QuantaWatch Python SDK
Python SDK for QuantaWatch — the post-quantum security layer for AI agents.
Route your AI SDK traffic through the QuantaWatch gateway for threat detection, policy enforcement, and tamper-evident audit logging — all signed with post-quantum cryptography (ML-DSA-65).
Installation
Not yet published to PyPI. Install from source until the first release.
git clone https://github.com/dyber-pqc/QuantaWatch.git
pip install -e QuantaWatch/sdk/python
Requirements: Python 3.10+
Quick Start
Option 1: Protect an existing AI client (recommended)
The protect() wrapper transparently routes your existing SDK's HTTP traffic through the gateway. No code changes needed beyond the wrap call.
from anthropic import Anthropic
from quantawatch import protect
# One line — all API calls now flow through QuantaWatch
client = protect(Anthropic(), gateway_url="http://localhost:9090")
# Use the client exactly as before
response = client.messages.create(
model="claude-sonnet-4-20250514",
max_tokens=1024,
messages=[{"role": "user", "content": "Hello!"}],
)
Works with any httpx-based SDK, including OpenAI:
from openai import OpenAI
from quantawatch import protect
client = protect(OpenAI(), gateway_url="http://localhost:9090")
response = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Hello!"}],
)
Option 2: Use the gateway client directly
The QuantaWatchClient gives you direct access to the gateway proxy and admin API.
import asyncio
from quantawatch import QuantaWatchClient
async def main():
async with QuantaWatchClient() as qw:
# Proxy a raw request through the gateway
response = await qw.proxy_request(
"POST",
"/v1/messages",
headers={
"x-api-key": "sk-ant-...",
"anthropic-version": "2023-06-01",
"Content-Type": "application/json",
},
body=b'{"model":"claude-sonnet-4-20250514","max_tokens":1024,"messages":[{"role":"user","content":"Hello!"}]}',
)
print(response.status_code, response.text)
# Query the admin API
sessions = await qw.get_sessions()
stats = await qw.get_stats()
audit = await qw.get_audit_entries(limit=10)
# Verify audit chain integrity
result = await qw.verify_audit_chain()
print("Audit chain valid:", result.get("valid"))
asyncio.run(main())
API Reference
protect(client, *, gateway_url="http://localhost:9090")
Wraps an AI SDK client so its HTTP traffic flows through the QuantaWatch gateway.
| Parameter | Type | Default | Description |
|---|---|---|---|
client |
Any |
— | An AI SDK client (Anthropic, OpenAI, or any httpx-based client) |
gateway_url |
str |
http://localhost:9090 |
URL of the QuantaWatch gateway |
Returns a proxy object that behaves identically to the original client.
QuantaWatchClient
Async client for the QuantaWatch gateway and admin APIs.
QuantaWatchClient(
gateway_url="http://localhost:9090",
admin_url="http://localhost:9091",
timeout=30.0,
)
| Method | Description |
|---|---|
proxy_request(method, path, headers, body) |
Proxy an HTTP request through the gateway |
get_sessions() |
List all gateway sessions |
get_audit_entries(limit=100) |
Fetch recent audit log entries |
get_stats() |
Fetch aggregate gateway statistics |
verify_audit_chain() |
Verify cryptographic audit chain integrity |
close() |
Close the underlying HTTP client |
Types
All response types are Pydantic models:
SessionInfo— Gateway session with agent name, token count, PQC key fingerprintAuditEntry— Signed audit log entry with sequence number and hash chainGatewayStats— Aggregate stats (sessions, requests, threats, audit entries)ThreatAssessment— Threat analysis result with severity and blocked statusDetectedThreat— Individual threat with category, severity, confidence, and pattern name
Prerequisites
The SDK requires a running QuantaWatch gateway. Start one with Docker:
git clone https://github.com/dyber-pqc/QuantaWatch.git
cd QuantaWatch
cp quantawatch.yaml.example quantawatch.yaml
export ANTHROPIC_API_KEY=sk-ant-...
docker compose up -d
Or build from source:
cargo run -p qw-gateway -- quantawatch.yaml
Development
# Install with dev dependencies
pip install -e ".[dev]"
# Run tests
pytest
# Type checking (if mypy installed)
mypy quantawatch/
License
Links
Release files for quantawatch 0.1.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| quantawatch-0.1.5.tar.gz | 10.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| quantawatch-0.1.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 21.8 kB
Release files / quantawatch-0.1.5.tar.gz
| Download URL | quantawatch-0.1.5.tar.gz |
|---|---|
| Size | 10.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ad2b32dff0ffc75a06b5b2d2fab42802f4bef6096d52c01cff1542821264e0fe
|
|
BLAKE2b-256 checksum How to use checksums |
cdf9328f1e847e43d781e9ef6c39d08c91e62d69c744e2ec52002642b3eb569d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 26, 2026.
Transparency logRelease files / quantawatch-0.1.5-py3-none-any.whl
| Download URL | quantawatch-0.1.5-py3-none-any.whl |
|---|---|
| Size | 11.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
de5c358cb36a70a7c0ebddbf63e57d00e240c1f4f9e3b56bcd4abdc42a01dd4d
|
|
BLAKE2b-256 checksum How to use checksums |
18fb9a3cef4a98067e838c06088dfe73c8d62abf631a9d522f27ba8403519c25
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 26, 2026.
Transparency log