Skip to main content

provenex-verifier

CI PyPI Python License: MIT

Standalone, offline verifier for Provenex receipts.

A Provenex receipt is a signed JSON artifact that a regulator or third party can validate without contacting the issuing organization. This library is the reference verifier: it takes a receipt and an Ed25519 public key, and tells you whether the signature is valid over the canonical payload.

  • No network. Runs in air-gapped environments. No telemetry, no analytics, no phone-home.
  • No provenex-core dependency. Implements the receipt-format spec directly.
  • One runtime dependency (cryptography) for Ed25519. Everything else is stdlib.
  • Tiny. Under 500 lines of actual code.

Install

pip install provenex-verifier

30-second example

import json
from provenex_verifier import verify_receipt

with open("receipt.json") as fh:
    receipt = json.load(fh)
with open("issuer_public_key.pem", "rb") as fh:
    public_key = fh.read()

result = verify_receipt(receipt, public_key)

if result.valid:
    print(f"Receipt OK. Signed by {result.signer} at {result.signed_at}.")
else:
    print("Receipt INVALID:")
    for err in result.errors:
        print(f"  - {err}")

Command line

provenex-verify receipt.json --public-key issuer_public_key.pem

Exit codes: 0 valid, 1 invalid, 2 usage error. Reads from stdin if the receipt argument is -.

API

Symbol Purpose
verify_receipt(receipt, public_key) -> VerificationResult Verify an Ed25519 receipt signature.
VerificationResult NamedTuple: valid, signer, signed_at, errors, warnings.
canonicalize(receipt) -> bytes Reproduce the canonical signed-payload bytes. Exposed so callers can audit the canonicalization step independently of signature verification.
verify_inclusion_proof(leaf_hash, proof, tree_root, leaf_index, tree_size) -> bool Verify an RFC 6962 Merkle inclusion proof.

Every public function carries an inline docstring. See the source for parameter shapes and edge-case behavior.

What this library does not do

The verifier is deliberately narrow:

  • No fingerprinting, normalization, indexing, or retrieval logic.
  • No policy evaluation. Receipts record decisions; this library does not re-interpret them.
  • No HTTP client, no key-fetching, no TSA lookups.
  • No automatic Merkle inclusion check, no trajectory walking. Those are layered on top by callers.

If you need to issue receipts, use provenex-core. This library is purely the verification half.

Algorithm support

  • Ed25519 -- yes. The verifier accepts public keys in PEM (SubjectPublicKeyInfo), DER, or 32-byte raw form.
  • HMAC-SHA256 -- explicitly rejected. HMAC is symmetric: anyone able to verify can forge. A third-party verifier is by definition not the producer, so HMAC receipts are out of scope. Receipts using HMAC fail with a clear unsupported signature algorithm error.

Spec compatibility

This library implements:

  • Receipt schema 2.5.0 canonicalization rules (docs/receipt_format.md in provenex-core).
  • RFC 6962 Merkle inclusion proofs.

Test vectors live in test-vectors/ and are versioned alongside the library. The cross-compatibility test in tests/test_merkle.py pins a proof generated by provenex-core and asserts this verifier accepts it.

Stability promise

This library is at v1.0.0 because the receipt format is. Any change that breaks a previously valid receipt is a breaking change and bumps the major version.

Security

Report vulnerabilities to contact@provenex.ai (see SECURITY.md). The library has no network surface area, but a verifier that mis-validates a tampered receipt is a security issue.

License

MIT. See LICENSE.

Release files for provenex-verifier 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for provenex-verifier 1.0.0
File Size Uploaded
provenex_verifier-1.0.0.tar.gz 25.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for provenex-verifier 1.0.0
File Interpreter ABI Platform
provenex_verifier-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 37.5 kB

Release files / provenex_verifier-1.0.0.tar.gz

Download URL provenex_verifier-1.0.0.tar.gz
Size 25.2 kB
Tags Source
SHA-256 checksum
How to use checksums
3189902400c4d088c75c2aef2b77ae9c3c99a0bcb58e41cddebad718031f9a26
BLAKE2b-256 checksum
How to use checksums
2a95a712252f2520af5afb147cae3ca05fca57500dd78ca74e32e0c6fe57ff6e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release files / provenex_verifier-1.0.0-py3-none-any.whl

Download URL provenex_verifier-1.0.0-py3-none-any.whl
Size 12.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
039404d1a09250b9a2d272799cd3906dfdd16a6f60b41f50ba06c4e5883f95ea
BLAKE2b-256 checksum
How to use checksums
823fdbbbd76b6a789d4c59b73196321ca066bf802c69523e21569b7f56f28eff
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.10

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page