Skip to main content

agent-manifest

Cryptographically anchor all 10 artifacts defining an AI agent at deployment.

The Agent Manifest SDK implements the Agent Manifest Specification v0.1 - a hardware-attestable document that binds every artifact defining an agent's behavior (system prompt, policy bundle, tool schemas, model identity, RAG corpus, memory state, audit chain, delegation chain, supply chain, and human approvals) into a single tamper-evident identity primitive.

pip install agent-manifest

Why

A signed JWT proves who called an API. An Agent Manifest proves who the agent was, what it was allowed to do, how it was built, what it decided, who approved it, and whether any of that changed between approval and execution.

from agent_manifest import (
    Manifest, ArtifactBindings,
    SystemPromptBinding, PolicyBundleBinding, ModelIdentityBinding,
    CryptoProfile, DeploymentType, EnforcementMode, PolicyLanguage,
    generate_ed25519, Ed25519Signer,
)
from agent_manifest._types import HashValue, ManifestId
from datetime import datetime, timedelta, timezone

now = datetime.now(timezone.utc)

manifest = Manifest(
    manifest_id=ManifestId("018f4a3b-2c1d-7e5f-a8b9-0d1e2f3a4b5c"),
    agent_id="spiffe://trust.example/agent/kyc/prod",
    issued_at=now,
    expires_at=now + timedelta(days=90),
    issuer="spiffe://trust.example/signing-authority",
    crypto_profile=CryptoProfile.standard,
    artifacts=ArtifactBindings(
        system_prompt=SystemPromptBinding(
            hash=HashValue("sha256:" + "a" * 64),
            bound_at=now,
        ),
        policy_bundle=PolicyBundleBinding(
            hash=HashValue("sha256:" + "b" * 64),
            policy_language=PolicyLanguage.cedar,
            version="1.0.0",
            enforcement_mode=EnforcementMode.enforce,
            bound_at=now,
        ),
        model_identity=ModelIdentityBinding(
            provider="example-provider",
            model_id="example-model-1",
            version="20251001",
            deployment_type=DeploymentType.api,
            bound_at=now,
        ),
    ),
)

keypair = generate_ed25519()
signer = Ed25519Signer(keypair)
sig_block = signer.sign(manifest.model_dump(mode="json", by_alias=True))
print(sig_block["algorithm"])   # Ed25519
print(sig_block["key_id"])      # sha256:<hex>

Composition-only manifests

Repository scanners can bind the artifacts they know before a model or runtime session exists. Set profile="composition-only" and explicitly name every artifact not bound by the document in unbound_artifacts. The verifier returns INCOMPLETE, not VALID, so this narrower document cannot be mistaken for a Level 0 agent manifest. Both fields are signature-covered.

manifest = Manifest(
    # identity, validity, issuer, and crypto fields omitted here for brevity
    profile="composition-only",
    unbound_artifacts=[
        "tool_manifest", "model_identity", "rag_corpus", "memory_baseline",
        "decision_trace", "delegation_chain", "supply_chain", "hitl_record",
    ],
    artifacts=ArtifactBindings(
        system_prompt=system_prompt_binding,
        policy_bundle=policy_bundle_binding,
    ),
)

Memory delta verification

The private SDK helper agent_manifest._memory_delta.verify_delta checks both the append-only proof and the operations claimed to have produced the advance:

verdict = verify_delta(
    previous_checkpoint, new_checkpoint,
    appended_ops, consistency_proof,
    representation="kv",  # or "vector" / "graph", matching the checkpoints
)

Migration for existing callers: pass only the operations appended since the previous checkpoint, in order, and supply the required representation keyword. The whole new log or an empty list for a nonempty advance is rejected as drift. Previously the helper ignored ops, so its acceptance did not authenticate them. Existing checkpoint roots and consistency proofs retain their formats.

Only fields included by the existing representation's leaf encoder are bound; extra operation metadata is not authenticated. The caller remains responsible for trusted checkpoints and policy inputs. This helper does not verify checkpoint approval signatures or establish whether the resulting memory behavior is safe.

Human approval and current applicability

VerificationResult.hitl_admissibility reports present applicability separately from fields_verified.hitl_record. The existing APPROVED result means the implemented approval checks passed; it does not establish that the approver still has authority or that the approval applies to current circumstances. The SDK has no current-state evidence input or successor-discovery mechanism for this decision.

Status Reason Meaning
UNDECIDABLE current_state_evidence_unavailable Approval checks passed, but current applicability is unknown.
UNDECIDABLE approval_checks_not_satisfied Approval checks did not pass; they cannot establish applicability.
UNDECIDABLE verification_incomplete Verification stopped before HITL evaluation, or an older result lacks this metadata.
NOT_REQUIRED approval_not_required The evaluated manifest and caller policy did not require approval. This is not a positive applicability verdict.

The legacy result is not a separate historical-authenticity verdict: for example, EXPIRED can be returned for malformed timestamps before signature verification. Approval duration sets a time window, not continuing authority. A signed previous_manifest_id link alone does not establish current applicability either.

This additive SDK reporting field does not change approval enforcement or the overall verification result. An overall VALID result can therefore coexist with UNDECIDABLE applicability. Callers requiring present applicability must apply their own evidence policy; they cannot treat UNDECIDABLE as permission to proceed. The field adds no manifest approval fields or normative specification requirements.

The 10 Attested Artifacts

# Artifact What it proves
1 System Prompt The exact prompt that defines the agent's persona and safety constraints
2 Policy Bundle The Cedar/Rego/YAML governance rules that were in force
3 Tool Manifest Every tool schema and description the agent was authorized to call
4 Model Identity Which model and version ran (binary hash for local, version for API)
5 RAG Corpus The knowledge base the agent was grounded on (Merkle root)
6 Memory Baseline Approved agent memory state with TTL-based re-approval
7 Decision-log baseline Audit-chain root at manifest issuance; runtime decisions remain separate linked evidence
8 A2A Delegation Signed delegation chain from human principal to current agent
9 Supply Chain Container digest, SLSA provenance, SBOM, MCP server supply chain
10 HITL Approvals Hardware-signed human oversight records (EU AI Act Art. 14)

Hardware Attestation

from agent_manifest._auto_provider import select_provider

# auto-selects: SEV-SNP → TDX → TPM → software  (OPAQUE is explicit opt-in via OPAQUE_ATTESTATION_URL)
provider = select_provider(level=1)   # Level 1+ requires hardware
provider.extend_manifest_hash(manifest_dict)
report = provider.get_attestation_report()
# report.platform: "amd-sev-snp" | "intel-tdx" | "tpm" | "opaque" | "software"
Provider Hardware Level Install
TPMProvider TPM 2.0 / AWS Nitro 1 apt install tpm2-tools
SEVSNPProvider AMD SEV-SNP 2 Needs /dev/sev-guest
TDXProvider Intel TDX 2 Needs /dev/tdx-guest
OPAQUEProvider OPAQUE Runtime 3 Set OPAQUE_ATTESTATION_URL

Verification

from agent_manifest._verify import verify_manifest, VerificationContext, RevocationStore

result = verify_manifest(
    manifest_dict,
    VerificationContext(
        system_prompt_hash="sha256:...",
        policy_bundle_hash="sha256:...",
        enforce_hitl=True,
    ),
    RevocationStore(),
)
print(result.result)   # VALID | MISMATCH | EXPIRED | REVOKED | ...

CLI

pip install "agent-manifest[cli]"

manifest keygen -d ./keys/
manifest create config.json -o draft.json
manifest sign draft.json --key keys/private.hex -o signed.json
manifest attest signed.json --provider auto --level 1 -o attested.json
manifest verify attested.json --public-key keys/public.hex
manifest revoke <manifest-id> --reason "key compromise" --revoked-by security@example.com

Without --public-key the verifier has no trusted issuer key, so a signed manifest fails closed as UNVERIFIABLE and the command exits 1.

Cryptography

  • Standard profile: Ed25519 (RFC 8032), SHA-256, RFC 8785 canonical JSON
  • Post-quantum profile: ML-DSA-65 (NIST FIPS 204), SHAKE-256 - pip install "agent-manifest[pq]"
  • Hybrid: Both signatures required, identical pre-image
  • Transparency: Rekor/Sigstore integration for non-repudiation

Specification

The full Agent Manifest Specification v0.2 is at spec/agent-manifest-spec-v0.2.md.

Proposed for contribution to CoSAI Working Stream 4, an OASIS Open Project.

License

Apache 2.0

Release files for agent-manifest 0.13.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agent-manifest 0.13.0
File Size Uploaded
agent_manifest-0.13.0.tar.gz 427.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agent-manifest 0.13.0
File Interpreter ABI Platform
agent_manifest-0.13.0-py3-none-any.whl Python 3 none any Details

Total release size: 617.1 kB

Release files / agent_manifest-0.13.0.tar.gz

Download URL agent_manifest-0.13.0.tar.gz
Size 427.2 kB
Tags Source
SHA-256 checksum
How to use checksums
fe01572b02839715ddde9edf06da9623132e58d1f843ea34542d3a1b2c749ce8
BLAKE2b-256 checksum
How to use checksums
a38264f39b00cdb9902c3f188ac786f933c78e4ff81663218f00a770bc06f535
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / agent_manifest-0.13.0-py3-none-any.whl

Download URL agent_manifest-0.13.0-py3-none-any.whl
Size 189.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
19238213724558e6d8c3d8b1181c8bf3ae8306dba6511344ef452aaaafae8455
BLAKE2b-256 checksum
How to use checksums
8c99e1e42a566aec889148faf0897b166f497db3504137fd91ba5e57cc168975
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.13.0 This release

2 release files

0.11.2

2 release files

0.11.1

2 release files

0.11.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page