Skip to main content

Typed declarative contracts for AI agent systems.

Project description

Contract4Agents

Contract4Agents banner

Contract4Agents is a free, open-source, typed contract language for building agent systems that are reviewable before they run and accountable afterward. The contract is the source of truth for agents, shared capabilities, authorization, composition, controls, quality criteria, and expected evidence. Target bindings supply only the framework-specific implementation details.

The product loop is:

Declare -> Compile -> Plan -> Materialize -> Run -> Trace -> Assure

That separation is the point. You can change a model, provider profile, or tool implementation without rewriting the portable agent design. Before execution, the plan shows exactly how the selected target will implement each requested semantic and blocks required guarantees it cannot honestly enforce. After execution, contract-bound traces and assurance results distinguish passed, violated, and unverified instead of treating missing evidence as success.

Quickstart

Install the core package and the OpenAI target:

pdm add "contract4agents[openai]"

To explore this repository's complete Incident Command example:

pdm install
pdm run python examples/incident-command/data/seed.py
pdm run contract4agents check examples/incident-command
pdm run contract4agents compile examples/incident-command --out .contract/build/incident-command
pdm run contract4agents plan examples/incident-command --target openai --profile test

The first two commands need no provider credentials and do not import or call application implementations. plan loads target bindings only far enough to validate coverage and safely inspect callable signatures; it does not construct agents or execute business code.

A Small Contract-First Team

Define portable types and a shared capability:

type SupportRequest:
    ticket_id: string
    question: string

type SupportReply:
    answer: string
    needs_follow_up: boolean

tool knowledge.search(query: string) -> SupportReply:
    description = "Search the approved support knowledge base."
    side_effect = false

Grant the capability to an agent. Availability, authorization, and execution are independent and explicit:

agent SupportResponder(request: SupportRequest) -> SupportReply:
    use knowledge.search:
        availability = enabled
        authorization = preapproved
        execution = host

    goal = "Answer the support request accurately."
    description = "Handles first-line support questions."
    guidance = [
        "Use only evidence returned by approved capabilities.",
        "Say when the available evidence is insufficient.",
    ]

Bind the portable name to one target implementation in contract4agents.targets.toml:

schema_version = "2"

[targets.openai]
adapter = "openai"

[targets.openai.tools."knowledge.search"]
python = "your_app.tools:search_knowledge"

[targets.openai.profiles.test]
default_model = "test-model"

[targets.openai.profiles.production]
default_model = "gpt-5.2"

Every target declares at least one named profile. Each profile is complete: a default_model or explicit per-agent model selects a model for every canonical agent, and stale agent overrides are rejected. The binding does not repeat prompts, permissions, schemas, agent factories, or controls. Those remain contract-owned.

Inspect Before Construction

Compile provider-neutral artifacts and review the resolved target plan:

contract4agents check agent_contracts
contract4agents compile agent_contracts --out .contract/build
contract4agents generate agent_contracts --out .contract/generated
contract4agents plan agent_contracts --target openai --profile production \
  --out .contract/build/production-plan.json

check remains provider-neutral when no target-binding file exists. When the file is present, it also validates every declared target and named profile. Compilation produces deterministic canonical IR, its digest, JSON Schemas, audience-safe instructions, reviewer documentation, and generated Pydantic, TypeScript, and Zod types. compile --check and generate --check make stale generated artifacts a CI failure.

The plan resolves models, bindings, grants, approvals, composition, controls, isolation mechanisms, host obligations, and expected telemetry. Each mapping is reported as exact, host_enforced, emulated, degraded, or unsupported. Required degraded or unsupported guarantees fail closed.

Materialize Normal Framework Objects

Contract4Agents constructs the complete native agent graph at runtime:

from agents import Runner
from contract4agents import materialize

result = materialize(
    "agent_contracts",
    target="openai",
    profile="production",
)

support_agent = result.agents["SupportResponder"]
reviewed_plan = result.plan
run_result = await Runner.run(support_agent, input="Where is my order?")

result.agents contains ordinary OpenAI Agents SDK Agent objects. Generated output types, host tools, approval hooks, delegations, and handoffs are wired from the contract graph and target bindings; host code does not maintain a parallel agent registry.

The host still owns credentials, approval decisions and UI, persistence, external services, and deterministic application workflow. Contract4Agents is not a general workflow language and does not hide provider differences.

Evidence, Evals, and Assurance

The normalized trace schema binds every event to a contract digest, plan digest, stable semantic IDs, provider-native correlation, provenance, and audience-safe redaction metadata. The same control assessor is used for controlled evals and imported production traces.

.eval files name scenarios and expectations. The target/profile eval workflow derives its agent, capability, grant, control, and telemetry inventory from the contract and plan; users do not restate the runtime in a fixture manifest. Repeated campaigns report pass, violation, and unverified rates with uncertainty, latency and cost summaries, thresholds, and optional baseline comparisons.

Assurance bundles join the canonical contract, materialization plan, normalized traces, control results, eval summaries, and semantic diffs into one portable review package. Missing or incomplete evidence remains explicitly unverified. This is useful evidence for compliance and release review; it is not a legal certification by itself.

Public Examples

  • Incident Command is the recommended first read. It demonstrates shared capabilities, different authorization grants, explicit context origins, generated delegations, controls, target bindings, and deterministic eval data.
  • Multi-Lens Research demonstrates a larger delegation graph, typed workflow boundaries, and an explicit isolation profile.
  • Market Research Brief demonstrates host tools alongside a provider-native web-search binding.

See the examples guide for the common project structure.

Documentation

The semantic model is the detailed architecture specification. Coding agents should begin with AGENTS.md.

Development

pdm install
pdm run docs-check
pdm run validate
pdm build

Normal local checks do not require an API key. Opt-in OpenAI live checks are documented in Validation and Quality Gates.

License

MIT. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

contract4agents-0.9.0.tar.gz (139.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

contract4agents-0.9.0-py3-none-any.whl (177.3 kB view details)

Uploaded Python 3

File details

Details for the file contract4agents-0.9.0.tar.gz.

File metadata

  • Download URL: contract4agents-0.9.0.tar.gz
  • Upload date:
  • Size: 139.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for contract4agents-0.9.0.tar.gz
Algorithm Hash digest
SHA256 736b16754e0f16cb6ce9c51f49912748042ee8eb0f020b54206f6654e8648168
MD5 12ad1589b33d2a7551313456aeaccd9a
BLAKE2b-256 f48b7aa2c2421e0e9b56715662822a8edb808ae16d38b96f7f8918a04b6f6a0f

See more details on using hashes here.

Provenance

The following attestation bundles were made for contract4agents-0.9.0.tar.gz:

Publisher: python-publish.yml on btfranklin/contract4agents

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file contract4agents-0.9.0-py3-none-any.whl.

File metadata

  • Download URL: contract4agents-0.9.0-py3-none-any.whl
  • Upload date:
  • Size: 177.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for contract4agents-0.9.0-py3-none-any.whl
Algorithm Hash digest
SHA256 622505ac43ca5846835834c54bf76b8140d8c42f49278b173398e35838d7ee71
MD5 af08506983ac560e84875d7cb636a92c
BLAKE2b-256 0d9d655b5a15846797b711107c2cfb924b2caeba4ea54117a1236195c9831227

See more details on using hashes here.

Provenance

The following attestation bundles were made for contract4agents-0.9.0-py3-none-any.whl:

Publisher: python-publish.yml on btfranklin/contract4agents

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page