Skip to main content

occ-openclaw

OCC cryptographic proof signing for OpenClaw.

Every tool call produces an Ed25519-signed proof entry in proof.jsonl, creating a tamper-evident audit log of agent actions.

Install

pip install occ-openclaw

Quick Start

Decorate Individual Tools

from occ_openclaw import occ_tool

@occ_tool
def get_weather(location: str) -> str:
    return f"Sunny in {location}"

Middleware (recommended)

from openclaw import Agent
from occ_openclaw import OccMiddleware

middleware = OccMiddleware()
agent = Agent(
    tools=[get_weather, search],
    middleware=[middleware],
)

Wrap All Tools

from occ_openclaw import wrap_tools

safe_tools = wrap_tools([get_weather, search])
agent = Agent(tools=safe_tools)

Custom Signer

from occ_openclaw import OCCSigner, OccMiddleware

signer = OCCSigner(state_dir="/tmp/.occ", proof_file="audit.jsonl")
middleware = OccMiddleware(signer=signer)

Proof Format

Each line in proof.jsonl is a JSON object:

{
  "version": "occ/proof/1",
  "timestamp": "2026-03-20T12:00:00.000Z",
  "signer": "<base64url-ed25519-public-key>",
  "payload": {
    "type": "tool-call",
    "tool": "get_weather",
    "inputHash": "<sha256-hex>",
    "outputHash": "<sha256-hex>"
  },
  "signature": "<base64url-ed25519-signature>",
  "prev": "<sha256-hex-of-previous-proof>"
}

Proofs are chained: each proof's prev field contains the SHA-256 hash of the previous proof's canonical JSON.

Configuration

  • State directory: Keypair stored in .occ/signer-state.json (defaults to CWD)
  • Proof file: Defaults to proof.jsonl in CWD
  • Both configurable via OCCSigner(state_dir=..., proof_file=...)

License

Apache-2.0

Metadata

Release files for occ-openclaw 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for occ-openclaw 0.2.0
File Size Uploaded
occ_openclaw-0.2.0.tar.gz 5.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for occ-openclaw 0.2.0
File Interpreter ABI Platform
occ_openclaw-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 11.7 kB

Release files / occ_openclaw-0.2.0.tar.gz

Download URL occ_openclaw-0.2.0.tar.gz
Size 5.4 kB
Tags Source
SHA-256 checksum
How to use checksums
5ef8dc3f0da20f0e13e69706bf1a95040139594d43c032e62d178fdf23f1001d
BLAKE2b-256 checksum
How to use checksums
26112fc2becc5ac6fa01bdbe119a14fc8145d4f27b36c0e14401f6181f1d7f6e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release files / occ_openclaw-0.2.0-py3-none-any.whl

Download URL occ_openclaw-0.2.0-py3-none-any.whl
Size 6.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7089e8a4228947a788d36bc512c868fa79799611bc9228b437c99808531268e7
BLAKE2b-256 checksum
How to use checksums
6152fb11b6125b33da1a8a34aec1f890fcec6fd9b7790481c7adb40b2408ef84
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.9.6

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page