Skip to main content

TRACE Tests

TRACE Conformance Test Suite

Verify your TRACE implementation before shipping

Full Documentation

Quick Start  |  Test Modules  |  Conformance Levels  |  Changelog

License: Apache 2.0 TRACE Spec Tests CI Discord

Test suite v0.2. Tracks TRACE Spec v0.2.

Conformance tests for TRACE (Trust Runtime Attestation and Compliance Evidence). Run this suite against your implementation to verify it meets the spec before claiming TRACE compliance.

Seven test modules covering the full specification: envelope structure, signature algorithms, TEE runtime claims, policy binding, tool-call transcripts, SCITT transparency anchoring, and supply chain provenance.

Quick start

pip install agentrust-trace-tests
trace-tests verify --record path/to/trust-record.jwt --level 1 \
  --expected-nonce "$VERIFIER_CHALLENGE"

A report you can hand to someone else

verify answers a question for the person running it. report produces an artifact for somebody who was not there: an auditor, a counterparty, an acquirer.

trace-tests report --record trust-record.json   --html report.html --json report.json --badge trace.svg

It runs every level up to --max-level rather than one, because the useful answer for a reader is the highest level the record reaches, not whether it cleared the level someone happened to pick. The HTML is self-contained: no scripts, no fonts, no external CSS, no badge service, nothing fetched at open time.

Use --fail-under 1 to gate CI on a level. Without it the command always exits 0, which is what you want when you are producing an artifact rather than enforcing a threshold.

The report is not evidence, and it says so on its face. It is unsigned HTML describing one run of one suite version, and anybody can edit it. So it carries the record's digest, the suite and library versions, and the exact command to reproduce the result. A reader who does not trust the sender is told, in the artifact, to go check the record instead. A conformance report that looks authoritative and cannot be checked is the same shape of thing as a control plane writing its own log.

report.json is stable under schema: agentrust-io/trace-tests/report/1 for dashboards and CI.

Test modules

Module ID Tests
Envelope TR-ENV EAT structure, required fields, iat validity
Signature TR-SIG ES256/ES384/EdDSA, key binding, chain
Runtime TR-RTE TEE platform, measurement format, RIM URI
Policy TR-POL Bundle hash, enforcement mode, TEE binding
Transcript TR-TXN Tool-call transcript hash binding (Phase 2+)
Transparency TR-ANC SCITT receipt URI, inclusion proof
Provenance TR-SCA SLSA level, builder URI, digest format

Resources

📖 Full documentation tests.agentrust-io.com
📄 TRACE Specification trace-spec
🗂 Test schemas schemas/
💬 Discussions GitHub Discussions
📋 Changelog CHANGELOG.md

Contributing

See CONTRIBUTING.md. New test cases must include a normative spec reference, a positive case, and a negative case with a structured error code (TR-<MODULE>-<NNN>).

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agentrust_trace_tests-0.5.1.tar.gz (132.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agentrust_trace_tests-0.5.1-py3-none-any.whl (28.5 kB view details)

Uploaded Python 3

File details

Details for the file agentrust_trace_tests-0.5.1.tar.gz.

File metadata

  • Download URL: agentrust_trace_tests-0.5.1.tar.gz
  • Upload date:
  • Size: 132.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for agentrust_trace_tests-0.5.1.tar.gz
Algorithm Hash digest
SHA256 79e9d98a7106ae1c47b8378c8808be26f1fa34a62779e9f7b0e954cf40a2a19c
MD5 0f79ea05536738ac8441456f63af0648
BLAKE2b-256 e8ea316b440c5b50b07e01cc5ed0257dbaefad5cb5f25a299a533d1228a1eaef

See more details on using hashes here.

Provenance

The following attestation bundles were made for agentrust_trace_tests-0.5.1.tar.gz:

Publisher: release.yml on agentrust-io/trace-tests

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agentrust_trace_tests-0.5.1-py3-none-any.whl.

File metadata

File hashes

Hashes for agentrust_trace_tests-0.5.1-py3-none-any.whl
Algorithm Hash digest
SHA256 5c13421d41357a5b2e096eced457f5dee65d4921b253b25dac53684b3d31eeeb
MD5 9ebed50b48798b7ea5472d8b1ab08578
BLAKE2b-256 4c54804f21e6dda302b5012e9391f677ce1f047f1cff76e03b0b6ce59fcd1a1e

See more details on using hashes here.

Provenance

The following attestation bundles were made for agentrust_trace_tests-0.5.1-py3-none-any.whl:

Publisher: release.yml on agentrust-io/trace-tests

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.5.1 This release

2 files

0.5.0

2 files

0.4.1

2 files

0.4.0

2 files

0.3.0

2 files

0.2.0

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page