Skip to main content

Independent, permanently Apache-2.0 receipt verifier for APL Sidecar

Project description

apl-verifier

The independent verification layer for APL Sidecar.

apl-verifier verifies APL receipts offline: schema shape, canonical hash, Ed25519 signature, and chain continuity. It is fail-close — anything unexpected is a verification failure. It contains the single trust-domain normalization rule and interface-only plugin Protocols, and nothing else: no planning, no automatic decomposition, no provider transport.

Licensing

This package is, and will remain, Apache-2.0. It is distributed independently of the APL runtime. Verification must stay permanently open so anyone can check an APL receipt without depending on the runtime's licensing. The dependency direction is one-way: the runtime depends on apl-verifier; apl-verifier never imports the runtime.

Install

pip install apl-verifier

Only dependency: cryptography (Ed25519).

Use

apl-verify <receipt.json> [more_receipts_in_chain_order...] --pubkey key.pem

--pubkey is required: the caller decides which public key to trust. The tool never searches repo-relative key directories, so a receipt can never steer it to an attacker-chosen filesystem path.

Exit codes: 0 verified, 1 failed, 2 usage.

Library:

from apl_verifier import verify_receipt, verify_chain, VerifyError

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

apl_verifier-0.2.0.tar.gz (15.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

apl_verifier-0.2.0-py3-none-any.whl (15.1 kB view details)

Uploaded Python 3

File details

Details for the file apl_verifier-0.2.0.tar.gz.

File metadata

  • Download URL: apl_verifier-0.2.0.tar.gz
  • Upload date:
  • Size: 15.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for apl_verifier-0.2.0.tar.gz
Algorithm Hash digest
SHA256 e0eee94594c47b4935940162051d56197b82694fe02b50e9d162e58b01a11fa8
MD5 e94dcca4b17b4813e8adecdc5bc05951
BLAKE2b-256 17c6df2302633b7f0e3076637b71587cd0baa953c32af224216ff133c0ee9d81

See more details on using hashes here.

Provenance

The following attestation bundles were made for apl_verifier-0.2.0.tar.gz:

Publisher: release.yml on OIA-LAB/apl-sidecar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file apl_verifier-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: apl_verifier-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 15.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for apl_verifier-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a26869400367d2551d60bf157bb29c3f46a8b07dcf776ab5081b1b8388129105
MD5 3218c0218798d7e87c53a57ea6798cc0
BLAKE2b-256 ced523aaf8e10b802afbfad0d8d21ffb4e358a32b4a83fa630e44717f21cdf6e

See more details on using hashes here.

Provenance

The following attestation bundles were made for apl_verifier-0.2.0-py3-none-any.whl:

Publisher: release.yml on OIA-LAB/apl-sidecar

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page