Skip to main content

inamprotocol (Python SDK)

Reference Python client for the INAM Protocol — parity with the TypeScript InamClient in ../sdk-js/src/client.ts. See ../SPEC.md for the full protocol specification.

Install (development)

python -m venv .venv
./.venv/Scripts/python.exe -m pip install -e . pytest   # Windows
# ./.venv/bin/python -m pip install -e . pytest          # macOS/Linux

Test

./.venv/Scripts/python.exe -m pytest -v

tests/test_interop.py is the important one: it checks this SDK's did:key encoding, canonical JSON, and Ed25519 signing against fixed values generated once by the TypeScript reference implementation (../scripts/interop-vectors.ts). If a change here ever breaks that test, a receipt signed by this SDK would stop verifying against a registry or another SDK written in a different language — that's the whole point of the test.

Usage

from inamprotocol import InamClient, generate_keypair

keypair = generate_keypair()
client = InamClient("http://localhost:4021", keypair)

profile = client.register_agent(["document-extraction"], {"name": "My Agent"})
print(profile["id"])  # did:key:z...

reputation = client.get_reputation(profile["id"])

Jobs (post -> offer -> accept -> execute -> receipt)

from datetime import datetime, timezone

now = datetime.now(timezone.utc).isoformat()
job = poster.post_job("document-extraction", "sha256:...")
worker.submit_offer(job["jobId"], "I can do this in an hour")
poster.accept_offer(job["jobId"], worker.did)

receipt = worker.submit_work(poster.did, {
    "jobId": job["jobId"],
    "task": {"capability": "document-extraction", "specHash": "sha256:...", "createdAt": now},
    "result": {"outputHash": "sha256:...", "completedAt": now},
    "verification": {"method": "payer_confirmation", "outcome": "success"},
})
poster.accept_work(receipt)  # finalizes the receipt and auto-completes the job

poster.cancel_job(job["jobId"]) cancels a not-yet-completed job (poster only); client.get_job(id) / client.search_jobs(capability=..., status=...) / client.list_offers(job_id) round out discovery.

External identity linking (challenge-response)

Linking a key-derived external identity (agentpass_id / aitp_id / passport_id; SPEC.md section 2.1) requires proving control of that external key via a single-use, ~60s challenge. a2a_endpoint isn't key-derived, so it skips straight to link_identity(protocol, value). ### Deciding whether to deal with an agent

check_trust turns an agent's reputation into allow, escrow (deal, but hold payment until delivery is confirmed), or deny, with the reasons. It runs on your side; the registry's numbers are a hint (SPEC.md §5.4).

from inamprotocol import check_trust

d = check_trust(did, client, allow={"min_evidence": "independently_verified", "min_trust_score": 5})
# {"decision": "escrow", "reasons": ["evidence countersigned is below independently_verified"], ...}

A revoked or unknown ID is deny; warning flags (in_dispute, attestation_rejected, nonperformance_reported, concentrated_counterparty) cap the decision at escrow (change with escrow_flags).

Verifying an x402 payee before paying

A payer pays only a payTo the payee's INAM ID proved control of (linked.erc8004_id), and only if its reputation meets the payer's policy (SPEC.md §11.2). counterparty_context records that decision as an x402 CounterpartyContext (x402 #1777), with policy_input_hash over the JCS form of exactly what was checked:

from inamprotocol import counterparty_context

agent, rep = client.get_agent(did), client.get_reputation(did)
request = {"resource": "https://paid.example/api", "amount": "1000", "network": "eip155:8453", "nonce": "req-0001"}
ctx = counterparty_context(agent, rep, [a["payTo"] for a in accepts], request, min_evidence="countersigned", min_trust_score=0)
# {"decision": "allow", "reason": "ok", "policy_input_hash": "sha256:...", ...}

decide_x402 is the decision alone and x402_policy_input the hashed input. Hashes and reasons match sdk-js byte for byte, checked against ../tests/vectors/x402-counterparty-context.json.

Publishing a receipt as ERC-8004 feedback

The receipt's requester can post it to ERC-8004's Reputation Registry from its linked erc8004_id (SPEC.md §11.1). The file carries the signed receipt, so readers can tell it from a bare score:

from inamprotocol import build_erc8004_feedback, verify_erc8004_feedback

fb = build_erc8004_feedback(receipt, requester_record, "eip155:8453:0x...", agent_id=42)
# host fb["file_text"] at feedbackURI, then send giveFeedback(**fb["args"], feedbackURI=...)

check = verify_erc8004_feedback(file_text, feedback_hash, client_address, client, value=100)
# {"valid": ..., "reasons": [...], "receipt_id": ..., "provider_did": ..., "provider_address": ...}

See examples/erc8004_demo.py.

See examples/interop_worker.py for this in a full running script.

# external_keypair stands in for whatever key AgentPass/AITP/Passport
# Alliance already issued this agent -- not an INAM keypair.
challenge = client.request_link_challenge("agentpass_id", to_base64(external_keypair.public_key), "ed25519")
proof = to_base64(sign(from_hex(challenge["challenge"]), external_keypair.private_key))
client.complete_link("agentpass_id", "ap_my_external_id", challenge["challengeId"], proof)

Verification (independent attestation)

A third party -- anyone but the receipt's own worker (agentB) -- can attest that a finalized receipt's output actually holds up (SPEC.md section 12), feeding a reputation boost:

verification = verifier_client.submit_verification(
    receipt_id=receipt["receiptId"],
    method="deterministic",  # or "agent_attestation"
    output_hash=receipt["result"]["outputHash"],
    result="verified",  # or "rejected"
)

verifier_client.get_verification(verification["verificationId"])
verifier_client.list_receipt_verifications(receipt["receiptId"])

See examples/interop_worker.py for a full worker-side flow (register, link an external identity, submit signed Execution Receipt drafts), and ../scripts/run-interop-demo.sh for the end-to-end cross-language demo (a TypeScript requester and this Python worker doing real business through the same live registry).

Metadata

Release files for inamprotocol 0.13.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for inamprotocol 0.13.0
File Size Uploaded
inamprotocol-0.13.0.tar.gz 37.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for inamprotocol 0.13.0
File Interpreter ABI Platform
inamprotocol-0.13.0-py3-none-any.whl Python 3 none any Details

Total release size: 65.4 kB

Release files / inamprotocol-0.13.0.tar.gz

Download URL inamprotocol-0.13.0.tar.gz
Size 37.1 kB
Tags Source
SHA-256 checksum
How to use checksums
b1f78b592ff6658c127e4f797ee3b50d3e27aa136ea0037e34b090f96a2f91b0
BLAKE2b-256 checksum
How to use checksums
89706b5effc5fe82fae8e040c717ca9895fc316538a743608fc001f5ea08643d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release files / inamprotocol-0.13.0-py3-none-any.whl

Download URL inamprotocol-0.13.0-py3-none-any.whl
Size 28.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7fd76c33946250a38c6536cd1847d20f9e5a8496e00c8705cd029a99ce8f48ae
BLAKE2b-256 checksum
How to use checksums
af88bf328cbbed883a82535574059ce13a2dedee0d1c22d462b197d881429e5e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.13.0 This release

2 release files

0.11.0

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.4

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page