Skip to main content

Typed declarative contracts for AI agent systems.

Project description

Contract4Agents

Contract4Agents banner

Contract4Agents is a free, open-source, typed contract language for building agent systems that are reviewable before they run and accountable afterward. The contract is the source of truth for agents, shared capabilities, authorization, composition, controls, quality criteria, and expected evidence. Target bindings supply only the framework-specific implementation details.

The product loop is:

Declare -> Compile -> Plan -> Materialize -> Run -> Trace -> Assure

That separation is the point. You can change a model, provider profile, or tool implementation without rewriting the portable agent design. Before execution, the plan shows exactly how the selected target will implement each requested semantic and blocks required guarantees it cannot honestly enforce. After execution, contract-bound traces and assurance results distinguish passed, violated, and unverified instead of treating missing evidence as success.

Quickstart

Install the core package and the OpenAI target:

pdm add "contract4agents[openai]"

To explore this repository's complete Incident Command example:

pdm install
pdm run python examples/incident-command/data/seed.py
pdm run contract4agents check examples/incident-command
pdm run contract4agents compile examples/incident-command --out .contract/build/incident-command
pdm run contract4agents plan examples/incident-command --target openai --profile test

The first two commands need no provider credentials and do not import or call application implementations. plan loads target bindings only far enough to validate coverage and safely inspect callable signatures; it does not construct agents or execute business code.

A Small Contract-First Team

Define portable types and a shared capability:

type SupportRequest:
    ticket_id: string
    question: string

type SupportReply:
    answer: string
    needs_follow_up: boolean

tool knowledge.search(query: string) -> SupportReply:
    description = "Search the approved support knowledge base."
    side_effect = false

Grant the capability to an agent. Availability, authorization, and execution are independent and explicit:

agent SupportResponder(request: SupportRequest) -> SupportReply:
    use knowledge.search:
        availability = enabled
        authorization = preapproved
        execution = host

    goal = "Answer the support request accurately."
    description = "Handles first-line support questions."
    guidance = [
        "Use only evidence returned by approved capabilities.",
        "Say when the available evidence is insufficient.",
    ]

Bind the portable name to one target implementation in contract4agents.targets.toml:

schema_version = "2"

[targets.openai]
adapter = "openai"

[targets.openai.tools."knowledge.search"]
python = "your_app.tools:search_knowledge"

[targets.openai.profiles.test]
default_model = "test-model"

[targets.openai.profiles.production]
default_model = "gpt-5.2"

Every target declares at least one named profile. Each profile is complete: a default_model or explicit per-agent model selects a model for every canonical agent, and stale agent overrides are rejected. The binding does not repeat prompts, permissions, schemas, agent factories, or controls. Those remain contract-owned.

Inspect Before Construction

Compile provider-neutral artifacts and review the resolved target plan:

contract4agents check agent_contracts
contract4agents compile agent_contracts --out .contract/build
contract4agents plan agent_contracts --target openai --profile production \
  --out .contract/build/production-plan.json

check remains provider-neutral when no target-binding file exists. When the file is present, it also validates every declared target and named profile. Compilation produces deterministic canonical IR, its digest, JSON Schemas, audience-safe instructions, reviewer documentation, and generated Pydantic, TypeScript, and Zod types. compile --check makes stale review artifacts a CI failure. Run generate separately only when application code imports generated source; generate --check then protects that machine-owned directory.

The plan resolves models, bindings, grants, approvals, composition, controls, isolation mechanisms, host obligations, and expected event types. Each mapping is reported as exact, host_enforced, emulated, degraded, or unsupported. Required degraded or unsupported guarantees fail closed.

Materialize Normal Framework Objects

Contract4Agents constructs the complete native agent graph at runtime:

from agents import Runner
from contract4agents import materialize

result = materialize(
    "agent_contracts",
    target="openai",
    profile="production",
)

support_agent = result.agents["SupportResponder"]
reviewed_plan = result.plan
run_result = await Runner.run(support_agent, input="Where is my order?")

result.agents contains ordinary OpenAI Agents SDK Agent objects. Generated output types, host tools, approval hooks, delegations, and handoffs are wired from the contract graph and target bindings; host code does not maintain a parallel agent registry.

The host still owns credentials, approval decisions and UI, persistence, external services, and deterministic application workflow. Contract4Agents is not a general workflow language and does not hide provider differences.

Evidence, Evals, and Assurance

The normalized trace schema binds every event to a contract digest, plan digest, stable semantic IDs, provider-native correlation, provenance, and audience-safe redaction metadata. Identity-bound closure evidence records which attempts, provider responses, and instrumentation channels were completely observed at an exact ordered trace frontier. OpenAI sessions expose consistent non-closing snapshots, validated cross-session retry continuation, and disposable router bindings. The same control assessor is used for controlled evals and imported production traces.

Run specs have a separate post-run assessor for host-supplied stage outputs, derived values, cardinality, assertions, and explicit workflow-completeness evidence. Controls and run specs remain distinct assurance results. Retried invocations can carry portable attempt identity and an explicit selected terminal attempt without moving retry or recovery decisions out of host code.

.eval files name scenarios and expectations. The target/profile eval workflow derives its agent, capability, grant, control, and event-type inventory from the contract and plan; users do not restate the runtime in a fixture manifest. Repeated campaigns report pass, violation, and unverified rates with uncertainty, latency and cost summaries, thresholds, and optional baseline comparisons.

Assurance bundles join the canonical contract, materialization plan, normalized traces, trace closure, control results, eval summaries, and semantic diffs into one portable review package. Missing or incomplete evidence remains explicitly unverified. This is useful evidence for compliance and release review; it is not a legal certification by itself.

Public Examples

  • Incident Command is the recommended first read. It demonstrates shared capabilities, different authorization grants, explicit context origins, generated delegations, controls, target bindings, and deterministic eval data.
  • Multi-Lens Research demonstrates a larger delegation graph, typed workflow boundaries, and an explicit isolation profile.
  • Market Research Brief demonstrates host tools alongside a provider-native web-search binding.

See the examples guide for the common project structure.

Documentation

The semantic model is the detailed architecture specification. Coding agents should begin with AGENTS.md.

Development

pdm install
pdm run docs-check
pdm run validate
pdm build

Normal local checks do not require an API key. Opt-in OpenAI live checks are documented in Validation and Quality Gates.

License

MIT. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

contract4agents-0.12.1.tar.gz (163.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

contract4agents-0.12.1-py3-none-any.whl (207.7 kB view details)

Uploaded Python 3

File details

Details for the file contract4agents-0.12.1.tar.gz.

File metadata

  • Download URL: contract4agents-0.12.1.tar.gz
  • Upload date:
  • Size: 163.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for contract4agents-0.12.1.tar.gz
Algorithm Hash digest
SHA256 c4e29b6dff252cb801e352df02fd459103d2867920127c7cb76465256b4442f2
MD5 fd8712a35c9fccace4c4e1f6a1469665
BLAKE2b-256 b8179a340eb96caca0714ffd6cc49f07802ce9e4eb3c7be635a18fec6f9a7bfb

See more details on using hashes here.

Provenance

The following attestation bundles were made for contract4agents-0.12.1.tar.gz:

Publisher: python-publish.yml on btfranklin/contract4agents

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file contract4agents-0.12.1-py3-none-any.whl.

File metadata

File hashes

Hashes for contract4agents-0.12.1-py3-none-any.whl
Algorithm Hash digest
SHA256 87e542f1e0a1daa13e7324362316f499a4a67322b1e01e802bac73b8e0572041
MD5 9cd61a7867a54942abc824cc62e73c76
BLAKE2b-256 44955fea38979a1b8a4ae1a0a763187927db1e21e131c4b174b771b64aa5c129

See more details on using hashes here.

Provenance

The following attestation bundles were made for contract4agents-0.12.1-py3-none-any.whl:

Publisher: python-publish.yml on btfranklin/contract4agents

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page