LlamaIndex Tools Integration: InsumerAPI
Wallet auth and condition-based access for LlamaIndex agents. Across 38 chains — read → evaluate → sign, returning an ECDSA-signed boolean your agent can verify offline against the public JWKS. Boolean, not balance: the API never exposes wallet holdings, only a signed yes-or-no against the conditions you configure.
Part of InsumerAPI. No secrets. No identity-first. No static credentials.
Installation
pip install llama-index-tools-insumer
# the Quickstart's agent additionally needs:
pip install llama-index-llms-openai
Quickstart
Get a key — no signup, no dashboard, no password. Two paths, both return an insr_live_... key instantly with 10 verification credits and 100 reads/day:
curl -X POST https://api.insumermodel.com/v1/keys/create \
-H "Content-Type: application/json" \
-d '{"email": "you@example.com", "appName": "my-agent", "tier": "free"}'
Or enter your email on insumermodel.com — the key appears inline. Already have a key? Manage it at insumermodel.com/developers/account/.
Then use the tool spec in any LlamaIndex agent:
import asyncio
from llama_index.core.agent.workflow import FunctionAgent
from llama_index.llms.openai import OpenAI
from llama_index.tools.insumer import InsumerToolSpec
insumer = InsumerToolSpec() # reads INSUMER_API_KEY; or pass api_key="insr_live_..."
agent = FunctionAgent(
tools=insumer.to_tool_list(),
llm=OpenAI(model="gpt-4o-mini"),
)
response = asyncio.run(agent.run(
"Does wallet 0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045 "
"hold at least 1 ETH on Ethereum?"
))
print(response)
The six tools
attest_wallet
Run wallet attestation against 1–10 conditions. Returns an ECDSA-signed verdict per condition plus a condition hash for tamper detection.
Supported condition types:
token_balance— ERC-20 / SPL / XRPL trust line / native BTC / TRC-20 / Stellar trustline / Sui-native ≥ thresholdnft_ownership— ERC-721/ERC-1155/XRPL NFToken holdingeas_attestation— EAS schema check (pass atemplatelikecoinbase_verified_accountor a rawschemaId)farcaster_id— Farcaster ID registered on Optimismratio_to_amount— self-scaling agent-spend rule: balance ≥multiple×amount(RPC EVM chains only)ratio_to_supply— share-of-supply rule: balance /totalSupply()≥minFraction, a fraction in (0, 1] (RPC EVM chains, ERC-20 only)
insumer.attest_wallet(
wallet="0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045",
conditions=[
{
"type": "token_balance",
"contractAddress": "native",
"chainId": 1,
"threshold": "1",
"decimals": 18,
"label": "ETH >= 1 on Ethereum", # a condition the example wallet reliably meets
},
],
)
token_balancethresholds are decimal strings — send"threshold": "100", not100. Keys created from 2026-06-10 sign withkid: insumer-attest-v2and reject a JSON number with a400(a string works on both v1 and v2 keys). This tool coerces a number to a string for you.
Response shape:
{
"ok": True,
"data": {
"attestation": {
"id": "ATST-...",
"pass": True,
"results": [...], # per-condition booleans + conditionHash
"passCount": 1,
"failCount": 0,
"attestedAt": "2026-04-16T...",
"expiresAt": "2026-04-16T...", # +30 min
},
"sig": "...", # ECDSA P-256 signature, base64 P1363
"kid": "insumer-attest-v2", # keys minted today; pre-cutover keys return insumer-attest-v1
"pqSig": "...", # ML-DSA-65 post-quantum companion signature, base64
"pqKid": "insumer-attest-pq1",
"jwt": "...", # only with format="jwt"; its ML-DSA-65 sibling pqJwt sits beside it
},
"meta": {"creditsRemaining": ..., "creditsCharged": 1, ...},
}
Since September 2026 every attest and trust response also carries an ML-DSA-65 post-quantum companion signature (pqSig, pqKid; pqJwt beside jwt) over the same bytes the classical kid selects. It is additive: sig and kid are unchanged. Trust responses carry kid: insumer-trust-v2 and pqKid: insumer-trust-pq1. insumer-verify 1.8.0 and later report the companion as a fifth verdict beside signature, condition hashes, freshness, and expiry.
Costs 1 credit per call (2 with proof="merkle" for EIP-1186 storage proofs).
get_trust_profile
Multi-dimensional wallet trust profile — stablecoins, governance, NFTs, staking, institutional stablecoins (plus Solana, XRPL, Bitcoin, Tron, Stellar, Sui when those wallet addresses are supplied). Returns a signed summary showing which dimensions have activity, without exposing raw balances. 44 base checks across 25 chains in 5 dimensions; up to 49 across 27 chains in 9 dimensions. A check whose chain wallet was not supplied stays in the signed profile with evaluated: false and is counted in notEvaluatedCount, never as a pass or a fail.
insumer.get_trust_profile(
wallet="0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045",
solana_wallet="...", # optional
xrpl_wallet="r...", # optional
bitcoin_wallet="bc1q...", # optional
tron_wallet="T...", # optional
stellar_wallet="G...", # optional
sui_wallet="0x...", # optional (64 hex chars)
)
Costs 3 credits per call (6 with proof="merkle").
list_compliance_templates
Discover pre-configured EAS compliance templates (Coinbase Verified Account, Coinbase Verified Country, Coinbase One, Gitcoin Passport, etc.). No API key required.
templates = insumer.list_compliance_templates()
# Use a template name directly in attest_wallet:
insumer.attest_wallet(
wallet="0x...",
conditions=[{"type": "eas_attestation", "template": "coinbase_verified_account"}],
)
get_jwks
Fetch the public JWKS used to sign attestation and trust responses. Enables offline verification of any result with a standard JWT/JOSE library. No API key required.
The set holds five entries over two keys: the ECDSA P-256 key under three kids, followed by the ML-DSA-65 post-quantum companion key under two RFC 9964 AKP entries (raw key in pub). Match on the kid or pqKid your response carries, never on position; treat an unknown kid as unverifiable. Values below are from the live file:
jwks = insumer.get_jwks()
# {
# "keys": [
# {"kty": "EC", "crv": "P-256",
# "x": "JtHPhDPnv8AfP0JSlGutxbOlxreV2Chey27Z76q3V2c",
# "y": "kn34HaxVSJfn8NxwNEBjjLkcrM_GDw1lgnqyADGuc4c",
# "use": "sig", "alg": "ES256", "kid": "insumer-attest-v1"},
# {..., "kid": "insumer-attest-v2"}, # same EC key; attest responses on current keys
# {..., "kid": "insumer-trust-v2"}, # same EC key; trust responses on current keys
# {"kty": "AKP", "alg": "ML-DSA-65", "use": "sig", "kid": "insumer-attest-pq1",
# "pub": "lWQSprOGRxWovc9LfqqiQtO6..."}, # 2603-char base64url ML-DSA-65 public key
# {..., "kid": "insumer-trust-pq1"} # same post-quantum key
# ]
# }
buy_api_key
Agentic commerce: let an agent purchase its own new API key on-chain with USDC or BTC. The transaction sender wallet becomes the registered identity. No email, no signup flow, no human in the loop. No API key required to call — the payment is the auth.
Pre-requisite: broadcast a USDC or BTC transfer to the platform wallet first, then submit the transaction hash here.
# After the agent broadcasts a 100 USDC transfer on Base to the platform wallet:
result = InsumerToolSpec().buy_api_key(
tx_hash="0xabc...",
chain_id=8453, # Base; use "solana", "bitcoin", or "tron" for those chains
app_name="my-agent",
amount=100.0, # USDC amount; not required for Bitcoin
)
new_key = result["data"]["key"] # insr_live_... — shown once, save it
One key per wallet — if the sending wallet already has a self-serve key, the API returns 409 and asks you to top up the existing key via buy_credits instead.
buy_credits
Top up credits on an existing API key (the one you passed to InsumerToolSpec) with a USDC or BTC payment. Same pattern: broadcast the transfer, submit the tx_hash.
insumer.buy_credits(
tx_hash="0xdef...",
chain_id=8453,
amount=100.0,
)
No key at all: x402 pay-per-call
This tool spec authenticates with an API key (free tier: 10 credits via POST /v1/keys/create, or on-chain purchase via buy_api_key). If your agent wants zero signup of any kind, the same core endpoints — POST /v1/attest, POST /v1/trust, POST /v1/trust/batch — also accept x402 payments directly: call with no credentials, receive a 402 quote, sign an EIP-3009 USDC authorization on Base for the exact quoted amount, retry with the X-PAYMENT header. $0.05 per attestation ($0.10 with a Merkle proof), settlement is gasless for the payer. That flow lives outside this package (it needs wallet signing, not an LLM tool), but the responses are identical — same signed attestations, verifiable against the same JWKS.
Pay-per-call wallets that reach $1.00 in cumulative spend become eligible to claim a soulbound Insumer Access pass (nothing mints unless the wallet asks — its first wallet-auth request is the claim), which unlocks prepaid credit rates ($0.04–$0.02/call) and single-round-trip calls. Details: insumermodel.com/llms.txt.
Supported chains
38 total:
- 32 EVM chains: Ethereum, Base, Arbitrum, Optimism, Polygon, Avalanche, BNB, XDC, Robinhood Chain, Unichain, Linea, zkSync, Scroll, Blast, Mantle, Celo, Gnosis, Sonic, Moonbeam, and more
- Solana (mainnet)
- XRPL (mainnet) — native XRP plus trust-line tokens
- Bitcoin (mainnet) — native BTC only
- Tron — native TRX plus TRC-20 (USDT-TRC20)
- Stellar — native XLM plus classic trustline assets (USDC, BENJI, etc.)
- Sui — native SUI plus Sui-native tokens (USDC)
Positioning
Wallet auth is the primitive. Condition-based access is the category. Token gating is one use case. The API turns a programmable predicate over on-chain state into a short-lived cryptographic artifact any service can verify.
- No secrets: conditions are public, the signature binds the condition hash.
- No identity-first: a wallet address and a condition are enough.
- No static credentials: every response has an expiry and is re-checkable.
Learn more
- Docs: insumermodel.com/developers/
- OpenAPI spec: insumermodel.com/openapi.yaml
- Public JWKS: api.insumermodel.com/.well-known/jwks.json
- Companion packages:
langchain-insumer(LangChain),mcp-server-insumer(Model Context Protocol),eliza-plugin-insumer(ElizaOS)
License
Apache-2.0
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file llama_index_tools_insumer-0.5.4.tar.gz.
File metadata
- Download URL: llama_index_tools_insumer-0.5.4.tar.gz
- Upload date:
- Size: 17.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
24dc7f38322f7a23674c88bd55becb3e23159d28d236b95b6ded0fbf26bd0fb6
|
|
| MD5 |
70055f577c2de73c6562e9d1f7ffa39d
|
|
| BLAKE2b-256 |
17591dfbda80142b0b80a51653c1a5f4d233f12e1945814edcfa09556418df45
|
File details
Details for the file llama_index_tools_insumer-0.5.4-py3-none-any.whl.
File metadata
- Download URL: llama_index_tools_insumer-0.5.4-py3-none-any.whl
- Upload date:
- Size: 18.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b0a764deec51ad0481f12c6bd1410ed42a5612556e89c583c2e4d743c1edfdfe
|
|
| MD5 |
5af8d763616cc24bb3a83c797f1463d2
|
|
| BLAKE2b-256 |
d2a7fd4fa06d02141159b9fbc38104bb3c823e14c6bfcdddd931b7be9c7f998f
|