Skip to main content

AgentOath ShadowOS Adapter

Trust receipts for an AI agent backend, wired in at the pipeline boundary.

This is a standalone adapter for the AgentOath trust protocol. It depends on agentoath and on nothing else -- it contains no ShadowOS code and does not import ShadowOS. It was written against a FastAPI agent backend, and the shape it assumes is a common one: an agent that calls tools, reads and writes memory, and answers over HTTP.

Quick Start

pip install agentoath-shadowos
from agentoath_shadowos import ShadowOSTrustAdapter

adapter = ShadowOSTrustAdapter.create(agent_name="MyAI Secretary")
adapter.save("agent_identity.json", password="...")

receipt = adapter.record_tool_call(
    tool="send_email",
    outcome="delivered",
    rating=9,
)

Reload a persisted identity rather than minting a new one -- a DID is derived from its key, so creating a second identity means a second agent as far as the protocol is concerned:

adapter = ShadowOSTrustAdapter.load("agent_identity.json", password="...")

The three pieces

ShadowOSTrustAdapter Owns the identity and turns operations into signed receipts
TrustHooks pre_* / post_* pairs to bracket each stage of an agent pipeline
AgentOathMiddleware ASGI middleware that adds trust headers to API responses

What to record, and what not to

Receipts are public and cannot be deleted. Record the operations somebody may later need you to prove happened -- an approval, a decision, a promise made to a customer. Do not record polling, cache hits, or debug traces: it turns the Registry into a log system, which is not what it is for, and the noise is permanent.

Recording must never break the operation it describes. Do the work first, then record, and let recording fail silently:

result = do_the_actual_work()
try:
    adapter.record_tool_call(tool="send_email", outcome="delivered", rating=9)
except Exception:
    pass          # a receipt that fails is not a request that failed
return result

Privacy

The Registry rejects receipts whose metadata contains any of 28 blocked keys -- prompt, email, raw, transcript, token and similar -- and the match is on underscore-separated words, so prompt_hash and user_email are rejected too. Send a digest, or rename the field to something that is not about the content. The full list and the reasoning are in the integration guide.

License

Apache-2.0. See LICENSE and NOTICE.

Metadata

Release files for agentoath-shadowos 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentoath-shadowos 0.2.0
File Size Uploaded
agentoath_shadowos-0.2.0.tar.gz 18.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentoath-shadowos 0.2.0
File Interpreter ABI Platform
agentoath_shadowos-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 34.6 kB

Release files / agentoath_shadowos-0.2.0.tar.gz

Download URL agentoath_shadowos-0.2.0.tar.gz
Size 18.9 kB
Tags Source
SHA-256 checksum
How to use checksums
6887e1e0c38b8f342c3f3b9f61f51b5b276c872aedcb7b316ccd6d526d10db8f
BLAKE2b-256 checksum
How to use checksums
657470355453a199919ed1b8e61902eff2db03819d15d82a95c941204f17a24e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.12

Release files / agentoath_shadowos-0.2.0-py3-none-any.whl

Download URL agentoath_shadowos-0.2.0-py3-none-any.whl
Size 15.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7cb715483250395e7bca4159275c52ec60585f3bc1d4e007e574d63a09137439
BLAKE2b-256 checksum
How to use checksums
2d1ec457b39b6a350d5462b9a9f1ee08990bd04996accdc51415356a7d3890bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.12

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page