Download the PHP package nais-standard/sdk without Composer
On this page you can find all versions of the php package nais-standard/sdk. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package sdk
nais-standard/sdk
PHP SDK for the Network Agent Identity Standard (NAIS).
Resolve and validate NAIS-compliant agent domains. Requires PHP 7.4+ and uses only built-in facilities — dns_get_record, ext-curl, and ext-sodium — with no third-party Composer dependencies. The SDK resolves directly: it reads the _agent.<domain> DNS TXT record, fetches the signed card over HTTPS (HTTPS-only, no cross-host redirects, 1 MiB cap), and verifies the card's mandatory Ed25519 signature against the DNS k= key. Server-side only — browsers cannot perform DNS lookups.
Installation
Usage
resolve(string $domain): array
Resolves a domain directly via DNS and HTTPS and returns a structured result array:
ok— overall success flag.domain— the normalized domain.agent_host— the host serving the card.dns—['records', 'parsed'], whereparsedexposesv,manifest, andk.manifest_url— the URL the card was fetched from.card— the decodedagent.json.signature—['present', 'verified', 'kid', 'alg', 'reason'].validation—['valid', 'errors', 'warnings'].
resolve() throws on an invalid domain, when no NAIS TXT record is found, or when the card fetch fails. It does not throw on a bad signature — that surfaces as $r['signature']['verified'] === false and $r['validation']['valid'] === false.
validate(string $domain): array
Returns a flattened summary array. Ideal for quick validation checks before using an agent.
Example output:
valid is true only when the card resolved, the schema validates, and the signature verifies.
verifyCard / canonicalize
The SDK also exposes the static helpers \Nais\Resolver::verifyCard($card, $dnsKey) and \Nais\Resolver::canonicalize($value) for verifying a card you already hold against a DNS k= key. The static helpers \Nais\Resolver::normalizeDomain and \Nais\Resolver::parseNaisTxt are also available.
Error handling
Testing without DNS or network
The constructor accepts injected lookupTxt and fetchCard callables, so resolution can be tested offline:
Requirements
- PHP 7.4 or higher
ext-curlext-jsonext-sodium(Ed25519 card signature verification)
No third-party Composer dependencies; DNS lookups use the built-in dns_get_record.
Notes
- Resolution is performed locally and directly: DNS TXT lookup, HTTPS card fetch, and Ed25519 signature verification all happen in-process. There is no central resolver.
- The card fetch is HTTPS-only, refuses cross-host redirects, and caps responses at 1 MiB.
- All SSL verification is enabled by default.
- Server-side only: browsers cannot perform DNS lookups.
License
MIT
All versions of sdk with dependencies
ext-curl Version *
ext-json Version *
ext-sodium Version *