Skip to main content

occ-langchain

OCC cryptographic proof signing for LangChain and LangGraph.

Every tool call produces an Ed25519-signed proof entry in proof.jsonl, creating a tamper-evident audit log of agent actions.

Install

pip install occ-langchain

Quick Start

Callback Handler (recommended)

from langchain.agents import AgentExecutor
from occ_langchain import OccCallbackHandler

handler = OccCallbackHandler()
executor = AgentExecutor(
    agent=your_agent,
    tools=tools,
    callbacks=[handler],
)
result = executor.invoke({"input": "Search for OCC proofs"})
# proof.jsonl now contains signed proof entries

Wrap Individual Tools

from langchain_community.tools import DuckDuckGoSearchRun
from occ_langchain import OccTool

search = DuckDuckGoSearchRun()
safe_search = OccTool(inner=search)

Wrap All Tools

from occ_langchain import wrap_tools

safe_tools = wrap_tools([search_tool, calc_tool])
executor = AgentExecutor(agent=agent, tools=safe_tools)

Custom Signer

from occ_langchain import OCCSigner, OccCallbackHandler

signer = OCCSigner(state_dir="/tmp/.occ", proof_file="audit.jsonl")
handler = OccCallbackHandler(signer=signer)

Proof Format

Each line in proof.jsonl is a JSON object:

{
  "version": "occ/proof/1",
  "timestamp": "2026-03-20T12:00:00.000Z",
  "signer": "<base64url-ed25519-public-key>",
  "payload": {
    "type": "tool-call",
    "tool": "search",
    "inputHash": "<sha256-hex>",
    "outputHash": "<sha256-hex>"
  },
  "signature": "<base64url-ed25519-signature>",
  "prev": "<sha256-hex-of-previous-proof>"
}

Proofs are chained: each proof's prev field contains the SHA-256 hash of the previous proof's canonical JSON.

Configuration

  • State directory: Keypair stored in .occ/signer-state.json (defaults to CWD)
  • Proof file: Defaults to proof.jsonl in CWD
  • Both configurable via OCCSigner(state_dir=..., proof_file=...)

License

Apache-2.0

Metadata

Release files for occ-langchain 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for occ-langchain 0.2.0
File Size Uploaded
occ_langchain-0.2.0.tar.gz 5.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for occ-langchain 0.2.0
File Interpreter ABI Platform
occ_langchain-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 12.9 kB

Release files / occ_langchain-0.2.0.tar.gz

Download URL occ_langchain-0.2.0.tar.gz
Size 5.9 kB
Tags Source
SHA-256 checksum
How to use checksums
5caddf3d45e03692bb233a7e1a1314862419ee7af809dc1b882e8473d11a44bd
BLAKE2b-256 checksum
How to use checksums
e519354357b4add4cd09f588332837d2fe05cf629fb05b73ec6be7950b6e660f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / occ_langchain-0.2.0-py3-none-any.whl

Download URL occ_langchain-0.2.0-py3-none-any.whl
Size 7.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f23568ee8ba487af3e81af316b2edfb9a615c870b7620a74e7696bce4d982d65
BLAKE2b-256 checksum
How to use checksums
650a90b283f416e4bbcf047785835720ad212875f4251ad82e2581128bb871a9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page