oneid-sdk
Python SDK for 1id.com -- hardware-anchored identity for AI agents.
Implements the AIRS (Agent Identity Registry System) drafts:
draft-drake-email-hardware-attestation-03-- email attestation via hardware keysdraft-drake-agent-identity-registry-04-- agent identity registry protocol
Quick start
import oneid
# Enroll at declared tier (no HSM needed, always works)
identity = oneid.enroll(request_tier="declared", display_name="Sparky")
print(f"Enrolled: {identity.handle}")
# URN: urn:aid:global:id-XXXXX-XXXXX-XXXXX-XXXXX
print(f"URN: {identity.agent_identity_urn}")
# Get an OAuth2 token for API access
token = oneid.get_token()
headers = {"Authorization": f"Bearer {token.access_token}"}
# Check identity
me = oneid.whoami()
print(f"I am {me.handle}, trust tier: {me.trust_tier.value}")
Hardware-backed enrollment
# TPM enrollment (sovereign tier) - requires Windows/Linux with TPM 2.0
identity = oneid.enroll(request_tier="sovereign")
# YubiKey enrollment (portable tier) - requires YubiKey 5 inserted
identity = oneid.enroll(request_tier="portable")
# Virtual TPM (VMware/Hyper-V/QEMU)
identity = oneid.enroll(request_tier="virtual")
Trust tiers
| Tier | Hardware | Sybil Resistant | Trust Level |
|---|---|---|---|
sovereign |
TPM (Intel, AMD, Infineon) with valid cert | Yes | Highest |
portable |
YubiKey / Nitrokey / Feitian with PIV attestation | Yes | High |
virtual |
VMware / Hyper-V / QEMU vTPM | No | Verified Hardware |
declared |
None (software keys) | No | Software |
request_tier is a requirement, not a preference. You get exactly what you ask for, or an exception. No silent fallbacks.
Key algorithms
Like SSH, agents can choose their preferred key algorithm for declared-tier enrollment. Only ECDSA P-256 (the default) and RSA keys can also sign email Hardware-Attestation (Mode 1) proofs; Ed25519 and P-384 keys work for authentication only:
identity = oneid.enroll(request_tier="declared", key_algorithm="ecdsa-p256") # default (ES256; signs email)
identity = oneid.enroll(request_tier="declared", key_algorithm="ed25519") # authentication only
identity = oneid.enroll(request_tier="declared", key_algorithm="rsa-4096") # RSA (RS256; signs email)
Installation
pip install oneid
Requires Python 3.10+.
License
Apache-2.0
Release files for oneid 3.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oneid-3.0.0.tar.gz | 137.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| oneid-3.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 243.2 kB
Release files / oneid-3.0.0.tar.gz
| Download URL | oneid-3.0.0.tar.gz |
|---|---|
| Size | 137.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3a731ee736ef03888d05839980432bd0dfa37023493576cb4ca4a0b5ae624cc9
|
|
BLAKE2b-256 checksum How to use checksums |
e8931544c955c2717e5a4bd0bc1f401ddde2c71d653a822c7db86969549226c8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.0
|
Release files / oneid-3.0.0-py3-none-any.whl
| Download URL | oneid-3.0.0-py3-none-any.whl |
|---|---|
| Size | 106.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d0920f201a4c6b7962456dcdc1180d578bae5f85db9f2b1c3f0832409d62bbd9
|
|
BLAKE2b-256 checksum How to use checksums |
f66eac60bb0d04190c0dc78f176e5659a9240bb838789edca9ce449671c082dd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.0
|