Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

attested-relay

A Python client for an AWS Nitro-attested relay. It carries an inner TLS 1.3 connection in ordinary HTTPS GET messages. The outer HTTPS server transports ciphertext; the inner peer is authenticated by Nitro before an upstream URL is sent.

from attested_relay import Relay

relay = Relay("https://YOUR-RELAY", expected_pcr0="YOUR_INDEPENDENTLY_VERIFIED_96_HEX_PCR0")
relay.verify()
response = relay.get("https://example.com/")
print(response.status_code, response.text)

The client checks the bundled AWS Nitro root, certificate chain, COSE signature, fresh client nonce and timestamp, pinned image measurement, debug PCR rejection, the actual inner TLS peer key, measured protocol parameters, Graviton5 readiness and current epoch state. Do not obtain the PCR0 pin solely from an untrusted relay operator; independently reproduce or audit the measured image.

The relay encrypts audit records under daily keys recoverable through public seven-segment native RandomX v2.0.1 puzzles. The intended delay is approximate sequential work from epoch activation, not a guaranteed wall-clock deadline or proven VDF. A deployment requires actual calibration and reviewed measurements. AWS Nitro and its attestation PKI are trusted.

This is an early prerelease. It does not silently accept a development server, an arbitrary enclave measurement, or an expired/nonready live attestation. A literal URL-fetch-only agent cannot independently calculate TLS or validate cryptographic signatures without additional execution capability.

The separate attested-relay-timelock distribution bundles the native solver. Archive verification is intentionally separate from live verification so that old, correctly signed records remain verifiable after certificate expiration.

CLI:

attested-relay verify https://YOUR-RELAY --pcr0 YOUR_PIN
attested-relay get https://YOUR-RELAY https://example.com/ --pcr0 YOUR_PIN

Release files for attested-relay 0.2.0a1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distribution (wheel)

Table of built distributions (wheels) for attested-relay 0.2.0a1
File Interpreter ABI Platform
attested_relay-0.2.0a1-py3-none-any.whl Python 3 none any Details

Release files / attested_relay-0.2.0a1-py3-none-any.whl

Download URL attested_relay-0.2.0a1-py3-none-any.whl
Size 16.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dad10496b48ad82f6bad376fbd345098c1d3aa0d1be702a51810f1b0dcd2786d
BLAKE2b-256 checksum
How to use checksums
e74eb1a071e918cec62724460967f47999ceeb6fe7b48825085f64d076e660c2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page