BurnLedger Python SDK
Python client for the BurnLedger API — cryptographic deletion certificates for regulatory compliance.
Scope
The SDK covers the data plane: systems, attestations, certificates, webhooks,
API keys, /v1/me, and the transparency log — everything involved in
measuring a datastore and verifying what came back.
Account management (teams, TOTP enrolment, subscriptions, invoices, the audit
log, billing) is deliberately not part of the SDK. Those are administrative
actions people take once, in the dashboard at
https://dashboard.burnledger.io, and they are available on the raw /v1 API
for anyone who needs to automate them.
Install
pip install burnledger
Requirements: Python 3.10+
Quick Start
from burnledger import BurnLedger
with BurnLedger(api_key="dp_...") as dp:
# 1. Attest — snapshot systems before deletion
att = dp.attest("user@example.com", system_ids=["sys_abc", "sys_def"])
# 2. Delete data (your code, your tools)
# 3. Verify — confirm deletion and get certificate
result = dp.verify(att.id, "user@example.com", timeout=60)
# 4. Download certificate PDF
dp.save_pdf(result.certificate.id, "./deletion-cert.pdf")
Async
from burnledger import AsyncBurnLedger
async with AsyncBurnLedger(api_key="dp_...") as dp:
att = await dp.attest("user@example.com", system_ids=["sys_abc"])
result = await dp.verify(att.id, "user@example.com", timeout=60)
Offline Verification
Verify certificates without network access using Ed25519 signatures:
from burnledger import verify_certificate, verify_transparency, PublicKeyInfo
key = PublicKeyInfo.from_hex("abcdef...", revoked=False)
keys = {key.key_id: key}
cert_result = verify_certificate(certificate, keys)
# VerificationResult.VALID or raises VerificationError
log_result = verify_transparency(certificate, keys)
# TransparencyResult.INCLUDED or raises VerificationError
Webhook Verification
Verify incoming webhook signatures (HMAC-SHA256):
from burnledger import verify_webhook_signature
valid = verify_webhook_signature(
secret=webhook_secret, # from dp.register_webhook()
body=request.body, # raw request body
signature=request.headers["X-BurnLedger-Signature"],
)
API Reference
Client
BurnLedger(
api_key: str,
*,
base_url: str = "https://api.burnledger.io",
timeout: float = 30.0,
max_retries: int = 2,
)
Systems
| Method | Returns |
|---|---|
register_system(**opts) |
System |
get_system(id) |
System |
list_systems(limit=25) |
SyncPaginator[System] |
deregister_system(id) |
None |
health_check(id) |
System |
Attestations
| Method | Returns |
|---|---|
attest(subject, **opts) |
Attestation |
batch_attest(subjects, **opts) |
BatchAttestationResponse |
get_attestation(id) |
Attestation |
wait_for(id, **opts) |
Attestation |
verify(id, subject, **opts) |
VerifyResult |
Certificates
| Method | Returns |
|---|---|
get_certificate(id) |
CertificateResponse |
list_certificates(limit=25) |
SyncPaginator[CertificateResponse] |
get_certificate_stats() |
CertificateStats |
export_certificates(**opts) |
bytes |
download_pdf(id) |
bytes |
save_pdf(id, path) |
None |
get_revocation_status(id) |
RevocationStatus |
revoke_certificate(id, reason=...) |
CertificateResponse |
batch_revoke_certificates(ids, reason=...) |
BatchRevokeResponse |
batch_revoke_certificates takes up to MAX_BATCH_REVOKE (100) ids under one
reason and returns whether all, some or none were revoked: the failures are in
errors, each naming the request index and certificate_id, so a partially
failed batch is inspected, not caught. More than 100 ids raises ValueError
before any request is made; chunk larger sets by MAX_BATCH_REVOKE.
Webhooks
| Method | Returns |
|---|---|
register_webhook(url=...) |
Webhook |
list_webhooks(limit=25) |
SyncPaginator[Webhook] |
delete_webhook(id) |
None |
rotate_webhook_secret(id) |
WebhookRotateResponse |
commit_webhook_rotation(id) |
None |
list_failed_deliveries(limit=25) |
SyncPaginator[FailedDelivery] |
retry_delivery(delivery_id) |
None |
resolve_delivery(delivery_id) |
None |
API Keys
| Method | Returns |
|---|---|
list_api_keys() |
list[ApiKeyListItem] |
create_api_key(role=..., team_id=None) |
ApiKeyResponse |
revoke_api_key(id) |
None |
Transparency Log
These methods do not require authentication.
| Method | Returns |
|---|---|
get_log_head() |
SignedTreeHead |
get_log_entry(index) |
LogEntry |
get_log_entries(start, end) |
list[LogEntry] |
get_inclusion_proof(index, tree_size) |
InclusionProof |
get_consistency_proof(old_size, new_size) |
ConsistencyProof |
Pagination
All list_* methods return a paginator that auto-fetches pages:
for cert in dp.list_certificates():
print(cert.id)
# async
async for cert in dp.list_certificates():
print(cert.id)
License
MIT
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file burnledger-0.8.0.tar.gz.
File metadata
- Download URL: burnledger-0.8.0.tar.gz
- Upload date:
- Size: 125.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.12.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
45838ae204463b3d940b004dda23039a42ace14829519fc2e417ef8d9081172b
|
|
| MD5 |
4ef8ac35dd6b027946bea17e54151e03
|
|
| BLAKE2b-256 |
f6cafabba00ae43403b33320784585ea267877ffd29ab55093962e791d6b4dfd
|
File details
Details for the file burnledger-0.8.0-py3-none-any.whl.
File metadata
- Download URL: burnledger-0.8.0-py3-none-any.whl
- Upload date:
- Size: 73.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.12.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
aa56a79835a0c6f86c632bc91089534328e71460c3b7c2921a44488311602aa1
|
|
| MD5 |
0b8b1ab6e2618a2d495947e8aab04d5e
|
|
| BLAKE2b-256 |
82c56259b3ba9de458561a40bc94c6f458f7ec51c0245830a023e91d0c975f86
|