Trust and limitations
Verify self-custody, release provenance, security boundaries and current limitations.
- Section
- Trust
- Maturity
- supported
- Applies to
- >=0.2.0 <0.3.0
- Last reviewed
- 2026-08-10
MeterKit never needs a seed phrase or provider private key. npm candidates are staged through OIDC and require human 2FA approval. The 0.2.0 packages carry registry provenance attestations; the historical 0.1.0 release does not claim provenance that npm did not expose.
Devnet transactions and automated agents are internal evidence, not revenue or external adoption. Start with the operating limits.