Skip to main content

pywrit

Python client + CLI for Writ — the gate before the write. Put a policy gate in front of your agent's dangerous actions.

Install

pip install pywrit

Python client

from pywrit import WritClient

client = WritClient(api_key="writ_...")

result = client.check(
    sponsor_id="acme",
    agent_id="agent-7",
    verb="db.write",
    target="prod.customers",
    purpose="backfill region field",
)

if result.decision == "ALLOW":
    # result.auth_token is a short-lived token bound to this exact write
    perform_write(...)
elif result.decision == "STEP_UP":
    # a human sponsor must approve first: client.grant(...), then re-check
    ...
else:
    # DENY
    ...

No API key yet? Try the keyless sandbox:

client = WritClient()
client.sandbox({
    "sponsorId": "acme",
    "agentId": "agent-7",
    "verb": "demo_write",       # sandbox only allows demo_write ...
    "target": "demo-customers", # ... on targets starting with demo-
    "purpose": "trying the gate",
})

What's covered

  • check(...) — the gate: ALLOW / DENY / STEP_UP, plus a receipt every time
  • verify_token(...) — validate an ALLOW auth token (catches purpose drift)
  • grant(...) — human-sponsor approval for the STEP_UP path
  • get_policy() / set_policy(...) — manage the tenant policy
  • revoke(...) / reinstate(...) / revoked() — the kill switch
  • receipts() / receipt(id) / verify_chain() / stream_receipts() — the audit log
  • sandbox(...) — keyless trial, no API key required

Every decision writes a receipt, so the audit log is the meter.

CLI

The same package ships the writ command:

writ check --key writ_... --sponsor acme --agent agent-7 \
  --verb db.write --target prod.customers --purpose "backfill region field"
writ scan ./my-repo
writ receipts --key writ_...
writ verify-chain --key writ_...

Run writ --help for the full command list.

Docs

Full API reference: withwrit.com/docs

License

MIT

Metadata

Release files for pywrit 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pywrit 0.2.1
File Size Uploaded
pywrit-0.2.1.tar.gz 16.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pywrit 0.2.1
File Interpreter ABI Platform
pywrit-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 32.4 kB

Release files / pywrit-0.2.1.tar.gz

Download URL pywrit-0.2.1.tar.gz
Size 16.4 kB
Tags Source
SHA-256 checksum
How to use checksums
5b1922a22309af38e2c4c64f13c0a208955b6e96d6a418c4f7f4a0bfe2437f74
BLAKE2b-256 checksum
How to use checksums
4b69db6a01fc90165a0dbc2cc995783bbcadc08ccfe831f086d6fb7345c7dbcb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.3

Release files / pywrit-0.2.1-py3-none-any.whl

Download URL pywrit-0.2.1-py3-none-any.whl
Size 16.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5ac07f58701aa00784ea55d7896fefdfd953bf9645a6f1ead3d77d15604f8c19
BLAKE2b-256 checksum
How to use checksums
13da1a82b0ed241d3f507cb369a36c6db82bb43e89c384008816765c48ad241e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.3

Release history Release notifications | RSS feed

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page