a Markdown report showing which acceptance test cases were actually exercised and passed in a given run, distinguishing between proven, failed, and unexercised scenarios. Additionally, \generate\_jws\_vectors.dart\ creates deterministic JWS signed-envelope test fixtures for RS256 and ML-DSA-65 algorithms, while \verify\_jws\_vectors.mjs\ uses the third-party \jose\ library to validate these vectors, ensuring the envelope format conforms to RFC 7515 general JSON serialization and can be verified by external implementations.
_packages/at\client/tool · high confidence
New barrel exports and optional SQLite storage backend
The at\_client package now exposes a consolidated set of public APIs through new barrel files (at\_client.dart and at\_client\_mixins.dart), making components like AtClient, AtClientStorage, enrollment services, and post-quantum signing mixins directly accessible. Additionally, a new sqlite.dart entry point provides SQLite-backed storage implementations, allowing applications to opt into this persistence layer without pulling in the dependency by default.
_packages/at\client/lib · high confidence
New chat UI components and styling utilities added
The chat interface now includes dedicated widgets for rendering incoming and outgoing message bubbles, a send-message input bar, and reusable UI elements such as a custom button, contact initials avatar, and a bottom-sheet delete confirmation dialog. These components are supported by new utility files defining message bubble colors, deterministic avatar background colors based on atsigns, and dialog helpers, providing a consistent visual style and interaction model for the chat experience.
_packages/at\_chat\flutter/lib/widgets · high confidence
New common UI components for the at\_events\_flutter package
The \common\_components\ directory now includes a suite of reusable Flutter widgets to standardize the user interface. This adds a \CustomButton\ for consistent styling, \CustomToast\ for notifications, and \CustomPopupRoutes\ for custom dialog transitions. It introduces \ContactListTile\ and \ContactInitial\ for displaying user profiles with initials or images, \DisplayTile\ for event details, and \InviteCard\ for event invitations. Additionally, it provides \OverlappingContacts\ for visualizing selected attendees, \EventTimeSelection\ for scheduling, \FloatingIcon\ for navigation drawers, \ErrorScreen\ and \LoadingDialog\ for state feedback, and utility widgets like \CustomHeading\, \DraggableSymbol\, \LocationTile\, \PopButton\, and \TextTile\.
_packages/at\_events\_flutter/lib/common\components · high confidence
New composite action for setting up Flutter and Dart with strict channel separation
A new GitHub Action, \actions/setup-flutter-and-dart\, has been introduced to standardize the installation of Flutter and Dart SDKs. This composite action allows users to specify the Flutter and Dart channels (defaulting to 'stable') and ensures that the \dart\ binary on the system path is not sourced from the Flutter SDK, preventing potential conflicts. It utilizes pinned commit SHAs from \flutter\_ref-stable\ and \flutter\_ref-beta\ files to cache and install specific versions, and includes validation to fail if these reference files are empty or null.
actions · high confidence
New dockerstats Flutter example for live container telemetry
Adds the \dockerstats\ example application, a multi-platform Flutter dashboard that subscribes to live Docker container statistics via Atsign notifications, persists samples to an on-device SQLite database with a five-tier incremental roll-up (raw, 1 min, 15 min, 1 h, 8 h), and renders time-series charts for CPU, Memory, Network I/O, and Block I/O. The app demonstrates a notification-based telemetry pattern distinct from \AtCollection\, featuring dynamic zoomable time windows and efficient SQL aggregation for rendering large datasets.
_packages/at\_client\flutter/examples/dockerstats · high confidence
New enrollment request list widget for Flutter apps
Added the EnrollmentRequestList widget, which displays a real-time list of pending enrollment requests and allows users to approve or deny them. The widget subscribes to the client's enrollment stream to update the UI dynamically, handles initial fetches of pending requests, and provides visual feedback via overlays and snack bars for approval/denial actions or authorization errors.
_packages/at\_client\flutter/lib/src/widgets/authorisation/containers · high confidence
New event and location notification data models
The \at\_events\_flutter\ package now includes a new set of data models to handle event and location sharing notifications. This introduces \EventNotificationModel\, \Event\, \Venue\, and \EventKeyLocationModel\ to parse and serialize event details, including recurring patterns, venue data, and group member sharing statuses. It also adds \EventMemberLocation\ for tracking individual member location shares and \HybridNotificationModel\ to unify event and location notifications under a single \NotificationType\ enum. Additionally, \enums\_model.dart\ provides helper functions to convert time-related enums into adjusted \DateTime\ objects for start and end times.
_packages/at\_events\flutter/lib/models · high confidence
New example scripts for atSign onboarding and app enrollment
The \packages/at\_auth/example\ directory now includes two new Dart scripts: \onboard.dart\ and \enrollment\_request.dart\. \onboard.dart\ demonstrates the initial atSign activation process using CRAM authentication, generating a \.atKeys\ file, and establishing PKAM privileges. \enrollment\_request.dart\ shows how a new application can submit an enrollment request to the server for approval, specifying details like app name, device name, and signing algorithm. These examples provide concrete usage patterns for the \at\_auth\ package's onboarding and enrollment capabilities.
_packages/at\auth/example · high confidence
New factory for caller-owned AtClient instances with explicit lifecycle management
The \at\_client\ package now provides a \buildAtClient\ factory function that allows applications to create and own their own \AtClient\ instances, distinct from the global singleton managed by \AtClientManager\. This new client type requires the caller to explicitly manage its lifecycle by calling \stop()\ when finished, and it supports injecting custom storage, lookup connections, and service builders (notification, sync, enrollment). It also enforces strict principal isolation, preventing multiple live clients for the same atSign/enrollment pair, and wires the client's services to its specific storage and connection context.
_packages/at\client/lib/src/client · high confidence
New hashing algorithm implementations and parameter types
The hashing module now includes dedicated implementations for Argon2id, HKDF (SHA-256 and SHA-384), MD5, SHA-256, and SHA-512. Argon2id supports configurable parameters (parallelism, memory, iterations, hash length) via \ArgonHashParams\, with a fallback to deterministic derivation for backward compatibility with existing key files. HKDF is exposed as \HkdfSha256\ and \HkdfSha384\, supporting extract, expand, and derive-key operations for key derivation in protocols like HPKE. MD5, SHA-256, and SHA-512 are available as simple hashing algorithms. New \HashParams\ and \ArgonHashParams\ classes allow customization of hashing behavior.
_packages/at\chops/lib/src/algorithm/hashing · high confidence
New keystore key model and public key hashing support
The keystore module introduces a new \AtKey\ class and a set of builder classes (\PublicKeyBuilder\, \SharedKeyBuilder\, \SelfKeyBuilder\, \LocalKeyBuilder\) to construct and manage atProtocol keys with explicit support for public, shared, self, and local key types. This change also adds a \PublicKeyHash\ class to represent and serialize the hash of an atSign's public encryption key along with the hashing algorithm used, replacing previous ad-hoc handling. Additionally, a \KeyUtil\ helper is provided to manage namespace qualification for keys.
_packages/at\commons/lib/src/keystore · high confidence
New library entry points and Atsign type extension
The at\_commons package now exposes two new top-level libraries, at\_builders.dart and at\_commons.dart, which consolidate exports for verb builders, exceptions, key management, and telemetry. Additionally, a new Atsign extension type is introduced, allowing strings to be converted into a validated, normalized Atsign type that automatically handles lowercasing, dot removal, and prefix addition, while rejecting invalid characters.
_packages/at\commons/lib · high confidence
New lifecycle abstraction for atSign activation and enrollment
The Flutter client now exposes an \AtsignFlows\ class in the lifecycle layer that wraps core atSign operations such as activation, opening a session, and the enrollment/resume-enrollment flows. This abstraction allows applications to manage the connection lifecycle and keychain interactions through a single, testable interface, while also providing a helper to stamp the selected root domain onto client preferences.
_packages/at\_client\flutter/lib/src/lifecycle · high confidence
New lifecycle verbs for opening, activating, and managing atSign enrollments
The at\_client package introduces a new lifecycle API allowing applications to open clients directly from keys, activate new atSigns with provisioning support, and manage device enrollments. Users can now call \Atsign.open\ to establish a connection with immediate status reporting (online, offline, or refused), use \Atsign.activate\ to provision a new atSign with optional post-quantum key support, and access \client.enrollments\ to approve, deny, or revoke device access. The system also provides \Atsign.authenticatesAs\ for credential verification and \PendingEnrollment\ to wait for approval of submitted enrollment requests, with connection state changes streamed via \AtConnection.changes\.
_packages/at\client/lib/src/lifecycle · high confidence
New location sharing feature added to at\_location\_flutter
The \at\_location\_flutter\ package now includes a complete location sharing capability, introducing a new \AtLocationFlutterPlugin\ widget that displays real-time locations of tracked @signs on a map with markers and clustering. Users can share their own location, request location data from others, and view ETA information. The update adds UI components for location prompts, confirmation dialogs, and custom toasts, along with services for managing location state and notifications.
_packages/at\_location\flutter/lib · high confidence
New modular authentication components for activation, onboarding, and credential handling
The \at\_auth\ package introduces a set of new, focused classes in \lib/src/auth\ to handle the authentication lifecycle. \activation.dart\ provides the \activateAtSign\ function to onboard a new atSign using a CRAM secret, mint key material, and establish the first enrollment. \onboarding\_mint.dart\ contains the logic for generating APKAM keypairs (supporting both legacy \rsa2048\ and post-quantum \mldsa65\) and legacy encryption keys. \at\_authenticator.dart\ exposes factory functions (\authenticatorFor\, \authenticatorForChops\, \authenticatorForCramSecret\, \authenticatorForPrivateKey\) to select the correct authentication strategy based on available credentials (keystore, injected AtChops, bare CRAM secret, or bare private key). Additionally, \cram\_authenticator.dart\ and \pkam\_authenticator.dart\ provide dedicated wrappers for CRAM and PKAM authentication verbs, respectively, separating these concerns from the broader \at\_lookup\ implementation.
_packages/at\auth/lib/src/auth · high confidence
New onboarding and authentication dialog widgets
The Flutter client now provides a suite of reusable UI components to guide users through atSign lifecycle events. This includes \AtKeysFileDialog\ for selecting local key files, \AtSignSelectionDialog\ for choosing an atSign and root domain, \PkamDialog\ for authenticating with existing keys, \CramDialog\ for activating via CRAM keys, \RegistrarCramDialog\ for obtaining keys via OTP, and \ApkamActivationDialog\ for post-quantum key enrollment. These widgets handle the underlying authentication flows, manage progress and error states, and return the resulting \AtClient\ instance to the application.
_packages/at\_client\flutter/lib/src/widgets · high confidence
New onboarding utility classes and secure key-file handling
The onboarding CLI now includes a suite of utility classes to manage the registration and key-file lifecycle. AtFileUtil provides cross-platform secure file permissions (chmod 600 on POSIX, icacls on Windows) and validates write access before creating the atKeys file, throwing specific exceptions if the file already exists or is unwritable. AtOnboardingPreference centralizes configuration, adding support for pass-phrases, proxy lookups, and explicit storage paths. OnboardingUtil handles the registrar API interactions for free atSign registration, OTP validation, and CRAM key retrieval, while new exception classes (AtOnboardingException, AtActivateException, etc.) provide structured error reporting. Additionally, createAtClientCli.dart standardizes client initialization with retry logic and post-quantum startup waiting.
_packages/at\_onboarding\cli/lib/src/util · high confidence
New post-quantum and authenticated encryption algorithms added to at\_chops
The encryption module now includes several new cryptographic capabilities: ML-KEM-768 and ML-KEM-1024 Key Encapsulation Mechanisms (KEM) are available in both pure-Dart and OpenSSL FFI backends, with ML-KEM-1024 provided as a 'no-hybrid' option compliant with CNSA 2.0. Authenticated encryption is expanded with AES-256-GCM (pure-Dart and FFI) and ChaCha20-Poly1305, the latter specifically supporting RFC 9180 HPKE. Additionally, AES-CTR is now supported via a new FFI backend for performance, alongside existing pure-Dart implementations.
_packages/at\chops/lib/src/algorithm/encryption · high confidence
New public API surface for CLI onboarding and authentication utilities
The at\_onboarding\_cli package now exposes a consolidated set of exports in its main library file, making core onboarding services (AtOnboardingService and its implementation), CLI argument parsing (AuthCliArgs), OTP enrollment requests (request\_enrollment\_otp), client creation utilities (create\_at\_client\_cli), and various helper utilities (auth\_key\_type, proxy\_lookups, exceptions, preferences) publicly available for external consumption.
_packages/at\_onboarding\cli/lib · high confidence
New public API surface for Flutter-specific helpers and UI components
The at\_client\_flutter package now exposes a consolidated public API via at\_client\_flutter.dart and extensions.dart. Users can import Flutter-specific utilities through the new extensions.dart file, which re-exports file utility helpers. The main library file provides direct access to keychain management classes (keychain\_data, keychain\_storage, keychain\_io\_impl), lifecycle flow models (AtsignSelection), and a comprehensive set of UI widgets for authentication dialogs (APKAM, CRAM, PKAM, Registrar CRAM), file picking, and authorization management (enrollment request lists, device cards, namespace chips).
_packages/at\_client\flutter/lib · high confidence
New response transformers for Get, Put, and Notification operations
The at\_client library now includes dedicated response transformers for Get, Put, and Notification operations. The GetResponseTransformer handles decoding and decryption of retrieved data, respecting the isEncrypted flag to avoid unnecessary decryption of unencrypted data. The NotificationResponseTransformer decrypts notification values and text messages, handling key parsing and namespace extraction. The PutResponseTransformer parses put operation responses using the DefaultResponseParser.
_packages/at\_client/lib/src/transformer/response\transformer · high confidence
New shared UI components for loading states and searchable input
Added two new reusable widgets to the shared library: a LoadingDialog for displaying customizable loading indicators with title and description, and a TypableDropdown that provides an autocomplete-style text field for selecting from a list of options with filtering and normalization support.
_packages/at\_client\flutter/lib/src/widgets/shared · high confidence
New signing, envelope, and notification mixins for at\_client
This change introduces three new mixins to the at\_client library: ApkamSigning, EnvelopeSigning, and AtClientBindings. ApkamSigning manages the lifecycle of APKAM signing keys, including publishing them to the public namespace and serializing write operations to prevent race conditions. EnvelopeSigning builds on this to wrap payloads in signed JSON envelopes and verify signatures from other clients, featuring optional public key caching. AtClientBindings provides a robust notification interface with configurable retry logic (defaulting to 3 attempts) and subscription capabilities.
_packages/at\client/lib/src/mixins · high confidence
New utility classes for validation, encryption, and sync operations
The at\_client library introduces a suite of new utility classes in the \src/util\ directory to support core client operations. \AtClientValidation\ provides strict validation for keys, metadata, and put requests, including checks for buffer overflow and namespace requirements. \EncryptionUtil\ handles AES and RSA encryption and decryption, with methods marked as deprecated in favor of the \at\_chops\ package. \SyncUtil\ offers helpers for retrieving the latest server commit ID and filtering keys that should be synced, while \AtClientUtil\ contains general helpers for metadata preparation and key formatting. Additional utilities include \AtCollectionUtil\ for forming AtKeys, \SwallowedError\ for logging background errors, and \CloseWithoutWaiting\ for non-blocking stream controller closure.
_packages/at\client/lib/src/util · high confidence
New utility layer for colors, text styles, and constants in at\_events\_flutter
The at\_events\_flutter package now includes a new set of utility files in the lib/utils directory to centralize design tokens and configuration. This adds a singleton color palette (AllColors) and a deterministic color generator for contact initials (ContactInitialsColors), a comprehensive library of pre-defined text styles (CustomTextStyles) for consistent typography, and a centralized constants class (MixedConstants) for managing map and API keys alongside event notification timing options. Additionally, static text strings for UI labels and messages (AllText) are now provided to support localization and consistency across the application.
_packages/at\_events\flutter/lib/utils · high confidence
New verb builders and APKAM enrollment support
The \packages/at\_commons/lib/src/verb\ directory now contains a comprehensive set of new verb builders (including \AbstractVerbBuilder\, \ConfigVerbBuilder\, \DeleteVerbBuilder\, \EnrollVerbBuilder\, \FromVerbBuilder\, \KeysVerbBuilder\, \LLookupVerbBuilder\, \LookupVerbBuilder\, \MonitorVerbBuilder\, \NotifyVerbBuilder\, \PkamVerbBuilder\, \PLookupVerbBuilder\, \ScanVerbBuilder\, \StatsVerbBuilder\, and \SyncVerbBuilder\) along with \EnrollParams\ and \OperationEnum\. This introduces support for the new APKAM enrollment workflow (with fields like \signingAlgo\, \apsk\, and \enrollmentStatusFilter\), adds new flags to the \Monitor\ verb for self-notifications, and updates the \Delete\ verb to support \force\, \noCommit\, and \deletedAt\ parameters.
_packages/at\commons/lib/src/verb · high confidence
OpenSSL FFI integration with runtime capability probing
The library now includes FFI bindings and a loader for OpenSSL's libcrypto, enabling high-performance implementations of AES-256-GCM, AES-256-CTR, X25519, ML-KEM-768, and ML-DSA-65. To ensure stability on systems with restricted or older OpenSSL versions, the loader provides runtime probes that check for specific algorithm support before use. This allows the library to gracefully fall back to pure-Dart implementations if the underlying OpenSSL library lacks the required features (e.g., ML-KEM/ML-DSA support in OpenSSL \< 3.5 or disabled ciphers in FIPS modes), preventing runtime crashes.
_packages/at\chops/lib/src/algorithm/ffi · high confidence
Post-quantum enrollment and self-retrofit capabilities
The at\_client SDK now supports post-quantum (PQ) activation and enrollment workflows. New entry points allow a brand-new atSign to be activated PQ-natively (using ML-DSA-65) via \pqNativeOnboard\, and existing atSigns to retrofit their legacy enrollment to a PQ enrollment via \selfRetrofit\. These changes introduce a new \enroll:update\ operation (via \EnrollmentUpdater\) that lets an enrollment rotate its APKAM authentication key and update its signing key advertisements (\\_apsk\) or metadata. The SDK also manages the atSign-level PQ signing root, minting it automatically during fully privileged onboarding or retrofitting. Additionally, new utilities handle authorized namespace resolution and enrollment conveyance, ensuring secrets are correctly sealed and conveyed during the approval process.
_packages/at\client/lib/src/enroll · high confidence
Post-quantum namespace key infrastructure and content key management
The at\_client now implements a post-quantum namespace key (nskey) system, introducing a new cryptographic data path for encrypting and conveying content keys. This change adds a \CkManager\ to handle content key rotation, caching, and eviction, ensuring forward secrecy by deleting superseded conveyance records. It introduces a \MintLock\ mechanism to serialize key generation across multiple enrollments, preventing race conditions during minting. The system supports multiple key establishment algorithms (such as X-Wing and ML-KEM 1024) via a new \NskeyKeyRing\ and \NskeyProvider\, allowing clients to negotiate the strongest shared sealing suite. Additionally, a \ContentKeyEviction\ listener automatically removes cached content keys when their conveyance records are deleted, and a \NskeyPrivateFiling\ system securely stores incoming private keys in \AtKeys\ to survive restarts.
_packages/at\client/lib/src/crypto/nskey · high confidence
Post-quantum readiness controlled via PqPosture and AtClientPreference
The at\_client library now introduces a structured post-quantum (PQ) rollout strategy centered on the new \PqPosture\ class and its integration into \AtClientPreference\. This change allows applications to define their cryptographic posture—ranging from \legacy\ (classical only) to \pqReady\ (PQ authentication, legacy data) and \pqActive\ (full PQ encryption)—by setting a single \posture\ parameter. This posture dictates multiple security axes, including the authentication key algorithm (e.g., ML-DSA-65 vs RSA-2048), data signing algorithms, key establishment methods, and whether legacy encryption is disallowed for new writes. The implementation enforces consistency between these axes (e.g., refusing to write PQ data if the client cannot read it) and provides a \rolloutDifferencesFrom\ method to detect incompatible configuration changes in running clients. Additionally, new configuration classes \AtClientConfig\ and \AtClientParticulars\ are introduced to manage versioning and client identification metadata.
_packages/at\client/lib/src/preference · high confidence
Prototype telemetry service for diagnostics
A new experimental telemetry service has been added to the AtProtocol client to support diagnostics. This includes an \AtClientTelemetryService\ that instruments the client to emit telemetry events and a corresponding \AtClientTelemetryConsumer\ that buffers these events for processing. Currently, the service is a prototype with placeholder implementations for taking and adding samples, but it establishes the infrastructure for collecting metrics such as key store size and network data usage.
_packages/at\client/lib/src/telemetry · high confidence
at\_contacts\_flutter package initialization and example app scaffolding
The at\_contacts\_flutter package and its example application have been added to the repository. This includes the core Flutter plugin structure, Android and iOS platform integration files, and a complete sample app demonstrating how to initialize the contact service, display contact lists, and manage blocked contacts.
_packages/at\_contacts\flutter · high confidence
Architecture
Refactored enrollment logic into dedicated sub-components
The enrollment workflow in at\_auth has been restructured from a monolithic implementation into distinct, focused classes: EnrollmentSubmitter handles request submission, EnrollmentApprover manages approval and denial decisions, and EnrollmentHandshake waits for approval and collects the resulting keys. This change also introduces new files for APKAM possession proof signing, APKS key advertisement, and key entry status management, providing a clearer separation of concerns for the enrollment process.
_packages/at\auth/lib/src/enroll · high confidence
Behavioural changes
Added macOS Runner configuration for .atkeys file support
The macOS example app now includes the necessary native configuration files to properly handle onboarding via .atkeys files. This change adds the AppDelegate, window controller, and interface builder files required for the macOS platform, along with an updated Info.plist that registers the .atkeys extension as a recognized file type (UTTypeIdentifier com.atsign.atkeys). This ensures the application can correctly open and process cryptographic key files during the setup process.
_packages/at\_location\flutter/example/macos/Runner · high confidence
Android example app scaffolded with Android 12 compatibility and V2 embedding
The Android example project for at\_chat\_flutter has been initialized with the standard Flutter V2 embedding structure. This includes a MainActivity extending FlutterActivity, splash screen resources, and theme definitions for light and dark modes. Crucially, the main AndroidManifest.xml now sets android:exported="true" on the launcher activity to satisfy Android 12 (API level 31+) requirements, ensuring the app can be launched correctly on modern devices. Debug and profile manifests include the necessary INTERNET permission for development workflows.
_packages/at\_chat\flutter/example/android · high confidence
Centralized network timeout policy with distinct budgets for operations and responses
The SDK now enforces a unified network timeout strategy via the new \AtNetworkTimeouts\ class, which caps any single network operation (such as connecting to an atServer or waiting for response bytes) at a maximum of 60 seconds, with a default of 30 seconds. This policy introduces separate, uncapped budgets for specific scenarios: a 5-minute timeout for the onboarding provisioning poll and a 90-second budget for the total duration of a single server response, ensuring that long-running or multi-chunk operations are not prematurely terminated by the per-operation cap. Additionally, \SecureSocketConfig\ now exposes a \connectTimeout\ setting that integrates with this central policy, allowing callers to specify a custom connection timeout that is automatically clamped to the defined maximum.
_packages/at\commons/lib/src/security · high confidence
Deprecate APKAM authentication mode
The APKAM authentication mode has been deprecated in the PkamAuthMode enum, marking it as unused. Users relying on this mode should migrate to the supported keysFile or sim modes for PKAM authentication.
_packages/at\commons/lib/src/auth · high confidence
Deprecated AtCollectionModel API marked for removal
The \AtCollectionModel\ class and its associated interfaces (such as \AtCollectionModelOperations\, \AtCollectionQueryOperations\, and \AtJsonCollectionModel\) in the \at\_client\ package are now marked as deprecated. Users are advised to migrate to the \AtClient.collection\ API for collection-style operations, as the legacy model-based approach is no longer the recommended path.
_packages/at\_client/lib/src/at\collection · high confidence
Deprecated compatibility API for cryptographic operations
The \AtChops\ base class and \AtChopsImpl\ implementation are now marked as deprecated, signaling that users should migrate to using the new algorithm classes directly for encryption, decryption, signing, and verification. This change introduces a cleaner, more modular design where specific algorithms (such as AES, RSA, ECC, and various hashing methods like SHA256/SHA512/Argon2id via \AtHashingAlgorithmFactory\) are instantiated and used explicitly, rather than through the legacy abstract interface. The \AtKeysCrypto\ class for passphrase-protected key encryption is also deprecated and slated for removal or relocation to the \at\_auth\ package. Existing code using \AtChops\ or \AtChopsImpl\ will continue to function but will trigger deprecation warnings, with the compatibility API scheduled for removal in the next major release.
_packages/at\chops/lib/src · high confidence
Deprecated utility class for legacy key generation and IV helpers
The \AtChopsUtil\ class in \packages/at\_chops/lib/src/util\ is now marked as deprecated and will be removed in the next major release. This utility previously provided static methods for generating initialization vectors (including legacy and base64-based variants) and various key pairs (RSA, EC, Ed25519, X25519, ML-KEM-768, X-Wing, ML-DSA-65, and AES). Users should migrate to using the static \generate\ methods on the specific key classes directly (e.g., \AtEncryptionKeyPair.create\, \AtMlKem768KeyPair.create\) and the algorithm classes for cryptographic operations, as indicated by the deprecation notice.
_packages/at\chops/lib/src/util · high confidence
Deprecation of legacy signing and encryption metadata/result classes
The \at\_chops\ library has deprecated its legacy compatibility API for data signing and encryption. New files in the metadata directory (\at\_signing\_input.dart\, \signing\_metadata.dart\, \signing\_result.dart\, \encryption\_metadata.dart\, \encryption\_result.dart\) introduce classes like \AtSigningInput\, \AtSigningResult\, and \AtEncryptionResult\, but mark them with \@Deprecated\ annotations. Users are now instructed to call \AtSigningAlgorithm\ implementations directly and handle result bytes and metadata themselves, as these compatibility wrappers will be removed in the next major release.
_packages/at\chops/lib/src/metadata · high confidence
Example app configuration and documentation refreshed
The example application for at\_sync\_ui\_flutter now includes a .env file setting ROOT\_DOMAIN to 'root.atsign.org', a standard .gitignore for Flutter artifacts, and an analysis\_options.yaml enabling strict linting rules (unawaited\_futures, await\_only\_futures). Documentation has been updated with a new README/EXAMPLE.md and logo images to guide users on setup and usage.
_packages/at\_sync\_ui\flutter/example · high confidence
Example app configuration and documentation updates
The example application for the at\_events\_flutter package has been updated with new configuration files and documentation. A .env file is now included to define the ROOT\_DOMAIN, and a .gitignore file has been added to exclude build artifacts and IDE-specific files from version control. Additionally, the project now includes an analysis\_options.yaml file to enforce standard Flutter linting rules, and the README and EXAMPLE documentation files have been refreshed to guide users through setup and usage.
_packages/at\_events\flutter/example · high confidence
Example app now supports Android and macOS platforms
The \at\_location\_flutter\ example application has been updated to run on Android and macOS. This change adds the necessary Android project structure, including \AndroidManifest.xml\ with location permissions (\ACCESS\_FINE\_LOCATION\, \ACCESS\_COARSE\_LOCATION\), a Kotlin \MainActivity\, and Gradle configuration. It also adds the macOS Xcode project files (\Runner.xcodeproj\), including the \Info.plist\, \AppDelegate.swift\, and build schemes, enabling developers to test the package on these additional platforms.
_packages/at\_location\_flutter/example/android, packages/at\_location\flutter/example/macos/Runner.xcodeproj · high confidence
Example app project structure and configuration standardized
The example application for at\_location\_flutter has been reorganized to follow standard Flutter project conventions. A .gitignore file was added to exclude build artifacts, IDE settings, and generated files, while a .metadata file was introduced to track the Flutter SDK version and channel. Documentation was updated with new README.md and EXAMPLE.md files that provide setup instructions and explain how the sample app uses onboarding and location services. Additionally, an analysis\_options.yaml file was added to enforce consistent linting and code quality standards via the flutter\_lints package.
_packages/at\_location\_flutter/example, packages/at\_theme\flutter/example · high confidence
Example project scaffolding and configuration updates
The at\_chat\_flutter example application has been restructured with the addition of a .gitignore file to exclude build artifacts and local configuration, a .metadata file tracking the Flutter stable channel, and an analysis\_options.yaml file enforcing standard Flutter lints. The README.md has also been updated to reflect the current package documentation and usage instructions.
_packages/at\_chat\flutter/example · high confidence
Introduce dedicated CLI entry points for activation and registration
New executable scripts, activate\_cli.dart and register\_cli.dart, have been added to the onboarding CLI package. The activation entry point now explicitly handles and returns non-zero exit codes upon failure, improving error visibility for users and scripts, while the registration entry point provides a dedicated invocation path for the registration workflow.
_packages/at\_onboarding\cli/bin · high confidence
Introduces algorithm type enums and stateless signing interfaces
The library now defines explicit enums for signing and hashing algorithms, including a \SigningAlgoType\ that establishes a verifier preference order (strongest first) and a \HashingAlgoType\ for algorithm identification. A new stateless \AtSignatureAlgorithm\ interface replaces the legacy, stateful \AtSigningAlgorithm\ by requiring key material to be passed per call, which improves thread safety and singleton usage. Additionally, a \KemSeedMixin\ standardizes seed handling for Key Encapsulation Mechanisms, and deprecated wrappers for legacy signing and hashing defaults are provided for backward compatibility.
_packages/at\chops/lib/src/algorithm · high confidence
Introduces enrollment status tracking and server-side key management constants
The at\_commons library now includes an EnrollmentStatus enum with a new 'expired' state alongside pending, approved, denied, and revoked, allowing systems to track the full lifecycle of an enrollment. Additionally, new EnrollmentConstants define server-side-only regex patterns for managing enrollment records, private encryption keys (PEK), and self-encryption keys (SEK), ensuring these sensitive identifiers are never synced to clients. A 'primary' enrollment ID is also established for an atSign's own credential, which is kept off the wire to simplify authentication.
_packages/at\commons/lib/src/enroll · high confidence
Introduction of granular AtKeys exception types
The at\_auth package now exposes a dedicated set of exceptions for handling AtKeys operations, replacing generic error handling with specific types such as AtKeysFileOverwriteException, AtKeysParseException, and AtKeysValidationException. A key addition is AtKeysSourceAbsentException (and its subclass AtKeysNotInMemoryException), which allows callers to distinguish between a key source that is genuinely empty (a cold start) and one that is unreadable due to corruption or missing passphrases, preventing silent failures in scenarios like notification park filing.
_packages/at\auth/lib/src/exception · high confidence
Keychain storage migrates to colon-delimited store names and supports multiple SPPs
The Flutter keychain implementation now uses a colon (\:\) delimiter in store names (e.g., \@atsigns:packageName\) instead of the legacy underscore (\\_\) format. Existing data stored with the underscore delimiter is automatically migrated to the new colon-delimited store on read, while the legacy store remains in place for backward compatibility until version 3.0.0. Additionally, the keychain now supports storing multiple Single-Passcode (SPP) entries per atSign via the new \SppListData\ structure, replacing the previous single-SPP limitation.
_packages/at\_client\flutter/lib/src/keychain · high confidence
Keyfile serialization refactored with typed vocabularies and passphrase salting
The keyfile serialization logic has been restructured to use strongly-typed extension types for cryptographic algorithms, roles, and material status, replacing previous string-based or enum-based approaches to ensure forward compatibility and prevent silent failures on unknown values. A new assurance module enforces structural invariants, such as rejecting keyfiles with duplicate active keys within an enrollment while tolerating multiple live enrollments for backward compatibility. Additionally, the passphrase envelope now uses a random salt for Argon2id key derivation (version 1), fixing a security weakness in the legacy unsalted derivation, while maintaining support for reading older, unsalted files.
_packages/at\auth/lib/src/keys/serialization · high confidence
Legacy encryption and decryption logic is extracted into a dedicated provider
The at\_client now isolates its pre-pluggable, legacy encryption scheme into a new \LegacyCryptoProvider\ within the \crypto/legacy\ directory. This change introduces dedicated \LegacyEncryption\ and \LegacyDecryption\ classes that handle self-encryption, shared-key encryption, and decryption for keys shared by or with other users. By wrapping these legacy algorithms in a standard \CryptoProvider\ interface, the client ensures that data stamped with the legacy provider ID is correctly routed to these specific decryption paths, maintaining compatibility with older encrypted records while cleaning up the internal crypto architecture.
_packages/at\client/lib/src/crypto/legacy · high confidence
Migrated event screens to Dart 3
The event creation and management screens in the \at\_events\_flutter\ package have been migrated to Dart 3. This update ensures compatibility with the latest Dart language version and resolves associated lint warnings and formatting issues across the event UI components.
_packages/at\_events\flutter/lib/screens · medium confidence
New auth\_cli replaces activate\_cli with expanded enrollment management and post-quantum support
The \auth\_cli\ command-line tool is now the primary interface for onboarding and authentication, superseding the deprecated \activate\_cli\. This new CLI introduces a comprehensive set of commands for managing device enrollments, including \list\, \fetch\, \approve\, \deny\, \revoke\, \unrevoke\, and \delete\, as well as an \auto\ command for automatic approval. It supports post-quantum cryptography via the \--posture\ flag (legacy, pqReady, pqActive) and allows users to decrypt passphrase-protected atKeys files. The tool also provides better user feedback, including a mandatory key backup warning during onboarding and version display via \--version\.
_packages/at\_onboarding\cli/lib/src/cli · high confidence
New isolated storage backends (Hive, SQLite, In-Memory) with explicit lifecycle management
The local storage layer for AtClient has been restructured to provide distinct backend implementations—Hive (the default), SQLite, and In-Memory—each encapsulating both the keystore and the sync queue. These backends enforce strict isolation: a storage instance is owned by a single client at a time, preventing accidental sharing of data between different clients or principals. The system now supports explicit lifecycle control, allowing clients to choose whether they are responsible for closing the storage backend upon stop (via the \closedByClient\ flag) or if the storage is borrowed and managed externally. This change ensures that multiple clients can safely coexist by isolating their data based on location and atSign, while also providing a clean in-memory option for testing.
_packages/at\client/lib/src/storage · high confidence
New persisted sync queue implementation with storage-path isolation
The sync subsystem now uses a dedicated \AtSyncQueue\ backed by a Hive box to persist pending client-to-server writes. This queue ensures that operations are correctly ordered by replaying persisted entries in timestamp order on startup and uses a monotonic sequence counter to handle rapid updates and deletes of the same key. Crucially, the queue is now isolated per storage path, allowing multiple clients for the same atSign in a single process to maintain separate queues without interfering with each other, resolving previous issues where different storage paths shared a single global queue.
_packages/at\client/lib/src/sync · high confidence
New post-quantum and symmetric key implementations with deprecated compatibility wrappers
The library now includes new key-pair implementations for post-quantum algorithms (ML-DSA-65, ML-KEM-768, X25519, and X-Wing) and symmetric encryption (AES), replacing the previous generic key structures with algorithm-specific classes. To support existing code during this transition, deprecated compatibility wrappers (such as AtEncryptionKeyPair, AtSigningKeyPair, and AtChopsKeys) are provided but marked for removal in the next major release, encouraging users to migrate to the new specific key classes and direct key material passing.
_packages/at\chops/lib/src/key/impl · high confidence
New registrar service for atSign generation and person registration
The registrar module has been replaced with a new v4 API implementation that handles atSign lifecycle operations. This includes generating free atSigns (randomly or by category), registering persons via email with OTP validation, and activating atSigns. The service uses a standard HTTP client by default for WASM compatibility, but supports a custom \dart:io\ client to allow ignoring bad certificates when needed (primarily for testing). API key validation is now enforced at initialization, and authentication failures return specific exceptions.
_packages/at\auth/lib/src/registrar · high confidence
New response parsing and notification model classes
The at\_client library introduces a new set of classes in the response package to handle server communication and notification data. This includes the AtNotification model, which now supports parsing the shared public key hash from metadata, and the Enrollment model, which exposes namespace permissions and enrollment status. Additionally, a new DefaultResponseParser and NotificationResponseParser are added to standardize how data and error prefixes are stripped from server responses and how notification lists are decoded, replacing previous ad-hoc parsing logic.
_packages/at\client/lib/src/response · high confidence
New stream notification models and file transfer deprecation
The stream handling layer now includes new data models for stream notifications (AtStreamNotification, AtStreamResponse, AtStreamStatus) to support future encryption metadata and status tracking. Additionally, the legacy FileTransferObject and FileStatus classes are explicitly deprecated with a notice that file sharing has moved to the app layer, signaling a shift in how file transfers are managed within the SDK.
_packages/at\client/lib/src/stream · high confidence
New typed authentication request, response, and session models
The at\_auth package introduces a new set of typed models for the authentication lifecycle: \AuthRequest\ and \AtOnboardingRequest\ define the inputs for activation, including specific signing algorithms, legacy material opt-outs, and key I/O sources; \AtOnboardingResponse\ and \AuthResponse\ represent the outcomes, explicitly carrying the resulting \AtAuthSession\; and \AtAuthSession\ serves as the typed hand-off containing the atSign, root domain, key source, and enrollment ID. Additionally, \RetryOptions\ provides configurable retry logic with distinct timeout behaviors for onboarding versus authentication. These changes replace previous ad-hoc or less structured approaches with a clear, type-safe contract for onboarding and session management.
_packages/at\auth/lib/src/auth/models · high confidence
New typed key management model with enrollment-scoped access
The \AtKeys\ class in \at\_auth\ has been replaced with a new in-memory model that organizes cryptographic material by enrollment rather than a flat list. Key identity is now defined by the combination of \enrollmentId\ and \keyId\, allowing multiple enrollments to hold keys with the same identifier without conflict. The model distinguishes between an atSign's own keys (like the signing root) and keys belonging to specific enrollments, providing typed accessors for both. It also introduces \AtKeysEnrollment\ to store metadata such as namespaces, app name, and device name, which are reconciled from the enrollment record. This change supports reading keyfiles with multiple live enrollments and ensures that key lookups are explicit about their scope.
_packages/at\auth/lib/src/keys · high confidence
Post-quantum crypto readiness and configurable legacy fallback
The at\_client SDK now defaults to a post-quantum-ready posture, introducing a new crypto configuration system that allows applications to control encryption schemes. Users can now explicitly disallow legacy (pre-post-quantum) encryption via the \disallowLegacyEncryption\ preference, which causes writes to destinations that cannot be reached with post-quantum keys to fail safely rather than falling back to weaker algorithms. The SDK supports a 'read PQ, write legacy' hybrid mode for gradual migration, ensuring existing records remain readable while new data can be secured with post-quantum algorithms. This change also introduces new exception types (\LegacyEncryptionRefusedException\, \NskeyPrivateUnavailableException\) to help applications handle these security decisions and key availability issues gracefully.
_packages/at\client/lib/src/crypto · high confidence
Post-quantum enrollment support and explicit signing algorithm selection
The enrollment models now support post-quantum cryptography by introducing a new key exchange mode where the approver generates and conveys the symmetric key via a key package, removing the RSA-wrapping step that is vulnerable to quantum adversaries. Additionally, apps enrolling over OTP can now explicitly specify the signing algorithm for their APKAM authentication keypair, preventing the creation of legacy RSA credentials on post-quantum deployments. The models also introduce a mechanism for callers to contribute signed metadata during enrollment and provide JSON serialization for enrollment responses.
_packages/at\auth/lib/src/enroll/models · high confidence
Redesigned keyfile storage with atomic updates and inter-process locking
The keyfile storage layer has been refactored to ensure data integrity during concurrent access. The new \FileAtKeysIo\ implementation wraps all read-modify-write operations in an inter-process advisory lock, preventing race conditions where multiple processes could silently overwrite each other's key additions. Updates are now atomic (write-to-temp then rename) and include validation to detect dropped material, ensuring no key data is lost during flushes. Additionally, the system preserves the legacy keyfile format as a backup when upgrading to the new typed format, maintaining compatibility with older builds.
_packages/at\auth/lib/src/keys/io · high confidence
Refactored at-sign switching logic and deprecated ConnectivityListener
The at-sign switching mechanism has been refactored to prevent duplicate events and improve stability: a new \SwitchAtSignEvent\ class now validates that the previous and new clients are distinct, and the \AtClientManager\ logic has been simplified to determine the previous client dynamically rather than storing it as an instance variable. Additionally, the \ConnectivityListener\ class is now deprecated, encouraging users to implement their own connectivity checks using external libraries.
_packages/at\client/lib/src/listener · high confidence
Refactored client lifecycle and connection management
The client manager now uses a new \AtClientManager\ singleton to hold the active \AtClient\ instance, replacing the deprecated \setCurrentAtSign\ method which is scheduled for removal in version 4.0. Switching atSigns now explicitly stops the outgoing client and recreates services, with idempotency checks to prevent race conditions when reusing the same atSign. The \Monitor\ class has been refactored to consume an \AtLookupMuxable\ connection instead of managing its own socket, simplifying connection handling and improving resilience against network interruptions. Additionally, a new \StorageManager\ class has been introduced to handle local persistence initialization, ensuring proper lifecycle management of the Hive storage bundle.
_packages/at\client/lib/src/manager · high confidence
Refactored exception hierarchy and added new error codes for enrollment and throttling
The exception handling in at\_commons has been restructured to support more granular error reporting. New exception classes have been introduced, including AtInvalidEnrollmentException, AtEnrollmentRevokeException, AtThrottleLimitExceeded, IllegalStateException, and StoppedException (for operations on stopped clients). Error codes have been mapped to these exceptions (e.g., AT0029 for expired enrollment, AT0028 for throttling, AT0032 for illegal state), and the AtExceptionUtils factory now routes these specific codes to their corresponding types. Additionally, client-side exceptions like InvalidPinException and CryptoProviderNotRegistered have been added to the AtClientException hierarchy.
_packages/at\commons/lib/src/exception · high confidence
Refactored key model with new key types and raw byte accessors
The key management API has been restructured to support a broader range of cryptographic algorithms and improved usability. New key types including RSA-4096, AES-256, X25519, and ML-KEM-768 are now explicitly defined in the key type enum, alongside updated key name constants for legacy and new keys. The core key classes have been consolidated into a sealed hierarchy (AbstractKey, SymmetricKey, AtPrivateKey, AtPublicKey, and AsymmetricKeyPair), providing a unified structure for all key representations. Additionally, a new RawKeyPairBytes mixin has been introduced to allow direct access to raw public and private key bytes for post-quantum and X25519 key pairs, simplifying operations that require raw byte manipulation.
_packages/at\chops/lib/src/key · high confidence
Refactored logging system and added progress tracking utilities
The at\_utils package has been significantly refactored to improve logging flexibility and add progress tracking capabilities. The AtSignLogger now accepts an optional LoggingHandler, allowing users to customize log destinations (such as Console, StdErr, File, or a new CLILoggingHandler for colored CLI output) instead of relying on a fixed default. The AtSignLogger.level setter is now case-insensitive, and the ConsoleLoggingHandler no longer prints an empty line after every record. Additionally, a new ProgressPublisher interface and ProgressEvent types have been introduced to allow subscribers to monitor and react to progress updates, and a PseudoServerSocket helper has been added for ALPN support.
_packages/at\utils · high confidence
Refactored notification service to expose listener lifecycle control
The NotificationService interface now exposes explicit methods to start and stop the underlying notification listener (Monitor), allowing application code to manage the listener's lifecycle rather than relying solely on automatic start/stop behavior. This change introduces \startListening()\ and \stopListening()\ methods, along with state getters (\targetListenerState\, \currentListenerState\) and a state change stream (\currentListenerStateStream\), giving developers finer control over when the client connects to the atServer for notifications.
_packages/at\client/lib/src/service · high confidence
Refactored request transformers to use CryptoRuntime and support encryption options
The request transformers for GET, PUT, and NOTIFY operations have been rewritten to integrate with the new CryptoRuntime. PUT requests now support explicit encryption options via PutRequestOptions, allowing users to control whether data is encrypted and which crypto provider is used, while public keys are signed instead of encrypted. NOTIFY requests now route through the crypto provider to handle namespace resolution and encryption metadata stamping, with a fallback to legacy encryption if a key is unavailable. GET requests have been updated to use the LookUpBuilderManager with explicit request options. These changes ensure consistent encryption handling and better support for namespace-aware keys across all write and read operations.
_packages/at\_client/lib/src/transformer/request\transformer · high confidence
Restructured public API and added PKCS7 padding support
The at\_chops package has been refactored to provide a cleaner public surface. The main barrel (at\_chops.dart) now explicitly exports algorithm interfaces, key implementations, and metadata classes, while deliberately hiding internal RFC 9180 key-schedule details to preserve API stability. A new FFI barrel (at\_chops\_ffi.dart) exposes OpenSSL-backed algorithms and the AtPqc module for non-web environments. Additionally, a new PKCS7 padding implementation and its associated types have been added to support AES encryption block alignment, and the legacy AtEncrypted model is now marked as deprecated in favor of application-specific payload models.
_packages/at\chops/lib · high confidence
Signing infrastructure refactored to support multiple algorithms and post-quantum keys
The signing module has been restructured to support multiple signing algorithms (including ML-DSA-65) alongside legacy RSA, allowing clients to mint, advertise, and retire signing keys based on a configurable set of preferred algorithms. This change introduces a new envelope signature format that explicitly names the signing algorithm and enrollment ID, ensuring verifiers can select the strongest available signature. The \\_apsk\ advertisement now supports both bare public key values for single RSA keys and JSON arrays for multiple or post-quantum keys, improving interoperability and security posture.
_packages/at\client/lib/src/signing · high confidence
Updated Android example apps for at\_sync\_ui\_flutter and at\_theme\_flutter
The Android example projects for at\_sync\_ui\_flutter and at\_theme\_flutter have been updated to comply with Android 12+ requirements by explicitly setting android:exported=true on the main activity. The examples now use the Flutter V2 embedding, target Gradle 7.5, and include proper .gitignore rules to prevent committing sensitive files like keystores.
_packages/at\_sync\_ui\_flutter/example/android, packages/at\_theme\flutter/example/android · high confidence
Updated at\_lookup example to reflect current API usage
The example script in the at\_lookup package has been updated to demonstrate interaction with the secondary server using the current verb builders (Update, Lookup, PLookup, LLookup, Delete, Scan, Notify, and NotifyList). The code now directly instantiates AtLookupImpl, which is marked as deprecated in favor of AtLookUp.withSecureSocket, and includes a TODO to rewrite the example against the new secure socket API in version 4.0.0.
_packages/at\lookup/example/bin · high confidence
Updated iOS example app to support iOS 12+ and modern Flutter tooling
The iOS example project for at\_location\_flutter has been regenerated to align with Flutter 3.10 standards. The minimum deployment target is now iOS 12.0, and the app bundle includes the necessary configuration files (such as AppFrameworkInfo.plist and xcconfig files) to support CocoaPods integration and modern Xcode build settings. This ensures the example app builds correctly with current Flutter tooling and supports the required location permissions.
_packages/at\_location\flutter/example/ios · high confidence
Updated iOS example project scaffolding for Flutter 3.0.13
The iOS example project for at\_chat\_flutter has been regenerated to align with the at\_chat\_flutter 3.0.13 update. This includes a new .gitignore, updated Xcode project and workspace configurations, and a minimum iOS deployment target of 12.0. The example app's Info.plist now includes the \UIApplicationSupportsIndirectInputEvents\ key to support newer iOS input behaviors, and the AppDelegate has been updated to use the modern \@main\ entry point.
_packages/at\_chat\flutter/example/ios · high confidence
Updated macOS example to include new plugin registrations
The macOS example project now includes a regenerated \GeneratedPluginRegistrant.swift\ file that registers additional plugins, including \at\_file\_saver\, \at\_login\_flutter\, \biometric\_storage\, \device\_info\_plus\, \emoji\_picker\_flutter\, \file\_picker\, \flutter\_image\_compress\_macos\, \flutter\_local\_notifications\, \geolocator\_apple\, \package\_info\_plus\, \path\_provider\_foundation\, \share\_plus\, \shared\_preferences\_foundation\, \sqflite\_darwin\, \url\_launcher\_macos\, and \webview\_flutter\_wkwebview\. This ensures these plugins are properly initialized when the macOS example app runs.
_packages/at\_location\flutter/example/macos/Flutter · high confidence
at\_auth package split into WASM-compatible core and dart:io-specific barrel
The at\_auth package is now structured into two entry points to support WebAssembly (WASM) targets. The main \at\_auth.dart\ barrel exports the core authentication, enrollment, and key material logic that does not depend on \dart:io\, allowing WASM clients to authenticate. A new \at\_auth\_io.dart\ barrel exports platform-specific implementations requiring filesystem or socket access (such as \FileAtKeysIo\ and \fileRetrofitSerializer\), which must be explicitly imported by \dart:io\ applications. This separation ensures that WASM builds remain free of \dart:io\ dependencies while preserving full functionality for native environments.
_packages/at\auth/lib · high confidence
at\_lookup v4.0: transport abstraction and authentication migration
The at\_lookup library has been refactored to decouple the connection transport from the core logic, introducing \AtLookUp.withSecureSocket\ as the primary entry point and deprecating the direct \AtLookupImpl\ constructor. This change requires callers to explicitly provide an \AtLookupTransport\ (such as \secureSocketTransport\ from \at\_lookup\_io.dart\) and an \AtAuthenticator\ closure, moving credential management out of the library. The \MonitorClient\ is deprecated in favor of using the shared connection's notification stream. Additionally, the \from:\ challenge format is now strictly validated to prevent malformed authentication attempts, and the \SecondaryUrlFinder\ exposes \retryDelaysMillis\ to allow clients to control retry behavior.
_packages/at\lookup/lib · high confidence
at\_onboarding\_cli v2.0.0: Lifecycle moved to at\_client, CLI requires explicit commands
The onboarding lifecycle has been refactored so that \at\_activate\ delegates activation and enrollment to \at\_client\'s \Atsign\ verbs, removing the legacy \AtOnboardingService\ orchestration. This is a breaking change: the CLI now requires an explicit command (e.g., \at\_activate onboard\) and refuses invocations with no command. The deprecated \--signingAlgoType\ flag is replaced by \--posture\ (defaulting to \at\_client\'s posture) and \enroll\ gains \--key-exchange\ to control how the enrollment's symmetric key travels. The checkpoint file is removed in favor of the keyfile acting as the resume record, and \authenticate()\ now authenticates as the keyfile's own enrollment rather than copying keys into local storage. Additionally, \createAtClient\ now waits for post-quantum startup completion, and single-shot commands skip this wait to avoid timeouts.
_packages/at\_onboarding\cli · high confidence
at\_server\_status now uses secure socket lookups and sends 'from:' before 'scan:'
The at\_server\_status package has been updated to use secure socket connections for its lookups by default, requiring an AtLookUpFactory that supports secure sockets. Additionally, the implementation now sends a 'from:' command before executing 'scan:' operations, ensuring compatibility with atServer proxy services. These changes improve security and reliability when checking the status of atSigns.
_packages/at\_server\status/lib · high confidence
at\_sync\_ui\_flutter package deprecated in version 1.2.0
The \at\_sync\_ui\_flutter\ package has been deprecated, with version 1.2.0 serving as its final minor release. Existing APIs like \AtSyncUIService\ and the associated Material/Cupertino widgets remain available to ensure current apps continue to compile, but users are advised to migrate to \AtCollection\<T\>\ and \Query.watch()\ from the \at\_client\ package. The package documentation now provides specific migration guidance and examples for using collection streams as the primary state source instead of global sync progress indicators.
_packages/at\_sync\_ui\flutter · high confidence
at\_theme\_flutter package is deprecated
The at\_theme\_flutter package is now deprecated and no longer recommended for new Flutter applications. Users should migrate to using Material3 themes in the at\_client\_flutter package instead. This change affects the package's documentation and status, signaling that the theme switching capabilities previously provided by at\_theme\_flutter are superseded by the native theming support in at\_client\_flutter.
_packages/at\_theme\flutter · high confidence
iOS example app scaffold updated for Flutter 3 and iOS 12
The iOS project files for the \at\_theme\_flutter\ example app have been regenerated to align with modern Flutter tooling. The minimum deployment target is now iOS 12.0, and the Xcode project structure includes updated build configurations, a new \AppFrameworkInfo.plist\, and standard asset storyboards. This ensures the example app builds correctly with current Flutter versions and Xcode requirements.
_packages/at\_theme\flutter/example/ios · high confidence
iOS example project scaffolded for Flutter 3.0+ and iOS 12+
The iOS example project for at\_sync\_ui\_flutter has been regenerated to support modern Flutter tooling and iOS 12.0 as the minimum deployment target. This update includes a new Xcode project structure with CocoaPods integration, updated build configurations, and a Swift-based AppDelegate, ensuring the example app builds and runs correctly on current iOS versions.
_packages/at\_sync\_ui\flutter/example/ios · high confidence
Fixes
Example app now supports custom sync indicators and theme toggling
The at\_sync\_ui\_flutter example application has been updated to demonstrate advanced customization and usability features. Users can now toggle between light and dark themes directly from the home screen. The example also introduces a custom sync indicator widget (CustomSyncIndicator) that allows for personalized visual feedback during synchronization, replacing the default indicator in the main sync view. Additionally, the app now properly handles the onAtSignRemoved callback, providing user feedback when an atSign is removed from the keychain, and fixes static analysis issues related to widget constructor argument ordering and BuildContext usage across async gaps.
_packages/at\_sync\_ui\flutter/example/lib · high confidence
Example app now uses AtAuthService for onboarding
The at\_chat\_flutter example app has been updated to replace the previous AtClientService with AtAuthService for the onboarding flow. Users now authenticate via a new sequence involving AtSignSelectionDialog, KeychainAtKeysIo (or file picker fallback), and PkamDialog, with credentials stored in the device keychain. The app also includes screens for initiating one-to-one chats and group chats, and allows clearing paired atsigns.
_packages/at\_chat\flutter/example/lib · high confidence
Fix for AtCollection query operations handling null values and missing keys
The AtCollection query implementation now correctly handles scenarios where retrieved keys are expired or have not yet been created. Specifically, \AtCollectionQueryOperationsImpl\ and related model operations now check if \AtValue.value\ is null after a get operation and skip those entries, preventing errors when processing expired or unborn keys. Additionally, the code now properly catches and continues past \AtKeyNotFoundException\ errors during collection queries, ensuring that missing keys do not interrupt the retrieval of other valid models.
_packages/at\_client/lib/src/at\collection/impl · high confidence
Fixes sync timer cancellation to prevent stale UI state
The AtSyncUIService now explicitly cancels the 'remove atSign' timer whenever a sync operation is initiated or completes. This ensures that the option to remove the atSign does not appear unexpectedly after a sync finishes or if a new sync is triggered, resolving issues where the UI remained in an incorrect state due to lingering timers.
_packages/at\_sync\_ui\flutter/lib/services · high confidence
New atKey validation implementation with specific length limits
The at\_commons package introduces a new implementation for validating atKeys, replacing previous logic. This change enforces strict key length limits, capping standard keys at 248 characters and cached keys at 255 characters. It also implements comprehensive validation for key format, ownership, and reserved entity checks to ensure keys adhere to the defined regex patterns and access control rules.
_packages/at\commons/lib/src/validators · high confidence
Test coverage
Added comprehensive test coverage for at\_lookup authentication, connection management, and lifecycle; Added initial widget test scaffold; Added proxy-based functional test infrastructure for CLI onboarding; Added sample scripts for at\_client operations and testing utilities; Added sample test scripts for at\_client encoding, sync, and streaming; Added sample tests for notification and connectivity monitoring; Added shared test infrastructure for PQ matrix scenarios; Added smoke tests for Flutter example apps; Added test coverage for Flutter keychain, enrollment, and dialog error handling; Added test for activation key computation; Added test helper for Material app widget testing; Added tests for AtClientStorage lifecycle and backend isolation; Added tests for AtRpc client lifecycle and JSON serialization; Added tests for Enrollment response parsing and permissions; Added tests for at\_cli\_commons utility functions; Added tests for at\_client process exit behavior; Added tests for the acceptance ledger and APKAM authorization; Added tests for the at\_client lifecycle and enrollment subsystems; Added unit and widget tests for AtSyncUI service and indicators; Added unit and widget tests for at\_events\_flutter; Added unit and widget tests for the theme package; Added unit tests for @sign status checks; Added unit tests for AtCollection implementation; Added unit tests for ChatService; Added unit tests for the PolicyService; Added unit tests for the at\_onboarding\_cli package; Added widget tests for chat UI components; Executable acceptance test suite for post-quantum readiness; Expanded test coverage for AES, Argon2id, and Post-Quantum Cryptography backends; Expanded test coverage for at\_auth key management and authentication flows; Expanded unit test coverage for at\_commons core types and verb builders; New end-to-end test infrastructure for APKAM and post-quantum scenarios; New end-to-end test suite for the at\_client SDK; New test utilities for mocking and key management; Post-quantum algorithm spec validation and output checking; Test fixtures now include pre-generated cryptographic keys for demo users.
Dependencies
Introduce at\_auth package and update at\_chat\_flutter Android build configuration
This change introduces the new \at\_auth\ package (version 4.0.0-rc2), which centralizes common logic for onboarding and authenticating an atsign to a secondary server, depending on \at\_commons ^5.18.0\, \at\_lookup ^3.7.0-rc2\, and \at\_chops ^3.6.0\. Additionally, the \at\_chat\_flutter\ example app's Android build configuration is updated to use Kotlin 1.8.20 and target SDK 34, aligning with modern Android development standards.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 67.
Lenses
- Code Health 86
- Architecture 93
- Maturity 68
- Readiness 79
- Security 69
- Domain Modelling 60
Changes since last survey
- 300 commits — 231 feature/other, 69 fixes
By area
- packages/at_client — 93 commits
- (repo) — 62 commits
- docs/projects — 36 commits
- packages/at_auth — 32 commits
- tests/at_functional_test — 15 commits
- packages/at_chops — 12 commits
- packages/at_client_flutter — 12 commits
- packages/at_onboarding_cli — 10 commits
- packages/at_lookup — 8 commits
- tests/at_onboarding_cli_functional_tests — 5 commits
- tests/at_end2end_test — 4 commits
- .github/workflows — 3 commits
- actions/setup-flutter-and-dart — 2 commits
- packages/at_client_skills — 2 commits
- (root) — 1 commit
- packages/at_commons — 1 commit
- packages/at_contact — 1 commit
- tests/at_onboarding_cli_functional_tests_proxy — 1 commit
Notable commits
- fix: Merge branch 'trunk' into fix/pr-2226-review-findings
- fix: Merge pull request #2226 from atsign-foundation/gkc-aes-ctr-ffi-review-fixes
- fix: Merge pull request #2227 from atsign-foundation/fix/pr-2226-review-findings
- fix: Merge pull request #2252 from srieteja/fix/pr2245-review-findings-2
- fix: Merge remote-tracking branch 'origin/fix/pr2245-review-findings' into gkc-deterministic-client-stop
- fix: chore(at_chops): prepare v3.7.0 with named key exception fix
- fix: chore(docs): fix the log message regarding disallowLegacyEncryption
- fix: fix(at_auth): a keyfile holding a keypair outranks an injected signer
- fix: fix(at_auth): a typed keyfile carries an empty top-level keys array
- fix: fix(at_auth): derive an AtChops from typed atSign material
- fix: fix(at_auth): do not refuse onboarding an atSign for having a public key
- fix: fix(at_auth): install an authenticator, and fall back to the ladder
- fix: fix(at_auth): stop deprecating what has no replacement
- fix: fix(at_auth): stop pausing 500ms before every PKAM attempt
- fix: fix(at_auth): the lookup gets an authenticator, not the ladder
- fix: fix(at_chops): bind EVP update inl as Int32 and guard the length
- fix: fix(at_chops): guard the GCM FFI update lengths
- fix: fix(at_chops): name the sibling exception the decrypt path actually throws
- fix: fix(at_chops): the FFI inl guard throws the algo's own exception type
- fix: fix(at_client)!: reinstate ApkamSigning's published key accessors
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
atsign-foundation/at_client_sdk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cb6b041cc70e10a75621ef0a6bfadd15be286651 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.