pywrit
Python client + CLI for Writ — the gate before the write. Put a policy gate in front of your agent's dangerous actions.
Install
pip install pywrit
Python client
from pywrit import WritClient
client = WritClient(api_key="writ_...")
result = client.check(
sponsor_id="acme",
agent_id="agent-7",
verb="db.write",
target="prod.customers",
purpose="backfill region field",
)
if result.decision == "ALLOW":
# result.auth_token is a short-lived token bound to this exact write
perform_write(...)
elif result.decision == "STEP_UP":
# a human sponsor must approve first: client.grant(...), then re-check
...
else:
# DENY
...
No API key yet? Try the keyless sandbox:
client = WritClient()
client.sandbox({
"sponsorId": "acme",
"agentId": "agent-7",
"verb": "demo_write", # sandbox only allows demo_write ...
"target": "demo-customers", # ... on targets starting with demo-
"purpose": "trying the gate",
})
What's covered
check(...)— the gate:ALLOW/DENY/STEP_UP, plus a receipt every timeverify_token(...)— validate anALLOWauth token (catches purpose drift)grant(...)— human-sponsor approval for theSTEP_UPpathget_policy()/set_policy(...)— manage the tenant policyrevoke(...)/reinstate(...)/revoked()— the kill switchreceipts()/receipt(id)/verify_chain()/stream_receipts()— the audit logsandbox(...)— keyless trial, no API key required
Every decision writes a receipt, so the audit log is the meter.
CLI
The same package ships the writ command:
writ check --key writ_... --sponsor acme --agent agent-7 \
--verb db.write --target prod.customers --purpose "backfill region field"
writ scan ./my-repo
writ receipts --key writ_...
writ verify-chain --key writ_...
Run writ --help for the full command list.
Docs
Full API reference: withwrit.com/docs
License
MIT
Metadata
Release files for pywrit 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pywrit-0.2.1.tar.gz | 16.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pywrit-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 32.4 kB
Release files / pywrit-0.2.1.tar.gz
| Download URL | pywrit-0.2.1.tar.gz |
|---|---|
| Size | 16.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5b1922a22309af38e2c4c64f13c0a208955b6e96d6a418c4f7f4a0bfe2437f74
|
|
BLAKE2b-256 checksum How to use checksums |
4b69db6a01fc90165a0dbc2cc995783bbcadc08ccfe831f086d6fb7345c7dbcb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|
Release files / pywrit-0.2.1-py3-none-any.whl
| Download URL | pywrit-0.2.1-py3-none-any.whl |
|---|---|
| Size | 16.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5ac07f58701aa00784ea55d7896fefdfd953bf9645a6f1ead3d77d15604f8c19
|
|
BLAKE2b-256 checksum How to use checksums |
13da1a82b0ed241d3f507cb369a36c6db82bb43e89c384008816765c48ad241e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.3
|