oneid-sdk
Python SDK for 1id.com -- hardware-anchored identity for AI agents.
Implements the AIRS (Agent Identity Registry System) drafts:
draft-drake-email-hardware-attestation-03-- email attestation via hardware keysdraft-drake-agent-identity-registry-04-- agent identity registry protocol
Quick start
import oneid
# Enroll at declared tier (no HSM needed, always works)
identity = oneid.enroll(request_tier="declared", display_name="Sparky")
print(f"Enrolled: {identity.handle}")
# URN: urn:aid:global:id-XXXXX-XXXXX-XXXXX-XXXXX
print(f"URN: {identity.agent_identity_urn}")
# Call an API that accepts 1ID tokens. Tokens are sender-constrained (cnf.jwk):
# each request is signed with your enrolled key (RFC 9421), so a copied token
# alone is refused. This does the signing for you:
response = oneid.send_http_request_with_sender_constrained_token(
"GET", "https://1id.com/api/v1/identity/devices")
# From the shell: oneid request GET https://1id.com/api/v1/identity/devices
# Check identity
me = oneid.whoami()
print(f"I am {me.handle}, trust tier: {me.trust_tier.value}")
Hardware-backed enrollment
# TPM enrollment (sovereign tier) - requires Windows/Linux with TPM 2.0
identity = oneid.enroll(request_tier="sovereign")
# YubiKey enrollment (portable tier) - requires YubiKey 5 inserted
identity = oneid.enroll(request_tier="portable")
# Virtual TPM (VMware/Hyper-V/QEMU)
identity = oneid.enroll(request_tier="virtual")
Trust tiers
| Tier | Hardware | Sybil Resistant | Trust Level |
|---|---|---|---|
sovereign |
TPM (Intel, AMD, Infineon) with valid cert | Yes | Highest |
portable |
YubiKey / Nitrokey / Feitian with PIV attestation | Yes | High |
virtual |
VMware / Hyper-V / QEMU vTPM | No | Verified Hardware |
declared |
None (software keys) | No | Software |
request_tier is a requirement, not a preference. You get exactly what you ask for, or an exception. No silent fallbacks.
Key algorithms
Like SSH, agents can choose their preferred key algorithm for declared-tier enrollment. Only ECDSA P-256 (the default) and RSA keys can also sign email Hardware-Attestation (Mode 1) proofs; Ed25519 and P-384 keys work for authentication only:
identity = oneid.enroll(request_tier="declared", key_algorithm="ecdsa-p256") # default (ES256; signs email)
identity = oneid.enroll(request_tier="declared", key_algorithm="ed25519") # authentication only
identity = oneid.enroll(request_tier="declared", key_algorithm="rsa-4096") # RSA (RS256; signs email)
Installation
pip install oneid
Requires Python 3.10+.
License
Apache-2.0
Release files for oneid 3.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oneid-3.1.0.tar.gz | 150.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| oneid-3.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 265.3 kB
Release files / oneid-3.1.0.tar.gz
| Download URL | oneid-3.1.0.tar.gz |
|---|---|
| Size | 150.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
10c769456cca07dd78f56b93ab242d8a1068ce00b3835a57f0a67cefde624a89
|
|
BLAKE2b-256 checksum How to use checksums |
0359418be7f138e1c6b9d1e370405cade235a0485a02b3e8b03e87bed11fd29d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.1
|
Release files / oneid-3.1.0-py3-none-any.whl
| Download URL | oneid-3.1.0-py3-none-any.whl |
|---|---|
| Size | 115.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e24bde96f6252853e24976ed9f51caf2a8dbc398d1a560ac80f395e02993cf2a
|
|
BLAKE2b-256 checksum How to use checksums |
647c161127fe1c78193d5905c9108fef60e5dc7a8e401500b16819f2ca2e134f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.1
|