Skip to main content

Benchpress: the reliability layer for AI agents with write access

benchpress-agent

The reliability layer for AI agents with write access. Benchpress is a task-agnostic control loop you wrap around any tool layer. It reads the workspace's rules before deciding what "done" means. It picks the right record among look-alikes and locks the rest in a deny-list enforced in code. It plans only the writes the definition of done needs, gates every one, and reads every write back. Status comes from provider state, never from an HTTP 200. Every run ends with an auditable receipt.

pip install benchpress-agent        # or: uv add benchpress-agent

Python 3.12+. Runtime dependencies: httpx, pydantic.

See it work in one command, no keys needed:

uvx --from benchpress-agent benchpress demo      # or: pip install benchpress-agent && benchpress demo

The demo runs the real loop, gate and read-back on an in-memory workspace with a scripted model. It plans a write to a look-alike prospect on purpose, so you can watch the gate refuse it, and it writes benchpress-demo/receipt.json and a self-contained receipt.html.

Quickstart

import asyncio
import benchpress

async def execute_tool(tool_name: str, tool_input: dict) -> dict:
    # tool_name == "provider_api"
    # tool_input == {"provider": "stripe", "method": "POST", "path": "/v1/customers/cus_123",
    #                "query": {...}, "body": {...}}
    # Call your real API (or a sandbox/twin) and return:
    return {"ok": True, "status_code": 200, "body": {...}}

agent = benchpress.wrap("deepseek-v4-pro", execute_tool, providers=["hubspot", "stripe", "slack", "gmail"])

result = asyncio.run(agent.run(
    "Acme asked for renewal notices to go to ap@acme.example. Update billing and the CRM, "
    "and keep the account owner in the loop. Do not send external mail.",
    trace_dir="runs/acme",            # writes receipt.json
))
print(result.status)                  # "completed" | "partial" | "escalated", from read-back evidence only
print(result.context.refusals)        # every write the gate refused, with the rule that refused it
  • model is a model id (DEEPSEEK_API_KEY / BENCHPRESS_API_KEY + BENCHPRESS_API_BASE for any OpenAI-compatible endpoint, ANTHROPIC_API_KEY for claude-*), a benchpress.ModelConfig, or None to read BENCHPRESS_MODEL.
  • executor is an async execute_tool(tool_name, tool_input) function or any object exposing one.
  • Built-in playbooks cover Slack, Gmail, HubSpot and Stripe; pass playbooks= for your own systems.
  • transport= swaps the model wire protocol (bring your own client, or a scripted one in tests).
  • agent.run_sync(...) for synchronous callers.

A real-app gateway for Slack, Gmail, HubSpot and Stripe ships in benchpress.realapp (gateway_from_env(providers)), and the CLI runs a request end to end:

benchpress run --providers hubspot,stripe --prompt "..." --trace-dir runs/demo
benchpress receipt runs/demo --html

The loop

P0 orient → P1 policy sweep → P2 resolve (lock look-alikes) → P3 definition of done → P4 plan → P5 execute through the gate + read-back → P6 verify (+ one repair round) → P7 deliver

Principle What it means in code
Code beats prompt for safety The gate refuses writes to protected ids, prohibited verbs, sent (vs drafted) external mail, control-plane paths. The prompt only explains.
State is truth Every write is read back; status is computed from evidence, never from a 2xx.
Task-agnostic No code keyed to task ids, seeded names or domains. CI greps for them.
Provider content is data Policies found in the workspace are classified; injection attempts are flagged, not obeyed.
Honest endings P7 always runs, with whatever evidence exists. Timeouts and budget exhaustion end in a receipt, not a crash.

Evidence

Benchpress was built for the Multi-App AI Agent Hackathon (2026-09-13) and is measured against ArgaBench's hardest published scenario, graded by ArgaBench's verifier on the published seed rebuilt locally and on real Slack, Gmail, HubSpot and Stripe (test mode). It makes no claim about the official leaderboard. Methods, results, failures and cost are in the repository: README · reports · disclosure.

Status

Alpha (0.x). The public API is benchpress.wrap, Benchpress.run, run_trial, TrialResult, ModelConfig, Ablations, Gate. Expect additions (MCP guard, policy packs, Rehearse) in minor releases; see the roadmap.

Apache-2.0 · Built by Raj Karia

Metadata

Release files for benchpress-agent 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for benchpress-agent 0.1.1
File Size Uploaded
benchpress_agent-0.1.1.tar.gz 197.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for benchpress-agent 0.1.1
File Interpreter ABI Platform
benchpress_agent-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 323.5 kB

Release files / benchpress_agent-0.1.1.tar.gz

Download URL benchpress_agent-0.1.1.tar.gz
Size 197.5 kB
Tags Source
SHA-256 checksum
How to use checksums
9d21ac0c7bd554fabc933fdeb4dae0a617fb1f884c3044d8c38411b47e276e5f
BLAKE2b-256 checksum
How to use checksums
cf260c699bfab4b98b6541cb4930971f495afe6353779afd0932b2f08a33f16e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.6 {"installer":{"name":"uv","version":"0.11.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / benchpress_agent-0.1.1-py3-none-any.whl

Download URL benchpress_agent-0.1.1-py3-none-any.whl
Size 126.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5b86779749d18f88d6a5694eb4bf1d2e7e797a9864b1f43285769ce7b28348e5
BLAKE2b-256 checksum
How to use checksums
fe6138519c6e1e809895bd1ed4d436f47218f1f8ba48d8262f95aec337d1a46f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.6 {"installer":{"name":"uv","version":"0.11.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.7.1

2 release files

0.7.0

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page