Skip to main content

awnest

Prove there is a human before you let them into the nest.

pip install awnest
from awnest import Nest, HmacKey, Policy

nest = Nest("action:checkout", key=HmacKey(SECRET), policy=Policy(min_score=70))
nest.require(token=attestation, subject=user_id)      # raises NotAdmitted

A nest is not a wall. It is a place with doors, and the job is knowing who came through which one.

The one thing this is built around

Every human check ever written fails open. Not by decision — by arithmetic. "We could not tell" and "it is fine" reach the caller as the same thing: an empty result, a None, a score of 0, a 500 somebody catches. The gate then denies nobody, and it passes every test written for it, because the tests assert that a bot is refused — and a bot is refused, right up until the evaluator has a bad afternoon.

So the verdict type here has no member meaning "ok":

Verdict.HUMAN      # earned it
Verdict.AGENT      # declared it
Verdict.UNKNOWN    # everything else, including "the check did not run"

UNKNOWN is what you get from an absent evaluator, an unparseable reply, a stale attestation, an empty evidence list, and a policy nobody configured. Admission is granted by naming a verdict, never by failing to reach one.

Two more rules fall out of the same idea:

  • Scored zero is not unscored. Evidence(score=None) means nobody judged it. It counts toward nothing and it is reported as nothing — never as a zero, which would turn a judge outage into a permanent accusation against real people.
  • A presented-but-invalid credential is not an absent one. A token that does not verify refuses there; it never falls through to whatever weaker evidence came with it. Forgery is the one event you want to be loud.

"Human or bot" is the wrong question

If the only way through a door is to be human, every legitimate automation is taught to imitate one, and you have spent your budget training the thing you are trying to detect.

from awnest import Evidence, DECLARED_AGENT, assess

assess([Evidence(DECLARED_AGENT, source="nightly-sync")]).verdict   # Verdict.AGENT

A caller that declares itself is believed, and a declaration cannot be outvoted by a good score presented alongside it. Honesty has to be the cheaper path or nobody takes it. Whether the agent door is open is one flag — Policy(allow_agents=True) — decided per door, never inherited.

Not a CAPTCHA

CAPTCHA asks a machine-solvable question and charges the cost to the human. It is worst for the people it should serve most, and the machines beat it, so the only party reliably filtered is the customer.

The bundled challenges ask instead for something a person has and a model does not: a particular life — an embodied sensation, felt time, a real reaction to being asked. Scoring is somebody else's job (a model, a person, a service), and this package refuses to pretend otherwise.

from awnest import select, judge_prompt
from awnest.judge import score_answers

issued = select(3)                    # one per category, never the same twice
evidence, judgement = score_answers("http://127.0.0.1:8080", issued, answers,
                                    model="whatever-you-run")

This is not proof, and the honest framing is cost. A determined operator can pay a person, or feed a model a real diary. What it does is move a fake account from free to about a human-minute, which is the entire game for spam economics. Need more? Stack another signal — the verdict plane takes several and reports the weakest, so adding one can never weaken the answer.

The judge sees the most personal thing a stranger will ever type into your product. base_url has no default on purpose: nobody should make that decision by inheriting one.

Attestations: bound, offline-verifiable, one-use

The check and the door are rarely the same process. Calling back to the verifier makes every gated action depend on it being up; a boolean in a session is a fact with no provenance. So: a small signed statement.

token = nest.issue(user_id, assessment, ttl_s=3600, method="challenges")

The format is shaped by replay, which is the real attack — not "bots solve the puzzle" but "a human solves it once, cheaply, and the result is reused":

field drop it and…
sub the token is transferable between people
aud one solve opens every door that trusts the issuer
ctx it can be lifted onto a different commit, request or transfer
nonce one solve opens the same door forever (with a Seen ledger, it does not)
exp the damage is unbounded in time

ctx is symmetric and unforgiving: a token carrying a context is refused by any verifier that does not name the same one, and a verifier that names a context refuses a token that carries none. A binding either side may decline to check is not a binding, and forgetting to check is what actually happens.

The token names its algorithm and the key decides it — a mismatch is a refusal. Reading alg out of the token is how alg: none and HMAC/RSA confusion emptied a decade of JWT deployments.

HmacKey is stdlib and means every verifier is also an issuer: fine inside one trust domain, wrong the moment a third party verifies. pip install awnest[ed25519] for the asymmetric half.

Signing commits with it

A signed commit says a key was present. When most commits are written by agents holding the same keys as the humans who run them, that is no longer the interesting fact. The interesting fact is whether a person stood behind the change, at what strength, and which person.

awnest commit-attest --identity "$AWIAM_SUBJECT" --repo acme/widgets \
       --tree "$(git rev-parse HEAD^{tree})" --score 82 --method challenges
# -> Awnest-Attestation: awn1.…   (append it as a trailer)

awnest commit-verify --message .git/COMMIT_EDITMSG --repo acme/widgets \
       --tree "$(git rev-parse HEAD^{tree})"

The binding is the tree, not the commit sha — an attestation lives inside the message, so it cannot contain a hash of the commit that contains it. That means it survives a reword, a rebase and a cherry-pick (same content, still attested) and does not cover the parent. If you need "approved on this branch", that belongs in the audience: repo:acme/widgets@release is a different door.

verify_commit re-reads the tree in front of you and compares. A valid attestation lifted off another commit verifies perfectly; only that comparison notices.

What it composes with

Each of these is a door with a name, built rather than typed (audience("channel", "#help")) because an issuer's spelling drift mints tokens for a door nobody guards — silently, unlike a verifier's, which refuses everyone and gets fixed in minutes.

with the door the question
an identity system who is this caller (the sub in the attestation)
an authz system what may they do — humanity is an input, not a replacement
a chat/relay channel:#help may this caller post here
version control repo:acme/widgets did a person stand behind this change
a mesh mesh:home may this peer join
a tunnel tunnel:api may this caller reach a service with no public address
an audit trail every verdict, including the refusals, kept where gaps show

Nothing above is a dependency. awnest holds the verdict, the format and the door; who you ask and what you do with the answer stay yours.

Command line

awnest challenge -n 3                  issue a set of challenges (JSON)
awnest judge --url … --model … --answers a.json
awnest mint   --subject u_42 --audience action:checkout --score 80
awnest verify TOKEN --audience action:checkout
awnest gate   TOKEN --audience action:checkout --subject u_42
awnest commit-attest / commit-verify   the git trailer, above
awnest --self-test                     prove this package can still fail

Exit codes: 0 admitted / ok · 1 refused or broke · 2 you asked wrongly.

Licence

Apache-2.0.

The aw family

Standalone tools that share one idea: replace something you would otherwise have to trust with something you can check.

Each installs on its own, works offline, and needs no account.

instead of trusting you check
awdk a framework's idea of how your agents should run one loop you can read, pointed at a backend you already pay for
awskills that an agent knows your procedure the procedure written down, versioned, and loadable by any agent
awm that memory stayed in its lane tenant:user:project scopes, so a write cannot cross a boundary
awnode a vendor's cloud with every prompt a local gateway routing to backends you chose
awgraph that grep found everything an AST + tree-sitter call graph an agent can traverse
awgit that no one else is editing this file a lease, refused at commit time if you do not hold it
awseal that the artifact came from who you think an Ed25519 seal — the key that verifies is not the key that forges
awshare that the download is intact content-addressed bundles, verified on fetch
awnest (you are here) that there is a person on the other end a verdict with evidence, where "we could not tell" is not "yes"
awnboard a share link anyone who sees it can use an invitation addressed to one person, for one gate, revocable
awnix that the box is what you left it as an immutable image you built, with atomic rollback
awrecover that the restore worked a restore that fully lands or does not land at all
awkno that the docs site is up, or that you remember the family the whole ecosystem in your terminal, with no network at all
awrelay a SaaS in the middle of your agents findings, alerts and coordination over your own transport
awmail a mailbox somebody else can read mail your agents send and receive over your own server
awfind one vendor's idea of the web results from whichever providers you configured
awbrowse that the page said what you were told the render, the DOM and the requests it made
aitherkvcache a vendor's quantisation defaults sub-byte KV cache kernels you can benchmark yourself
AitherZero a pile of scripts nobody has numbered numbered, discoverable automation with declarative playbooks
AitherConnect what a page tells your browser to do a federated search and desktop bridge you host
awreason a confident paragraph the phases it went through, and every tool call it made to get there
awrecurse that everything you pasted in was actually read which slices it opened, and what it concluded from each
awprism the first explanation that fits the ranked alternatives, and the observation that separates them
awrepl what the agent believes the value is the value, printed from the live session
awresearch a summary of pages nobody opened every claim against the source it came from

awnix is the ground floor — A Linux you can hand to an agent — immutable base, capabilities included.

The Aitherium ecosystem

Every repository here is public. Each publishes an aither-manifest.json beside its page, so any surface can read every sibling's — the network is browsable from any node in it.

repo what it is pages
awdk Build AI agent fleets — 3 lines, any backend, local or cloud docs
awskills Portable agent skills — self-contained procedures an agent loads on demand docs
awm A portable, scoped agent memory docs
awnode A lightweight local gateway — bridges your apps to the AI backends you chose docs
awrun A priority-aware queue and dispatcher for agentic runs and ad-hoc CI builds docs
awgraph A semantic code graph for agents — AST + tree-sitter, call graphs docs
awgit Semantic version control on top of git — edit-ops and leases docs
awseal Sign an artifact so a stranger can verify it docs
awshare Publish an artifact and fetch it back verified docs
awnest (you are here) Prove there is a human before you let them into the nest docs
awnboard A front gate you can put in front of anything, and hand someone the key to docs
awnix A Linux you can hand to an agent — immutable base, capabilities included docs
awrecover Labelled snapshots with an all-or-nothing restore docs
awkno The man page for the Aither World — every brick, stack and law, offline docs
awrelay Portable agent messaging — findings, alerts, coordination docs
awmail Give an agent an email address — send, and actually receive docs
awfind A portable search client — query, results, ranking docs
awbrowse A portable browser client — navigate, console, network, DOM, screenshot docs
aitherkvcache Near-optimal KV cache quantization for LLM inference — sub-byte compression docs
AitherZero PowerShell 7+ automation framework — numbered, self-describing scripts docs
AitherConnect Browser extension — federated AI search, page context, and the Living OS overlay docs
awreason A portable reasoning client — sessions, phases, thoughts, and the chain that produced the answer docs
awrecurse Answer a question over a context far larger than the window — recursively, with the trace kept docs
awprism Turn a failure into ranked hypotheses — and say what would confirm each one docs
awrepl A REPL an agent can actually use — state that survives between turns docs
awresearch Ask a research question, get a cited report you can check docs

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

awnest-0.1.0.tar.gz (59.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

awnest-0.1.0-py3-none-any.whl (53.6 kB view details)

Uploaded Python 3

File details

Details for the file awnest-0.1.0.tar.gz.

File metadata

  • Download URL: awnest-0.1.0.tar.gz
  • Upload date:
  • Size: 59.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for awnest-0.1.0.tar.gz
Algorithm Hash digest
SHA256 6d63159b8aba760d5da6138c948efb9e803d4b645337f1f8699cc1629fc59ac1
MD5 f3cef56ec46770b06b205ad988a5e723
BLAKE2b-256 ef9c1b8c16e182bd640aa2937c8c2017cf7bd4fd988e4d51b1e36b0e66756c54

See more details on using hashes here.

File details

Details for the file awnest-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: awnest-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 53.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for awnest-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a091dec00e9622a5212090967c770fd67b4ddeea70995f96639bddd66b2d8b05
MD5 1dbba8720ec803cefe6241ea58ddd449
BLAKE2b-256 c18800b67e7b1d63313c9e826bb78a4f58aa6544f6d48e6aafb743ce72c1f83f

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page