Skip to main content

Auths Python SDK

Decentralized identity for developers and AI agents. Sign, verify, and manage cryptographic identities with Git-native storage.

Install

pip install auths

Quick start

from auths import Auths

auths = Auths()

# Verify an attestation
result = auths.verify(attestation_json=data, issuer_key=public_key_hex)
print(result.valid)  # True

# Sign bytes
signature = auths.sign(b"hello world", private_key=secret_key_hex)

Identity management

from auths import Auths

auths = Auths(repo_path="~/.auths")

# Create a cryptographic identity
identity = auths.identities.create(label="laptop")
print(identity.did)  # did:keri:EBfd...

# Provision an agent (for CI, MCP servers, etc.)
agent = auths.identities.provision_agent(
    identity.did,
    name="deploy-bot",
    capabilities=["sign"],
)

# Sign using the keychain-stored identity key
sig = auths.sign_as(b"hello world", identity=identity.did)

# Link and manage devices
device = auths.devices.link(identity_did=identity.did, capabilities=["sign"])
auths.devices.revoke(device.did, identity_did=identity.did, note="replaced")

Keyless service-to-service verify

Verify an agent's credential presentation offline against a pinned root — one call, a typed Status enum, no exception for a denial:

from auths import verify_presentation, PresentationStatus

report = verify_presentation(bundle_json)  # the Auths-Presentation request bundle
if report.status is not PresentationStatus.VALID:
    raise PermissionError(f"denied: {report.status}")  # WRONG_AUDIENCE, EXPIRED, …

print(report.subject, report.caps)  # granted holder + capabilities

verify_credential(bundle_json) returns a CredentialReport the same way — e.g. report.status is CredentialStatus.CREDENTIAL_REVOKED carries report.revoked_at. Malformed input returns a typed MALFORMED_REQUEST status; it never raises.

Git commit verification

from auths.git import verify_commit_range

result = verify_commit_range("HEAD~5..HEAD")
for commit in result.commits:
    print(f"{commit.commit_sha}: {'valid' if commit.is_valid else commit.error}")

Time-pinned verification

# Verify an attestation's authenticity at a historical point in time
result = auths.verify(attestation_json=data, issuer_key=key, at="2024-06-15T00:00:00Z")

Capability/role authority is no longer checked at verification time. A capability grant comes from a holder-verified ACDC credential, not the attestation.

Agent auth for MCP / AI frameworks

from auths.agent import AgentAuth

auth = AgentAuth(
    bridge_url="https://bridge.example.com",
    attestation_chain_path=".auths/agent-chain.json",
)
token = auth.get_token(capabilities=["read", "write"])

Error handling

from auths import Auths, VerificationError, NetworkError

auths = Auths()
try:
    result = auths.verify(attestation_json=data, issuer_key=key)
except VerificationError as e:
    print(e.code)     # "expired_attestation"
    print(e.message)  # "Attestation expired at 2024-01-15T..."
except NetworkError as e:
    if e.should_retry:
        pass  # safe to retry

All errors inherit from AuthsError and carry .code, .message, and .context.

Configuration

# Auto-discover (uses ~/.auths)
auths = Auths()

# Explicit repo path
auths = Auths(repo_path="/path/to/identity-repo")

# With passphrase (or set AUTHS_PASSPHRASE env var)
auths = Auths(passphrase="my-secret")

# Headless / CI mode
# Set AUTHS_KEYCHAIN_BACKEND=file for environments without a system keychain

API reference

Type stubs are bundled (py.typed + __init__.pyi). Your editor will show full signatures, docstrings, and return types for all methods.

License

Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

auths-0.1.6.tar.gz (1.7 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

auths-0.1.6-cp38-abi3-win_amd64.whl (7.6 MB view details)

Uploaded CPython 3.8+Windows x86-64

auths-0.1.6-cp38-abi3-musllinux_1_2_x86_64.whl (7.8 MB view details)

Uploaded CPython 3.8+musllinux: musl 1.2+ x86-64

auths-0.1.6-cp38-abi3-musllinux_1_2_aarch64.whl (7.3 MB view details)

Uploaded CPython 3.8+musllinux: musl 1.2+ ARM64

auths-0.1.6-cp38-abi3-manylinux_2_28_x86_64.whl (7.8 MB view details)

Uploaded CPython 3.8+manylinux: glibc 2.28+ x86-64

auths-0.1.6-cp38-abi3-manylinux_2_28_aarch64.whl (7.3 MB view details)

Uploaded CPython 3.8+manylinux: glibc 2.28+ ARM64

auths-0.1.6-cp38-abi3-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl (14.0 MB view details)

Uploaded CPython 3.8+macOS 10.12+ universal2 (ARM64, x86-64)macOS 10.12+ x86-64macOS 11.0+ ARM64

File details

Details for the file auths-0.1.6.tar.gz.

File metadata

  • Download URL: auths-0.1.6.tar.gz
  • Upload date:
  • Size: 1.7 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for auths-0.1.6.tar.gz
Algorithm Hash digest
SHA256 30dc4cbb10f529dc8fc870459f2b02eb8e57454da7c1923a22b34b3050d12771
MD5 357226da472b632c1b070c9c2ec604c4
BLAKE2b-256 30db42e8eec350ab56f61876cd71caf278e1a15a54423323541611575edab3c2

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6.tar.gz:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file auths-0.1.6-cp38-abi3-win_amd64.whl.

File metadata

  • Download URL: auths-0.1.6-cp38-abi3-win_amd64.whl
  • Upload date:
  • Size: 7.6 MB
  • Tags: CPython 3.8+, Windows x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for auths-0.1.6-cp38-abi3-win_amd64.whl
Algorithm Hash digest
SHA256 01a789056cb70ee45998ffb30ddaafe0c91161c65a9a37d9bde59b94f494ed94
MD5 b6a47cc526a2b0cd35ff560bc643eed2
BLAKE2b-256 f7c0ed7c2f412f76540161af72a0253864f5ff24a4bd5653b7a1c5a00fb5a758

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6-cp38-abi3-win_amd64.whl:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file auths-0.1.6-cp38-abi3-musllinux_1_2_x86_64.whl.

File metadata

  • Download URL: auths-0.1.6-cp38-abi3-musllinux_1_2_x86_64.whl
  • Upload date:
  • Size: 7.8 MB
  • Tags: CPython 3.8+, musllinux: musl 1.2+ x86-64
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for auths-0.1.6-cp38-abi3-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 e5dcb09d32913e879fa2923615013de06108395e1c7f06cf5d6c34042d0f50be
MD5 9d80e0e7b337c92e9e9bf8d31bce3c4b
BLAKE2b-256 d8e8a67dd102e627b9ee73e0db431115c61ff3e859c3c020e4c3f08c6d168df9

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6-cp38-abi3-musllinux_1_2_x86_64.whl:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file auths-0.1.6-cp38-abi3-musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for auths-0.1.6-cp38-abi3-musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 43f7c098300243c52e2484fe0b1f68bdfe232827e1e868b62012f1da52f25438
MD5 57834386aef1c2dd420a707b2a37f066
BLAKE2b-256 e90557299601137cff4f22ce7dee210a2982f2bcac86d4ee9df5336a6dd0f81e

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6-cp38-abi3-musllinux_1_2_aarch64.whl:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file auths-0.1.6-cp38-abi3-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for auths-0.1.6-cp38-abi3-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 6d2d5a626658fd4bca57851676214cd5be7f346ee7ac44ba50e37c85ce2c2aeb
MD5 01f2e9e2b5acd1a6a4079df5649a155a
BLAKE2b-256 563ca054b88cd83aaa4656bc8a7f22a8d316de2754f0d229fe848c0cc6941efc

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6-cp38-abi3-manylinux_2_28_x86_64.whl:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file auths-0.1.6-cp38-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for auths-0.1.6-cp38-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 506653aa2575c177d9aa2fef8fc0c6394ed6462e4d8ac90161f0fb2b64b4632f
MD5 a0c4173c3142c20f8d038ce7eaec644f
BLAKE2b-256 1360df1e490f898ca8cfbda4b820db6394479f71a9581a868e4eea2fc2c7acda

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6-cp38-abi3-manylinux_2_28_aarch64.whl:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file auths-0.1.6-cp38-abi3-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl.

File metadata

File hashes

Hashes for auths-0.1.6-cp38-abi3-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl
Algorithm Hash digest
SHA256 5c98b347620a51a3f7530fb74012d8d94775eb5cfa094fa1ac5baf87b26532bf
MD5 5dcc44338db9f4a94be476e1a547b728
BLAKE2b-256 bc9ae4d8c250ecd0004122a5efba392d1d865ebc5102ffaba8aabb1961eaeaf1

See more details on using hashes here.

Provenance

The following attestation bundles were made for auths-0.1.6-cp38-abi3-macosx_10_12_x86_64.macosx_11_0_arm64.macosx_10_12_universal2.whl:

Publisher: publish-python.yml on auths-dev/auths

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.16

7 files

0.1.13

7 files

0.1.12

7 files

0.1.11

7 files

0.1.10

7 files

0.1.9

7 files

0.1.8

7 files

0.1.7

7 files

This release

0.1.6 This release

7 files

0.1.5

7 files

0.1.3

7 files

0.1.2

7 files

0.1.1

7 files

0.1.0

5 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page