Skip to main content

oneid-sdk

Python SDK for 1id.com -- hardware-anchored identity for AI agents.

RFC: draft-drake-email-hardware-attestation-00

Quick start

import oneid

# Enroll at declared tier (no HSM needed, always works)
identity = oneid.enroll(request_tier="declared", display_name="Sparky")
print(f"Enrolled: {identity.handle}")
print(f"URN: {identity.agent_identity_urn}")

# Get an OAuth2 token for API access
token = oneid.get_token()
headers = {"Authorization": f"Bearer {token.access_token}"}

# Check identity
me = oneid.whoami()
print(f"I am {me.handle}, trust tier: {me.trust_tier.value}")

Hardware-backed enrollment

# TPM enrollment (sovereign tier) - requires Windows/Linux with TPM 2.0
identity = oneid.enroll(request_tier="sovereign")

# YubiKey enrollment (portable tier) - requires YubiKey 5 inserted
identity = oneid.enroll(request_tier="portable")

# Virtual TPM (VMware/Hyper-V/QEMU)
identity = oneid.enroll(request_tier="virtual")

Trust tiers

Tier Hardware Sybil Resistant Trust Level
sovereign TPM (Intel, AMD, Infineon) with valid cert Yes Highest
portable YubiKey / Nitrokey / Feitian with PIV attestation Yes High
virtual VMware / Hyper-V / QEMU vTPM No Verified Hardware
declared None (software keys) No Software

request_tier is a requirement, not a preference. You get exactly what you ask for, or an exception. No silent fallbacks.

Key algorithms

Like SSH, agents can choose their preferred key algorithm for declared-tier enrollment:

identity = oneid.enroll(request_tier="declared", key_algorithm="ed25519")     # default, strongest
identity = oneid.enroll(request_tier="declared", key_algorithm="ecdsa-p384")  # NIST P-384
identity = oneid.enroll(request_tier="declared", key_algorithm="rsa-4096")    # RSA compat

Installation

pip install oneid

Requires Python 3.10+.

License

Apache-2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

oneid-1.5.0.tar.gz (111.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

oneid-1.5.0-py3-none-any.whl (89.9 kB view details)

Uploaded Python 3

File details

Details for the file oneid-1.5.0.tar.gz.

File metadata

  • Download URL: oneid-1.5.0.tar.gz
  • Upload date:
  • Size: 111.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.15

File hashes

Hashes for oneid-1.5.0.tar.gz
Algorithm Hash digest
SHA256 ee34e9b44f4abd9ac9173161788b06f62305a2f160173aa00028409358a0c1a7
MD5 10429b50f3e325ffcf11b77754bb6d9d
BLAKE2b-256 193d4e04d226199d3ed75b56d9e9b2b615ab50bc31a0c220a29db98e097d84a4

See more details on using hashes here.

File details

Details for the file oneid-1.5.0-py3-none-any.whl.

File metadata

  • Download URL: oneid-1.5.0-py3-none-any.whl
  • Upload date:
  • Size: 89.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.15

File hashes

Hashes for oneid-1.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 e0c301da95a6a40b07245e9181d721499a153e42e951bafd703e2de18794d2f6
MD5 881b2f187ecaf1cbe1faa2e790c89f71
BLAKE2b-256 11c625e85563961f2f92f57e0416b219b3033f8667bb64e45fc5f2f6f44e3d1d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page