SIGNEDBYME SDK - Human-Controlled Identity for Autonomous Agents
Project description
SIGNEDBYME Python SDK
Human-Controlled Identity for Autonomous Agents
What is SIGNEDBYME?
SIGNEDBYME is the identity layer for autonomous agents. Agents prove membership in enterprise-authorized groups using Groth16 zero-knowledge proofs — without revealing which agent they are. The enterprise gets a boolean: authorized. No identity revealed.
This SDK enables agents to generate cryptographic identity, produce zero-knowledge proofs, and authenticate to enterprises via NOSTR and OIDC.
Installation
pip install signedby
Quick Start
from signedby import AgentIdentity, EncryptedFileStorage, MembershipProver, NostrClient
# Initialize secure storage
storage = EncryptedFileStorage("./agent_data")
# Create agent identity (one-time setup)
identity = AgentIdentity(storage)
state = identity.initialize()
print(f"Agent npub: {state.agent_npub}")
print(f"Leaf commitment: {state.leaf_commitment}")
# Generate Groth16 proof for authentication
prover = MembershipProver.from_circuits_dir("./circuits")
leaf_secret = identity.get_leaf_secret()
witness = load_witness(storage, "acme")
proof = prover.generate_proof(leaf_secret, witness)
print(f"Proof generated in {proof.proof_time_ms}ms")
# Publish proof to NOSTR (async)
client = await NostrClient.connect(identity)
await client.publish_proof_event(proof_data)
Features
- DID Generation: secp256k1 keypair in secure storage (OS keyring, Keychain, DPAPI), never extractable
- Groth16 ZK Proofs: BN254 curve, ~101K constraints, <3s on ARM64 via native Rust core (PyO3)
- Bitcoin-Backed: Identity fused with Lightning payment at creation via NWC (NIP-47)
- NOSTR Integration: Publish kinds 28101 (proof), 28102 (delegation ack), 28103 (revocation ack); poll for kinds 28200/28250/28251; NIP-42 relay authentication; decentralized audit trail on public relays
- Witness Caching: Merkle path cached locally, auto-refresh when root rotates out of 30-root window
Modules
| Module | Purpose |
|---|---|
signedby.AgentIdentity |
DID generation, leaf_secret derivation |
signedby.EncryptedFileStorage |
Encrypted storage with OS keyring (ChaCha20-Poly1305) |
signedby.MembershipProver |
Groth16 proof generation via native Rust |
signedby.NostrClient |
NOSTR relay client with NIP-42 auth |
signedby.EnrollmentBootstrap |
Three-gate genesis flow |
signedby.DelegationValidator |
Delegation validation (kind 28250/28251) |
signedby.NwcWallet |
NWC wallet integration (NIP-47) |
SDK Lifecycle
One-Time Initialization
- Generate DID in secure storage
- Derive leaf_secret (5 BN254 field elements)
- Compute leaf_commitment = Poseidon2(leaf_secret)
- Load Groth16 proving key (~88MB)
- Initialize NWC wallet for Lightning
Enrollment per Enterprise
Three-gate genesis flow — runs once per enterprise:
- Gate 1: Email + token verification via kind 28202
- Gate 2: Human signs kind 28250 delegation
- Gate 3: Leaf appended to Merkle tree
Authentication
- Generate Groth16 proof from leaf_secret + cached witness
- Publish kind 28101 to NOSTR
- Enterprise validates and calls API
- Agent receives OIDC id_token
Requirements
- Python 3.9+
- Native libraries bundled for supported platforms
Supported Platforms
- Linux x64 (glibc)
- Linux ARM64 (glibc)
- macOS x64 (Intel)
- macOS ARM64 (Apple Silicon)
- Windows x64
Documentation
License
SSAL-1.0 (SIGNEDBYME Source-Available License)
Links
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file signedby-1.0.1.tar.gz.
File metadata
- Download URL: signedby-1.0.1.tar.gz
- Upload date:
- Size: 12.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: maturin/1.13.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b31c1924901dcc13873a30dedb72a97c3ebc9872106fc8294cabbafbd5da87d4
|
|
| MD5 |
23e8ad9f6bff8b8adf8d188c8423b51e
|
|
| BLAKE2b-256 |
13ceea3eec1c874e6de05caec097e429ea58356975f256a92dbbad36d8893130
|
File details
Details for the file signedby-1.0.1-cp311-cp311-manylinux_2_34_x86_64.whl.
File metadata
- Download URL: signedby-1.0.1-cp311-cp311-manylinux_2_34_x86_64.whl
- Upload date:
- Size: 285.7 kB
- Tags: CPython 3.11, manylinux: glibc 2.34+ x86-64
- Uploaded using Trusted Publishing? No
- Uploaded via: maturin/1.13.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8d01b2b9c649dbc98ee38fc20d6baae57d88bded9a62296b1385bc48fa475785
|
|
| MD5 |
b722c929d015b6c2ffa5a2497aa2ef90
|
|
| BLAKE2b-256 |
12a8046ff67f9eaf16cd224633f5b482ce6e87cce3107f496cf2b09f2f1060a1
|