Skip to main content

CLI helper: sign any event into your Etch audit chain from the command line.

Project description

etch-record

Small CLI helper. Signs any event into your Etch audit chain from the command line.

Built for the marketing-agent workflow: every research call, draft generation, review decision, and outreach send emits a signed event. Also usable standalone for any local activity you want notarized.

Latest: v0.10.0 — Wave 5 COMPLETE. Adds chain-of-custody export bundle (--custody-export-session + --custody-export-declaration-regime) with four regimes: FRE 902(11), 902(13), 902(14), and eIDAS qualified. Thirteen endpoints total now available on your Etch chain across Waves 1-5. See CHANGELOG.md.

Install

pip install etch-record

Or from a local checkout during development:

cd ~/etch-marketing/etch-record
pip install -e .

Configure

Set three env vars in your shell rc (~/.zshrc or ~/.bashrc):

export ETCH_PROJECT_ID="your_project_id"
export ETCH_APP_TOKEN="wm_your_app_token"
export ETCH_BASE_URL="https://etch.systems"   # default; override for local dev

Get project_id + app_token from your Etch signup provisioning page. ETCH_BASE_URL defaults to https://etch.systems if unset.

Use

# Simple event
etch-record "posted X thread about Etch's audit chain"

# With tags + evidence
etch-record "researched contact via Gemini" \
  --tags research,marketing \
  --evidence-json '{"contact":"...","dossier_lines":247}'

# Load evidence from a file
etch-record "drafted 3 message variants" \
  --tags draft,claude \
  --evidence-file drafts_evidence.json

# Group events under a session (default = today's ISO date)
etch-record "approved draft v2" --session-id outreach-2026-07-26 --tags review,approved

# Print what would be sent without hitting the API
etch-record "dry run test" --dry-run

Event shape

Every call becomes a signed record_event MCP tool call on your Etch chain:

  • event_type: "tool_call" (only enum value that works for arbitrary marketing events)
  • session_id: --session-id OR auto-generated as etch-record-YYYY-MM-DD
  • entities: derived from --tags
  • description: your quoted string (positional arg)
  • evidence: from --evidence-json or --evidence-file
  • success: true unless --failed

The Etch server appends to the SHA-256 Merkle chain, closes epochs at threshold (default 1024 events), hybrid-signs (Ed25519 + SLH-DSA-SHA2-128f), and optionally anchors to Sigstore Rekor + Bitcoin OpenTimestamps.

Verify

Every event is verifiable offline forever:

etch-verify \
  --base-url https://etch.systems \
  --project-id your_project_id

Governance metadata (Wave 1 #1, v0.2.0)

Attach a signed governance sub-record to any event. Any of the five flags below triggers a second call to POST /v1/etch-chain/governance-record on your Etch base URL, which hashes the governance object canonically and signs it into the Etch parallel chain.

etch-record "KYC decision on customer ABC" \
  --tags kyc,fintech,decision \
  --policy-hash sha256:9f8c... \
  --authority-file authority.json \
  --uncertainty '0.87:hash-lookup-match-rate' \
  --invalidation-file invalidation_conditions.json

authority.json:

{
  "identity": "compliance-officer@acme.example",
  "scope": ["fintech-kyc-decisions"],
  "expires_at": "2026-12-31T23:59:59Z"
}

invalidation_conditions.json:

[
  {"if": "SOP hash changes", "then": "re-approve required"}
]

Assumptions file uses the same shape:

[
  {"claim": "SOP v3.2 is current", "source_ref": "doc_hash:xyz"}
]

Output when both calls succeed:

OK  session=etch-record-2026-08-01  event_id=abc-def-123
OK  governance_seq=1  governance_hash=sha256:xyz...

The base event was recorded via the OSS chain; the governance sub-record was signed into the Etch parallel chain and cross-references the event by ID. Both chains verify offline via etch-verify (OSS) and etch-chain-verify (Etch).

Exit codes

  • 0 success (including two-call success when governance flags were set)
  • 1 config error (missing env vars)
  • 2 MCP record_event error
  • 3 unexpected exception
  • 4 rate limit (client-side sliding window)
  • 5 governance sub-record failed — the base event was recorded successfully; use the printed event_id to retry the governance call
  • 13 stop-condition sub-record failed
  • 14 postmortem sub-record failed
  • 15 cross-chain-reference sub-record failed
  • 16 hsm-attestation sub-record failed
  • 17 custody-export sub-record failed

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

etch_record-0.10.0.tar.gz (56.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

etch_record-0.10.0-py3-none-any.whl (40.9 kB view details)

Uploaded Python 3

File details

Details for the file etch_record-0.10.0.tar.gz.

File metadata

  • Download URL: etch_record-0.10.0.tar.gz
  • Upload date:
  • Size: 56.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for etch_record-0.10.0.tar.gz
Algorithm Hash digest
SHA256 1e1c8cd4dbe1d90e2967e3f6ce558e9c50a070bc0db3b1afab3bb2cb0fb0af87
MD5 9920ee7ce0cc9996e209db9c6eb51936
BLAKE2b-256 ae226cc1d9e9649464c5b8d26bce9ad343f695e7d631bbd3222a2483b200bfab

See more details on using hashes here.

Provenance

The following attestation bundles were made for etch_record-0.10.0.tar.gz:

Publisher: release.yml on SaravananJaichandar/etch-record

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file etch_record-0.10.0-py3-none-any.whl.

File metadata

  • Download URL: etch_record-0.10.0-py3-none-any.whl
  • Upload date:
  • Size: 40.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for etch_record-0.10.0-py3-none-any.whl
Algorithm Hash digest
SHA256 5f6627affba4886951bc92f082b49820d76dd0a3e6ee80c3ca5f05fed8d1060a
MD5 5459dc072855cc56256eeaf05917b549
BLAKE2b-256 b49ec5ff38ba387462d7582365bbf2e14ef099f693f94d3d8cff0b8b83f67ad4

See more details on using hashes here.

Provenance

The following attestation bundles were made for etch_record-0.10.0-py3-none-any.whl:

Publisher: release.yml on SaravananJaichandar/etch-record

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page