Cryptographic receipts for AI agent tool calls
Project description
manifest-sdk
Cryptographic receipts for AI agent tool calls — Python SDK.
Pure Python implementation of the manifest receipt format. Generates receipts that are byte-for-byte verifiable by the Rust CLI.
Install
pip install manifest-sdk
Quick Start
from manifest_sdk import Manifest
m = Manifest(identity="my-agent", db="receipts.db")
receipt = m.record(
tool="send_email",
input={"to": "bob@example.com", "subject": "Hello"},
output={"status": "sent"}
)
print(receipt.id) # urn:uuid:...
print(receipt.proof.signature) # ed25519:...
print(receipt.content_hash()) # sha256:...
Features
- Ed25519 signing — Key generation, signing, verification (32-byte seed files)
- Merkle tree — Append-only tree matching the Rust implementation
- Policy evaluation — Tool allowlists, spending limits, PII detection
- SQLite storage — Same schema as the Rust CLI (cross-readable)
- Receipt chaining — Each receipt links to the previous via content hash
- JSON-LD receipts — Same format as the MCP proxy
Advanced Usage
from manifest_sdk import (
AgentIdentity, IdentitySource, Action, Delta,
ReceiptBuilder, Signer, MerkleTree, Storage, PolicyConfig,
)
# Manual control over each component
signer = Signer.generate()
merkle = MerkleTree()
storage = Storage.open("receipts.db")
identity = AgentIdentity(
name="procurement-bot",
deployer="acme-corp",
environment="production",
source=IdentitySource.CONFIG,
)
receipt = (
ReceiptBuilder()
.agent(identity)
.action(Action(tool="db_query", input={"sql": "SELECT 1"}, output={"rows": 1}))
.delta(Delta(authorized=True))
.build(signer, merkle)
)
storage.insert_receipt(receipt, session_id="session-1")
# Verify the signature
canonical = receipt.canonical_bytes()
assert signer.verify(canonical, receipt.proof.signature)
License
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
manifest_sdk-0.2.1.tar.gz
(17.8 kB
view details)
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file manifest_sdk-0.2.1.tar.gz.
File metadata
- Download URL: manifest_sdk-0.2.1.tar.gz
- Upload date:
- Size: 17.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
dcb895a85fd1e4f0c93d78d30dd9d828e7b52f9f6da23a445bea57b052c79366
|
|
| MD5 |
a5a291db537ce73a3850a7817910008f
|
|
| BLAKE2b-256 |
eac1bce97cf1099ca0464b186de86e45f155dd670a22f5f8233856325663cc4a
|
File details
Details for the file manifest_sdk-0.2.1-py3-none-any.whl.
File metadata
- Download URL: manifest_sdk-0.2.1-py3-none-any.whl
- Upload date:
- Size: 15.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
915ed1c9f7f67473ceceec3592f64ecf83cc3107422bae21afd24b532525385f
|
|
| MD5 |
23b137db9d950ebab8d68433e4c73c89
|
|
| BLAKE2b-256 |
c691a54c77db13717b85756bc27207fed26f4d0628632778583c1302a3660646
|