Skip to main content

CapiscIO CLI

Catch bad agents before your users do.

PyPI version Python Versions License Downloads

CapiscIO CLI validates A2A agent cards, tests live endpoints, and blocks broken deployments — one command in your pipeline.

CLI secures your pipeline. Agent Guard secures your runtime.

Installation

pip install capiscio

Also available via npm: npm install -g capiscio

Quick Start

# Validate an agent card (local file or URL)
capiscio validate ./agent-card.json

# Validate a live agent endpoint
capiscio validate https://my-agent.example.com

# JSON output for CI pipelines
capiscio validate https://my-agent.example.com --json

# Strict mode — fail on warnings too
capiscio validate ./agent-card.json --strict

What It Checks

Check Description
Schema Agent card conforms to A2A specification
Signatures JWS badge signatures are valid
Endpoints Live agent responds correctly (--test-live)
Trust Level Badge trust level meets your threshold

Use Cases

  • Pre-commit hooks — Validate agent cards before you push
  • CI/CD gates — Block deployments with misconfigured agents (GitHub Action)
  • Vendor due diligence — Validate third-party agents before integration
  • Cron monitoring — Continuous health checks on agent endpoints

Dev & Testing Commands

The CLI also exposes badge and key management commands for local development and testing:

# Issue a self-signed badge (dev/testing only)
capiscio badge issue --self-sign

# Verify a badge
capiscio badge verify "$TOKEN"

# Generate a key pair
capiscio key gen

# Start the gateway sidecar
capiscio gateway start --port 8080 --target http://localhost:3000

For full CLI reference, see the capiscio-core documentation.

Wrapper Utilities

Command Description
capiscio --wrapper-version Display the version of this Python wrapper package
capiscio --wrapper-clean Remove the cached binary (forces re-download on next run)

How It Works

This package is a lightweight Python wrapper around capiscio-core (written in Go). On first run it downloads the correct binary for your platform — zero overhead after that.

  1. Detects your OS (Linux, macOS, Windows) and architecture (AMD64, ARM64)
  2. Downloads the binary to your user cache (with SHA-256 checksum verification)
  3. Replaces the Python process with the Go binary — native speed, no shim

Supported Platforms

  • macOS: AMD64 (Intel), ARM64 (Apple Silicon)
  • Linux: AMD64, ARM64
  • Windows: AMD64

Binary Integrity Verification

On first run, the wrapper downloads the capiscio-core binary and verifies its SHA-256 checksum against the published checksums.txt from the GitHub release.

Two failure modes exist:

  1. Checksum mismatch ("Binary integrity check failed"): The downloaded file does not match the published checksum. This indicates tampering or corruption and cannot be bypassed. Delete the cached binary and retry.

  2. Checksums unavailable ("checksums.txt could not be fetched" or "no entry for …"): The checksums file could not be downloaded or does not contain an entry for the platform binary. This can happen with pre-release versions or network issues. To bypass:

# Bypass only when checksums.txt is unavailable (not for mismatches)
export CAPISCIO_SKIP_CHECKSUM=true

Troubleshooting

"Permission denied" errors: Ensure your user has write access to the cache directory. You can reset the cache by running:

capiscio --wrapper-clean

"Binary not found" or download errors: If you are behind a corporate firewall, ensure you can access github.com.

"Binary integrity check failed": The downloaded binary does not match the published checksum — this may indicate a corrupted or tampered download. Delete the cached binary (capiscio --wrapper-clean) and retry. This error cannot be bypassed with CAPISCIO_SKIP_CHECKSUM.

"Checksum verification failed: checksums.txt could not be fetched": The checksums file is unavailable (network issue or pre-release version). You can set CAPISCIO_SKIP_CHECKSUM=true to proceed without verification, but only do this in development environments.

License

Apache-2.0

Related Packages

Package What it does Install
Agent Guard Runtime trust verification for A2A agents pip install capiscio-sdk
MCP Guard Trust enforcement for MCP tool servers pip install capiscio-mcp
capiscio-core Go library and full CLI reference go install

Documentation · Website · Platform

Metadata

Release files for capiscio 2.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for capiscio 2.7.0
File Size Uploaded
capiscio-2.7.0.tar.gz 68.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for capiscio 2.7.0
File Interpreter ABI Platform
capiscio-2.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 80.5 kB

Release files / capiscio-2.7.0.tar.gz

Download URL capiscio-2.7.0.tar.gz
Size 68.7 kB
Tags Source
SHA-256 checksum
How to use checksums
642899a15df50e6e1cc74de9e0b7f2a098a5fc045eb5cab67f02e37e50418938
BLAKE2b-256 checksum
How to use checksums
729460ac0a58dfefec5bad9061992d495a28a90022208227a58ce88cf03e5163
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 13, 2026.

Transparency log

Release files / capiscio-2.7.0-py3-none-any.whl

Download URL capiscio-2.7.0-py3-none-any.whl
Size 11.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
540303995f54024da87b956ac1736b7d1877df9371de66282a7d89bdd196a3c3
BLAKE2b-256 checksum
How to use checksums
06104d8ac252ea0374cb5214c13727947ff71e752efa28cccd1f899350e7e7d7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 13, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2.7.0 This release

2 release files

2.6.0

2 release files

2.5.0

2 release files

2.4.0

2 release files

2.3.1

2 release files

2.2.0

2 release files

2.1.3

2 release files

2.1.2

2 release files

2.0.0

2 release files

1.2.6

2 release files

1.2.5

2 release files

1.2.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page