Skip to main content

awbac

Docs · Source · pip install awbac · The Aither World

The Aither World is an operating system for agents — a Linux you can hand to one, the runtimes it works in, and the tools it works with. awnix is the Linux underneath it; awbac is one of its 33 bricks — each installs on its own, runs offline, and needs no account.

Start here: Gate one endpoint and read the explanation it gives for a denial.

Role-based access control that fails closed and explains itself.

pip install awbac
from awbac import Policy

p = (Policy()
     .role("reader", ["doc:read:*"])
     .role("editor", ["doc:write:*"], inherits=["reader"])
     .assign("david", "editor"))

d = p.check("david", "doc:read:handbook")
if d:
    ...
print(d.reason)     # granted by 'doc:read:*'
awbac check   policy.json david doc:read:handbook   # 0 allow · 1 deny · 2 could not judge
awbac explain policy.json david doc:write:secret
# DENY: none of 2 grant(s) cover 'doc:write:secret'

The bug this package is shaped around

Permissions are colon-separated: workspace:read:*. The obvious matcher is granted.startswith(requested), and it fails open:

"workspace:readwrite".startswith("workspace:read")   # True

A grant of workspace:read silently covers workspace:readwrite. Nothing raises, no happy-path test notices, and it stays invisible until someone writes to something they could only read.

So matching is on segments, never characters. * matches exactly one segment; ** matches one or more trailing segments and is refused anywhere but last, because a mid-position ** reads as a typo far more often than as intent.

granted requested result
workspace:read workspace:readwrite deny
doc:read:* doc:read:handbook allow
doc:* doc:read:handbook deny* is one segment
doc:** doc:read:handbook allow
doc:read doc:read:handbook deny — grant is narrower

Fails closed on every path

Unknown role, unknown subject, anonymous caller, empty permission, malformed policy, inheritance cycle, an exception mid-evaluation — every one denies, with the cause named:

  • an unknown role contributes nothing, not everything
  • an inheritance cycle resolves what it can rather than raising (one bad role must not take down all authorization) or looping forever
  • an exception returns a denial that says so, instead of propagating to a caller who might treat a raise as an allow
  • an unreadable policy file exits 2, not 1 — "denied" is routine and would be shrugged off, so a missing policy has to look different from a refused request

Every decision carries a reason

A deny nobody can explain gets worked around. An allow nobody can attribute cannot be audited. So Decision carries reason, and an allow also carries via — the exact grant that permitted it.

Tests

15 tests, and they run in both directions: a suite that only asserts denials passes on a policy that denies everything, and one that only asserts allows passes on a policy that allows everything. There is a test whose whole job is to fail if the policy were replaced by a deny-all.

pip install -e ".[dev]" && pytest

Where it sits

package question
awiam who is this caller?
awbac may this subject do X to Y?
awseal what proves it?

Deliberately three packages. An identity service that also owns authorization has nobody to check it, and one that owns its own key material has nobody to attest it.

Apache-2.0.

The aw family

Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.

Each installs on its own, works offline, and needs no account.

instead of trusting you check
awdk a framework's idea of how your agents should run one loop you can read, pointed at a backend you already pay for
awskills that an agent knows your procedure the procedure written down, versioned, and loadable by any agent
awm that memory stayed in its lane tenant:user:project scopes, so a write cannot cross a boundary
awnode a vendor's cloud with every prompt a local gateway routing to backends you chose
awgraph that grep found everything an AST + tree-sitter call graph an agent can traverse
awgit that no one else is editing this file a lease, refused at commit time if you do not hold it
awseal that the artifact came from who you think an Ed25519 seal — the key that verifies is not the key that forges
awshare that the download is intact content-addressed bundles, verified on fetch
awnest that there is a person on the other end a verdict with evidence, where "we could not tell" is not "yes"
awnboard a share link anyone who sees it can use an invitation addressed to one person, for one gate, revocable
awnix that the box is what you left it as an immutable image you built, with atomic rollback
awrecover that the restore worked a restore that fully lands or does not land at all
awrelay a SaaS in the middle of your agents findings, alerts and coordination over your own transport
awmail a mailbox somebody else can read mail your agents send and receive over your own server
awfind one vendor's idea of the web results from whichever providers you configured
awbrowse that the page said what you were told the render, the DOM and the requests it made
aitherkvcache a vendor's quantisation defaults sub-byte KV cache kernels you can benchmark yourself
AitherZero a pile of scripts nobody has numbered numbered, discoverable automation with declarative playbooks
AitherConnect what a page tells your browser to do a federated search and desktop bridge you host
awreason a confident paragraph the phases it went through, and every tool call it made to get there
awrecurse that everything you pasted in was actually read which slices it opened, and what it concluded from each
awprism the first explanation that fits the ranked alternatives, and the observation that separates them
awrepl what the agent believes the value is the value, printed from the live session
awresearch a summary of pages nobody opened every claim against the source it came from
awpredict a model because it trained without erroring its prediction against a self-updating lookup, on the rows that are actually novel
awkno that the docs site is up, or that you remember the family the whole ecosystem in your terminal, with no network at all

awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.

The Aitherium ecosystem

Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.

repo what it is pages
awdk Build AI agent fleets — 3 lines, any backend, local or cloud docs
awskills Portable agent skills — self-contained procedures an agent loads on demand docs
awm A portable, scoped agent memory docs
awnode A lightweight local gateway — bridges your apps to the AI backends you chose docs
awrun A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds docs
awgraph A semantic code graph for agents — AST + tree-sitter, call graphs docs
awgit Semantic version control on top of git — edit-ops and leases docs
awseal Sign an artifact so a stranger can verify it docs
awshare Publish an artifact and fetch it back verified docs
awdit An append-only audit trail whose gaps are DETECTABLE docs
awbac (you are here) Role-based access control that fails closed and explains itself docs
awiam Who is this caller? A directory and session store that fails honestly docs
awtunnel Reach a service that has no public address docs
awnest Prove there is a human before you let them into the nest docs
awnboard A front gate you can put in front of anything, and hand someone the key to docs
awnix A Linux you can hand to an agent — immutable base, capabilities included docs
awrecover Labelled snapshots with an all-or-nothing restore docs
awrelay Portable agent messaging — findings, alerts, coordination docs
awmail Give an agent an email address — send, and actually receive docs
awnet The agentic web — agents host a mesh, and agents join one docs
awfind A portable search client — query, results, ranking docs
awbrowse A portable browser client — navigate, console, network, DOM, screenshot docs
awknowledge How to run a coding agent so the result survives — the laws, with evidence docs
aitherkvcache Near-optimal KV cache quantization for LLM inference — sub-byte compression docs
AitherZero PowerShell 7+ automation framework — numbered, self-describing scripts docs
AitherConnect Browser extension — federated AI search, page context, and the Living OS overlay docs
awreason A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer docs
awrecurse Answer a question over a context far larger than the window — recursively, with the trace kept docs
awprism Turn a failure into ranked hypotheses — and say what would confirm each one docs
awrepl A REPL an agent can actually use — state that survives between turns docs
awresearch Ask a research question, get a cited report you can check docs
awpredict Predict what your environment does next, and how surprised you were docs
awkno The man page for the Aither World — every brick, stack and law, offline docs
<script src="aither-constellation.js"></script>

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

awbac-0.1.0.tar.gz (21.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

awbac-0.1.0-py3-none-any.whl (18.0 kB view details)

Uploaded Python 3

File details

Details for the file awbac-0.1.0.tar.gz.

File metadata

  • Download URL: awbac-0.1.0.tar.gz
  • Upload date:
  • Size: 21.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for awbac-0.1.0.tar.gz
Algorithm Hash digest
SHA256 b53e7197011363bd85b373aa1a55bd4030d9b46080555f977425578e02e5a27b
MD5 2fbd15200cc86a18f73c8387cea3918d
BLAKE2b-256 cefcd3ae963896ea1b63cd0f235638f8fc3df0ed08000511f5f50470dc03c9e6

See more details on using hashes here.

File details

Details for the file awbac-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: awbac-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 18.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for awbac-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 fb57daf2f9cfdd6f7d16edaa880afbee1635c6a6bb4a6c27f8260b4057b3decf
MD5 f5363142f16441127f440c879b61c62d
BLAKE2b-256 5e3726c3800eb25a8f57c5ec09131d8c463ecefbe8e89f9b819b3028158541b4

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page