gdp-ts
A TypeScript library, linter presets, and AI agent skill implementing Ghosts of Departed Proofs to catch authorization and entitlement bugs at compile time.
At a Glance
Free to use, modify, and distribute under the MIT License.
Engagement
Available On
Listed Oct 2026
About gdp-ts
gdp-ts is an open-source TypeScript library, linter, and AI skill published under the rauchg GitHub account. It implements Ghosts of Departed Proofs so that authorization and entitlement checks are enforced by the type checker rather than by convention. The library ships on npm as @gdp-ts/core, and the skill can be installed to guide coding agents.
What It Is
gdp-ts is a verification pattern for TypeScript API contracts. Instead of letting any caller invoke a sensitive function with a raw id, the function signature demands a proof, such as that a user is a project admin or that a plan includes a feature. Calling it with no proof, a wrong proof, a proof about a different value, or a raw id is a compile error. The README says the approach works with any TypeScript codebase and runtime, and does not change how you do I/O.
How the Proof Workflow Works
The workflow has three steps. First, name(x, k) gives a runtime value a compile-time-only name inside a callback, so two string ids become distinguishable to the compiler. Second, a small trusted module in proofs/ performs a check and returns a Proof, or null; only that module can mint the proof, and at runtime a proof is a frozen object. Third, sensitive data-layer functions declare proof parameters about their exact arguments, so routes, Server Actions, or jobs cannot skip the check.
Package, Linter, and Agent Skill
@gdp-ts/core contains name(), defineProof(), Named and Proof with no dependencies, plus ESLint and Oxlint presets that catch forged proofs such as casting with as or minting proofs outside proofs/. The agent skill is plain Markdown covering a workflow checklist, a six-step recipe, patterns, error reading, documented limits, and guidance on where to stop. It requires TypeScript 5.4 or newer.
Where It Fits
The README distinguishes gdp-ts from policy engines (it ensures a decision reaches the dependent function rather than making the decision), from branded types (names identify which value, not just what kind), and from validation libraries (it proves relationships between values rather than data shape). Examples include a framework-free basic demo, an Express 5 app, and an Express with Drizzle and PGlite app.
Community Discussions
Be the first to start a conversation about gdp-ts
Share your experience with gdp-ts, ask questions, or help others learn from your insights.
Pricing
Open Source (MIT)
Free to use, modify, and distribute under the MIT License.
- Library @gdp-ts/core with name(), defineProof(), Named and Proof, no dependencies
- ESLint and Oxlint lint presets
- AI skill installable via npx skills add rauchg/gdp-ts
- Requires TypeScript 5.4 or newer
Capabilities
Key Features
- Compile-time enforcement of authorization and entitlement checks
- name() for compile-time-only value names
- defineProof() for minting proofs in trusted modules
- ESLint and Oxlint presets to prevent forged proofs
- Agent skill guiding coding agents through the pattern
- Incrementally adoptable with any TypeScript codebase and runtime
- Near-zero runtime overhead
- Examples with Express and Drizzle
