scrybe-mermaid
Standalone PNG iTXt codec: embeds and extracts Mermaid diagram source as invisible metadata inside a PNG file. Python on the outside, Rust on the inside.
What it does
Uses the PNG iTXt (international text) metadata chunk mechanism to store Mermaid diagram source alongside the rendered image. The PNG is fully valid and renders normally in any image viewer. The source text travels with the image and can be round-tripped without loss.
Python quick start
pip install scrybe-mermaid
from pathlib import Path
from scrybe_mermaid import embed, extract
source = """
graph TD
A[Christmas] -->|Get money| B(Go shopping)
B --> C{Let me think}
C -->|One| D[Laptop]
C -->|Two| E[iPhone]
"""
# diagram.png: any PNG — render one with mmdc, Kroki, or the Mermaid live editor
png_in = Path("diagram.png").read_bytes()
png_out = embed(png_in, source)
Path("diagram-with-source.png").write_bytes(png_out)
payload = extract(png_out) # verifies the embedded sha256 — raises ValueError if tampered
if payload.source != source: # optional
raise ValueError("Round-trip mismatch")
print(f"Round-tripped {len(payload.source)} chars; sha256={payload.sha256[:12]}…")
The resulting PNG renders normally in any image viewer and carries its own Mermaid source for round-tripping. See the API reference below.
Codec format
- Chunk key:
scrybe-mermaid - Value: JSON
{ "source": "<mermaid source>", "sha256": "<hex>", "uuid": "<v4>" }
The sha256 field is a SHA-256 digest of the source bytes, and extract
enforces it by default: the digest is recomputed from the extracted
source and compared against the stored value. Three outcomes are
distinguished:
| Outcome | Python | Rust |
|---|---|---|
| Digest present and matching | payload with verified == True |
Ok(VerifiedPayload) with VerificationStatus::Verified |
| Digest present but mismatched (tampered) | raises ValueError |
Err(MermaidError::VerificationFailed { expected, actual, .. }) |
| No digest stored (older/foreign payload) | payload with verified == False, sha256 == "" |
Ok(VerifiedPayload) with VerificationStatus::NoDigest |
A payload with no digest is never reported as verified. For forensics on
tampered or foreign payloads, extract_unverified returns the raw stored
fields without any check.
Role in the architecture
scrybe-mermaid is a self-contained utility crate with no dependency on
scrybe-core. It is used by scrybe-mcp-server (the embed/extract tools),
scrybe-cli (scrybe mermaid embed/extract/verify), and the Tauri backend.
Key public types and entry points
| Symbol | Description |
|---|---|
embed(png_bytes, source) -> Result<Vec<u8>> |
Inserts iTXt chunk; returns modified PNG bytes |
extract(png_bytes) -> Result<VerifiedPayload> |
Reads the iTXt chunk and verifies the stored sha256 against the source; mismatch → MermaidError::VerificationFailed |
extract_unverified(png_bytes) -> Result<MermaidPayload> |
Raw stored fields, no digest check (forensics) |
VerifiedPayload |
source: String + uuid: String + verification: VerificationStatus |
VerificationStatus |
Verified { algorithm, digest } or NoDigest (older/foreign payloads) |
MermaidPayload |
Raw stored source + sha256 + uuid (unchecked) |
MermaidError |
Error type covering missing chunk, malformed JSON, PNG decode failure, digest mismatch (VerificationFailed { expected, actual, .. }) |
Build and test
cargo build -p scrybe-mermaid
cargo test -p scrybe-mermaid
The codec parses PNG chunks from first principles — no external binaries required.
Metadata
Release files for scrybe-mermaid 0.6.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| scrybe_mermaid-0.6.3.tar.gz | 56.1 kB | Details |
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| scrybe_mermaid-0.6.3-cp39-abi3-win_amd64.whl | CPython 3.9 | abi3 | Windows x86-64 | Details |
| scrybe_mermaid-0.6.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.9 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| scrybe_mermaid-0.6.3-cp39-abi3-macosx_11_0_arm64.whl | CPython 3.9 | abi3 | macOS 11.0+ ARM64 | Details |
Total release size: 913.0 kB
Release files / scrybe_mermaid-0.6.3.tar.gz
| Download URL | scrybe_mermaid-0.6.3.tar.gz |
|---|---|
| Size | 56.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bd59022621331e0b9a1ead7be0b4bac14a347d7966b15689cb430a0ea6b964ba
|
|
BLAKE2b-256 checksum How to use checksums |
3e9f1f60d974fe8b81cc5be2cf23403e1e3733d1b2e697529105125a5942eabb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.
Transparency logRelease files / scrybe_mermaid-0.6.3-cp39-abi3-win_amd64.whl
| Download URL | scrybe_mermaid-0.6.3-cp39-abi3-win_amd64.whl |
|---|---|
| Size | 199.8 kB |
| Tags | CPython 3.9 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
4306e92f21f51a1cb719269b11e876af0a25bbd13879993b6854cbeb0579dac9
|
|
BLAKE2b-256 checksum How to use checksums |
730e39ad309c5bc56f724d0830745c5a5be0ff742c4477bb8f012938b36f8b70
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.
Transparency logRelease files / scrybe_mermaid-0.6.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | scrybe_mermaid-0.6.3-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 349.1 kB |
| Tags | CPython 3.9 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
fcb672bd2e3ee275c3fe84dca6b6bb86b2510a13dbee72191951506ec9725849
|
|
BLAKE2b-256 checksum How to use checksums |
081b5cd10d10079033c7a3cef98910d634a0a9d44a27836fb0c40928fe28e84b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.
Transparency logRelease files / scrybe_mermaid-0.6.3-cp39-abi3-macosx_11_0_arm64.whl
| Download URL | scrybe_mermaid-0.6.3-cp39-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 308.0 kB |
| Tags | CPython 3.9 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
28f08f83b6a0fc9c631563e496b8dbf2a9241a67aabdb3db507e1fc6a5ae4e9d
|
|
BLAKE2b-256 checksum How to use checksums |
41c9407bb54e3294f30f963071162183590a078fd9c6e8c5f339240c3aff1865
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 21, 2026.
Transparency log