authweave-http-signatures
Payment HTTP Message Signatures profile (authweave-payment-http-sig-v1)
for AuthWeave. Verifies RFC 9530 Content-Digest and RFC 9421 signatures after
machine authentication (mTLS or DPoP), then binds keyid to the authenticated
principal and consumes a signature nonce.
This package does not authenticate callers and does not implement business
idempotency. Structured Fields parsing uses the maintained
http-message-signatures library (RFC 8941 / RFC 9421).
PaymentHttpSignatureVerifier(..., observer=...) emits logical integrity and
nonce-replay observations through the neutral authweave-core observer seam.
verify(..., links=(TraceCorrelation(...),)) supports async/retry causality;
linked trace context never participates in authentication or key binding.
Frozen/custom verifier clocks are request-local; the package does not mutate the process-global clock of the Structured Fields/signature implementation.
sign_payment_message is a local reference/test helper and accepts an in-process
Ed25519PrivateKey. Production producers keep non-exportable keys in their own KMS/HSM
signer and emit the same documented RFC 9421 profile outside this verifier package.
uv add authweave-http-signatures
See ADR 0004 and docs/roadmap.md. Optional extras: [redis], [litestar].
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file authweave_http_signatures-8.0.0.tar.gz.
File metadata
- Download URL: authweave_http_signatures-8.0.0.tar.gz
- Upload date:
- Size: 11.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a37a9a924cebeb3f8c33f9aad50436de50a073e912fda03ff55bd6bd6001d4b8
|
|
| MD5 |
cde9a589d34f54e896470f029483aa87
|
|
| BLAKE2b-256 |
f15f87190e2f782e11e6d11e7aa72c70575a28d22ee36ed87f51ace5da13e014
|
Provenance
The following attestation bundles were made for authweave_http_signatures-8.0.0.tar.gz:
Publisher:
3_release.yml on ZYLVEXT/litestar-auth
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
authweave_http_signatures-8.0.0.tar.gz -
Subject digest:
a37a9a924cebeb3f8c33f9aad50436de50a073e912fda03ff55bd6bd6001d4b8 - Sigstore transparency entry: 2579611454
- Sigstore integration time:
-
Permalink:
ZYLVEXT/litestar-auth@407607d5e0dbcf8ef1f295e0e6e43867dfb2b65d -
Branch / Tag:
refs/tags/8.0.0 - Owner: https://github.com/ZYLVEXT
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
3_release.yml@407607d5e0dbcf8ef1f295e0e6e43867dfb2b65d -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file authweave_http_signatures-8.0.0-py3-none-any.whl.
File metadata
- Download URL: authweave_http_signatures-8.0.0-py3-none-any.whl
- Upload date:
- Size: 17.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2ee4dedff1e303a286a416854ea7aa10b2ca87461966baf1196716c77173c8c1
|
|
| MD5 |
faa26b4838eaaa94bfa0e1a8931b3be2
|
|
| BLAKE2b-256 |
63ef59b028ec53b9b13f968b30cb093d42fde45a1c10e1de69a716a321cb47be
|
Provenance
The following attestation bundles were made for authweave_http_signatures-8.0.0-py3-none-any.whl:
Publisher:
3_release.yml on ZYLVEXT/litestar-auth
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
authweave_http_signatures-8.0.0-py3-none-any.whl -
Subject digest:
2ee4dedff1e303a286a416854ea7aa10b2ca87461966baf1196716c77173c8c1 - Sigstore transparency entry: 2579611456
- Sigstore integration time:
-
Permalink:
ZYLVEXT/litestar-auth@407607d5e0dbcf8ef1f295e0e6e43867dfb2b65d -
Branch / Tag:
refs/tags/8.0.0 - Owner: https://github.com/ZYLVEXT
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
3_release.yml@407607d5e0dbcf8ef1f295e0e6e43867dfb2b65d -
Trigger Event:
workflow_dispatch
-
Statement type: