A memory firewall for coding agents — thin Python SDK over the dent8 CLI's JSON contract.
Project description
dent8 (Python)
A memory firewall for coding agents — the thin Python SDK.
Every call runs the dent8 binary with
--output json and returns the parsed payload as a dict. The wire contract is
the product: each payload carries schema_version; every error carries a stable
status plus a machine-readable code (insufficient-authority,
authority-ceiling, content-rejected, …), raised as Dent8Rejected /
Dent8Invalid so you branch on error.code, never on prose.
Because the CLI resolves the store itself (repo-confined .dent8/ discovery,
DENT8_LOG / DENT8_STORE_URL), routes writes through a local daemon when
DENT8_DAEMON_SOCKET is set, and defaults --source/--authority from the
active signed grant, the SDK inherits all of it with zero configuration.
Install
pip install dent8
cargo install dent8-cli --locked # the binary the SDK drives
Use
from dent8 import Dent8, Dent8Rejected
d8 = Dent8() # finds `dent8` on PATH; Dent8(binary=..., env={"DENT8_LOG": ...}) to pin
d8.assert_fact("repo:myproj", "database", "postgres",
authority="high", source="user:alice")
try:
d8.supersede("repo:myproj", "database", "mysql",
authority="low", source="web:scrape")
except Dent8Rejected as rejection:
assert rejection.code == "insufficient-authority" # branch on the code
fact = d8.explain("repo:myproj", "database")
assert fact["value"]["text"] == "postgres" # the firewall held
report = d8.verify() # findings are a result: status ok | integrity_issues
disputes = d8.conflicts() # status contested when live disputes exist
The belief surface maps 1:1 onto the CLI: assert_fact (Python keyword), supersede,
contradict, retract, reinforce, expire, derive(basis=(subject, predicate)),
explain, replay, facts, verify, conflicts. Temporal keywords accept the CLI's
whole grammar — unix millis, "now", "-7d", RFC 3339, or a bare UTC date.
LangChain tools
pip install "dent8[langchain]" adds dent8.langchain, native LangChain StructuredTools
over the belief surface (no MCP subprocess):
from dent8.langchain import dent8_tools
from langgraph.prebuilt import create_react_agent
tools = dent8_tools(source="source:agent", authority="low")
agent = create_react_agent(model, tools)
The tools expose what to record (subject, predicate, value); source and authority are your configuration, not LLM arguments, so the agent cannot escalate its own authority. A refused write returns as a tool result the agent reads and adapts to, not an exception. See examples/langchain.
For other frameworks (LlamaIndex, Vercel AI SDK, any MCP client), use the MCP server
(dent8 mcp serve, over stdio / daemon / HTTP). This SDK core stays zero-dependency and is
for programmatic access from Python code.
Test
cargo build -p dent8-cli
DENT8_BIN=../../target/debug/dent8 python -m pytest
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file dent8-0.7.3.tar.gz.
File metadata
- Download URL: dent8-0.7.3.tar.gz
- Upload date:
- Size: 9.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
572185af6a05e42654408a076e2172edf52ade83b6b0afb16daae64601863793
|
|
| MD5 |
3050b5fc79d4b97a93e0b8cefa88c5b5
|
|
| BLAKE2b-256 |
6c17c40ecd45ac1d52c352b839fd880bc75ba1f8b3f5cb9c76e0f7af702e9c4d
|
Provenance
The following attestation bundles were made for dent8-0.7.3.tar.gz:
Publisher:
release.yml on xyzzylabs/dent8
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
dent8-0.7.3.tar.gz -
Subject digest:
572185af6a05e42654408a076e2172edf52ade83b6b0afb16daae64601863793 - Sigstore transparency entry: 2161002032
- Sigstore integration time:
-
Permalink:
xyzzylabs/dent8@8e29f8de546cd052c3c3d706b24b635aaeac47e3 -
Branch / Tag:
refs/tags/v0.7.3 - Owner: https://github.com/xyzzylabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@8e29f8de546cd052c3c3d706b24b635aaeac47e3 -
Trigger Event:
push
-
Statement type:
File details
Details for the file dent8-0.7.3-py3-none-any.whl.
File metadata
- Download URL: dent8-0.7.3-py3-none-any.whl
- Upload date:
- Size: 8.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cb6e511372c6db0febe364ac79939956bd7a1f36d084a0b3589a1f7caa32c276
|
|
| MD5 |
c64a3f283d175b8e6f77f696cad9e8d8
|
|
| BLAKE2b-256 |
4246250d52ea58285ad81015d48098c4e03db7d9150bf073f625fbb71e577837
|
Provenance
The following attestation bundles were made for dent8-0.7.3-py3-none-any.whl:
Publisher:
release.yml on xyzzylabs/dent8
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
dent8-0.7.3-py3-none-any.whl -
Subject digest:
cb6e511372c6db0febe364ac79939956bd7a1f36d084a0b3589a1f7caa32c276 - Sigstore transparency entry: 2161002362
- Sigstore integration time:
-
Permalink:
xyzzylabs/dent8@8e29f8de546cd052c3c3d706b24b635aaeac47e3 -
Branch / Tag:
refs/tags/v0.7.3 - Owner: https://github.com/xyzzylabs
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@8e29f8de546cd052c3c3d706b24b635aaeac47e3 -
Trigger Event:
push
-
Statement type: