Standalone, offline verifier for Provenex receipts. Implements the receipt-format spec; no network, no telemetry, no dependencies on provenex-core.
Project description
provenex-verifier
Standalone, offline verifier for Provenex receipts.
A Provenex receipt is a signed JSON artifact that a regulator or third party can validate without contacting the issuing organization. This library is the reference verifier: it takes a receipt and an Ed25519 public key, and tells you whether the signature is valid over the canonical payload.
- No network. Runs in air-gapped environments. No telemetry, no analytics, no phone-home.
- No
provenex-coredependency. Implements the receipt-format spec directly. - One runtime dependency (
cryptography) for Ed25519. Everything else is stdlib. - Tiny. Under 500 lines of actual code.
Install
pip install provenex-verifier
30-second example
import json
from provenex_verifier import verify_receipt
with open("receipt.json") as fh:
receipt = json.load(fh)
with open("issuer_public_key.pem", "rb") as fh:
public_key = fh.read()
result = verify_receipt(receipt, public_key)
if result.valid:
print(f"Receipt OK. Signed by {result.signer} at {result.signed_at}.")
else:
print("Receipt INVALID:")
for err in result.errors:
print(f" - {err}")
Command line
provenex-verify receipt.json --public-key issuer_public_key.pem
Exit codes: 0 valid, 1 invalid, 2 usage error. Reads from stdin if the receipt argument is -.
API
| Symbol | Purpose |
|---|---|
verify_receipt(receipt, public_key) -> VerificationResult |
Verify an Ed25519 receipt signature. |
VerificationResult |
NamedTuple: valid, signer, signed_at, errors, warnings. |
canonicalize(receipt) -> bytes |
Reproduce the canonical signed-payload bytes. Exposed so callers can audit the canonicalization step independently of signature verification. |
verify_inclusion_proof(leaf_hash, proof, tree_root, leaf_index, tree_size) -> bool |
Verify an RFC 6962 Merkle inclusion proof. |
Every public function carries an inline docstring. See the source for parameter shapes and edge-case behavior.
What this library does not do
The verifier is deliberately narrow:
- No fingerprinting, normalization, indexing, or retrieval logic.
- No policy evaluation. Receipts record decisions; this library does not re-interpret them.
- No HTTP client, no key-fetching, no TSA lookups.
- No automatic Merkle inclusion check, no trajectory walking. Those are layered on top by callers.
If you need to issue receipts, use provenex-core. This library is purely the verification half.
Algorithm support
- Ed25519 -- yes. The verifier accepts public keys in PEM (
SubjectPublicKeyInfo), DER, or 32-byte raw form. - HMAC-SHA256 -- explicitly rejected. HMAC is symmetric: anyone able to verify can forge. A third-party verifier is by definition not the producer, so HMAC receipts are out of scope. Receipts using HMAC fail with a clear
unsupported signature algorithmerror.
Spec compatibility
This library implements:
- Receipt schema 2.5.0 canonicalization rules (
docs/receipt_format.mdinprovenex-core). - RFC 6962 Merkle inclusion proofs.
Test vectors live in test-vectors/ and are versioned alongside the library. The cross-compatibility test in tests/test_merkle.py pins a proof generated by provenex-core and asserts this verifier accepts it.
Stability promise
This library is at v1.0.0 because the receipt format is. Any change that breaks a previously valid receipt is a breaking change and bumps the major version.
Security
Report vulnerabilities to contact@provenex.ai (see SECURITY.md). The library has no network surface area, but a verifier that mis-validates a tampered receipt is a security issue.
License
MIT. See LICENSE.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file provenex_verifier-1.0.0.tar.gz.
File metadata
- Download URL: provenex_verifier-1.0.0.tar.gz
- Upload date:
- Size: 25.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3189902400c4d088c75c2aef2b77ae9c3c99a0bcb58e41cddebad718031f9a26
|
|
| MD5 |
ede79b3c968d02dc6e6ac43c0929c559
|
|
| BLAKE2b-256 |
2a95a712252f2520af5afb147cae3ca05fca57500dd78ca74e32e0c6fe57ff6e
|
File details
Details for the file provenex_verifier-1.0.0-py3-none-any.whl.
File metadata
- Download URL: provenex_verifier-1.0.0-py3-none-any.whl
- Upload date:
- Size: 12.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.10
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
039404d1a09250b9a2d272799cd3906dfdd16a6f60b41f50ba06c4e5883f95ea
|
|
| MD5 |
80e15baceb4951af6f6806bbe1b01c68
|
|
| BLAKE2b-256 |
823fdbbbd76b6a789d4c59b73196321ca066bf802c69523e21569b7f56f28eff
|