aqta-verify-receipt
Offline verifier for Seal receipts (ATTESTATION-v1).
Seal signs the model call at runtime. This package checks that signature without contacting Aqta. No account. Same algorithm as the npm package.
30-second check
pip install aqta-verify-receipt
aqta-verify-receipt receipt.json \
--key 9Y3Eiq6V8QjRDUM5nPqSwKIOPQaoEU4SbagfYFdvWa4
Default output is one compact line (words carry meaning; colour is optional):
✓ valid ALLOWED 2d41…871e94c pinned issuer key
Invalid:
✕ invalid signature mismatch 2d41…871e94c
Optional flourish (never the proof):
aqta-verify-receipt receipt.json --key <pinned> --pretty
# …
◈ seal intact · verified offline
Or pipe:
curl -sS https://api.aqta.ai/r/YOUR_RECEIPT_ID | aqta-verify-receipt - \
--key 9Y3Eiq6V8QjRDUM5nPqSwKIOPQaoEU4SbagfYFdvWa4
| Exit | Meaning |
|---|---|
0 |
valid |
1 |
invalid |
2 |
usage / IO |
Current production key id: aqta-att-01269bb4b6a7d950
(/v1/attestation/public-key).
Pin that string; do not re-fetch it inside a verify loop. Keys rotate and
receipts do not: a receipt verifies against the key current when it was
signed, and the permanent key record (with retired keys and their validity
windows) is at
app.aqta.ai/security/issuer-keys.txt.
Library
from aqta_verify_receipt import verify_receipt, fetch_published_public_key
# Once per environment: fetch, then pin somewhere you control.
trusted = fetch_published_public_key()
result = verify_receipt(receipt, trusted_public_key=trusted)
if not result.valid:
raise ValueError(result.reason)
CLI
aqta-verify-receipt <file|-> --key <base64url> [--no-strict] [--json] [--pretty] [-q]
aqta-verify-receipt <file|-> --integrity-only [--no-strict] [--json] [--pretty] [-q]
| Flag | Meaning |
|---|---|
--key |
Pin issuer identity (required for counsel-grade). |
--integrity-only |
Signature vs embedded key only; returns untrusted. Anyone can self-sign. |
--no-strict |
Allow unknown top-level fields |
--json |
One JSON object on stdout |
--pretty |
Optional human flourish after the compact line (not the proof) |
-q |
Silent; exit code only |
NO_COLOR=1 disables colour. Meaning never depends on colour alone.
Pinning is required by default. Without --key, pass --integrity-only
(embedded key only; anyone can self-sign; result is marked untrusted).
Dependencies
cryptography (>= 42) for constant-time Ed25519. Nothing else.
What this is not
Not a governance dashboard. Not a cost router. A small verifier for one signed model-call receipt. The novel part is the receipt format and offline verification model, not ASCII theatre.
Licence
Apache-2.0. Aqta Technologies Limited.
If you implement or cite the ATTESTATION-v1 format itself, credit under CC-BY-4.0: see the repo CITATION.cff.
Release files for aqta-verify-receipt 1.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aqta_verify_receipt-1.2.1.tar.gz | 24.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aqta_verify_receipt-1.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 45.1 kB
Release files / aqta_verify_receipt-1.2.1.tar.gz
| Download URL | aqta_verify_receipt-1.2.1.tar.gz |
|---|---|
| Size | 24.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e4f96d8996b8e65eb0215feaaad0eec4dd9da319ab0bf360d589eb970031fd84
|
|
BLAKE2b-256 checksum How to use checksums |
f17595794840a091b4c64cb639b0a161cec225413358dc5da7cf03e1d0c7807e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.8
|
Release files / aqta_verify_receipt-1.2.1-py3-none-any.whl
| Download URL | aqta_verify_receipt-1.2.1-py3-none-any.whl |
|---|---|
| Size | 20.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b2d13852dfd90b759d937751063270cdc0b8c0648c7eaeb8d63bcf99094addf3
|
|
BLAKE2b-256 checksum How to use checksums |
bd8162616b481c963522566172882942aacccd4c2faf10bd3bd2e24c8c670fab
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.8
|