Skip to main content

CLI helper: sign any event into your Etch audit chain from the command line.

Project description

etch-record

Small CLI helper. Signs any event into your Etch audit chain from the command line.

Built for the marketing-agent workflow: every research call, draft generation, review decision, and outreach send emits a signed event. Also usable standalone for any local activity you want notarized.

Latest: v0.2.0 — Wave 1 #1 governance flags (--policy-hash, --authority-file, --assumptions-file, --uncertainty, --uncertainty-file, --invalidation-file) attach a signed governance sub-record on the Etch parallel chain. See CHANGELOG.md.

Install

pip install etch-record

Or from a local checkout during development:

cd ~/etch-marketing/etch-record
pip install -e .

Configure

Set three env vars in your shell rc (~/.zshrc or ~/.bashrc):

export ETCH_PROJECT_ID="your_project_id"
export ETCH_APP_TOKEN="wm_your_app_token"
export ETCH_BASE_URL="https://etch.systems"   # default; override for local dev

Get project_id + app_token from your Etch signup provisioning page. ETCH_BASE_URL defaults to https://etch.systems if unset.

Use

# Simple event
etch-record "posted X thread about Etch's audit chain"

# With tags + evidence
etch-record "researched contact via Gemini" \
  --tags research,marketing \
  --evidence-json '{"contact":"...","dossier_lines":247}'

# Load evidence from a file
etch-record "drafted 3 message variants" \
  --tags draft,claude \
  --evidence-file drafts_evidence.json

# Group events under a session (default = today's ISO date)
etch-record "approved draft v2" --session-id outreach-2026-07-26 --tags review,approved

# Print what would be sent without hitting the API
etch-record "dry run test" --dry-run

Event shape

Every call becomes a signed record_event MCP tool call on your Etch chain:

  • event_type: "tool_call" (only enum value that works for arbitrary marketing events)
  • session_id: --session-id OR auto-generated as etch-record-YYYY-MM-DD
  • entities: derived from --tags
  • description: your quoted string (positional arg)
  • evidence: from --evidence-json or --evidence-file
  • success: true unless --failed

The Etch server appends to the SHA-256 Merkle chain, closes epochs at threshold (default 1024 events), hybrid-signs (Ed25519 + SLH-DSA-SHA2-128f), and optionally anchors to Sigstore Rekor + Bitcoin OpenTimestamps.

Verify

Every event is verifiable offline forever:

etch-verify \
  --base-url https://etch.systems \
  --project-id your_project_id

Governance metadata (Wave 1 #1, v0.2.0)

Attach a signed governance sub-record to any event. Any of the five flags below triggers a second call to POST /v1/etch-chain/governance-record on your Etch base URL, which hashes the governance object canonically and signs it into the Etch parallel chain.

etch-record "KYC decision on customer ABC" \
  --tags kyc,fintech,decision \
  --policy-hash sha256:9f8c... \
  --authority-file authority.json \
  --uncertainty '0.87:hash-lookup-match-rate' \
  --invalidation-file invalidation_conditions.json

authority.json:

{
  "identity": "compliance-officer@acme.example",
  "scope": ["fintech-kyc-decisions"],
  "expires_at": "2026-12-31T23:59:59Z"
}

invalidation_conditions.json:

[
  {"if": "SOP hash changes", "then": "re-approve required"}
]

Assumptions file uses the same shape:

[
  {"claim": "SOP v3.2 is current", "source_ref": "doc_hash:xyz"}
]

Output when both calls succeed:

OK  session=etch-record-2026-08-01  event_id=abc-def-123
OK  governance_seq=1  governance_hash=sha256:xyz...

The base event was recorded via the OSS chain; the governance sub-record was signed into the Etch parallel chain and cross-references the event by ID. Both chains verify offline via etch-verify (OSS) and etch-chain-verify (Etch).

Exit codes

  • 0 success (including two-call success when governance flags were set)
  • 1 config error (missing env vars)
  • 2 MCP record_event error
  • 3 unexpected exception
  • 4 rate limit (client-side sliding window)
  • 5 governance sub-record failed — the base event was recorded successfully; use the printed event_id to retry the governance call

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

etch_record-0.2.1.tar.gz (26.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

etch_record-0.2.1-py3-none-any.whl (17.8 kB view details)

Uploaded Python 3

File details

Details for the file etch_record-0.2.1.tar.gz.

File metadata

  • Download URL: etch_record-0.2.1.tar.gz
  • Upload date:
  • Size: 26.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for etch_record-0.2.1.tar.gz
Algorithm Hash digest
SHA256 c78c9a8f4fdd7b8ff8a792e6e000da951818b8ebfd9e9ab8492a6f6729cb06c3
MD5 21bae2657a1b9c25d71e62f50ec6c359
BLAKE2b-256 86a3b769ca4c45ac10e9c2d0ebf722436b6cfb4893ca2c7604b76c9b68afc494

See more details on using hashes here.

Provenance

The following attestation bundles were made for etch_record-0.2.1.tar.gz:

Publisher: release.yml on SaravananJaichandar/etch-record

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file etch_record-0.2.1-py3-none-any.whl.

File metadata

  • Download URL: etch_record-0.2.1-py3-none-any.whl
  • Upload date:
  • Size: 17.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for etch_record-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 1a2c42b92d8bf060f836c5702c9c8e72ed78d88f616730b2119022e0bf8c1921
MD5 0ed7a205133447e9419b3fc37287fe22
BLAKE2b-256 31581a21b22dec0b0ef16e0c07a7f91320042a1ddeb1c0efdf36d81e2966a8da

See more details on using hashes here.

Provenance

The following attestation bundles were made for etch_record-0.2.1-py3-none-any.whl:

Publisher: release.yml on SaravananJaichandar/etch-record

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page