This release is a pre-release and may not be stable for production use.
ratify-protocol-native
You almost certainly do not need this package.
Install ratify-protocol instead.
That is the Python SDK: it verifies proofs, issues delegations, signs
challenges, and stores identities, in pure Python, on every platform.
This package is a small optional add-on to that SDK. It exists to provide one function, and nothing else.
What this package does
It provides deterministic key generation: turning two 32-byte seeds into the same Ratify identity every time, and the same identity that the Go, Rust, TypeScript, and C SDKs derive from those seeds.
That is the whole scope. It contains no verification logic, no signing logic, and no protocol implementation. Installing it does not change how anything else in the Python SDK behaves.
Do you need it?
No, if you are verifying proofs, issuing delegations, signing challenges, or
saving an identity to reuse later. All of that works in ratify-protocol with
nothing extra. To persist an identity, store its key bytes and load them back.
Yes, if you need the same seeds to produce the same identity in Python as in another language. For example: a Go service generates an identity from seeds it holds, and a Python process must reconstruct that identity from the same seeds.
If you are not sure, you do not need it.
Install
pip install 'ratify-protocol[native]'
Install it through the extra rather than by name. The extra pins the two packages to matching versions, which is what keeps them compatible.
Once installed, nothing changes in how you write code. The function that previously raised now works:
from ratify_protocol import hybrid_keypair_from_seeds, derive_id
ed_seed = bytes(range(32))
ml_seed = bytes((0xA0 + i) & 0xFF for i in range(32))
public, private = hybrid_keypair_from_seeds(ed_seed, ml_seed)
# The same identity every SDK derives from these seeds.
assert derive_id(public) == "3823136b5a5fc4c755b22704474172c0"
Without this package, that call raises NotImplementedError with instructions.
It never returns a wrong answer.
Why it has to be a separate package
ratify-protocol is pure Python and ships a single wheel that installs on any
platform and any supported CPython. Keeping it that way matters for a library
whose main job is verifying proofs inside other people's applications.
Deterministic ML-DSA-65 key generation cannot be done in pure Python here.
pqcrypto, the library the SDK uses for post-quantum signing, calls PQClean's
crypto_sign_keypair, which reads the operating system's random number
generator and ignores any seed the caller supplies. The pure-Python ML-DSA
implementations that exist carry explicit warnings against use in cryptographic
applications, so they are not an option either.
So this one operation runs through the Ratify Rust core, compiled into a small
extension. Because compiled code is platform-specific, it lives here instead of
in the SDK. If your platform has no wheel for this package, ratify-protocol
still installs and works; you simply do not get this one function.
What is inside
A single Rust function exposed to Python through PyO3, calling the same
hybrid_keypair_from_seeds that the Ratify Rust SDK exposes. Signing and
verification are untouched and continue to use pqcrypto.
Wheels are built with the abi3 stable ABI, so one wheel per platform covers
CPython 3.10 and every later version.
Handling seeds
Both seeds are key material. Anyone holding them can reconstruct the identity and act as it. Store them with the same protection you would give a private key, and generate them from a cryptographically secure source.
Links
- The SDK this belongs to:
ratify-protocol - Protocol specification: SPEC.md
- SDK contract and the reason this package exists: docs/SDKS.md
- Source: github.com/identities-ai/ratify-protocol
Apache-2.0.
Metadata
Release files for ratify-protocol-native 1.0.0a20
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ratify_protocol_native-1.0.0a20.tar.gz | 91.1 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| ratify_protocol_native-1.0.0a20-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| ratify_protocol_native-1.0.0a20-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| ratify_protocol_native-1.0.0a20-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ ARM64 | Details |
| ratify_protocol_native-1.0.0a20-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
| ratify_protocol_native-1.0.0a20-cp310-abi3-macosx_10_12_x86_64.whl | CPython 3.10 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 1.5 MB
Release files / ratify_protocol_native-1.0.0a20.tar.gz
| Download URL | ratify_protocol_native-1.0.0a20.tar.gz |
|---|---|
| Size | 91.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a36f1e67ba2d3475caf0f67aae20896142fbfa054402f0b82d5dab2a91d0ab13
|
|
BLAKE2b-256 checksum How to use checksums |
1c5aa8e6f26783c8f34aec963f0961bf0ab2881e1b7ad784ba3e20fa35f07402
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / ratify_protocol_native-1.0.0a20-cp310-abi3-win_amd64.whl
| Download URL | ratify_protocol_native-1.0.0a20-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 186.0 kB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
9ec4fa939064d66cbb3d9c74ba28b10adbe29a0169325f9cb628dd73dbde72d8
|
|
BLAKE2b-256 checksum How to use checksums |
c8800f40fd56a24f733e770c0e13180f61b488898a4499d532a79a9aac4500ff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / ratify_protocol_native-1.0.0a20-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | ratify_protocol_native-1.0.0a20-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 336.6 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
4ede9b47a0fe237efd6c6c90a9900c4006efeef6e27ad10ac50a9d2e954e5e3d
|
|
BLAKE2b-256 checksum How to use checksums |
f437860aaaf73478b72155f2cb9aed9268134d24422853143680bb34eb65f007
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / ratify_protocol_native-1.0.0a20-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | ratify_protocol_native-1.0.0a20-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 333.1 kB |
| Tags | CPython 3.10 Linux glibc 2.17+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
b7d2884c24122f752b61aeeb2bbf7934c6935c1574c1a49b712050d7b39bc0fd
|
|
BLAKE2b-256 checksum How to use checksums |
9491e2fffb58ba781b43fcda60f27136c15132dddbf0f52047f7ab2420c75884
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / ratify_protocol_native-1.0.0a20-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | ratify_protocol_native-1.0.0a20-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 297.8 kB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
07e1e039478550fef3e8af0fecb00f01c5fb44bbc5294727e7b707c077e9db15
|
|
BLAKE2b-256 checksum How to use checksums |
db58fcf683b2e5eee950f015c4625179aab5d6fb58bb83ffca568be4ecbb5e0f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / ratify_protocol_native-1.0.0a20-cp310-abi3-macosx_10_12_x86_64.whl
| Download URL | ratify_protocol_native-1.0.0a20-cp310-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 287.1 kB |
| Tags | CPython 3.10 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
04efa1553770a22b7d788c3f535a91e94539aafd01b879c89840acd17ab60455
|
|
BLAKE2b-256 checksum How to use checksums |
8eea969c47a868b2a0a6a5bef8b218135a52326ccaeca0962ab567ca81868de2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency log