Skip to main content

mirra-sdk

One wrapper call gives any agent a persistent recognized identity, tamper-evident portable memory of its relationships, behavior that adapts per relationship, and execution that only happens when verified.

import mirra

wrapped = mirra.wrap(my_agent, principal="team-key-1", profile="dev_balanced")

wrapped.identity                     # recognized across sessions, not met fresh
wrapped.remember("alice", "…")       # signed scroll — verify-on-read, fail-closed
wrapped.recall("alice")              # only cryptographically verified memories
wrapped.interact("alice", "hi")      # context built from alice's own history
wrapped.execute("shell.exec", "…")   # deterministic, signed decision record

This is Edge 1 (the SDK) of the MIRRA platform's one-core/three-edges architecture. The SDK speaks only the frozen v1 core contract (mirra-core-contract); the enforcement engine (MVAR via ClawZero) and the signed memory store (ClawSeal) plug in beneath it, and optional capability providers can be injected at runtime for identity enrichment and epistemic verification.

The four pillars

Pillar API Guarantee
Recognition wrapped.identity Same principal → same identity + fingerprint across sessions; keys generated on first run, never stored in a repo
Portable signed memory remember / recall / verify Sign-on-write, verify-on-read; tampered memories are dropped, never returned
Per-relationship behavior interact / build_context The agent sees each subject's own verified history
Permissioned execution execute / protect_tool Deterministic allow/block with an Ed25519-signed witness; forged records fail verification; no engine → refuse

Profiles: build against dev_balanced (safe actions allow, hostile ones block, risky ones step up). The default is prod_locked — the fail-closed production posture where every action is refused unless the caller supplies risk context or step-up approval. If you omit profile and everything blocks, that is the lockdown working as designed.

Fail-closed by design

  • No enforcement engine → every action is blocked, never silently allowed.
  • No memory backend → wrap() raises, never runs with unsigned memory.
  • Damaged identity keystore → raises, never silently mints a new identity.
  • Tampered scroll or forged decision record → fails verification.

Demo

Installed (pip):

mirra-demo                   # live 5-check report; run twice — the second run proves recognition

From a checkout:

python3 demo/demo_sdk.py     # narrative version of the same proof

See DEMO.md for the five-minute walkthrough.

Tests

python3 -m pytest tests/ -q

The suite is organized by acceptance criterion: test_recognition.py, test_signed_memory.py, test_differentiated_behavior.py, test_permissioned_execution.py, test_boundary.py (public/private leak gate).

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mirra_sdk-0.1.0.tar.gz (35.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mirra_sdk-0.1.0-py3-none-any.whl (33.7 kB view details)

Uploaded Python 3

File details

Details for the file mirra_sdk-0.1.0.tar.gz.

File metadata

  • Download URL: mirra_sdk-0.1.0.tar.gz
  • Upload date:
  • Size: 35.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0

File hashes

Hashes for mirra_sdk-0.1.0.tar.gz
Algorithm Hash digest
SHA256 663e6f759087a73dba2a71fbd41b775e85a5c75e5bdf26072f06f44e1be39a58
MD5 0808d24adaed0f8e1460daa11351ea32
BLAKE2b-256 7d60a2a0955b789c0abcaeaca3502e2dd18b905f6fed036b9ae29e88a04ef8a9

See more details on using hashes here.

File details

Details for the file mirra_sdk-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: mirra_sdk-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 33.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0

File hashes

Hashes for mirra_sdk-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b7b83ffdc49950db31f01da7f5c622c4fab41f468e9e75101fb02f41f7778168
MD5 021cf10dfbd14436488e308042585651
BLAKE2b-256 7ee3104406cc55422ccb59f62dad67b1ec1bde244ab23c40db1e8e7af6c76a35

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page