Skip to main content

decidio (Python)

The one-line approval gate for AI-agent actions — the agent suspends for human approval and resumes, sealing a portable Authority Receipt the customer owns. Decidio gates (proceed | route | block) + records; the agent executes its own action on resume. Decidio never executes and holds no downstream credentials. Python-first, with a TS twin (@decidio/sdk) that emits an identical request + receipt (conformance-asserted).

from decidio import guard

# one line — same surface in every runtime
create_opp = guard.protect(
    create_opp_raw,
    lambda o: {"action": "createOpportunity", "amount": o["Amount"], "scope": "Opportunity"},
)
  • proceed → runs immediately (auto-approved under a named, versioned policy rule), sealed.
  • routesuspends (DecidioSuspended): parks the call args in an agent-side store, the process may exit; resumes when a human approves and re-runs your function.
  • block → raises DecidioBlocked; your function never runs.

Setup

pip install 'decidio[signing]'
export DECIDIO_API_URL=https://decidio-api.onrender.com   # the hosted sandbox
python -m decidio init my-agent   # sign in, register the agent, mint its API token, write .env

Every later command reads .env from the same directory. First run tip: pass mode="blocking" to guard.protect(...) to watch the whole loop live (trigger → route to a human → approve with python -m decidio approvals approve <id> → your function executes). A brand-new agent matches no auto-approve rule, so every request routes to a human — deny-by-default is the product working, not a misconfiguration. Other commands: doctor (config + connectivity + token scope), receipt <id> (download the sealed Authority Receipt). The core is stdlib-only; adapters and the verifier are extras.

Durable resume (real approvals take minutes to days)

Without mode="blocking", a routed action suspends: it parks its call args locally and raises DecidioSuspended; the process may exit. Self-serve transport — start here: guard.worker() — a durable poll worker that re-executes parked actions on approval, exactly once. No inbound URL, no shared secrets; this is the transport for the hosted sandbox.

Operator deployments can use the signed webhook instead — Decidio POSTs a verdict to your resume URL and the handler verifies the HMAC fail-closed:

# FastAPI
@app.post("/decidio/resume")
async def decidio_resume(req: Request):
    return guard.resume.handle(await req.body(), req.headers.get("x-decidio-signature"))

Honest requirement: webhook signing uses a shared secret configured on BOTH sides — your DECIDIO_WEBHOOK_SECRET must equal the Decidio server's, and self-hosted production also allow-lists resume hosts. Against the hosted sandbox, use the worker. Either way, re-execution is single-use (no double-write).

Engine adapters (durable suspend on the engine you already run)

Thin translators onto each engine's native durable wait — pip install decidio[langgraph|temporal|openai]:

# LangGraph — true drop-in (interrupt() is contextvar-based)
create_opp = guard.protect(create_opp_raw, describe, adapter="langgraph")

# Inngest / Temporal / OpenAI Agents — pass the engine handle:
await decidio.adapters.inngest.gate(step, guard, ctx, run=lambda: create_opp_raw(o))
await decidio.adapters.temporal.gate(wf, guard, ctx, run=..., )
resolved, pending = decidio.adapters.openai.gate_interruptions(guard, run_state, describe)

Own the record — verify it yourself

Every outcome is a sealed W3C-VC (Ed25519 did:key), tamper-evident and offline-verifiable with no Decidio dependency:

pip install decidio[verify]
python -m decidio.verify receipt.json

Invariants

Decidio never executes downstream / holds no downstream credentials (the only downstream touch is the opt-in, read-only read-back tier) · holds none of the parked payload · fail-closed signatures · single-use idempotent resume · deny-by-default policy · request-bound identity proof. The agent executes; Decidio gates, records, and signals.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

decidio-0.1.3.tar.gz (45.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

decidio-0.1.3-py3-none-any.whl (54.3 kB view details)

Uploaded Python 3

File details

Details for the file decidio-0.1.3.tar.gz.

File metadata

  • Download URL: decidio-0.1.3.tar.gz
  • Upload date:
  • Size: 45.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.14

File hashes

Hashes for decidio-0.1.3.tar.gz
Algorithm Hash digest
SHA256 2914de47a24edb4b42cc75538f7f553a6b2c2f2508bd61d30984d14b3823c7a5
MD5 ee6cde280fcd9b9f429c3a61e666827c
BLAKE2b-256 d20045b12b32bfc5897c9b58a2829bae191f7e74ce740a5c8cf647ac6f9023cc

See more details on using hashes here.

File details

Details for the file decidio-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: decidio-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 54.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.14

File hashes

Hashes for decidio-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 43cdad9e91d9240aa5b76e47652394cb7aaaeb48aaadf0abbd3e810489ae242d
MD5 850b747bfa59ae60c78fbb212313ae29
BLAKE2b-256 7b2be8734e0f39df2148fc174e319fdb018df07a636db9e7b0a03d0780059ae3

See more details on using hashes here.

Release history Release notifications | RSS feed

0.5.0

2 files

0.4.4

2 files

0.4.3

2 files

0.4.1

2 files

0.4.0

2 files

0.3.5

2 files

0.3.3

2 files

0.3.0

2 files

0.2.2

2 files

0.2.1

2 files

0.2.0

2 files

0.1.12

2 files

0.1.11

2 files

0.1.10

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

0.1.6

2 files

0.1.5

2 files

0.1.4

2 files

This release

0.1.3 This release

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page