aer1-llamaindex
AER-1 verifiable workflow receipts for LlamaIndex.
Attach one collector to a CallbackManager and every run emits a
hash-chained, offline-verifiable verifiable workflow receipt (AER-1,
Section 8): what the agent did, in what order, with per-step hashes and
a Merkle root over the whole run. No network calls, no behavior changes,
the collector only observes.
The AER-1 framework collector family
The LlamaIndex collector in the AER-1 framework collector family. Any agent running on these frameworks can emit verifiable AER-1 execution receipts: every step recorded, hash-chained, one Merkle root over the whole run.
- aer1-llamaindex, LlamaIndex agents via callback handler
- aer1-smolagents, SmolAgents agents via step callbacks
- aer1-openai-agents, the OpenAI Agents SDK via its TracingProcessor
- aer1-crewai, CrewAI crews via the event bus
- aer1-langgraph, LangGraph swarms via callback handler
- aer1-autogen, AutoGen multi-agent chats
Install
pip install aer1-llamaindex
Use it (copy, paste, run, no API keys needed)
# pip install aer1-llamaindex
from aer1_llamaindex import AER1ReceiptCollector
from llama_index.core.callbacks import CallbackManager
from llama_index.core.callbacks.schema import CBEventType
def get_weather(location: str) -> str:
"""Local mock tool: executed on this machine, no network."""
return f"Sunny, 22C in {location}"
collector = AER1ReceiptCollector(goal="check the Paris weather")
manager = CallbackManager([collector]) # line 1: register the collector
# A two-step flow: LLM reasoning, then a tool call. In production these
# events come from your real agent, query engine, or workflow, which gets
# `manager` as its callback_manager.
eid = manager.on_event_start(
CBEventType.LLM, payload={"messages": ["What is the weather in Paris?"]})
manager.on_event_end(
CBEventType.LLM, payload={"response": "I will call get_weather."}, event_id=eid)
eid = manager.on_event_start(
CBEventType.FUNCTION_CALL,
payload={"tool_name": "get_weather", "tool_kwargs": {"location": "Paris"}})
observation = get_weather("Paris")
manager.on_event_end(
CBEventType.FUNCTION_CALL, payload={"observation": observation}, event_id=eid)
receipt = collector.finalize(final_answer=observation) # line 2
assert collector.verify(receipt) == [] # VALID
collector.save("receipt.json", workflow=receipt)
That is the whole integration: attach the collector, run, finalize. The receipt is a plain JSON object you can store, ship to an auditor, or render in a UI.
What the receipt contains
Workflow level (AER-1 Section 8, Table 2):
type,version,workflow_id,receipt_id,session_idgoal,statussteps: one record per event, seq 1..n in ordermerkle_root: Section 8.1 root over the ordered step receipt idsoutput_hash: SHA-256 of the final answerverify_url: where the verification procedure is documented
Step level (AER-1 Section 8, Table 3):
seq,receipt_id,tool,receipt_hash,started_at,ended_at,status
Each step tool is the callback event type (for example llm,
function_call, retrieval, synthesis). arguments is the
event-start payload and observations is the event-end payload; each
step receipt_hash is SHA-256 over the canonical JSON of those three,
so the hash commits to what actually happened. The receipt stays
compact while the hash commits to the content.
Verification
collector.verify(receipt) runs the full offline check and returns a
list of failure reasons, empty when valid:
- all Table 2 / Table 3 members present and well-formed
seqvalues exactly 1..n in order, no gaps- no two steps share a
receipt_id(MM-1) merkle_rootmatches the recomputed Section 8.1 root- strict RFC 3339 timestamps, lowercase UUIDs, 64-char hex digests
Tamper with any field and verification fails. Try it:
receipt["steps"][0]["tool"] = ""
assert collector.verify(receipt) != [] # fails, as it should
Notes
- Pass the
CallbackManageras thecallback_managerof your agent, query engine, or workflow; the collector records every event as a step, in event-end order. - Pass
goal=to the collector; LlamaIndex does not forward a task description through callback events, so the constructor is the reliable place for it. - Exception events (event-end payload carrying an
exception) are recorded withstatus: "error", which marks the whole receipt error. - Use
event_starts_to_ignore/event_ends_to_ignore(standardBaseCallbackHandlerarguments) to skip noisy event types. session_iddefaults to a fresh UUID per collector; pass your own to correlate receipts across runs.verify_urldefaults to the AER-1 specification page; point it at your own verifier in production.
Spec
AER-1: Agent Execution Receipts is an IETF Internet-Draft,
draft-zambo-aer1,
https://datatracker.ietf.org/doc/draft-zambo-aer1/
See it live
Your receipt is offline-verifiable, but you can also check it on the live verifier:
- Copy the receipt JSON your code produced
- Paste it at https://zambo.dev/verify
- See the verification result with the Merkle root and step hashes
Or mint a live receipt directly: run any call at https://zambo.dev/demo and get a shareable receipt URL like https://zambo.dev/run/.
License
Apache-2.0
Metadata
Release files for aer1-llamaindex 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aer1_llamaindex-0.1.0.tar.gz | 9.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aer1_llamaindex-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.5 kB
Release files / aer1_llamaindex-0.1.0.tar.gz
| Download URL | aer1_llamaindex-0.1.0.tar.gz |
|---|---|
| Size | 9.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cf6aa810dfaaa401ff61478a8c20a5989c475754574c1c1f51c6f842746a9d96
|
|
BLAKE2b-256 checksum How to use checksums |
766ddc339db7277cf611fdcc243785ea625e6f3c74eaf24c66c9f7c2a5c0c79e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|
Release files / aer1_llamaindex-0.1.0-py3-none-any.whl
| Download URL | aer1_llamaindex-0.1.0-py3-none-any.whl |
|---|---|
| Size | 8.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7134fba71bf0a3e9d5f42b400881e80b9577a87a14bdb5d80ca241faed5e3e2b
|
|
BLAKE2b-256 checksum How to use checksums |
94c5ba66afcdcf7429737c3af456efad3f04afd28c477b3d2267bcadc67c1c36
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|