Download the PHP package iajson/client without Composer
On this page you can find all versions of the php package iajson/client. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download iajson/client
More information about iajson/client
Files in iajson/client
Package client
Short Description PHP reference library for consuming ia.json files — the universal standard for AI interaction with websites
License MIT
Homepage https://iajson.org
Informations about the package client
iajson/client
PHP reference library for consuming ia.json files -- the universal standard for AI interaction with websites.
Requirements
- PHP 8.1 or higher
- ext-json
- ext-hash
Installation
Note: The package will be available on Packagist soon. In the meantime, install from GitHub:
Quick Start
Discovery
The library follows the ia.json discovery algorithm:
- Tries
https://{domain}/ia.json - Falls back to
https://{domain}/.well-known/ia.json - Validates the spec structure and version compatibility
Browsing Endpoints
Authentication
Signed Key Registration
For protected endpoints, you must register your AI agent and receive credentials:
Using Existing Credentials
If you already have credentials from a previous registration:
OAuth2 (User Authorization)
For user_required endpoints, you need the user's OAuth2 token:
Request Signing
The Signer class implements the ia.json HMAC signing algorithm:
Error Handling
The library throws typed exceptions for different error conditions:
Laravel Integration
This package includes first-class Laravel support with auto-discovery.
Setup
-
Publish the configuration:
- Add your credentials to
.env:
Using the Facade
Dependency Injection
Verifying Incoming AI Agent Requests
If your Laravel application serves as an ia.json-enabled site and receives requests from AI agents, use the VerifyIaSignature middleware:
-
Register the middleware alias in your
bootstrap/app.php(Laravel 11+) or kernel: -
Apply it to your routes:
- Configure the secret resolver in
config/iajson.php:
The verified API key is available in the request:
Configuration Reference
The full config/iajson.php supports the following options:
| Key | Env Variable | Description |
|---|---|---|
domain |
IAJSON_DOMAIN |
Domain to discover ia.json from |
api_key |
IAJSON_API_KEY |
Agent API key |
secret |
IAJSON_SECRET |
Agent secret |
oauth.client_id |
IAJSON_OAUTH_CLIENT_ID |
OAuth2 client ID |
oauth.client_secret |
IAJSON_OAUTH_CLIENT_SECRET |
OAuth2 client secret |
cache_ttl |
IAJSON_CACHE_TTL |
Spec cache TTL in seconds |
verification.algorithm |
IAJSON_VERIFY_ALGORITHM |
HMAC algorithm for verification |
verification.header_prefix |
IAJSON_VERIFY_HEADER_PREFIX |
Auth header prefix |
verification.max_age_seconds |
IAJSON_VERIFY_MAX_AGE |
Max timestamp age |
Spec Compliance
This library implements the ia.json v1.0.0 specification:
- Discovery at
/ia.jsonand/.well-known/ia.json - Version validation (major version check)
- File size limit enforcement (1 MB)
- All three access levels:
public,protected,user_required - HMAC-SHA256 and HMAC-SHA512 request signing
- Timestamp-based replay attack prevention
- Agent registration and domain verification flow
- OAuth2 with PKCE support
- Structured error responses per the spec format
License
MIT License. See the ia.json project for the full specification.