Skip to main content

mzprov

Cryptographic provenance for mass spectrometry data.

mzprov signs mass spectrometry data files with an Ed25519 attestation and verifies them later. A signature binds the file's content to the tool that produced it, its configuration and a signing key, so any change made after signing is detected. This package is the Python reference implementation of the mzprov specification.

Supported formats:

Format How it is hashed Where the attestation lives
Bruker .d canonical SQLite content plus binary JSON sidecar, or embedded in analysis.tdf
mzML canonical spectrum content, all binary arrays JSON sidecar, or embedded in the file
Thermo and Waters .raw opaque whole-file digest JSON sidecar
SCIEX .wiff the whole .wiff / .wiff.scan bundle JSON sidecar

mzprov guarantees provenance, not truth. A valid signature says these bytes have not changed since this key signed them. It does not say the data came from an instrument, or that the experiment was sound.

Install

pip install mzprov

Python 3.8 to 3.13. The only runtime dependency is cryptography.

Use

# Sign a Bruker .d. --config binds the run to its configuration bytes.
mzprov sign run.d --experiment-name run-001 --config run.toml \
    --tool-name timsTOF --tool-version 1.0

# Sign an mzML produced by any tool (--config is optional here).
mzprov sign run.mzML --experiment-name run-001 \
    --tool-name msconvert --tool-version 3.0.24

# Verify. The sidecar or embedded record is discovered from the data path.
mzprov verify run.d
mzprov verify run.mzML

# Verify and require a known signer.
mzprov verify run.d --expected-key-id <key-id>
mzprov verify run.d --require-trusted

The first sign generates a signing key at ~/.config/mzprov/keys/signing_key.pem and prints its key id. Manage keys and the trusted-keys registry with mzprov keys show|export|trust|list|untrust.

Exit codes are fixed by the specification: 0 verified, 1 generic error, 2 key error, 3 sidecar or artifact error, 4 unsigned (with --strict), 5 hash mismatch, 6 signature mismatch, 7 signer not trusted. Add --json to verify for a machine-readable result.

Python API

from mzprov import sign_mzml_output, verify_sidecar

sidecar = sign_mzml_output(
    mzml_path="run.mzML",
    config_path=None,
    experiment_name="run-001",
    tool_name="msconvert",
    tool_version="3.0.24",
)
result = verify_sidecar(sidecar)
assert result.overall_ok

Provenance chains (prototype)

A chain signs derivations: each output records the artifacts it was made from, and verification walks the lineage back to a trusted root.

# The root: a raw acquisition, signed by the lab.
mzprov chain sign run.raw --experiment-name acq001 --tool-name timsTOF

# A derived file names its inputs by role and chain sidecar.
mzprov chain sign run.mzML --experiment-name acq001 --tool-name msconvert \
    --input source_raw=run.raw.chain.json

# Walk run.mzML back to run.raw; the root's key must be trusted
# (mzprov keys trust <signer's public key PEM> --comment ...).
mzprov chain verify run.mzML

chain verify exits 0 verified, 3 malformed sidecar or graph, 5 an artifact changed, 6 a bad signature, 7 an untrusted root, 8 an input that does not match the parent it points to, and 9 an input with no provenance. Chains are Python-only and a v1 draft, not yet part of the frozen v0 specification. A verified chain shows the provenance claims are intact, not that each transform was correct.

License

Apache-2.0. The specification and documentation are CC-BY-4.0 and the test vectors CC0; see the repository's LICENSE.

Metadata

Release files for mzprov 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mzprov 0.1.2
File Size Uploaded
mzprov-0.1.2.tar.gz 123.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mzprov 0.1.2
File Interpreter ABI Platform
mzprov-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 214.2 kB

Release files / mzprov-0.1.2.tar.gz

Download URL mzprov-0.1.2.tar.gz
Size 123.8 kB
Tags Source
SHA-256 checksum
How to use checksums
13a2ddcf3266e31b65cec6403612b03be60d701a459c95ea34d39f2703857ab7
BLAKE2b-256 checksum
How to use checksums
4c3000abb52f2ad45a3e2d3a28a0313c7745e4eed3b6f5b7332f39e844c165ed
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / mzprov-0.1.2-py3-none-any.whl

Download URL mzprov-0.1.2-py3-none-any.whl
Size 90.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6e4dc1685573cd99886449e9d9b451e7b6d0295a86ae87ae93d8b66d043f9420
BLAKE2b-256 checksum
How to use checksums
e79b2457ffd9782086de6ae75a03c08d2e42a9a206a0ddcb86ca26d6c69ef1a6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page