langchain-alex
Verify signed ALEX Evidence Packages inside LangChain and LangGraph workflows. The verifier checks the package against a public key obtained separately from the evidence bundle and fails closed on unsupported schemas, signature failures, incomplete evidence, or inconsistent declared outcomes.
valid=True means that the evidence package passed verification and carries a verified outcome.
Authentic bundles documenting failed or inconclusive runs remain rejected; inspect reason and
outcome separately.
Requirements
- Python 3.10 or newer
- OpenSSL available as
opensslonPATH
Install
pip install langchain-alex
Verify an Evidence Package
from langchain_alex import AlexEvidenceVerifier
verifier = AlexEvidenceVerifier.from_key_files("alex-public-key.pem")
result = verifier.verify_file("evidence-bundle.json")
print(result.valid, result.reason, result.outcome)
The trust anchor is intentionally supplied separately. A public key embedded only in the bundle is not trusted.
LangChain tool
tool = verifier.as_tool()
result = tool.invoke({"bundle": evidence_bundle})
The tool returns a JSON-serializable object with valid, reason, bundle_id, schema_version,
outcome, and claim_ladder.
LangGraph node
from typing_extensions import TypedDict
from langgraph.graph import END, START, StateGraph
class State(TypedDict):
evidence_bundle: dict
alex_verification: dict
graph = StateGraph(State)
graph.add_node("alex_verify", verifier.as_langgraph_node())
graph.add_edge(START, "alex_verify")
graph.add_edge("alex_verify", END)
app = graph.compile()
result = app.invoke({"evidence_bundle": evidence_bundle})
assert result["alex_verification"]["valid"] is True
The node returns a state update and does not mutate its input state. Route on both valid and
outcome when the graph controls a consequential action.
Development
python -m pip install -e ".[dev]"
python -m pytest
ruff check .
python -m build
The verifier implementation is also used by the repository's standalone Python CLI at
tools/verify-bundle/verify.py; the integration does not maintain a second verdict algorithm.
Release files for langchain-alex 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| langchain_alex-0.1.0.tar.gz | 14.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| langchain_alex-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.8 kB
Release files / langchain_alex-0.1.0.tar.gz
| Download URL | langchain_alex-0.1.0.tar.gz |
|---|---|
| Size | 14.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
171ddfc59dfeec82b444bf1aed5a6909a918db0c751e45f0ab0549bfee2c2b9e
|
|
BLAKE2b-256 checksum How to use checksums |
287e17d14d442cfd5e8812a19d26bf22e392bdec6f5893f4e74ccceffe742653
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency logRelease files / langchain_alex-0.1.0-py3-none-any.whl
| Download URL | langchain_alex-0.1.0-py3-none-any.whl |
|---|---|
| Size | 15.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
edc586211b14b7e28dd9f653bafea5c3ce3e67ffa87986e04c1ee58c276a15d1
|
|
BLAKE2b-256 checksum How to use checksums |
a5c0e57927e067da908b96d90fffac929fd27a63f10af6518417828a79afd6ee
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 29, 2026.
Transparency log