Skip to main content

Reference Python verifier for the Allowly Receipt Format

Project description

Python Reference Verifier

Packaged Python verifier for Allowly Receipt Format 2.0.0.

Install

pip install allowly-receipt-format

Only dependency: cryptography for Ed25519 signature verification.

CLI

Verify a single receipt:

allowly-receipt-verify path/to/receipt.json path/to/keys.json

Verify a whole export or audit-package chain in one go (.jsonl or .jsonl.gz):

# Each line is either a bare receipt (audit-package chain.jsonl) or a
# {"receipt_id", ..., "receipt": {...}} export wrapper — both are handled.
allowly-receipt-verify --export chain.jsonl keys.json

Verify only one authorization's chain and check its structure (exactly one authorization.create, at most one authorization.revoke, well-formed timestamps), printing the timeline:

allowly-receipt-verify --export export.jsonl.gz keys.json --authorization-id auth_01HXZ2...

For local development without installing from PyPI:

pip install -e .
python verifier.py path/to/receipt.json path/to/keys.json

Exit codes:

  • 0 — all receipts valid (and, with --authorization-id, the chain is well-formed)
  • 1 — any receipt invalid, no receipts matched, or a chain anomaly (reason on stderr)

Library

from allowly_receipt_format import verify_receipt, VerificationError, load_keys_from_json
import json

with open("receipt.json") as f:
    receipt = json.load(f)
with open("keys.json") as f:
    keys_doc = json.load(f)
keys = load_keys_from_json(keys_doc)

try:
    verify_receipt(receipt, keys, expected_workspace_id=keys_doc["workspace_id"])
    print("valid")
except VerificationError as e:
    print(f"invalid: {e}")

Always pass expected_workspace_id to bind the receipt to a workspace — a key_id alone does not (spec §7, "Workspace binding"). The allowly-receipt-verify CLI enforces this automatically using the key document's workspace_id:

verify_receipt(receipt, keys, expected_workspace_id="ws_01HXA1B2C3D4E5F6G7H8J9K0L1")

The package exposes typed verifier exceptions:

  • SchemaError
  • UnknownKeyError
  • KeyOutsideActiveWindowError
  • SignatureMismatchError

All inherit from VerificationError.

verify_receipt accepts an already-parsed object. Python's normal JSON parser cannot report duplicate member names or preserve whether an integer was written as 1, 1.0, or 1e0; reject those forms at the raw-JSON boundary when the original receipt text is untrusted (spec §4.2).

Test vectors

Run against the shared test vectors:

pip install -e .
python test_vectors.py ../../test-vectors.json
python test_exception_types.py ../../test-vectors.json

All should_verify vectors must pass; all should_reject vectors must be rejected with the expected reason.

License

Apache 2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

allowly_receipt_format-2.0.0.tar.gz (12.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

allowly_receipt_format-2.0.0-py3-none-any.whl (12.1 kB view details)

Uploaded Python 3

File details

Details for the file allowly_receipt_format-2.0.0.tar.gz.

File metadata

  • Download URL: allowly_receipt_format-2.0.0.tar.gz
  • Upload date:
  • Size: 12.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for allowly_receipt_format-2.0.0.tar.gz
Algorithm Hash digest
SHA256 06bce39ad9c207fb3c4e4db1e1ead9cf0232ff0fa23e129a3baa6bb1d6d45321
MD5 c9902aa1f3993c48dbc5f0180c849eb5
BLAKE2b-256 6f73c7cf5f18e32db273fdd3d7f0293960c4db03612df9693aa8267ed29ed498

See more details on using hashes here.

Provenance

The following attestation bundles were made for allowly_receipt_format-2.0.0.tar.gz:

Publisher: publish-python.yml on Allowly-AI/allowly-receipt-format

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file allowly_receipt_format-2.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for allowly_receipt_format-2.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f238697d353aadb3de73812c24699fdd7e5efb7aeb304b5fdc844416f9abe92c
MD5 5a6d34b7b08546e5ffd91b697bbad119
BLAKE2b-256 7600020664ea46655e665a44e5eef217eecca9cca3f8e26cc9c0cc3e026d7c04

See more details on using hashes here.

Provenance

The following attestation bundles were made for allowly_receipt_format-2.0.0-py3-none-any.whl:

Publisher: publish-python.yml on Allowly-AI/allowly-receipt-format

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page