Skip to main content

RuntimeTruth

Runtime integrity verification for AI agents.

PyPI Python CI License

RuntimeTruth detects drift between intended and live AI-agent runtime state. It compares evidence from declared, resolved, and live sources across models, instructions, tools, MCP servers, permissions, runtime versions, and the execution environment.

PyPI · Sidelobe overview · Case study · Engineering note · Release notes

Public alpha · v0.2.1. Core inspect, diff, verification, policy, and signed-baseline flows are covered by CI and exercised against real local runtimes.

Why

AI agents have more mutable runtime state than ordinary applications:

  • model and provider routing
  • system and project instructions
  • tools and MCP schemas
  • skills and plugins
  • sandbox and network permissions
  • executable/runtime versions
  • environment and process identity
  • repository/code state

A deployment can therefore look unchanged while the effective agent runtime has drifted.

RuntimeTruth currently focuses on two questions:

  1. What runtime state can be established with explicit evidence?
  2. What changed since a known baseline?

Broader policy evaluation and organizational provenance remain later phases. The current policy file is intentionally narrow: it persists only the evidence selectors that should gate runtime verification.

Project model

RuntimeTruth is currently distributed as free, local-first open-source software. There is no RuntimeTruth hosted control plane, account system, telemetry service, paid support plan or SLA.

A verification result is deliberately narrow: PASS means the selected evidence matched the selected baseline. It does not mean the agent is secure, compliant, safe, or correctly configured in ways RuntimeTruth did not inspect.

See the trust model, data handling, support policy, and MIT License for the current project boundary.

Origin

RuntimeTruth grew out of operating self-hosted workers and noticing that source code and deployment configuration were not enough to answer a simple question: what is actually running right now?

The project is built from evidence outward. It started with systemd, procfs, and Git identity, then used the same model to inspect agent-specific Codex state.

Read the origin story.

Installation

For the CLI, use an isolated tool environment:

pipx install runtimetruth

or:

uv tool install runtimetruth

Standard pip is also supported inside a virtual environment:

python -m pip install runtimetruth

Then verify the install:

runtimetruth --version

For CI workflows that require an exact source revision, pin the Git commit rather than following a moving branch. See CI integration.

Quick start

Capture effective Codex runtime state:

runtimetruth inspect codex . --resolve-thread --pretty > baseline.json

Verify the current runtime against that baseline:

runtimetruth verify baseline.json --codex . --resolve-thread

Protect only selected runtime invariants when strict snapshot equality is too broad:

runtimetruth verify baseline.json --codex . --resolve-thread \
  --protect codex.thread.model \
  --protect codex.instructions

Persist repeated selectors in an explicit TOML policy:

version = 1
protect = [
  "codex.thread.model",
  "codex.thread.sandbox",
  "codex.instructions",
]
runtimetruth verify baseline.json --codex . --resolve-thread \
  --policy .runtimetruth/policy.toml

The same policy can be used with verify-attestation; signer identity and baseline binding are verified before policy evaluation.

Add --json for a versioned machine-readable PASS/DRIFT report.

Bind a reviewed baseline to an identity-backed Sigstore attestation:

runtimetruth digest baseline.json

runtimetruth attest baseline.json \
  --statement baseline.intoto.json \
  --bundle baseline.sigstore.json

runtimetruth verify-attestation \
  baseline.json \
  --statement baseline.intoto.json \
  --bundle baseline.sigstore.json \
  --certificate-identity "EXPECTED_IDENTITY" \
  --certificate-oidc-issuer "EXPECTED_ISSUER" \
  --codex . \
  --resolve-thread

Attestation uses RFC 8785 canonical JSON, SHA-256, in-toto Statement v1 and Sigstore Cosign rather than a RuntimeTruth-specific signature scheme. See signed baseline attestations.

Current CLI

Inspect a local target:

runtimetruth inspect systemd <unit>
runtimetruth inspect git <path>
runtimetruth inspect codex <cwd>
runtimetruth inspect codex <cwd> --resolve-thread
runtimetruth inspect codex <cwd> --resolve-mcp

Compare two snapshots:

runtimetruth diff <before.json> <after.json>

Verify a current snapshot against a baseline:

runtimetruth verify <baseline.json> <current.json>

Or collect the current Codex runtime and verify it directly:

runtimetruth verify <baseline.json> --codex <cwd> --resolve-thread
runtimetruth verify <baseline.json> --codex <cwd> --resolve-mcp

Verification uses stable process exit codes:

  • 0 — runtime matches the baseline
  • 2 — semantic runtime drift detected
  • 1 — collection, input, or comparison error

Selective runtime invariants can be protected explicitly:

runtimetruth verify baseline.json --codex <cwd> --resolve-thread \
  --protect codex.thread.model \
  --protect codex.instructions

For automation, add --json to emit a versioned structured PASS/DRIFT report without changing the exit-code contract.

Canonical baseline identity and signed verification are separate commands:

runtimetruth digest <baseline.json>

runtimetruth attest <baseline.json> \
  --statement <baseline.intoto.json> \
  --bundle <baseline.sigstore.json>

runtimetruth verify-attestation <baseline.json> [current.json] \
  --statement <baseline.intoto.json> \
  --bundle <baseline.sigstore.json> \
  --certificate-identity <expected-identity> \
  --certificate-oidc-issuer <expected-issuer>

verify-attestation can also use --codex <cwd>, --resolve-thread, --resolve-mcp, --policy <file>, repeatable --protect, and --json.

Creating or verifying identity-backed attestations requires a recent Sigstore Cosign executable. Normal inspect/diff/verify commands do not require Cosign.

--resolve-thread creates an ephemeral Codex thread without starting a turn. --resolve-mcp additionally probes thread-scoped MCP runtime state and may contact configured MCP servers or refresh authentication; it does not call MCP tools.

Evidence currently collected

The intentionally narrow implementation includes:

  • systemd unit/runtime state
  • procfs process identity
  • Git repository identity
  • Codex executable/version
  • Codex canonical resolved workspace configuration
  • effective state materialized for an ephemeral Codex thread
  • Codex-reported instruction source paths
  • SHA-256 fingerprints of those instruction source files without storing their plaintext
  • thread-scoped MCP server status and bounded tool-catalog fingerprints

Each evidence record keeps its provenance and is classified as declared, resolved, or live where the source supports that claim.

Project boundary

RuntimeTruth is not intended to become a generic process monitor, LLM trace backend, MCP proxy/firewall, GitOps controller, or hosted observability dashboard.

The current focus is external validation of the baseline, attestation and policy model before adding additional agent adapters or cloud features.

See:

Development

Requires Python 3.12+.

python -m venv .venv
source .venv/bin/activate
python -m pip install -e ".[dev]"
ruff check .
ruff format --check .
pytest

License

MIT.

Metadata

Release files for runtimetruth 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for runtimetruth 0.2.1
File Size Uploaded
runtimetruth-0.2.1.tar.gz 196.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for runtimetruth 0.2.1
File Interpreter ABI Platform
runtimetruth-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 224.0 kB

Release files / runtimetruth-0.2.1.tar.gz

Download URL runtimetruth-0.2.1.tar.gz
Size 196.3 kB
Tags Source
SHA-256 checksum
How to use checksums
aeb7c4a352616900ba2f4057a742217fb221418e5376e2cb2755e314f45d5db3
BLAKE2b-256 checksum
How to use checksums
05684430a8ab823e754a9dfb8d3fbe1682090bcf2f88861c2049695297b404bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / runtimetruth-0.2.1-py3-none-any.whl

Download URL runtimetruth-0.2.1-py3-none-any.whl
Size 27.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6cb0f09d307c744440a02d8f8c8256677c3085c43212bb3c90b0e7f62f709d2c
BLAKE2b-256 checksum
How to use checksums
72ac5c07d702c621e43d45aca67d7b3a9eea309eaafadd21c7b0b3ca25323bc5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.1 This release

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page