Skip to main content

aqta-verify-receipt

PyPI npm Licence

Offline verifier for Seal receipts (ATTESTATION-v1).

Seal signs the model call at runtime. This package checks that signature without contacting Aqta. No account. Same algorithm as the npm package.

30-second check

pip install aqta-verify-receipt
aqta-verify-receipt receipt.json \
  --key gUoUhIvptKAoLTnry3VrDtOQEWggGQveLrHFVrfNqmE

Or pipe:

curl -sS https://api.aqta.ai/r/YOUR_RECEIPT_ID | aqta-verify-receipt - \
  --key gUoUhIvptKAoLTnry3VrDtOQEWggGQveLrHFVrfNqmE

ok + exit 0 means the Ed25519 signature verifies against the pinned key. Production key id: aqta-att-0a18c7c16bc18a12 (/v1/attestation/public-key).

Pin that string. Do not re-fetch it inside a verify loop.

Library

from aqta_verify_receipt import verify_receipt, fetch_published_public_key

# Once per environment: fetch, then pin somewhere you control.
trusted = fetch_published_public_key()

result = verify_receipt(receipt, trusted_public_key=trusted)
if not result.valid:
    raise ValueError(result.reason)

CLI

aqta-verify-receipt <file|-> --key <base64url> [--no-strict] [-q]
aqta-verify-receipt <file|-> --integrity-only [--no-strict] [-q]

Pinning is required by default. Without --key, pass --integrity-only (embedded key only; anyone can self-sign; result is marked untrusted).

Dependencies

cryptography (>= 42) for constant-time Ed25519. Nothing else.

What this is not

Not a governance dashboard. Not a cost router. A small verifier for one signed model-call receipt.

Licence

Apache-2.0. Aqta Technologies Limited.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aqta_verify_receipt-1.0.4.tar.gz (8.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aqta_verify_receipt-1.0.4-py3-none-any.whl (8.3 kB view details)

Uploaded Python 3

File details

Details for the file aqta_verify_receipt-1.0.4.tar.gz.

File metadata

  • Download URL: aqta_verify_receipt-1.0.4.tar.gz
  • Upload date:
  • Size: 8.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.8

File hashes

Hashes for aqta_verify_receipt-1.0.4.tar.gz
Algorithm Hash digest
SHA256 f1fa91b168b118bd1aa7d9fe7c34c0ac91d937df1c3e41760f0b8822985c4feb
MD5 052421329ad5d0fc6a68cef14f8a9c57
BLAKE2b-256 7c49071c5df103b959a15abd85936047aecafa8aaf6d0ecd15b15de71c173e6b

See more details on using hashes here.

File details

Details for the file aqta_verify_receipt-1.0.4-py3-none-any.whl.

File metadata

File hashes

Hashes for aqta_verify_receipt-1.0.4-py3-none-any.whl
Algorithm Hash digest
SHA256 0ef5f4226ea6b704153340b71cd30cb6b0c51f582f1e2c9eadc115646f96a5ef
MD5 fc0991436f5e717deb3bbaddb2404eb4
BLAKE2b-256 327c3e3725206d8c30d9cc51503f14ad183c120916816afcbdaf7e6e74346f75

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page