QuoxProof
Offline-verifiable, Ed25519-signed receipts for every AI agent tool call.
import quoxproof
quoxproof.enable()
@quoxproof.tool
def search(query: str) -> str:
return f"results for {query}"
search("agentic AI")
Every call writes a signed, hash-chained receipt to ~/.quox/proofs/. Verify it
later with no server, no account, no shared secret:
quoxproof verify ~/.quox/proofs/<session>.ndjson
Why it is different
A backend audit service signs receipts with a secret shared with its own server, so a receipt cannot be checked without that server and your API key. QuoxProof signs with Ed25519 (asymmetric) and carries the public key in the receipt, so anyone can verify it offline. The verifier reports the trust ladder honestly and never collapses it to a single green tick: a receipt that proves "the SDK recorded this call" is a weaker claim than "this action ran through a governed plane", and QuoxProof says which one it can back.
Checkpoints (anti-rewrite anchor)
Pin the head of a chain with a signed checkpoint, then detect any later truncation or tail-rewrite:
quoxproof checkpoint ~/.quox/proofs/<session>.ndjson # writes <session>.tip.json
quoxproof verify ~/.quox/proofs/<session>.ndjson --tip ~/.quox/proofs/<session>.tip.json
A checkpoint is a WARD tip by another name (Ed25519 over the head hash). It is an anti-rewrite anchor, not third-party witnessing, and the verifier says so.
In-browser viewer
viewer/receipt-viewer.html is a single self-contained page: drop a receipt file
(and optionally a checkpoint) and it verifies the signatures and hash chain in your
browser via WebCrypto. No install, no upload, no backend.
Status: local signing, chaining, checkpoints, and offline verification are driven end to end (Python + an in-browser verifier). LangChain and MCP auto-hooks are driven against the real frameworks. QuoxCORE witnessing and governed execution are the upgrade tiers.
Metadata
Release files for quoxproof 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| quoxproof-0.2.0.tar.gz | 26.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| quoxproof-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.5 kB
Release files / quoxproof-0.2.0.tar.gz
| Download URL | quoxproof-0.2.0.tar.gz |
|---|---|
| Size | 26.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e2ceee2b95392bbef2580cb490b3a7d84bf6857d215a7a4c01101c241df1bd85
|
|
BLAKE2b-256 checksum How to use checksums |
0fe5e7ec91a0050ff1b583c1dba0abd9d43b166313c608cbedc0d67a46fd9700
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.
Transparency logRelease files / quoxproof-0.2.0-py3-none-any.whl
| Download URL | quoxproof-0.2.0-py3-none-any.whl |
|---|---|
| Size | 24.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
91188208e5bb016b34bb94f9066bc355b9e8b8c08ca85f28e564f611d3c74e22
|
|
BLAKE2b-256 checksum How to use checksums |
b8e3f20ff1eab97f9dc49a3b125eed780c978e87f818ef473e1f90600cc18552
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.
Transparency log