mintid-proof-core
Python bindings of the MintID proof core: the anonymous-credential core,
written in Rust and compiled into this package, with the headless holder
library (proof_core.holder) and the issuance side that an issuer service
uses. A holder obtains a credential blind (the issuer never sees it in the
clear), keeps its witnesses current, and answers a verifier's challenge with
a zero-knowledge presentation that proves predicates such as "over 18",
"grade at least A3" or "still active", and nothing else. The holder can also
revoke its own credential without revealing which one it is (holder
self-revocation, the holder's kill switch).
Where it fits
MintID is a network for verifiable, human-backed identity. Accepted issuers verify people and issue the credentials; the chain publishes their status roots, their bonds and the registries; each verifier decides on its own service. MintID itself issues nothing, certifies nothing and verifies nobody.
The holder library is headless: it runs in the holder's own
infrastructure, next to the keys the holder already custodies. The Python agent
client (mintid-agent) builds on it. Verification is not in this package:
it is in the verifier SDK (mintid-verifier-sdk), on the relying party's own
service.
Install
pip install mintid-proof-core # Python 3.12 or later
The Rust core is compiled in; where no wheel matches your platform, pip
builds it from the source distribution, which needs a Rust toolchain.
Version 0.4.0, published from the main repository,
https://gitlab.com/mintid/mintid (identity-proof-core/python).
Upgrading from 0.3. Holder.present now checks the verifier's
challenge signature before it builds anything (SPEC-1 §10.5): it needs the
verifier's {request, signature_hex} unmodified and a source of verifiers'
request keys, given as verifiers= to Holder.issue, Holder.from_storage
or present itself (ProvenVerifierKeys over a proven chain read, or
StaticVerifierKeys of records you pinned). A bare or unsigned request, a
holder without a source, an unknown or retired key and a bad signature are
refused with ChallengeRefused (its reason names which). Only against a
devnet verifier started with --insecure-unsigned-challenges,
present(..., insecure_skip_challenge_signature=True) skips the check, and
warns every time.
Example
import proof_core
from proof_core.holder import Holder, StaticVerifierKeys
print(proof_core.core_version()) # the Rust core compiled into this package
# Where the holder reads verifiers' request keys: a proven chain read
# (ProvenVerifierKeys) or the records you pinned (StaticVerifierKeys).
holder = Holder.issue(offer, verifiers=StaticVerifierKeys(pinned_records))
holder.refresh_witness() # right before presenting; material that does not verify is refused
envelope = holder.present(challenge) # the verifier's {request, signature_hex}: the signature is
# checked first (ChallengeRefused otherwise), then one bound,
# 10-second presentation, or nothing is sent
custody = holder.storage_bytes() # holds the link secret: encrypt it under your own key
There is no export: the custody encoding is the only serialisation, and a lost key is recoverable by nobody (you verify again and get a fresh credential, unlinkable to the old one).
Status
Built and in production on the single-node production chain. An independent audit of the implementation is scheduled as a milestone; its findings will be published, and it gates nothing.
Where to test
On the public testnet and its KYC sandbox, and only there: check the status line of its page first. Nothing issued on it carries weight. The single-node production chain is not for third parties and is never a place to test.
Links
- Documentation: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/08-credentials-and-holders.md
- Source: https://gitlab.com/mintid/mintid (
identity-proof-core), where issues and merge requests go - Public testnet: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/17-sandbox-and-testnet.md
- Security: report a vulnerability privately to security@mintid.net, never in a public issue; policy: https://gitlab.com/mintid/mintid/-/blob/main/SECURITY.md
- Website: https://mintid.net
Licence
Apache License 2.0. Author: Marc Molas.
Metadata
Release files for mintid-proof-core 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mintid_proof_core-0.4.0.tar.gz | 271.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mintid_proof_core-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.12 | abi3 | Linux glibc 2.17+ x86-64 | Details |
Total release size: 1.4 MB
Release files / mintid_proof_core-0.4.0.tar.gz
| Download URL | mintid_proof_core-0.4.0.tar.gz |
|---|---|
| Size | 271.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
36f5eed39cdb65d1cb3664d6a4a4d604b9623d6b3fbbff2bd6c0e7575f24ac18
|
|
BLAKE2b-256 checksum How to use checksums |
b9d25e05d249eecb38f3ef107641f3f64294456d3f98aa145f1074f79ade7958
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.12.15
|
Release files / mintid_proof_core-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | mintid_proof_core-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 1.1 MB |
| Tags | CPython 3.12 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
4ae6eefa6650aef6f4ee9cd65ff21bc8ce090086c36022d8cacbab3599e27f03
|
|
BLAKE2b-256 checksum How to use checksums |
516b748da5bd8ac1f0f96345b1ba4fb64a506b0d0fc36bf7923cb50103a70aee
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.12.15
|