Skip to main content

A memory firewall for coding agents — thin Python SDK over the dent8 CLI's JSON contract.

Project description

dent8 (Python)

A memory firewall for coding agents — the thin Python SDK.

Every call runs the dent8 binary with --output json and returns the parsed payload as a dict. The wire contract is the product: each payload carries schema_version; every error carries a stable status plus a machine-readable code (insufficient-authority, authority-ceiling, content-rejected, …), raised as Dent8Rejected / Dent8Invalid so you branch on error.code, never on prose.

Because the CLI resolves the store itself (repo-confined .dent8/ discovery, DENT8_LOG / DENT8_STORE_URL), routes writes through a local daemon when DENT8_DAEMON_SOCKET is set, and defaults --source/--authority from the active signed grant, the SDK inherits all of it with zero configuration.

Writes above the agent tier (medium / high / canonical authority) require a valid signed identity: run dent8 init (which provisions one by default) and let the SDK inherit its DENT8_TRUST / DENT8_GRANT / DENT8_IDENTITY_KEY env, then write as that source:* identity. Agent-tier writes (low) need no identity.

Install

pip install dent8
cargo install dent8-cli --locked   # the binary the SDK drives

Use

from dent8 import Dent8, Dent8Rejected

d8 = Dent8()  # finds `dent8` on PATH; Dent8(binary=..., env={"DENT8_LOG": ...}) to pin

# A high-authority write is signed as the active `source:*` identity (from `dent8 init`).
d8.assert_fact("repo:myproj", "database", "postgres",
               authority="high", source="source:alice")

try:
    d8.supersede("repo:myproj", "database", "mysql",
                 authority="low", source="web:scrape")
except Dent8Rejected as rejection:
    assert rejection.code == "insufficient-authority"   # branch on the code

fact = d8.explain("repo:myproj", "database")
assert fact["value"]["text"] == "postgres"              # the firewall held

report = d8.verify()          # findings are a result: status ok | integrity_issues
disputes = d8.conflicts()     # status contested when live disputes exist

The belief surface maps 1:1 onto the CLI: assert_fact (Python keyword), supersede, contradict, retract, reinforce, expire, derive(basis=(subject, predicate)), explain, replay, facts, verify, conflicts. Temporal keywords accept the CLI's whole grammar — unix millis, "now", "-7d", RFC 3339, or a bare UTC date.

LangChain tools

pip install "dent8[langchain]" adds dent8.langchain, native LangChain StructuredTools over the belief surface (no MCP subprocess):

from dent8.langchain import dent8_tools
from langgraph.prebuilt import create_react_agent

tools = dent8_tools(source="source:agent", authority="low")
agent = create_react_agent(model, tools)

The tools expose what to record (subject, predicate, value); source and authority are your configuration, not LLM arguments, so the agent cannot escalate its own authority. A refused write returns as a tool result the agent reads and adapts to, not an exception. See examples/langchain.

For other frameworks (LlamaIndex, Vercel AI SDK, any MCP client), use the MCP server (dent8 mcp serve, over stdio / daemon / HTTP). This SDK core stays zero-dependency and is for programmatic access from Python code.

Test

cargo build -p dent8-cli
DENT8_BIN=../../target/debug/dent8 python -m pytest

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dent8-0.8.0.tar.gz (11.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dent8-0.8.0-py3-none-any.whl (9.0 kB view details)

Uploaded Python 3

File details

Details for the file dent8-0.8.0.tar.gz.

File metadata

  • Download URL: dent8-0.8.0.tar.gz
  • Upload date:
  • Size: 11.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for dent8-0.8.0.tar.gz
Algorithm Hash digest
SHA256 7b4810282aaa2be4490d4ef14e1915871c425c3b823293ae3df50345745f9c41
MD5 b55be23a8fd1c7595574fde91d72c58a
BLAKE2b-256 e4756574f151b50a9844035212db7ae93cb7fae9398559cb6b90b7bcedfcabb6

See more details on using hashes here.

Provenance

The following attestation bundles were made for dent8-0.8.0.tar.gz:

Publisher: release.yml on xyzzylabs/dent8

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file dent8-0.8.0-py3-none-any.whl.

File metadata

  • Download URL: dent8-0.8.0-py3-none-any.whl
  • Upload date:
  • Size: 9.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for dent8-0.8.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f6629f91fb5493e9309ab4599e5302f6fc5ac02d051e2520ca7287d75354ec4b
MD5 4e52a41650bde3b2fd05f3ba5aa0a6ae
BLAKE2b-256 7f89b744c1549fe0af7b819007bfc11dd3cf2f9fc065759758d0ca6200c4beb9

See more details on using hashes here.

Provenance

The following attestation bundles were made for dent8-0.8.0-py3-none-any.whl:

Publisher: release.yml on xyzzylabs/dent8

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page