Cryptographic receipts for AI agent tool calls
Project description
manifest-sdk
Cryptographic receipts for AI agent tool calls — Python SDK.
Pure Python implementation of the manifest receipt format. Generates receipts that are byte-for-byte verifiable by the Rust CLI.
Install
pip install manifest-sdk
Quick Start
from manifest_sdk import Manifest
m = Manifest(identity="my-agent", db="receipts.db")
receipt = m.record(
tool="send_email",
input={"to": "bob@example.com", "subject": "Hello"},
output={"status": "sent"}
)
print(receipt.id) # urn:uuid:...
print(receipt.proof.signature) # ed25519:...
print(receipt.content_hash()) # sha256:...
Features
- Ed25519 signing — Key generation, signing, verification (32-byte seed files)
- Merkle tree — Append-only tree matching the Rust implementation
- Policy evaluation — Tool allowlists, spending limits, PII detection
- SQLite storage — Same schema as the Rust CLI (cross-readable)
- Receipt chaining — Each receipt links to the previous via content hash
- JSON-LD receipts — Same format as the MCP proxy
Advanced Usage
from manifest_sdk import (
AgentIdentity, IdentitySource, Action, Delta,
ReceiptBuilder, Signer, MerkleTree, Storage, PolicyConfig,
)
# Manual control over each component
signer = Signer.generate()
merkle = MerkleTree()
storage = Storage.open("receipts.db")
identity = AgentIdentity(
name="procurement-bot",
deployer="acme-corp",
environment="production",
source=IdentitySource.CONFIG,
)
receipt = (
ReceiptBuilder()
.agent(identity)
.action(Action(tool="db_query", input={"sql": "SELECT 1"}, output={"rows": 1}))
.delta(Delta(authorized=True))
.build(signer, merkle)
)
storage.insert_receipt(receipt, session_id="session-1")
# Verify the signature
canonical = receipt.canonical_bytes()
assert signer.verify(canonical, receipt.proof.signature)
License
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
manifest_sdk-0.2.4.tar.gz
(17.8 kB
view details)
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file manifest_sdk-0.2.4.tar.gz.
File metadata
- Download URL: manifest_sdk-0.2.4.tar.gz
- Upload date:
- Size: 17.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9f90ad31bfca3db5d4fcea18340f7eb1c6710e28b6f737138856f02c0ecfb076
|
|
| MD5 |
45508b3e828c1a60d10e892e5793adae
|
|
| BLAKE2b-256 |
c86e84853588bdc44eb21f2a67439ec59409b1c875380fa23675c8084d5d0ea3
|
File details
Details for the file manifest_sdk-0.2.4-py3-none-any.whl.
File metadata
- Download URL: manifest_sdk-0.2.4-py3-none-any.whl
- Upload date:
- Size: 15.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4942bba29ecfd396af23a4964b95d9d8a3b0534ae0e50598b02ca0fb4f13067f
|
|
| MD5 |
4aa77566ed242c8f4a2e30b9a3fca68a
|
|
| BLAKE2b-256 |
00945afbfaeb2c96588d0001458fe56aea5941f3855a71af9c4094dd6090b7a8
|