Skip to main content

asqav

GitHub stars

Python SDK for asqav.com, the evidence layer for AI agents.

Every agent action gets a signed, hash-chained compliance receipt: ML-DSA-65 (FIPS 204, post-quantum), timestamped against independent witnesses, and verifiable by anyone — auditor, counterparty, regulator — without an Asqav account and without trusting us.

Zero native dependencies. Cryptography runs server-side.

Install

pip install asqav

Quick start

pip install "asqav[cli]"
asqav login        # validates your key, saves it to ~/.asqav/credentials
import asqav

# govern() = init() + Agent.create() in one call
agent = asqav.govern(api_key="sk_...", agent_name="my-agent")

sig = agent.sign("api:openai:chat", {"model": "gpt-4o"})

print(sig.action_ref)             # "sha256:..." over the JCS-canonical action
print(sig.previous_receipt_hash)  # 64 hex; "0"*64 on this agent's first receipt
print(sig.verification_url)       # anyone can open this

One install, one govern, one sign. asqav.init() + asqav.Agent.create() remain available when you want control over algorithm, capabilities and other agent options.

Verify it without an account

This is the point of the whole thing — the receipt stands on its own:

Run this right now, with no key and no signup:

import asqav

result = asqav.verify("sig_example_regulator_cold_verify_2026")
print(result["verified"])     # False -- and that is the point, see below
print(result["chain_hash"])   # recomputed on your machine from the canonical bytes

That id is a shape example: its signature bytes are placeholders and its kid resolves to no key, so the verifier returns verified: false instead of waving it through. Swap in a signature_id of your own for a receipt that passes. A verifier that says no when the evidence is absent is the only kind worth having.

From the shell (the cli extra provides the asqav command):

pip install "asqav[cli]"
asqav verify <your_signature_id>

Offline or air-gapped, snapshot the keys once and verify with no network at all. This re-derives the signature itself, so it needs the verify extra (dilithium-py for ML-DSA-65, cryptography for the Ed25519 and ES256 axes — without it those signatures report INCOMPLETE rather than verifying):

pip install "asqav[verify]"
import asqav, json

jwks = asqav.fetch_jwks()                     # online, once
json.dump(jwks, open("jwks.json", "w"))

receipt = json.load(open("receipt.json"))     # offline from here
result  = asqav.verify_receipt_offline(receipt, json.load(open("jwks.json")))
assert result["verdict"] == "PASS", result["axes"]

Pass predecessor=prev_receipt to check the hash-chain link too. Guide: offline and air-gapped verification.

No account? Queue locally

from asqav.local import local_sign, LocalQueue

local_sign("my-agent", "api:openai:chat", {"model": "gpt-4o"})  # -> ~/.asqav/queue/

import asqav
asqav.init(api_key="sk_...")
LocalQueue().sync()            # {"synced": N, "failed": M}

Data handling modes

The SDK picks the safer default for where you point it:

  • Cloud (*.asqav.com) — hash-only. A SHA-256 fingerprint is computed locally and only the hash plus action_type, agent_id, session_id, model_name, tool_name is sent. Prompts and tool arguments never leave your side.
  • Self-hosted — full payload, so the server can run policy checks and richer audit.
asqav.init(api_key="...", base_url="https://api.asqav.com", mode="hash-only")

High-value actions

For regulated or high-risk actions, pass envelope fields that an auditor will look for:

sig = agent.sign(
    "payment.wire_transfer",
    {"amount_eur": 850000, "beneficiary_iban": "DE89370400440532013000"},
    receipt_type="protectmcp:decision",
    risk_class="high",                 # low | medium | high | unknown
    issuer_id="legal:Acme GmbH",       # LEI, EIN, CIK or W3C DID
    iteration_id="task-2026-Q2-4821",  # logical task, distinct from session
)

CLI

asqav whoami                       # active key source, validated
asqav init                         # print a ready-to-paste snippet
asqav verify <signature_id>        # verify a receipt (no key needed)
asqav sign --agent-id ID --action-type T --action-json action.json
asqav agents list | create | revoke
asqav replay-verify <agent_id> <session_id> [--strict]
asqav audit-pack export --start ISO --end ISO --output-file bundle.json
asqav payloads erase <signature_id>          # right-to-erasure

Full command reference: asqav.com/docs/cli.

Framework integrations

Native callbacks under asqav.extras.* for LangChain, CrewAI, LiteLLM, OpenAI Agents and others, plus a pytest plugin. Adapters install behind documented extras (asqav[langchain], asqav[litellm], asqav[openai-agents]). See integrations and pytest plugin.

What a receipt does not prove

Stated plainly, because an auditor will ask:

  • Not that the action ran, or ran once. A receipt records a decision and the bytes that passed through, never the effect. A retry produces a second receipt.
  • Not that the policy was correct. policy_digest proves which policy artefact existed, not that it was the right one.
  • Not that the environment was intact. No field here carries a remote attestation result.
  • Tamper-evident, not tamper-proof. Modification is detectable, not prevented.

The full list is in the IETF profile under "What a Compliance Receipt Does Not Prove".

Reference

Topic Docs
Threat-framework mappings (MITRE, OWASP, NIST AI RMF, ISO 42001, EU AI Act) threat-framework-mapping
NSA CSI U/OO/6030316-26 receipt fields nsa-mcp-csi-alignment
Build provenance (executable_hash, sbom_digest, SLSA) executable-hash-and-sbom-provenance
Witness policy and multi-witness anchoring multi-witness-anchoring
Binding tool output (result_digest) result-digest
Configuration-change receipts configuration-change-receipts
Code-authorship receipts code-authorship-receipts
Structured receipts (optional schema) structured-receipts
Bring-your-own DLP / policy detectors scanning
Audit Pack export compliance
Independent verification protocol independent-verification

Requirements

Python 3.10+. Uses httpx. Zero native dependencies.

Standards

Profiled in the IETF Internet-Draft draft-marques-asqav-compliance-receipts, an Independent Submission profiling draft-farley-acta-signed-receipts. Aligns with NIST FIPS 204 (ML-DSA), RFC 8785 (JCS) and NSA CSI U/OO/6030316-26.

Links

Docs · SDK guide · Repository · Discovery descriptor

License

Elastic License 2.0. Get an API key at asqav.com.

Metadata

Release files for asqav 0.10.10

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for asqav 0.10.10
File Size Uploaded
asqav-0.10.10.tar.gz 226.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for asqav 0.10.10
File Interpreter ABI Platform
asqav-0.10.10-py3-none-any.whl Python 3 none any Details

Total release size: 491.2 kB

Release files / asqav-0.10.10.tar.gz

Download URL asqav-0.10.10.tar.gz
Size 226.4 kB
Tags Source
SHA-256 checksum
How to use checksums
21d730969cc056b8b5af0faf1b89342d047c88ea8adf9d161dd315a7e3ca68f8
BLAKE2b-256 checksum
How to use checksums
bbd19a8cf170000c945cf820c9ae5a8b34cbeed92e5a8d1f98aabddd8467f052
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.

Transparency log

Release files / asqav-0.10.10-py3-none-any.whl

Download URL asqav-0.10.10-py3-none-any.whl
Size 264.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8acbbdb884659ee26e4029e9155edf7fd0fc59672c78fdfab2bf50636dbf4693
BLAKE2b-256 checksum
How to use checksums
1f07d8ebd8961574242e57a439d7232ac0964993057aae72f64ebc508611d500
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.10.10 This release

2 release files

0.10.2

2 release files

0.10.1

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.3

2 release files

0.8.2

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.5

2 release files

0.6.4

2 release files

0.6.3

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.16

2 release files

0.5.15

2 release files

0.5.14

2 release files

0.5.9

1 release file

0.5.8

1 release file

0.5.7

2 release files

0.5.6

2 release files

0.5.5

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.11

2 release files

0.4.10

2 release files

0.4.9

2 release files

0.4.8

2 release files

0.4.7

2 release files

0.4.6

2 release files

0.4.5

2 release files

0.4.4

2 release files

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.9

2 release files

0.3.8

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.22

2 release files

0.2.21

2 release files

0.2.20

2 release files

0.2.18

2 release files

0.2.17

2 release files

0.2.16

2 release files

0.2.15

2 release files

0.2.14

2 release files

0.2.13

2 release files

0.2.12

2 release files

0.2.11

2 release files

0.2.10

2 release files

0.2.9

2 release files

0.2.8

2 release files

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page