fipsign-sdk
Post-quantum signing SDK for Python. Signs and verifies any payload using ML-DSA-65 (NIST FIPS 204) — resistant to Shor's algorithm, standardized by NIST in August 2024.
Not just for auth. Sign users, orders, documents, devices, AI agents, events — any entity that needs a tamper-proof, quantum-resistant signature.
📖 Full documentation, API reference, and guides →
Install
pip install fipsign-sdk
For async support (httpx-based):
pip install fipsign-sdk[async]
Quick start
- Create a free account at app.fipsign.dev.
- In the dashboard, create a project, then create an API key inside it. Save the key — it won't be shown again.
- Use it:
from fipsign import PQAuth
pq = PQAuth("pqa_your_api_key")
result = pq.sign("user_123", role="admin")
token = result.token
verified = pq.verify(token)
if not verified.valid:
raise PermissionError("invalid token")
print(verified.payload["sub"]) # "user_123"
That's signing and verifying. The SDK also covers async usage (AsyncPQAuth), Flask/FastAPI middleware, offline (in-memory) verification, revocation, webhooks, and a full Certificate Authority module (PQCert + X.509) for issuing post-quantum certificates to devices and services — all in the developer guide.
Mandate — authorization for AI agents
Give an agent a bounded, revocable credential: which actions it may perform, how much it may spend, and until when. Check every action with one call, and suspend or revoke the mandate at any time.
result = pq.mandate.emit(
agent_id="agent-reporting-v2",
issued_by="user@empresa.com",
scope=["read:crm", "send_reply"],
budget_total=1000,
expires_in_seconds=28800,
)
check = pq.mandate.verify(result.mandate.token, "send_reply", 1)
if check.result != "granted":
raise PermissionError(check.reason)
To make a copied token useless on its own, emit the mandate with the agent's public key (agent_public_key=): the agent then signs every call with its private key (generate_agent_key_pair() and sign_agent_call()). Details in the Mandate section of the guide.
Why ML-DSA-65?
JWT with RS256/ES256 and standard OAuth tokens rely on ECDSA or RSA — both breakable by Shor's algorithm on a sufficiently powerful quantum computer. ML-DSA-65 is based on lattice problems (Module-LWE / Module-SIS) with no known quantum speedup. Standardized by NIST in August 2024 as FIPS 204.
Links
- 📖 Developer guide — full API reference, error codes, webhooks, CA/X.509
- Dashboard: app.fipsign.dev
- API status: status.fipsign.dev
- NIST FIPS 204: csrc.nist.gov/pubs/fips/204/final
Metadata
Release files for fipsign-sdk 0.12.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fipsign_sdk-0.12.0.tar.gz | 45.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fipsign_sdk-0.12.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 95.0 kB
Release files / fipsign_sdk-0.12.0.tar.gz
| Download URL | fipsign_sdk-0.12.0.tar.gz |
|---|---|
| Size | 45.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2dd966993a9ccee270018eabad30c1f2b22315eb77490cab3d90dc3122a9434d
|
|
BLAKE2b-256 checksum How to use checksums |
4ad9e0d65a966dc49a9f1b4344650e84db4d038c0c05029f28337d9d6bd3899b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.2
|
Release files / fipsign_sdk-0.12.0-py3-none-any.whl
| Download URL | fipsign_sdk-0.12.0-py3-none-any.whl |
|---|---|
| Size | 49.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a57adb7602646923a5b2f4de45b606782b9d012f0270a4a6b6d757083215a051
|
|
BLAKE2b-256 checksum How to use checksums |
1af6712e6181684d3ac736c2215750a2343042c9c06861fac864bdbc3a6c4425
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.2
|