Skip to main content

moss-autogen

MOSS signing integration for AutoGen. Unsigned output is broken output.

PyPI

Installation

pip install moss-autogen

Quick Start: Explicit Signing (Recommended)

Sign messages, function results, and conversations:

from autogen import AssistantAgent
from moss_autogen import sign_message, sign_function_result, sign_conversation

# Create your agent
agent = AssistantAgent(name="analyst", llm_config={"model": "gpt-4"})

# Get a reply and sign it
reply = agent.generate_reply(messages=[{"content": "Analyze this"}])
result = sign_message(reply, agent_id="analyst")
print(f"Signed: {result.signature[:20]}...")

# Sign function/tool results
func_result = execute_tool(args)
result = sign_function_result(func_result, agent_id="analyst", function="execute_tool")

# Sign entire conversation
result = sign_conversation(chat_history, agent_id="chat-session")

Enterprise Mode

Set MOSS_API_KEY for automatic policy evaluation:

import os
os.environ["MOSS_API_KEY"] = "your-api-key"

from moss_autogen import sign_message, enterprise_enabled

print(f"Enterprise: {enterprise_enabled()}")  # True

result = sign_message(
    {"role": "assistant", "content": "Transfer approved"},
    agent_id="finance-agent",
    context={"user_id": "u123", "action": "transfer"}
)

if result.blocked:
    print(f"Blocked by policy: {result.policy.reason}")

Verification

from moss_autogen import verify_envelope

verify_result = verify_envelope(result.envelope)
if verify_result.valid:
    print(f"Signed by: {verify_result.subject}")

All Functions

Function Description
sign_message() Sign a message
sign_message_async() Async version
sign_function_result() Sign tool/function result
sign_function_result_async() Async version
sign_conversation() Sign full conversation
sign_conversation_async() Async version
sign_reply() Sign generate_reply output
sign_reply_async() Async version
verify_envelope() Verify a signed envelope

Legacy API

The old wrapper API is still available:

from moss_autogen import signed_agent

agent = signed_agent(
    AssistantAgent(name="analyst", ...),
    "moss:lab:analyst"
)
# agent.moss_envelope available after each reply

Enterprise Features

Feature Free Enterprise
Local signing ✓ ✓
Offline verification ✓ ✓
Policy evaluation - ✓
Evidence retention - ✓
Audit exports - ✓

Links

License

This package is licensed under the Business Source License 1.1.

  • Free for evaluation, testing, and development
  • Free for non-production use
  • Production use requires a MOSS subscription
  • Converts to Apache 2.0 on January 25, 2030

Metadata

Release files for moss-autogen 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for moss-autogen 1.0.0
File Size Uploaded
moss_autogen-1.0.0.tar.gz 8.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for moss-autogen 1.0.0
File Interpreter ABI Platform
moss_autogen-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 14.9 kB

Release files / moss_autogen-1.0.0.tar.gz

Download URL moss_autogen-1.0.0.tar.gz
Size 8.2 kB
Tags Source
SHA-256 checksum
How to use checksums
d83d36056bd16da36ad5aa598a4f22855198448c6eeefa2dc2f147f0684a1afe
BLAKE2b-256 checksum
How to use checksums
035230843ef21afc856c1e94987292ef1911eaceca8295598fe4f1ec1138e105
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 25, 2026.

Transparency log

Release files / moss_autogen-1.0.0-py3-none-any.whl

Download URL moss_autogen-1.0.0-py3-none-any.whl
Size 6.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
daeb64b00bcf7166121a76860df22d5be8ddf73f279122953b4cd997615ecdae
BLAKE2b-256 checksum
How to use checksums
144cae31d5dfdfbe42c2395059c1ac116eb5fc6d4cc972f0f619187f23bd54cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page