oneid-sdk
Python SDK for 1id.com -- hardware-anchored identity for AI agents.
Implements the AIRS (Agent Identity Registry System) drafts:
draft-drake-email-hardware-attestation-03-- email attestation via hardware keysdraft-drake-agent-identity-registry-04-- agent identity registry protocol
Quick start
import oneid
# Enroll at declared tier (no HSM needed, always works)
identity = oneid.enroll(request_tier="declared", display_name="Sparky")
print(f"Enrolled: {identity.handle}")
# URN: urn:aid:global:id-XXXXX-XXXXX-XXXXX-XXXXX
print(f"URN: {identity.agent_identity_urn}")
# Call an API that accepts 1ID tokens. Tokens are sender-constrained (cnf.jwk):
# each request is signed with your enrolled key (RFC 9421), so a copied token
# alone is refused. This does the signing for you:
response = oneid.send_http_request_with_sender_constrained_token(
"GET", "https://1id.com/api/v1/identity/devices")
# From the shell: oneid request GET https://1id.com/api/v1/identity/devices
# Check identity
me = oneid.whoami()
print(f"I am {me.handle}, trust tier: {me.trust_tier.value}")
Hardware-backed enrollment
# TPM enrollment (sovereign tier) - requires Windows/Linux with TPM 2.0
identity = oneid.enroll(request_tier="sovereign")
# YubiKey enrollment (portable tier) - requires YubiKey 5 inserted
identity = oneid.enroll(request_tier="portable")
# Virtual TPM (VMware/Hyper-V/QEMU)
identity = oneid.enroll(request_tier="virtual")
Trust tiers
| Tier | Hardware | Sybil Resistant | Trust Level |
|---|---|---|---|
sovereign |
TPM (Intel, AMD, Infineon) with valid cert | Yes | Highest |
portable |
YubiKey / Nitrokey / Feitian with PIV attestation | Yes | High |
virtual |
VMware / Hyper-V / QEMU vTPM | No | Verified Hardware |
declared |
None (software keys) | No | Software |
request_tier is a requirement, not a preference. You get exactly what you ask for, or an exception. No silent fallbacks.
Key algorithms
Like SSH, agents can choose their preferred key algorithm for declared-tier enrollment. Only ECDSA P-256 (the default) and RSA keys can also sign email Hardware-Attestation (Mode 1) proofs; Ed25519 and P-384 keys work for authentication only:
identity = oneid.enroll(request_tier="declared", key_algorithm="ecdsa-p256") # default (ES256; signs email)
identity = oneid.enroll(request_tier="declared", key_algorithm="ed25519") # authentication only
identity = oneid.enroll(request_tier="declared", key_algorithm="rsa-4096") # RSA (RS256; signs email)
Installation
pip install oneid
Requires Python 3.10+.
License
Apache-2.0
Release files for oneid 3.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oneid-3.1.1.tar.gz | 151.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| oneid-3.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 267.5 kB
Release files / oneid-3.1.1.tar.gz
| Download URL | oneid-3.1.1.tar.gz |
|---|---|
| Size | 151.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bd84a757971cce8ab0e6eaf2d2482c1957e76cfa878b24e668da37ab03ab19ff
|
|
BLAKE2b-256 checksum How to use checksums |
9b753eb3f97697ae3e57701999b83ba8f0a746aaeb2f2aceff263afa2fb47254
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.1
|
Release files / oneid-3.1.1-py3-none-any.whl
| Download URL | oneid-3.1.1-py3-none-any.whl |
|---|---|
| Size | 116.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9630ecc74279a3a868b306b580a350148a1758aec0d9b8ba5429065e071817d0
|
|
BLAKE2b-256 checksum How to use checksums |
8794851eb86dc3a4f139a86da04347324b14e48830b2b03e16466909ad1705ee
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.1
|