Python Reference Verifier
Packaged Python verifier for Allowly Receipt Format wire version 4.
Install
pip install allowly-receipt-format
Only dependency: cryptography for Ed25519 signature verification.
CLI
Verify a single receipt:
allowly-receipt-verify \
--workspace-id "$ALLOWLY_WORKSPACE_ID" \
--trusted-key-fingerprint "$ALLOWLY_TRUSTED_KEY_FINGERPRINT" \
path/to/receipt.json path/to/keys.json
Verify a whole export or audit-package chain in one go (.jsonl or .jsonl.gz):
# Each line is either a bare receipt (audit-package chain.jsonl) or a
# {"receipt_id", ..., "receipt": {...}} export wrapper — both are handled.
allowly-receipt-verify \
--export chain.jsonl \
--workspace-id "$ALLOWLY_WORKSPACE_ID" \
--trusted-key-fingerprint "$ALLOWLY_TRUSTED_KEY_FINGERPRINT" \
keys.json
If the export includes checkpoint evidence, recompute every listed checkpoint from the already verified receipt lines:
allowly-receipt-verify \
--export chain.jsonl \
--checkpoint-evidence checkpoint_evidence.json \
--workspace-id "$ALLOWLY_WORKSPACE_ID" \
--trusted-key-fingerprint "$ALLOWLY_TRUSTED_KEY_FINGERPRINT" \
keys.json
Verify only one authorization's chain and check its structure (exactly one
authorization.create, at most one authorization.revoke, well-formed
timestamps), printing the timeline:
allowly-receipt-verify \
--export export.jsonl.gz \
--authorization-id auth_01HXZ2... \
--workspace-id "$ALLOWLY_WORKSPACE_ID" \
--trusted-key-fingerprint "$ALLOWLY_TRUSTED_KEY_FINGERPRINT" \
keys.json
--workspace-id and at least one --trusted-key-fingerprint are required.
Fingerprints use sha256:<64 lowercase hex> over the decoded raw 32-byte
Ed25519 public key. Repeat the fingerprint flag for every trusted rotation key
that may have signed the selected receipts.
For local development without installing from PyPI:
pip install -e .
python verifier.py \
--workspace-id "$ALLOWLY_WORKSPACE_ID" \
--trusted-key-fingerprint "$ALLOWLY_TRUSTED_KEY_FINGERPRINT" \
path/to/receipt.json path/to/keys.json
Exit codes:
0— all presented receipts valid (and, with--authorization-id, the presented chain is structurally well-formed)1— any receipt invalid, no receipts matched, or a chain anomaly (reason on stderr)
Library
from allowly_receipt_format import verify_receipt, VerificationError, load_keys_from_json
import json
import os
with open("receipt.json") as f:
receipt = json.load(f)
with open("keys.json") as f:
keys_doc = json.load(f)
configured_workspace_id = os.environ["ALLOWLY_WORKSPACE_ID"]
trusted_fingerprints = {os.environ["ALLOWLY_TRUSTED_KEY_FINGERPRINT"]}
if keys_doc.get("workspace_id") != configured_workspace_id:
raise ValueError("key document workspace does not match configuration")
keys = load_keys_from_json(keys_doc)
try:
verify_receipt(
receipt,
keys,
expected_workspace_id=configured_workspace_id,
trusted_key_fingerprints=trusted_fingerprints,
)
print("valid")
except VerificationError as e:
print(f"invalid: {e}")
Always pass expected_workspace_id to bind the receipt to a workspace — a
key_id alone does not (spec §7, "Workspace binding"). Take that ID from
caller-trusted configuration, never from the receipt or key document, and
reject a key document that declares a different workspace. The CLI requires
that caller-trusted workspace ID plus one or more caller-trusted key
fingerprints. It checks the workspace against the key document and receipts,
and requires every selected receipt key to be pinned. A workspace ID or
fingerprint copied from the same untrusted bundle as the receipts is not an
independent trust anchor:
verify_receipt(
receipt,
keys,
expected_workspace_id="ws_01HXA1B2C3D4E5F6G7H8J9K0L1",
trusted_key_fingerprints={"sha256:<64 lowercase hex>"},
)
public_key_fingerprint(key) returns that canonical fingerprint over the
decoded raw 32-byte Ed25519 public key. load_keys_from_json validates an
advertised public_key_fingerprint, but the advertised value is not itself a
trust anchor.
The package exposes typed verifier exceptions:
SchemaErrorUnknownKeyErrorKeyOutsideActiveWindowErrorSignatureMismatchError
All inherit from VerificationError.
Verify a daily checkpoint
verify_checkpoint verifies the checkpoint and member signatures, period,
count, Merkle root, and optional prior linkage. The workspace id must come from
caller-trusted configuration, and key fingerprints should come from an
authenticated channel:
from allowly_receipt_format import verify_checkpoint
verify_checkpoint(
checkpoint,
member_receipts,
keys,
expected_workspace_id=configured_workspace_id,
trusted_key_fingerprints=trusted_fingerprints,
previous_checkpoint=previous_checkpoint,
)
Success proves the supplied set matches the signed commitment. Without an external anchor it does not prove the issuer registered or retained every receipt before constructing the checkpoint.
Match a keyed pseudonym reference
matches_ref implements the optional hmac-v1 convention in specification
Appendix A. Decode the show-once integration key, then match locally:
import base64
from allowly_receipt_format import matches_ref
encoded_key = "<pseudonym_key_b64url>"
key = base64.urlsafe_b64decode(encoded_key + "=" * (-len(encoded_key) % 4))
assert matches_ref(
key,
"record",
"MRN-48291",
receipt["context"]["record_ref"],
)
Use the context.ref_key_version recorded in the receipt to select the retained
key version. Matching occurs entirely offline; it does not ask Allowly to
resolve an identifier.
verify_receipt accepts an already-parsed object, so it cannot detect duplicate
raw JSON names that a normal parser has already overwritten. The CLI uses a
duplicate-aware parser and rejects them. The verifier also rejects parsed
floating-point values, including the results of 1.0 and 1e0; callers using
a different parser must preserve that distinction (spec §4.2).
Test vectors
Run against the shared test vectors:
pip install -e .
python test_vectors.py ../../test-vectors.json
python test_exception_types.py ../../test-vectors.json
All should_verify vectors must pass; all should_reject vectors must be rejected with the expected reason.
License
Apache 2.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file allowly_receipt_format-4.0.1.tar.gz.
File metadata
- Download URL: allowly_receipt_format-4.0.1.tar.gz
- Upload date:
- Size: 18.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
952d6570bfc4b9d367157f72db4653add3284930a76fac322c0adbac46dc46ff
|
|
| MD5 |
c9cbeb7ef8fc3c8ce657885c0dd1d288
|
|
| BLAKE2b-256 |
fcf8e3e98e0aeaa288b730047219ec3a92b60b725e1972ecdfe0ed7eac216d1f
|
Provenance
The following attestation bundles were made for allowly_receipt_format-4.0.1.tar.gz:
Publisher:
publish-python.yml on Allowly-AI/allowly-receipt-format
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
allowly_receipt_format-4.0.1.tar.gz -
Subject digest:
952d6570bfc4b9d367157f72db4653add3284930a76fac322c0adbac46dc46ff - Sigstore transparency entry: 2341493206
- Sigstore integration time:
-
Permalink:
Allowly-AI/allowly-receipt-format@731c9003bf130e94a30d757a9565dfd2b7568a4f -
Branch / Tag:
refs/tags/v4.0.1 - Owner: https://github.com/Allowly-AI
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-python.yml@731c9003bf130e94a30d757a9565dfd2b7568a4f -
Trigger Event:
push
-
Statement type:
File details
Details for the file allowly_receipt_format-4.0.1-py3-none-any.whl.
File metadata
- Download URL: allowly_receipt_format-4.0.1-py3-none-any.whl
- Upload date:
- Size: 16.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
557cb4c9e2ceffb705626815716227fa66cc792aa33b9a289c4e9a73e53469c5
|
|
| MD5 |
11677d8b727a615d5834f4358a361c19
|
|
| BLAKE2b-256 |
6c41fc6bcf26f3735dc1e985abed0ffdf42d5a8bd7cec87565c026ac03364d38
|
Provenance
The following attestation bundles were made for allowly_receipt_format-4.0.1-py3-none-any.whl:
Publisher:
publish-python.yml on Allowly-AI/allowly-receipt-format
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
allowly_receipt_format-4.0.1-py3-none-any.whl -
Subject digest:
557cb4c9e2ceffb705626815716227fa66cc792aa33b9a289c4e9a73e53469c5 - Sigstore transparency entry: 2341493212
- Sigstore integration time:
-
Permalink:
Allowly-AI/allowly-receipt-format@731c9003bf130e94a30d757a9565dfd2b7568a4f -
Branch / Tag:
refs/tags/v4.0.1 - Owner: https://github.com/Allowly-AI
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-python.yml@731c9003bf130e94a30d757a9565dfd2b7568a4f -
Trigger Event:
push
-
Statement type: