occ-gemini
OCC cryptographic proof signing for Google Gemini.
Every tool/function call produces an Ed25519-signed proof entry in proof.jsonl, creating a tamper-evident audit log of agent actions.
Install
pip install occ-gemini
Quick Start
Wrap a Client (recommended)
from google import genai
from occ_gemini import wrap_client
client = genai.Client(api_key="...")
safe_client = wrap_client(client)
response = safe_client.models.generate_content(
model="gemini-2.0-flash",
contents="What's the weather?",
)
# proof.jsonl now contains signed proof entries for any function calls
Decorate Individual Tools
from occ_gemini import occ_tool
@occ_tool
def get_weather(location: str) -> str:
return f"Sunny in {location}"
Custom Signer
from occ_gemini import OCCSigner, wrap_client
signer = OCCSigner(state_dir="/tmp/.occ", proof_file="audit.jsonl")
safe_client = wrap_client(client, signer=signer)
Legacy API (wrap_model)
wrap_model also accepts a google.genai.Client or a legacy google.generativeai.GenerativeModel:
from occ_gemini import wrap_model
safe_client = wrap_model(client)
Proof Format
Each line in proof.jsonl is a JSON object:
{
"version": "occ/proof/1",
"timestamp": "2026-03-20T12:00:00.000Z",
"signer": "<base64url-ed25519-public-key>",
"payload": {
"type": "tool-call",
"tool": "get_weather",
"inputHash": "<sha256-hex>",
"outputHash": "<sha256-hex>"
},
"signature": "<base64url-ed25519-signature>",
"prev": "<sha256-hex-of-previous-proof>"
}
Proofs are chained: each proof's prev field contains the SHA-256 hash of the previous proof's canonical JSON.
Configuration
- State directory: Keypair stored in
.occ/signer-state.json(defaults to CWD) - Proof file: Defaults to
proof.jsonlin CWD - Both configurable via
OCCSigner(state_dir=..., proof_file=...)
License
Apache-2.0
Metadata
Release files for occ-gemini 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| occ_gemini-0.2.0.tar.gz | 6.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| occ_gemini-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.2 kB
Release files / occ_gemini-0.2.0.tar.gz
| Download URL | occ_gemini-0.2.0.tar.gz |
|---|---|
| Size | 6.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a67373caf077c5b35e27d3b910453837fd93a141369a895c6f814fbd9e2bd7be
|
|
BLAKE2b-256 checksum How to use checksums |
0758b77b1a494bd94d7f572e9c11ef0caa74241ff15378df90288c24b918d898
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / occ_gemini-0.2.0-py3-none-any.whl
| Download URL | occ_gemini-0.2.0-py3-none-any.whl |
|---|---|
| Size | 7.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
decc15fef159d3feca447cf9cf66fa6f545bef43de1bc49c783ca90cf823512a
|
|
BLAKE2b-256 checksum How to use checksums |
ccc73c945cc0b133ffe966ce5a9e64d1e497e94072d6b791756609debac469f0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|