Skip to main content

Standalone, offline verifier for Provenex receipts. Implements the receipt-format spec; no network, no telemetry, no dependencies on provenex-core.

Project description

provenex-verifier

CI PyPI Python License: MIT

Standalone, offline verifier for Provenex receipts.

A Provenex receipt is a signed JSON artifact that a regulator or third party can validate without contacting the issuing organization. This library is the reference verifier: it takes a receipt and an Ed25519 public key, and tells you whether the signature is valid over the canonical payload.

  • No network. Runs in air-gapped environments. No telemetry, no analytics, no phone-home.
  • No provenex-core dependency. Implements the receipt-format spec directly.
  • One runtime dependency (cryptography) for Ed25519. Everything else is stdlib.
  • Tiny. Under 500 lines of actual code.

Install

pip install provenex-verifier

30-second example

import json
from provenex_verifier import verify_receipt

with open("receipt.json") as fh:
    receipt = json.load(fh)
with open("issuer_public_key.pem", "rb") as fh:
    public_key = fh.read()

result = verify_receipt(receipt, public_key)

if result.valid:
    print(f"Receipt OK. Signed by {result.signer} at {result.signed_at}.")
else:
    print("Receipt INVALID:")
    for err in result.errors:
        print(f"  - {err}")

Command line

provenex-verify receipt.json --public-key issuer_public_key.pem

Exit codes: 0 valid, 1 invalid, 2 usage error. Reads from stdin if the receipt argument is -.

API

Symbol Purpose
verify_receipt(receipt, public_key) -> VerificationResult Verify an Ed25519 receipt signature.
VerificationResult NamedTuple: valid, signer, signed_at, errors, warnings.
canonicalize(receipt) -> bytes Reproduce the canonical signed-payload bytes. Exposed so callers can audit the canonicalization step independently of signature verification.
verify_inclusion_proof(leaf_hash, proof, tree_root, leaf_index, tree_size) -> bool Verify an RFC 6962 Merkle inclusion proof.

Every public function carries an inline docstring. See the source for parameter shapes and edge-case behavior.

What this library does not do

The verifier is deliberately narrow:

  • No fingerprinting, normalization, indexing, or retrieval logic.
  • No policy evaluation. Receipts record decisions; this library does not re-interpret them.
  • No HTTP client, no key-fetching, no TSA lookups.
  • No automatic Merkle inclusion check, no trajectory walking. Those are layered on top by callers.

If you need to issue receipts, use provenex-core. This library is purely the verification half.

Algorithm support

  • Ed25519 -- yes. The verifier accepts public keys in PEM (SubjectPublicKeyInfo), DER, or 32-byte raw form.
  • HMAC-SHA256 -- explicitly rejected. HMAC is symmetric: anyone able to verify can forge. A third-party verifier is by definition not the producer, so HMAC receipts are out of scope. Receipts using HMAC fail with a clear unsupported signature algorithm error.

Spec compatibility

This library implements:

  • Receipt schema 2.5.0 canonicalization rules (docs/receipt_format.md in provenex-core).
  • RFC 6962 Merkle inclusion proofs.

Test vectors live in test-vectors/ and are versioned alongside the library. The cross-compatibility test in tests/test_merkle.py pins a proof generated by provenex-core and asserts this verifier accepts it.

Stability promise

This library is at v1.0.0 because the receipt format is. Any change that breaks a previously valid receipt is a breaking change and bumps the major version.

Security

Report vulnerabilities to contact@provenex.ai (see SECURITY.md). The library has no network surface area, but a verifier that mis-validates a tampered receipt is a security issue.

License

MIT. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

provenex_verifier-1.0.0.tar.gz (25.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

provenex_verifier-1.0.0-py3-none-any.whl (12.3 kB view details)

Uploaded Python 3

File details

Details for the file provenex_verifier-1.0.0.tar.gz.

File metadata

  • Download URL: provenex_verifier-1.0.0.tar.gz
  • Upload date:
  • Size: 25.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.10

File hashes

Hashes for provenex_verifier-1.0.0.tar.gz
Algorithm Hash digest
SHA256 3189902400c4d088c75c2aef2b77ae9c3c99a0bcb58e41cddebad718031f9a26
MD5 ede79b3c968d02dc6e6ac43c0929c559
BLAKE2b-256 2a95a712252f2520af5afb147cae3ca05fca57500dd78ca74e32e0c6fe57ff6e

See more details on using hashes here.

File details

Details for the file provenex_verifier-1.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for provenex_verifier-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 039404d1a09250b9a2d272799cd3906dfdd16a6f60b41f50ba06c4e5883f95ea
MD5 80e15baceb4951af6f6806bbe1b01c68
BLAKE2b-256 823fdbbbd76b6a789d4c59b73196321ca066bf802c69523e21569b7f56f28eff

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page