/** * Sovereign Node Key — SnapKitty execution gate. * Without a valid key, model routing refuses to compute. * * Get your key: licensing@snapkittywest.dev * Copyright (C) 2026 Bel Esprit D'Accord Irrevocable Trust (EIN 42-697643) */ import { createHmac, timingSafeEqual } from 'crypto' const KEY_PREFIX = 'SNK-' const KEY_HEADER = 'x-sovereign-node-key' const KEY_ENV = 'SNAPKITTY_NODE_KEY' const WALL = ` ╔══════════════════════════════════════════════════╗ ║ SOVEREIGN NODE KEY REQUIRED ║ ║ ║ ║ This software requires a valid SnapKitty ║ ║ node key to activate model routing. ║ ║ ║ ║ Get your key: ║ ║ licensing@snapkittywest.dev ║ ║ https://github.com/SNAPKITTYWEST ║ ║ ║ ║ Copyright (C) 2026 Bel Esprit D'Accord ║ ║ Irrevocable Trust (EIN 42-697643) ║ ╚══════════════════════════════════════════════════╝ ` export function verifyNodeKey(key) { const secret = process.env.SNAPKITTY_NODE_SECRET if (!key || !key.startsWith(KEY_PREFIX) || !secret) return false try { const inner = key.slice(KEY_PREFIX.length) const lastDash = inner.lastIndexOf('-') if (lastDash === -1) return false const payload = inner.slice(0, lastDash) const signature = inner.slice(lastDash + 1) const expected = createHmac('sha256', secret) .update(payload) .digest('hex') .slice(0, 32) const a = Buffer.from(expected) const b = Buffer.from(signature.padEnd(32, '0').slice(0, 32)) return a.length === b.length && timingSafeEqual(a, b) } catch { return false } } export function requireNodeKey(key) { const k = key || process.env[KEY_ENV] || '' if (!verifyNodeKey(k)) { throw new Error(WALL) } } // Express / Hono middleware export function nodeKeyMiddleware(req, res, next) { const key = req.headers[KEY_HEADER] || req.query?.node_key || '' try { requireNodeKey(key) next() } catch (e) { res.status(401).json({ error: 'SOVEREIGN_NODE_KEY_REQUIRED', message: 'Valid node key required for model routing.', obtain: 'licensing@snapkittywest.dev' }) } }