Skip to main content

Cryptographic receipts for AI agent tool calls

Project description

manifest-sdk

Cryptographic receipts for AI agent tool calls — Python SDK.

Pure Python implementation of the manifest receipt format. Generates receipts that are byte-for-byte verifiable by the Rust CLI.

Install

pip install manifest-sdk

Quick Start

from manifest_sdk import Manifest

m = Manifest(identity="my-agent", db="receipts.db")

receipt = m.record(
    tool="send_email",
    input={"to": "bob@example.com", "subject": "Hello"},
    output={"status": "sent"}
)

print(receipt.id)                    # urn:uuid:...
print(receipt.proof.signature)       # ed25519:...
print(receipt.content_hash())        # sha256:...

Features

  • Ed25519 signing — Key generation, signing, verification (32-byte seed files)
  • Merkle tree — Append-only tree matching the Rust implementation
  • Policy evaluation — Tool allowlists, spending limits, PII detection
  • SQLite storage — Same schema as the Rust CLI (cross-readable)
  • Receipt chaining — Each receipt links to the previous via content hash
  • JSON-LD receipts — Same format as the MCP proxy

Advanced Usage

from manifest_sdk import (
    AgentIdentity, IdentitySource, Action, Delta,
    ReceiptBuilder, Signer, MerkleTree, Storage, PolicyConfig,
)

# Manual control over each component
signer = Signer.generate()
merkle = MerkleTree()
storage = Storage.open("receipts.db")

identity = AgentIdentity(
    name="procurement-bot",
    deployer="acme-corp",
    environment="production",
    source=IdentitySource.CONFIG,
)

receipt = (
    ReceiptBuilder()
    .agent(identity)
    .action(Action(tool="db_query", input={"sql": "SELECT 1"}, output={"rows": 1}))
    .delta(Delta(authorized=True))
    .build(signer, merkle)
)

storage.insert_receipt(receipt, session_id="session-1")

# Verify the signature
canonical = receipt.canonical_bytes()
assert signer.verify(canonical, receipt.proof.signature)

License

Apache 2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

manifest_sdk-0.2.3.tar.gz (17.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

manifest_sdk-0.2.3-py3-none-any.whl (15.0 kB view details)

Uploaded Python 3

File details

Details for the file manifest_sdk-0.2.3.tar.gz.

File metadata

  • Download URL: manifest_sdk-0.2.3.tar.gz
  • Upload date:
  • Size: 17.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.12

File hashes

Hashes for manifest_sdk-0.2.3.tar.gz
Algorithm Hash digest
SHA256 453cb70b282bbaa4c042831ac3ff3227bc66039613cad4adf3787cc185c34757
MD5 562fd6aa9d4a88d42847e5b83783850b
BLAKE2b-256 d221aa7588d9c778a3ef4d1bc784bf8f3e3e61bed6cffe2a2cdc14f22fb67d7e

See more details on using hashes here.

File details

Details for the file manifest_sdk-0.2.3-py3-none-any.whl.

File metadata

  • Download URL: manifest_sdk-0.2.3-py3-none-any.whl
  • Upload date:
  • Size: 15.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.12

File hashes

Hashes for manifest_sdk-0.2.3-py3-none-any.whl
Algorithm Hash digest
SHA256 ad04735a448203bc432ff635fbea2998e92e5a48af18a293ae0970d68bd94087
MD5 206c3b93d8b13c4c4bbe418a75b783b3
BLAKE2b-256 f007adf5e4f5ad549662fba2c77dc8b63322b77fe2f92d7c29d1601ce694673d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page