Skip to main content

TRACE Tests

TRACE Conformance Test Suite

Community updates and contributor highlights: AgenTrust on LinkedIn.

Check a TRACE record and see which conformance level it reaches

Full Documentation

Quick Start  |  Test Modules  |  Conformance Levels  |  Changelog

License: Apache 2.0 TRACE Spec Tests CI Discord

Tracks TRACE Spec v0.2.

Check a TRACE record, inspect the findings, and produce a reproducible conformance report. The suite checks the record and supplied evidence; a passing report does not establish that an entire implementation meets every specification requirement.

Eight modules cover envelope, signature, runtime, policy, appraisal, transcript, transparency, and provenance checks. Read the limitations to interpret their results.

Quick start

pip install agentrust-trace-tests
trace-tests verify --record path/to/trust-record.jwt --level 1 \
  --expected-nonce "$VERIFIER_CHALLENGE"

A report you can hand to someone else

verify answers a question for the person running it. report produces an artifact for somebody who was not there: an auditor, a counterparty, an acquirer.

trace-tests report --record trust-record.json   --html report.html --json report.json --badge trace.svg

It runs every level up to --max-level rather than one, because the useful answer for a reader is the highest level the record reaches, not whether it cleared the level someone happened to pick. The HTML is self-contained: no scripts, no fonts, no external CSS, no badge service, nothing fetched at open time.

Use --fail-under 1 to gate CI on a level. Without it the command always exits 0, which is what you want when you are producing an artifact rather than enforcing a threshold.

The report is not evidence, and it says so on its face. It is unsigned HTML describing one run of one suite version, and anybody can edit it. So it carries the record's digest, the suite and library versions, and the exact command to reproduce the result. A reader who does not trust the sender is told, in the artifact, to go check the record instead. A conformance report that looks authoritative and cannot be checked is the same shape of thing as a control plane writing its own log.

report.json is stable under schema: agentrust-io/trace-tests/report/1 for dashboards and CI. Reports produced by the CLI include an additive, version-tagged obligation_accounting object for the bounded TR-APR-001, TR-POL-003, and TR-SCA-002 pilot. During supported report construction, its rows are reconciled against the executable registry identified by registry_id and registry_sha256. The operational TR-POL-003 rule is identified separately from schema fragments that support its field shape. Every source locator carries a digest of the exact resolved value so a reader holding the pinned trace-spec bytes can re-resolve and compare it. Accounted JSON, HTML, badge, and verdict projections consume one immutable execution-derived snapshot. A JSON-only request does not pre-render unrequested formats; when multiple formats are requested, they are emitted in the CLI's existing order. The existing contribution policy continues to determine the report verdict. The tag identifies this emitted object shape; the repository does not currently ship a separate formal JSON Schema for it.

This treats report/1 as additively extensible: existing members retain their meaning, and obligation_accounting is the sole new top-level member. Compatibility with consumers that require the exact historical key set is not established. The report remains an unsigned self-report; see Known Limitations.

Test modules

Module ID Tests
Envelope TR-ENV EAT structure, required fields, iat validity
Signature TR-SIG ES256/ES384/EdDSA, key binding, chain
Runtime TR-RTE TEE platform, measurement format, RIM URI
Policy TR-POL Bundle hash, enforcement mode, TEE binding
Transcript TR-TXN Tool-call transcript hash binding (Phase 2+)
Transparency TR-ANC SCITT receipt URI, inclusion proof
Provenance TR-SCA SLSA level, builder URI, digest format

Resources

📖 Full documentation trace.agentrust-io.com/conformance/
📄 TRACE Specification trace-spec
🗂 Test schemas schemas/
💬 Discussions GitHub Discussions
📋 Changelog CHANGELOG.md
⚠️ Known limitations LIMITATIONS.md

Contributing

See CONTRIBUTING.md. New test cases must include a normative spec reference, a positive case, and a negative case with a structured error code (TR-<MODULE>-<NNN>).

From a source checkout

git clone https://github.com/agentrust-io/trace-spec.git
cd trace-spec/conformance
pip install --require-hashes -r requirements/test.txt
pip install --no-deps -e .
python -m pytest

The package name and CLI remain unchanged. The original repository retains historical commits used by obligation-accounting source locators. See the migration record for publishing and documentation cutover work.

Metadata

Release files for agentrust-trace-tests 0.6.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentrust-trace-tests 0.6.2
File Size Uploaded
agentrust_trace_tests-0.6.2.tar.gz 277.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentrust-trace-tests 0.6.2
File Interpreter ABI Platform
agentrust_trace_tests-0.6.2-py3-none-any.whl Python 3 none any Details

Total release size: 334.0 kB

Release files / agentrust_trace_tests-0.6.2.tar.gz

Download URL agentrust_trace_tests-0.6.2.tar.gz
Size 277.6 kB
Tags Source
SHA-256 checksum
How to use checksums
6bb0a86f5514c266223818d0883ea9c7c1a449d87947a0b7bd57dcdf58dbfbea
BLAKE2b-256 checksum
How to use checksums
290348b3c313bc9797e6de0f9e9fc0eabc1f9941f8355ae40042ee2eb146afbd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release files / agentrust_trace_tests-0.6.2-py3-none-any.whl

Download URL agentrust_trace_tests-0.6.2-py3-none-any.whl
Size 56.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bb2021031b0705645a75780ee443e6be16e8758d83ad4486d1cbf0e2f5b59fad
BLAKE2b-256 checksum
How to use checksums
5819bad4dda4fec2e67aee6ba9c90781c21dda0442f374ed0ca4a03d3cf0557e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.6.2 This release

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page