Skip to main content

OPP Python SDK (opp_py)

Instrumentation + CLI for ODIN Provenance Passport (OPP).

Features

  • @stamp(step_type, attrs=..., inputs=..., outputs=...) decorator emits start/end signed receipts.
  • Automatic input/output content IDs (CIDs) via optional callables.
  • Fallback lightweight OPE client (no external odin-sdk required) using env Ed25519 seed.
  • Graph + Passport generation (opp graph, opp passport).
  • Policy evidence aggregation & breach summary (opp policy).
  • Optional C2PA bridge (opp.c2pa.embed_bundle_cid) to embed bundle CID into images (extra deps).

Install (editable dev)

pip install -e packages/opp_py

Required env for stamping (generate a random 32‑byte seed once):

export OPP_GATEWAY_URL=http://127.0.0.1:8080
export OPP_SENDER_PRIV_B64=<base64url_32byte_seed>
export OPP_SENDER_KID=opp-sender

Generate a seed (PowerShell):

$bytes = New-Object byte[] 32; [Security.Cryptography.RandomNumberGenerator]::Create().GetBytes($bytes); \
$seed = [Convert]::ToBase64String($bytes).TrimEnd('=') -replace '\+','-' -replace '/','_'; $seed

Decorator Usage

from opp.decorators import stamp

@stamp(
		"train.v1",
		attrs={"model":"resnet"},
		inputs=lambda args, kwargs: {"hyperparams": kwargs.get("hp")},
		outputs=lambda ret: {"metrics": ret.get("metrics")}
)
def train(data, *, hp):
		# ... training ...
		return {"metrics": {"accuracy": 0.93}}

train([], hp={"lr":1e-3})

Emitted start receipt includes inputs_cid; end receipt includes outputs_cid and status.

CLI

opp graph --trace TRACE --gateway $OPP_GATEWAY_URL         # build minimal graph
opp validate --trace TRACE --gateway $OPP_GATEWAY_URL      # continuity + basic validation
opp passport --trace TRACE --gateway $OPP_GATEWAY_URL      # rich model/data passport JSON
opp policy --trace TRACE --gateway $OPP_GATEWAY_URL        # summarized policy evidence + breaches

Passport Fields (excerpt)

{
	"trace_id": "...",
	"receipts": 12,
	"steps": ["ingest.v1","train.v1"],
	"dataset_roots": ["sha256:..."],
	"model_id": "model-123",
	"metrics": {"accuracy": 0.93},
	"safety_flags": {"pii_redacted": true},
	"policy_engines": ["opa"],
	"policy_breaches": [{"rule":"no_public_data","outcome":"deny"}]
}

Policy Evidence

If receipts carry a normalized policy object with engine + decisions[], breaches are auto‑derived when an outcome is not in {allow, pass, ok}.

Optional C2PA Bridge

pip install c2pa Pillow
python examples/c2pa_embed.py image.png

Adds a custom assertion with the bundle_cid to the image manifest.

Airflow & Dagster Examples

See examples/airflow_dag.py and examples/dagster_job.py for task/op instrumentation and trace continuity.

Testing

pytest -q packages/opp_py/tests

Backward Compatibility

New fields are additive; existing receipt payload fields preserved. Hashing uses canonical JSON (stable order, no whitespace).

License

Apache 2.0

Metadata

Release files for opp-py 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for opp-py 0.1.1
File Size Uploaded
opp_py-0.1.1.tar.gz 12.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for opp-py 0.1.1
File Interpreter ABI Platform
opp_py-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 23.7 kB

Release files / opp_py-0.1.1.tar.gz

Download URL opp_py-0.1.1.tar.gz
Size 12.3 kB
Tags Source
SHA-256 checksum
How to use checksums
d7e2f307ee53eda3d2fff3ab2d235b5bb717b9aa6adacbe26164c2bc5ebb78a9
BLAKE2b-256 checksum
How to use checksums
21cc216fecc91091854b82305372a0b1afdcf2a249d977b29b6e7aabc320b297
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.13

Release files / opp_py-0.1.1-py3-none-any.whl

Download URL opp_py-0.1.1-py3-none-any.whl
Size 11.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3aa017c3bb2313931d9a9427a49970c5e711be9465d459e62dcadf93f592e646
BLAKE2b-256 checksum
How to use checksums
1bb97100f5e879fa97d20cf40298161aa890c5718165d5e4cd9721bc6ee83542
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.13

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page