Cryptographic verification for LLM API interactions
Project description
Keystamp
Keystamp lets you add a cryptographic seal of trust to any LLM API interaction, making your experiments trustworthy and reproducible.
Just prefix your existing Python code with keystamp sign, and Keystamp will:
- Transparently proxy all requests to LLM providers (OpenAI, Anthropic, etc.)
- Collect all requests and responses
- Create a cryptographically-signed transcript for every interaction
- Return the signed transcripts, while seamlessly executing your code.
These signed transcripts enable you to prove the authenticity of your LLM interactions to peers, reviewers, and the broader research community.
Why this Matters
Current research involving cloud-based frontier Large Language Models is virtually irreproducible. Models are regularly updated, and rapidly deprecated. Even making the same request to the same model results in different responses. Simultaneously, LLMs are starting to be used in research outside of computer science – particularly in the social sciences, in which reproducibility has recently been a major issue.
Keystamp aims to provide a layer of trust over raw text files, by signing off on LLM requests and responses as an independent third party. If you publish keystamped transcripts with your code, anyone can verify their digital signatures using our public key. This makes it easy to confirm that model interactions happened exactly as claimed, and hard to fabricate results by tampering with LLM responses.
Quickstart
Install Keystamp using pip install keystamp (Python 3.8+, MacOS & Linux), and instantly start signing your LLM requests:
$ keystamp sign [-m] your_script.py --your_args
That's it! Your signed transcripts will appear in transcripts/ by default. To verify saved transcripts:
$ keystamp verify transcripts/
Keystamp: Verifying transcripts at `transcripts`:
✅ OFFICIAL KEY: transcripts/2025-02-05/b11b4705ba2212a707c2478bfc58f...453.json
✅ OFFICIAL KEY: transcripts/2025-02-05/aaa9a654ac0bc9485ac1349debd79...db1.json
✅ OFFICIAL KEY: transcripts/2025-02-05/194a3f682a2b20abe4c5fc1729449...f2a.json
Verification successful: All transcripts verified!
Frequently Asked Questions
-
Free: We hope to offer this service to researchers for free indefinitely. This is a labor of love – please don't abuse our servers.
-
Rate limits: Keystamp is currently in early public beta. We are restricting usage to 100 requests every ten minutes, and have whitelisted a set of AI API providers. This should expand significantly as the project develops. If you'd like a larger limit and can show that you're working on research in any way (an .edu email is sufficient), please send us a message!
-
API support: Keystamp has been tested with OpenAI and Anthropic libraries, but should work with any Python package whose HTTP client uses the
HTTP_PROXYandSSL_CERT_FILEenvironment variables (e.g. httpx, aiohttp, urrlib3). -
Privacy: Unfortunately, the only way for Keystamp to provide a credible signature is by passing your requests through our signing server. This is required so that we can attest to the response at its source. However, we intentionally do not log the contents of requests and responses. We do log IP addresses and endpoint URLs, for the purposes of rate limiting and managing misuse. Our server code is available in full in this repository, and we'd welcome a routine third-party audit arrangement. (If you do this for a living, please reach out!)
-
Security: While Keystamp's design prioritizes security, this is ultimately a community project, with the primary goal of improving reproducibility in AI research. As such, we do not recommend sending personal, proprietary, or highly confidential information in prompts.
Documentation & Support
- 📚 Full Documentation: Coming soon
- 🐛 Report Issues
- 📧 Contact: @dcx
Contributing
We welcome contributions! Watch this space for a contributor's guide.
Citing Keystamp
If you use Keystamp in your research, we'd appreciate if you cited our project:
@software{keystamp2025,
author = {Chong, Derek and Shi, Weiyan and Goldstein, Josh A. and Tomz, Michael and Manning, Christopher D.},
title = {Keystamp: Cryptographic Verification for LLM Interactions},
year = {2025},
publisher = {GitHub},
url = {https://github.com/keystamp/keystamp}
}
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file keystamp-0.1.0.tar.gz.
File metadata
- Download URL: keystamp-0.1.0.tar.gz
- Upload date:
- Size: 24.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
022226a7c202799c1243dd1399a3176771333ebf8b2088af1d4200bc7cb571f5
|
|
| MD5 |
e8c75afa767d7deba0658457e34a6bfe
|
|
| BLAKE2b-256 |
1ce06a249c7fbcf0f91124485870f8c3ace408530a4ceb6d3bf9468ffe0e5196
|
File details
Details for the file keystamp-0.1.0-py3-none-any.whl.
File metadata
- Download URL: keystamp-0.1.0-py3-none-any.whl
- Upload date:
- Size: 25.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f726fe821666bd7edc0f8196622fbc2ea0f758e09ee1423eb302162a17bf4e6c
|
|
| MD5 |
6645cc4f08d2d13ff534bb9e864c4f5c
|
|
| BLAKE2b-256 |
e1f86f49b610d839b8161398ce68feba641abf7d2fb9d053efead29a2a8fc5ae
|