npm · @verax-ai/body
$npx -y @verax-ai/body@0.4.7 VERAX_ISSUER (required) — Issuer the agent's token must carry. The body refuses to start without one; `verax doctor` names what is missing.
VERAX_JWKS_URL (required) — Where the body fetches the keys that verify that token.
VERAX_AUDIENCE (required) — Audience the token must name, so a token minted for something else is refused.
VERAX_STATE_DIR (required) — Directory the ledger, keys and approvals live in. It stays on this machine.
VERAX_POLICY_FILE (required) — Policy the gate applies. @verax-ai/proxy ships policy/default.json, which denies what it does not name.
VERAX_BIND — host:port the body listens on. Anything but loopback needs VERAX_TLS_TERMINATED=1.
VERAX_INVENTORY_FILE — Roster document the body serves; the format is @verax-ai/inventory.