Skip to main content

ollama-openttt

TTTPS Proof-of-Time reverse proxy for Ollama. Sits in front of ollama serve and attaches a cryptographic audit-trail timestamp (a signed Proof-of-Time receipt) to every /api/generate and /api/chat response, sealed against the public self-serve KPP Provenance API.

This attaches a cryptographic audit-trail timestamp and integrity hash. It does not certify legal or regulatory compliance (EU AI Act, FDA, and so on). Treat it as an audit-trail timestamp, not a compliance claim.

Install

pip install ollama-openttt

Usage

Mint a free key with POST https://kpp.kenosian.com/v1/keys, then start the proxy next to your running Ollama daemon:

export KPP_API_KEY=...

ollama serve &            # upstream, port 11434
ollama-openttt --port 11435

python -m ollama_openttt does the same thing.

Point any Ollama client at the proxy port instead of the daemon port. Requests and responses are otherwise identical, so existing clients need no other change:

curl http://127.0.0.1:11435/api/chat -d '{
  "model": "qwen2.5:0.5b",
  "messages": [{"role": "user", "content": "hi"}],
  "stream": false
}'

The response carries an extra top-level key:

{
  "model": "qwen2.5:0.5b",
  "message": {"role": "assistant", "content": "Hello! How can I help you today?"},
  "done": true,
  "tttps_receipt": {
    "status": "ok",
    "content_hash": "sha256:...",
    "receipt_id": "...",
    "receipt": "...",
    "time": "...",
    "time_source": "...",
    "verify_url": "https://kpp.kenosian.com/v1/verify?receipt_id=...",
    "overhead_ms": "<round trip spent on the anchor call>"
  }
}

Non-streaming responses also expose X-TTTPS-Status and X-TTTPS-Receipt headers. A receipt can be re-checked at any time via POST https://kpp.kenosian.com/v1/verify with {"receipt_id": ...}.

Streaming

Ollama streams NDJSON by default. Every delta line is forwarded through unchanged and immediately, and only the final "done": true line gets the tttps_receipt key added, computed over the accumulated text. The anchor round trip is paid once, after generation has already finished, so token-by-token delivery is never delayed, and any parser that only reads the known keys is unaffected by the extra one.

Configuration

Variable Default Meaning
KPP_API_KEY empty Provenance key from POST /v1/keys
KPP_BASE https://kpp.kenosian.com Provenance API base URL
KPP_TIMEOUT_S 1.0 Fail-open deadline for the anchor call
OLLAMA_UPSTREAM http://127.0.0.1:11434 Ollama daemon base URL
OLLAMA_TIMEOUT_S 120.0 Deadline for the upstream Ollama call

CLI flags: --host, --port, --upstream, --log-level. GET /health reports whether the upstream daemon is reachable.

Fail-open

A missing key, an unreachable or slow Provenance API, or any unexpected error degrades the receipt to {"status": "degraded", "reason": ...}. The underlying Ollama response is never blocked or altered.

Why a proxy

Ollama has no plugin or middleware extension point: its HTTP router is built with a fixed pair of middlewares and is not extensible from outside the binary. A reverse proxy is therefore the way to attach anything to an Ollama response, which is the pattern other Ollama proxies use as well.

License

MIT

Metadata

Release files for ollama-openttt 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ollama-openttt 0.1.0
File Size Uploaded
ollama_openttt-0.1.0.tar.gz 6.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ollama-openttt 0.1.0
File Interpreter ABI Platform
ollama_openttt-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 13.6 kB

Release files / ollama_openttt-0.1.0.tar.gz

Download URL ollama_openttt-0.1.0.tar.gz
Size 6.2 kB
Tags Source
SHA-256 checksum
How to use checksums
fdda8754d59bdaa68e60cb69d1adb5870b43dde5ad5634e22029bb3592cc1a1f
BLAKE2b-256 checksum
How to use checksums
d8eff548fd293a5245b994befb171891f040f6f7475a68b501bfa8382b3830d2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.7

Release files / ollama_openttt-0.1.0-py3-none-any.whl

Download URL ollama_openttt-0.1.0-py3-none-any.whl
Size 7.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
24ce83fefe7c471f3ed96614c1b6a9773c927bc183535683f9a5a8cf938b971b
BLAKE2b-256 checksum
How to use checksums
0b461ae1cfeaecce1732b4a3d337c537e6da1056559619a95acb23e6407ea94d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.7

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page