Nuggets authority middleware for LangChain / LangGraph
Project description
langchain-nuggets
Authority middleware for LangChain / LangGraph — pre-execution trust enforcement on every tool call.
Wrap any ToolNode and the middleware calls the Nuggets authority endpoint before each tool executes. The backend evaluates a scoped delegation, returns an ALLOW or DENY decision, and signs an audit proof. Tools that aren't allowed never run.
Installation
pip install langchain-nuggets
For LangGraph Platform OIDC auth:
pip install langchain-nuggets[langgraph]
Authority Middleware
from langchain_nuggets.middleware import NuggetsAuthorityMiddleware, MiddlewareConfig
from langgraph.prebuilt import ToolNode
config = MiddlewareConfig(
api_url="https://accounts.nuggets.life",
oidc_issuer_url="https://auth.nuggets.life",
agent_id="did:web:auth.nuggets.life:your-agent-id",
controller_id="did:web:auth.nuggets.life:your-controller-id",
delegation_id="42",
agent_private_key="/secrets/agent-jwks.json",
)
middleware = NuggetsAuthorityMiddleware(config)
tool_node = ToolNode(
tools=your_tools,
wrap_tool_call=middleware.wrap_tool_call,
)
Execution model: Agent → Tool Call → Nuggets Authority Check → Allow/Deny → Emit Proof
Trust primitives enforced: Actor Identity, Authority (delegation), Policy, Intent, Consent, Accountability (provenance).
| Behaviour | Detail |
|---|---|
| ALLOW | Tool executes; cryptographic proof artifact emitted |
| DENY | Tool blocked; structured error returned with reason_code |
| ERROR | Fail closed — tool not executed |
To provision the agent identity, private key, and delegation referenced above, see the agent provisioning runbook.
Agent private key
The accounts portal generates an RS256 keypair at agent creation and lets you download the private key as a JWKS file. MiddlewareConfig.agent_private_key accepts:
- A filesystem path to a PEM, JWK JSON, or JWKS JSON file
- A raw PEM string
- A JWK or JWKS dict
The key is never transmitted; only the signed agent_proof JWS is sent.
Test mode
test_mode=True short-circuits the live auth flow during local development — every check returns ALLOW, no HTTP is made, and the emitted proof artifact is flagged as test-mode-unverifiable.
LangGraph Platform OIDC auth
from langchain_nuggets.langgraph import NuggetsAuth
nuggets = NuggetsAuth(issuer_url="https://auth.nuggets.life")
auth = nuggets.auth # pass to langgraph.json
Pre-built authorization helpers:
from langchain_nuggets.langgraph import require_scopes, ownership_filter
Self-hosted / private CA
Point the URLs at your own deployment and pass ca_cert to either constructor:
MiddlewareConfig(
api_url="https://nuggets.internal.example.com",
oidc_issuer_url="https://oidc.internal.example.com",
# ...
ca_cert="/etc/ssl/private-ca/nuggets-ca.pem",
)
Set verify_ssl=False to disable TLS verification (development only).
License
MIT
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file langchain_nuggets-0.6.0.tar.gz.
File metadata
- Download URL: langchain_nuggets-0.6.0.tar.gz
- Upload date:
- Size: 30.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f3e9b4585f0984f152b05ab315cf026052577e8480f0f253784561355b4c1ad1
|
|
| MD5 |
3f109ce9a7df16b8fdb8cf49fad033ab
|
|
| BLAKE2b-256 |
b3040660424bd07ad5b90dff7b7216ea9f9f06015d8e204a72098a5538968014
|
Provenance
The following attestation bundles were made for langchain_nuggets-0.6.0.tar.gz:
Publisher:
release-pypi.yml on NuggetsLtd/langchain-nuggets
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
langchain_nuggets-0.6.0.tar.gz -
Subject digest:
f3e9b4585f0984f152b05ab315cf026052577e8480f0f253784561355b4c1ad1 - Sigstore transparency entry: 1765636001
- Sigstore integration time:
-
Permalink:
NuggetsLtd/langchain-nuggets@3ce73dba8cc4cda593ddce2a8c66af740a826f6c -
Branch / Tag:
refs/tags/python-v0.6.0 - Owner: https://github.com/NuggetsLtd
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-pypi.yml@3ce73dba8cc4cda593ddce2a8c66af740a826f6c -
Trigger Event:
push
-
Statement type:
File details
Details for the file langchain_nuggets-0.6.0-py3-none-any.whl.
File metadata
- Download URL: langchain_nuggets-0.6.0-py3-none-any.whl
- Upload date:
- Size: 24.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1f2c86e77653d7493b73af082b9ce62b4364d1a84d51ebe042a4807d72d3a711
|
|
| MD5 |
52498bfb1b5ca6cf85ae5d654c61e93c
|
|
| BLAKE2b-256 |
63043ebe8a347e532329507c517b002addaa53f6f5fc856cbdda26b9d22564aa
|
Provenance
The following attestation bundles were made for langchain_nuggets-0.6.0-py3-none-any.whl:
Publisher:
release-pypi.yml on NuggetsLtd/langchain-nuggets
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
langchain_nuggets-0.6.0-py3-none-any.whl -
Subject digest:
1f2c86e77653d7493b73af082b9ce62b4364d1a84d51ebe042a4807d72d3a711 - Sigstore transparency entry: 1765636186
- Sigstore integration time:
-
Permalink:
NuggetsLtd/langchain-nuggets@3ce73dba8cc4cda593ddce2a8c66af740a826f6c -
Branch / Tag:
refs/tags/python-v0.6.0 - Owner: https://github.com/NuggetsLtd
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-pypi.yml@3ce73dba8cc4cda593ddce2a8c66af740a826f6c -
Trigger Event:
push
-
Statement type: