Skip to main content

moss-google

MOSS signing integration for Google GenAI SDK (Gemini). Unsigned output is broken output.

PyPI

Installation

pip install moss-google

Quick Start

Sign function calls, responses, and content from Gemini:

import google.generativeai as genai
from moss_google import sign_function_call, sign_response, sign_content

genai.configure(api_key="...")
model = genai.GenerativeModel("gemini-pro")

# Get a response with function calling
response = model.generate_content(
    "What's the weather in NYC?",
    tools=[get_weather_tool]
)

# Sign the full response
result = sign_response(response, agent_id="weather-bot")
print(f"Signed: {result.signature[:20]}...")

# Sign individual function calls
for part in response.candidates[0].content.parts:
    if hasattr(part, "function_call"):
        result = sign_function_call(part.function_call, agent_id="weather-bot")

Enterprise Mode

Set MOSS_API_KEY for automatic policy evaluation:

import os
os.environ["MOSS_API_KEY"] = "your-api-key"

from moss_google import sign_function_call, enterprise_enabled

print(f"Enterprise: {enterprise_enabled()}")  # True

result = sign_function_call(
    function_call,
    agent_id="finance-bot",
    context={"user_id": "u123"}
)

if result.blocked:
    print(f"Blocked by policy: {result.policy.reason}")

Verification

from moss_google import verify_envelope

verify_result = verify_envelope(result.envelope)
if verify_result.valid:
    print(f"Signed by: {verify_result.subject}")

All Functions

Function Description
sign_function_call() Sign a function call
sign_function_call_async() Async version
sign_response() Sign a GenerateContentResponse
sign_response_async() Async version
sign_content() Sign a Content object
sign_content_async() Async version
sign_part() Sign a Part (text or function call)
sign_part_async() Async version
verify_envelope() Verify a signed envelope

Enterprise Features

Feature Free Enterprise
Local signing ✓ ✓
Offline verification ✓ ✓
Policy evaluation - ✓
Evidence retention - ✓
Audit exports - ✓

Links

License

This package is licensed under the Business Source License 1.1.

  • Free for evaluation, testing, and development
  • Free for non-production use
  • Production use requires a MOSS subscription
  • Converts to Apache 2.0 on January 25, 2030

Metadata

Release files for moss-google 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for moss-google 1.0.0
File Size Uploaded
moss_google-1.0.0.tar.gz 5.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for moss-google 1.0.0
File Interpreter ABI Platform
moss_google-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 11.4 kB

Release files / moss_google-1.0.0.tar.gz

Download URL moss_google-1.0.0.tar.gz
Size 5.7 kB
Tags Source
SHA-256 checksum
How to use checksums
1daf823aa1819ce398b05eaa11c572caea3e33aa5342f4d8bf3be1b860eb5e7d
BLAKE2b-256 checksum
How to use checksums
262402adc0adcfe0d48f0232c11a71fd5347c6889649aa7b7fc65d82c2d7d28e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 25, 2026.

Transparency log

Release files / moss_google-1.0.0-py3-none-any.whl

Download URL moss_google-1.0.0-py3-none-any.whl
Size 5.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ab5453a858f78bb8b12ec1a5986bcc09148dbbdfef2f7f3418c1ce24a0e9bcfe
BLAKE2b-256 checksum
How to use checksums
3503dae082b59c2411f7b0e2a9a5ef65935cee05e1cb04ed8e11113823a9f816
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page