Skip to main content

Python SDK for QuantaWatch — AI agent security gateway

Project description

QuantaWatch Python SDK

License

Python SDK for QuantaWatch — the post-quantum security layer for AI agents.

Route your AI SDK traffic through the QuantaWatch gateway for threat detection, policy enforcement, and tamper-evident audit logging — all signed with post-quantum cryptography (ML-DSA-65).

Installation

Not yet published to PyPI. Install from source until the first release.

git clone https://github.com/dyber-pqc/QuantaWatch.git
pip install -e QuantaWatch/sdk/python

Requirements: Python 3.10+

Quick Start

Option 1: Protect an existing AI client (recommended)

The protect() wrapper transparently routes your existing SDK's HTTP traffic through the gateway. No code changes needed beyond the wrap call.

from anthropic import Anthropic
from quantawatch import protect

# One line — all API calls now flow through QuantaWatch
client = protect(Anthropic(), gateway_url="http://localhost:9090")

# Use the client exactly as before
response = client.messages.create(
    model="claude-sonnet-4-20250514",
    max_tokens=1024,
    messages=[{"role": "user", "content": "Hello!"}],
)

Works with any httpx-based SDK, including OpenAI:

from openai import OpenAI
from quantawatch import protect

client = protect(OpenAI(), gateway_url="http://localhost:9090")
response = client.chat.completions.create(
    model="gpt-4o",
    messages=[{"role": "user", "content": "Hello!"}],
)

Option 2: Use the gateway client directly

The QuantaWatchClient gives you direct access to the gateway proxy and admin API.

import asyncio
from quantawatch import QuantaWatchClient

async def main():
    async with QuantaWatchClient() as qw:
        # Proxy a raw request through the gateway
        response = await qw.proxy_request(
            "POST",
            "/v1/messages",
            headers={
                "x-api-key": "sk-ant-...",
                "anthropic-version": "2023-06-01",
                "Content-Type": "application/json",
            },
            body=b'{"model":"claude-sonnet-4-20250514","max_tokens":1024,"messages":[{"role":"user","content":"Hello!"}]}',
        )
        print(response.status_code, response.text)

        # Query the admin API
        sessions = await qw.get_sessions()
        stats = await qw.get_stats()
        audit = await qw.get_audit_entries(limit=10)

        # Verify audit chain integrity
        result = await qw.verify_audit_chain()
        print("Audit chain valid:", result.get("valid"))

asyncio.run(main())

API Reference

protect(client, *, gateway_url="http://localhost:9090")

Wraps an AI SDK client so its HTTP traffic flows through the QuantaWatch gateway.

Parameter Type Default Description
client Any An AI SDK client (Anthropic, OpenAI, or any httpx-based client)
gateway_url str http://localhost:9090 URL of the QuantaWatch gateway

Returns a proxy object that behaves identically to the original client.

QuantaWatchClient

Async client for the QuantaWatch gateway and admin APIs.

QuantaWatchClient(
    gateway_url="http://localhost:9090",
    admin_url="http://localhost:9091",
    timeout=30.0,
)
Method Description
proxy_request(method, path, headers, body) Proxy an HTTP request through the gateway
get_sessions() List all gateway sessions
get_audit_entries(limit=100) Fetch recent audit log entries
get_stats() Fetch aggregate gateway statistics
verify_audit_chain() Verify cryptographic audit chain integrity
close() Close the underlying HTTP client

Types

All response types are Pydantic models:

  • SessionInfo — Gateway session with agent name, token count, PQC key fingerprint
  • AuditEntry — Signed audit log entry with sequence number and hash chain
  • GatewayStats — Aggregate stats (sessions, requests, threats, audit entries)
  • ThreatAssessment — Threat analysis result with severity and blocked status
  • DetectedThreat — Individual threat with category, severity, confidence, and pattern name

Prerequisites

The SDK requires a running QuantaWatch gateway. Start one with Docker:

git clone https://github.com/dyber-pqc/QuantaWatch.git
cd QuantaWatch
cp quantawatch.yaml.example quantawatch.yaml
export ANTHROPIC_API_KEY=sk-ant-...
docker compose up -d

Or build from source:

cargo run -p qw-gateway -- quantawatch.yaml

Development

# Install with dev dependencies
pip install -e ".[dev]"

# Run tests
pytest

# Type checking (if mypy installed)
mypy quantawatch/

License

Apache License 2.0

Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

quantawatch-0.1.4.tar.gz (10.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

quantawatch-0.1.4-py3-none-any.whl (11.0 kB view details)

Uploaded Python 3

File details

Details for the file quantawatch-0.1.4.tar.gz.

File metadata

  • Download URL: quantawatch-0.1.4.tar.gz
  • Upload date:
  • Size: 10.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for quantawatch-0.1.4.tar.gz
Algorithm Hash digest
SHA256 40040b8fa09eb1fd339898cdb3218780bb3963183f87dab041004c7822902114
MD5 1bb28bdb8943469a7c57bc10ee07af11
BLAKE2b-256 0025565d6860768aca47fff6689baa1dc158bf69abb764056b634e70b8c81add

See more details on using hashes here.

Provenance

The following attestation bundles were made for quantawatch-0.1.4.tar.gz:

Publisher: release.yml on dyber-pqc/QuantaWatch

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file quantawatch-0.1.4-py3-none-any.whl.

File metadata

  • Download URL: quantawatch-0.1.4-py3-none-any.whl
  • Upload date:
  • Size: 11.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for quantawatch-0.1.4-py3-none-any.whl
Algorithm Hash digest
SHA256 325d034129d3ef0ce1b50043c3ab49cc9652ba821379e3efc49eb27f449e92e9
MD5 c59c9d6803eee730bd6e7d3af5217f49
BLAKE2b-256 fa617565c5da90d8ec240829669390b9c6f46d998c77379fc8815b63c12a4b83

See more details on using hashes here.

Provenance

The following attestation bundles were made for quantawatch-0.1.4-py3-none-any.whl:

Publisher: release.yml on dyber-pqc/QuantaWatch

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page