oneid-sdk
Python SDK for 1id.com -- hardware-anchored identity for AI agents.
Implements the AIRS (Agent Identity Registry System) drafts:
draft-drake-email-hardware-attestation-03-- email attestation via hardware keysdraft-drake-agent-identity-registry-04-- agent identity registry protocol
Quick start
import oneid
# Enroll at declared tier (no HSM needed, always works)
identity = oneid.enroll(request_tier="declared", display_name="Sparky")
print(f"Enrolled: {identity.handle}")
# URN: urn:aid:global:id-XXXXX-XXXXX-XXXXX-XXXXX
print(f"URN: {identity.agent_identity_urn}")
# Get an OAuth2 token for API access
token = oneid.get_token()
headers = {"Authorization": f"Bearer {token.access_token}"}
# Check identity
me = oneid.whoami()
print(f"I am {me.handle}, trust tier: {me.trust_tier.value}")
Hardware-backed enrollment
# TPM enrollment (sovereign tier) - requires Windows/Linux with TPM 2.0
identity = oneid.enroll(request_tier="sovereign")
# YubiKey enrollment (portable tier) - requires YubiKey 5 inserted
identity = oneid.enroll(request_tier="portable")
# Virtual TPM (VMware/Hyper-V/QEMU)
identity = oneid.enroll(request_tier="virtual")
Trust tiers
| Tier | Hardware | Sybil Resistant | Trust Level |
|---|---|---|---|
sovereign |
TPM (Intel, AMD, Infineon) with valid cert | Yes | Highest |
portable |
YubiKey / Nitrokey / Feitian with PIV attestation | Yes | High |
virtual |
VMware / Hyper-V / QEMU vTPM | No | Verified Hardware |
declared |
None (software keys) | No | Software |
request_tier is a requirement, not a preference. You get exactly what you ask for, or an exception. No silent fallbacks.
Key algorithms
Like SSH, agents can choose their preferred key algorithm for declared-tier enrollment. Only ECDSA P-256 (the default) and RSA keys can also sign email Hardware-Attestation (Mode 1) proofs; Ed25519 and P-384 keys work for authentication only:
identity = oneid.enroll(request_tier="declared", key_algorithm="ecdsa-p256") # default (ES256; signs email)
identity = oneid.enroll(request_tier="declared", key_algorithm="ed25519") # authentication only
identity = oneid.enroll(request_tier="declared", key_algorithm="rsa-4096") # RSA (RS256; signs email)
Installation
pip install oneid
Requires Python 3.10+.
License
Apache-2.0
Release files for oneid 3.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oneid-3.0.1.tar.gz | 138.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| oneid-3.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 245.5 kB
Release files / oneid-3.0.1.tar.gz
| Download URL | oneid-3.0.1.tar.gz |
|---|---|
| Size | 138.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ac2d27b1e1743d20316d5d7edb39c1e6b049f245117241b49986061fddb82deb
|
|
BLAKE2b-256 checksum How to use checksums |
25c6f80479f376c17d6f8a30564990f9a1532f50f81b540eb68aa29b6a15472c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.1
|
Release files / oneid-3.0.1-py3-none-any.whl
| Download URL | oneid-3.0.1-py3-none-any.whl |
|---|---|
| Size | 106.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
efaae4e1acb247069ff3d99a615f67631e5723b2eeaac790d8eecdfbf81ca8a9
|
|
BLAKE2b-256 checksum How to use checksums |
e214d750885beb0a52d6a342bcb800e0be288731972219a09ccdcbd4c2e49156
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.1
|