agno-aer1
Every tool call your Agno agent makes, recorded as an AER-1 verifiable execution receipt. Four lines of code. No new infrastructure.
AER-1 is an open IETF Internet-Draft (draft-zambo-aer1) defining a small vocabulary for recording one AI agent tool call as a portable, independently checkable receipt. A receipt proves the recorded result was not changed. It does not prove the tool was correct.
Install
pip install agno-aer1
10-minute quickstart
from agno.agent import Agent
from agno.models.openai import OpenAIChat
from agno_aer1 import AER1Recorder
recorder = AER1Recorder()
agent = Agent(
model=OpenAIChat(id="gpt-4o-mini"),
tools=[...],
tool_hooks=[recorder],
)
agent.run("What is 17 * 24?")
print(f"{len(recorder.receipts)} receipts recorded")
recorder.save("receipts.jsonl")
That is the whole integration. tool_hooks is Agno's native middleware seam for tool execution (the same seam observability integrations use): each hook wraps a tool call, sees the function name and arguments, runs the tool, and observes the result. The recorder sits in that chain and emits one receipt per call, then returns the result untouched.
What a receipt looks like
{
"id": "3f9a2c1e-7b4d-4f8a-9c2e-1a5b6d7e8f90",
"receipt_schema_version": "0.3",
"created_at": "2026-10-05T22:30:00.123456Z",
"tool": {"name": "calculator", "version": "3.1.1", "scope": "public"},
"provenance_class": "EXECUTED BY AGNO",
"canonical_bytes": "eyJpbnB1dHMiOi...",
"output_hash": "sha256:9f2c...",
"verification_status": "verified"
}
The canonical bytes are a deterministic JSON payload (tool, inputs, output). Anyone can base64-decode them, recompute SHA-256, and compare with output_hash. That is the entire verification procedure.
Verify a receipt yourself
from agno_aer1 import verify_receipt
failures = verify_receipt(recorder.receipts[0])
assert failures == [], failures
print("receipt checks out")
Honest boundaries
- A receipt proves the recorded bytes were not changed. It does not prove the tool was correct, or that the model chose the right tool.
- Tool calls that raise produce no receipt; the error propagates exactly as Agno handles it without the recorder.
- If you enable Agno's tool-result cache, cache replays also pass through the middleware and emit receipts. Each receipt still commits to the exact bytes the agent observed.
- The recorder never changes a tool result. If receipt construction itself ever fails, the tool result is still returned untouched.
Links
- AER-1 spec (IETF Internet-Draft): https://datatracker.ietf.org/doc/draft-zambo-aer1/
- Conformance kit: https://gitlab.com/rambozambodotdev/zambo
- Zambo: https://zambo.dev
Metadata
Release files for agno-aer1 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agno_aer1-0.1.0.tar.gz | 5.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agno_aer1-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 11.9 kB
Release files / agno_aer1-0.1.0.tar.gz
| Download URL | agno_aer1-0.1.0.tar.gz |
|---|---|
| Size | 5.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5777b938c9ee8e8959c607174d64f9afddfd7677cd9b7c85141ee11af802f046
|
|
BLAKE2b-256 checksum How to use checksums |
11b9f302c5412dab88c0107aa2bbe35ae5a9e7b9ef72a72df0c0528a425255f2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|
Release files / agno_aer1-0.1.0-py3-none-any.whl
| Download URL | agno_aer1-0.1.0-py3-none-any.whl |
|---|---|
| Size | 6.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d6bd6febc98702409d9fe12f3cca5aa9c3b9da98d20cb15a6d972893dcd8df9d
|
|
BLAKE2b-256 checksum How to use checksums |
3badc419033d2965556fb7eb61f9626257d6fdd8b9fbfdb668d4bd62af193da3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|