Juntai IAM Contracts
juntai-iam-contracts is the language-neutral schema and conformance publication for Juntai peer-principal IAM. Humans, agents, and services are durable authorization peers. Authenticators, sessions, credentials, workloads, delegators, and channels remain separate context.
The package publishes JSON Schema Draft 2020-12 definitions for:
- Principal/v2, AgentPrincipal/v1, and AuthenticatorBinding/v1;
- DelegationGrant/v1, including user consent and operator creation evidence;
- IdentityContext/v2, safe principal presentation, and assisting-agent views;
- agent credential claims and audience-narrowing requests;
- protected-resource metadata for remote MCP and ordinary APIs;
- common evaluation requests, authorization decisions, and stable errors; and
- the exact unmodified Casdoor 3.125 AgentPrincipal record mapping. Casdoor
preserves the Application as token
sub, emits its publicclientIdas bothazpand standard credentialaud, and emits the logical platform audience, resource, and binding attributes through nativeJWT-CustomJwtItem[]configuration; the secret is never part of the contract.
The contracts/fixtures documents and contracts/conformance/authorization-cases.v1.json are canonical cross-language inputs. In delegated mode, evaluators must use current grantor authority intersected with the exact live grant and all remaining ceilings. Agent self grants are absent from that equation and must never be unioned.
This repository contains no listener, token issuer, network client, secret, database, policy or grant store, administration workflow, runtime registry, domain resource vocabulary, or authorization implementation. Casdoor owns durable persistence and primary OAuth issuance. Enforcement libraries and domains consume this exact release.
Install and verify
The wheel is a convenient immutable transport for the same neutral JSON files. Install version 1.1.1, install the test extra, then run ruff, pytest, and build.
Every release records schema and fixture SHA-256 checksums. Consumers must pin one immutable version and reject unsupported schemaVersion values.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file juntai_iam_contracts-1.1.1.tar.gz.
File metadata
- Download URL: juntai_iam_contracts-1.1.1.tar.gz
- Upload date:
- Size: 16.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cc7222c681b3db83acc0411f948a61a7c9a8f504dc9cd8d97853cf53867ffd14
|
|
| MD5 |
062d794addc37ba6f6079a37374726c9
|
|
| BLAKE2b-256 |
af71b199020ae8a9afe9d43c04988ed6cfff1d4fd0678456e026f603e7bd026f
|
Provenance
The following attestation bundles were made for juntai_iam_contracts-1.1.1.tar.gz:
Publisher:
publish-python.yml on zephytiju/JuntaiIAMContracts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
juntai_iam_contracts-1.1.1.tar.gz -
Subject digest:
cc7222c681b3db83acc0411f948a61a7c9a8f504dc9cd8d97853cf53867ffd14 - Sigstore transparency entry: 2537761966
- Sigstore integration time:
-
Permalink:
zephytiju/JuntaiIAMContracts@a37b6d6daaba75efd8c15c19b440a3081ba761c5 -
Branch / Tag:
refs/tags/v1.1.1 - Owner: https://github.com/zephytiju
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-python.yml@a37b6d6daaba75efd8c15c19b440a3081ba761c5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file juntai_iam_contracts-1.1.1-py3-none-any.whl.
File metadata
- Download URL: juntai_iam_contracts-1.1.1-py3-none-any.whl
- Upload date:
- Size: 26.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e1daa81386669cfbf74b119c73f822d80a2f5e7a64a187538c54dcff07643cf1
|
|
| MD5 |
cd6935e516e73ed20e707ea9d0235b43
|
|
| BLAKE2b-256 |
098fe638004a4d2bdb3de79666580ec30634463b628dc7ecde6c11267a0316aa
|
Provenance
The following attestation bundles were made for juntai_iam_contracts-1.1.1-py3-none-any.whl:
Publisher:
publish-python.yml on zephytiju/JuntaiIAMContracts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
juntai_iam_contracts-1.1.1-py3-none-any.whl -
Subject digest:
e1daa81386669cfbf74b119c73f822d80a2f5e7a64a187538c54dcff07643cf1 - Sigstore transparency entry: 2537762734
- Sigstore integration time:
-
Permalink:
zephytiju/JuntaiIAMContracts@a37b6d6daaba75efd8c15c19b440a3081ba761c5 -
Branch / Tag:
refs/tags/v1.1.1 - Owner: https://github.com/zephytiju
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-python.yml@a37b6d6daaba75efd8c15c19b440a3081ba761c5 -
Trigger Event:
push
-
Statement type: