Skip to main content

Cryptographic receipts for AI agent tool calls

Project description

manifest-sdk

Cryptographic receipts for AI agent tool calls — Python SDK.

Pure Python implementation of the manifest receipt format. Generates receipts that are byte-for-byte verifiable by the Rust CLI.

Install

pip install manifest-sdk

Quick Start

from manifest_sdk import Manifest

m = Manifest(identity="my-agent", db="receipts.db")

receipt = m.record(
    tool="send_email",
    input={"to": "bob@example.com", "subject": "Hello"},
    output={"status": "sent"}
)

print(receipt.id)                    # urn:uuid:...
print(receipt.proof.signature)       # ed25519:...
print(receipt.content_hash())        # sha256:...

Features

  • Ed25519 signing — Key generation, signing, verification (32-byte seed files)
  • Merkle tree — Append-only tree matching the Rust implementation
  • Policy evaluation — Tool allowlists, spending limits, PII detection
  • SQLite storage — Same schema as the Rust CLI (cross-readable)
  • Receipt chaining — Each receipt links to the previous via content hash
  • JSON-LD receipts — Same format as the MCP proxy

Advanced Usage

from manifest_sdk import (
    AgentIdentity, IdentitySource, Action, Delta,
    ReceiptBuilder, Signer, MerkleTree, Storage, PolicyConfig,
)

# Manual control over each component
signer = Signer.generate()
merkle = MerkleTree()
storage = Storage.open("receipts.db")

identity = AgentIdentity(
    name="procurement-bot",
    deployer="acme-corp",
    environment="production",
    source=IdentitySource.CONFIG,
)

receipt = (
    ReceiptBuilder()
    .agent(identity)
    .action(Action(tool="db_query", input={"sql": "SELECT 1"}, output={"rows": 1}))
    .delta(Delta(authorized=True))
    .build(signer, merkle)
)

storage.insert_receipt(receipt, session_id="session-1")

# Verify the signature
canonical = receipt.canonical_bytes()
assert signer.verify(canonical, receipt.proof.signature)

License

Apache 2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

manifest_sdk-0.2.0.tar.gz (17.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

manifest_sdk-0.2.0-py3-none-any.whl (15.0 kB view details)

Uploaded Python 3

File details

Details for the file manifest_sdk-0.2.0.tar.gz.

File metadata

  • Download URL: manifest_sdk-0.2.0.tar.gz
  • Upload date:
  • Size: 17.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.12

File hashes

Hashes for manifest_sdk-0.2.0.tar.gz
Algorithm Hash digest
SHA256 5338d29da2899010ea4d402b083c2e0f22cf9a771f69961ae92756b2b2c2aef2
MD5 263bcc6095d020aa8297ac3bd2a08013
BLAKE2b-256 2535e9c614745516d318c9df679dfdc376d7ac5596093ba39167650fa2bb389a

See more details on using hashes here.

File details

Details for the file manifest_sdk-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: manifest_sdk-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 15.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.12

File hashes

Hashes for manifest_sdk-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f96a0f402ea108f24bcdc90598f28e30538165f3bb94c349e9843b1d4eaf76b9
MD5 11db7eebb5cf58e1b8212eec093ebf18
BLAKE2b-256 2af0aa11a2c8215a096e75f51674fad25b9108f21884875bab0a436630fb9b2f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page