pywrit
Python client + CLI for Writ — the gate before the write. Put a policy gate in front of your agent's dangerous actions.
Install
pip install pywrit
Python client
from pywrit import WritClient
client = WritClient(api_key="writ_...")
result = client.check(
sponsor_id="acme",
agent_id="agent-7",
verb="db.write",
target="prod.customers",
purpose="backfill region field",
)
if result.decision == "ALLOW":
# result.auth_token is a short-lived token bound to this exact write
perform_write(...)
elif result.decision == "STEP_UP":
# a human sponsor must approve first: client.grant(...), then re-check
...
else:
# DENY
...
No API key yet? Try the keyless sandbox:
client = WritClient()
client.sandbox({
"sponsorId": "acme",
"agentId": "agent-7",
"verb": "demo_write", # sandbox only allows demo_write ...
"target": "demo-customers", # ... on targets starting with demo-
"purpose": "trying the gate",
})
What's covered
check(...)— the gate:ALLOW/DENY/STEP_UP, plus a receipt every timeverify_token(...)— validate anALLOWauth token (catches purpose drift)grant(...)— human-sponsor approval for theSTEP_UPpathget_policy()/set_policy(...)— manage the tenant policyrevoke(...)/reinstate(...)/revoked()— the kill switchreceipts()/receipt(id)/verify_chain()/stream_receipts()— the audit logsandbox(...)— keyless trial, no API key required
Every decision writes a receipt, so the audit log is the meter.
CLI
The same package ships the writ command:
writ check --key writ_... --sponsor acme --agent agent-7 \
--verb db.write --target prod.customers --purpose "backfill region field"
writ scan ./my-repo
writ receipts --key writ_...
writ verify-chain --key writ_...
Run writ --help for the full command list.
Docs
Full API reference: withwrit.com/docs
License
MIT
Metadata
Release files for pywrit 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pywrit-0.2.0.tar.gz | 16.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pywrit-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 32.3 kB
Release files / pywrit-0.2.0.tar.gz
| Download URL | pywrit-0.2.0.tar.gz |
|---|---|
| Size | 16.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4455e01a4c8fbce4e1808b08d222f6ab21ad065e39ab4c05f4be2f2e889edf6f
|
|
BLAKE2b-256 checksum How to use checksums |
21cdbf74240a9a653f9d50ae5a82d1be595c48b2c17b68d375c125676457a8d7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|
Release files / pywrit-0.2.0-py3-none-any.whl
| Download URL | pywrit-0.2.0-py3-none-any.whl |
|---|---|
| Size | 16.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0079a17bc248325dc30646c01554bab84ca18756300e12a323b0ff6adb3236aa
|
|
BLAKE2b-256 checksum How to use checksums |
9f60908430af5862cf61817e0c7e5d6e8aa3fb7376c9a9de5a63c17c20da3d50
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|