Skip to main content

mintid-proof-core

Python bindings of the MintID proof core: the anonymous-credential core, written in Rust and compiled into this package, with the headless holder library (proof_core.holder) and the issuance side that an issuer service uses. A holder obtains a credential blind (the issuer never sees it in the clear), keeps its witnesses current, and answers a verifier's challenge with a zero-knowledge presentation that proves predicates such as "over 18", "grade at least A3" or "still active", and nothing else. The holder can also revoke its own credential without revealing which one it is (holder self-revocation, the holder's kill switch).

Where it fits

MintID is a network for verifiable, human-backed identity. Accepted issuers verify people and issue the credentials; the chain publishes their status roots, their bonds and the registries; each verifier decides on its own service. MintID itself issues nothing, certifies nothing and verifies nobody.

The holder library is headless: it runs in the holder's own infrastructure, next to the keys the holder already custodies. The Python agent client (mintid-agent) builds on it. Verification is not in this package: it is in the verifier SDK (mintid-verifier-sdk), on the relying party's own service.

Install

pip install mintid-proof-core   # Python 3.12 or later

The Rust core is compiled in; where no wheel matches your platform, pip builds it from the source distribution, which needs a Rust toolchain. Version 0.4.0, published from the main repository, https://gitlab.com/mintid/mintid (identity-proof-core/python).

Upgrading from 0.3. Holder.present now checks the verifier's challenge signature before it builds anything (SPEC-1 §10.5): it needs the verifier's {request, signature_hex} unmodified and a source of verifiers' request keys, given as verifiers= to Holder.issue, Holder.from_storage or present itself (ProvenVerifierKeys over a proven chain read, or StaticVerifierKeys of records you pinned). A bare or unsigned request, a holder without a source, an unknown or retired key and a bad signature are refused with ChallengeRefused (its reason names which). Only against a devnet verifier started with --insecure-unsigned-challenges, present(..., insecure_skip_challenge_signature=True) skips the check, and warns every time.

Example

import proof_core
from proof_core.holder import Holder, StaticVerifierKeys

print(proof_core.core_version())       # the Rust core compiled into this package

# Where the holder reads verifiers' request keys: a proven chain read
# (ProvenVerifierKeys) or the records you pinned (StaticVerifierKeys).
holder = Holder.issue(offer, verifiers=StaticVerifierKeys(pinned_records))
holder.refresh_witness()               # right before presenting; material that does not verify is refused
envelope = holder.present(challenge)   # the verifier's {request, signature_hex}: the signature is
                                       # checked first (ChallengeRefused otherwise), then one bound,
                                       # 10-second presentation, or nothing is sent
custody = holder.storage_bytes()       # holds the link secret: encrypt it under your own key

There is no export: the custody encoding is the only serialisation, and a lost key is recoverable by nobody (you verify again and get a fresh credential, unlinkable to the old one).

Status

Built and in production on the single-node production chain. An independent audit of the implementation is scheduled as a milestone; its findings will be published, and it gates nothing.

Where to test

On the public testnet and its KYC sandbox, and only there: check the status line of its page first. Nothing issued on it carries weight. The single-node production chain is not for third parties and is never a place to test.

Licence

Apache License 2.0. Author: Marc Molas.

Metadata

Release files for mintid-proof-core 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mintid-proof-core 0.4.0
File Size Uploaded
mintid_proof_core-0.4.0.tar.gz 271.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mintid-proof-core 0.4.0
File Interpreter ABI Platform
mintid_proof_core-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.12 abi3 Linux glibc 2.17+ x86-64 Details

Total release size: 1.4 MB

Release files / mintid_proof_core-0.4.0.tar.gz

Download URL mintid_proof_core-0.4.0.tar.gz
Size 271.6 kB
Tags Source
SHA-256 checksum
How to use checksums
36f5eed39cdb65d1cb3664d6a4a4d604b9623d6b3fbbff2bd6c0e7575f24ac18
BLAKE2b-256 checksum
How to use checksums
b9d25e05d249eecb38f3ef107641f3f64294456d3f98aa145f1074f79ade7958
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.12.15

Release files / mintid_proof_core-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL mintid_proof_core-0.4.0-cp312-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 1.1 MB
Tags CPython 3.12 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
4ae6eefa6650aef6f4ee9cd65ff21bc8ce090086c36022d8cacbab3599e27f03
BLAKE2b-256 checksum
How to use checksums
516b748da5bd8ac1f0f96345b1ba4fb64a506b0d0fc36bf7923cb50103a70aee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.12.15

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page