Skip to main content

SIGNEDBYME SDK - Human-Controlled Identity for Autonomous Agents

Project description

SIGNEDBYME Python SDK

Human-Controlled Identity for Autonomous Agents

What is SIGNEDBYME?

SIGNEDBYME is the identity layer for autonomous agents. Agents prove membership in enterprise-authorized groups using Groth16 zero-knowledge proofs — without revealing which agent they are. The enterprise gets a boolean: authorized. No identity revealed.

This SDK enables agents to generate cryptographic identity, produce zero-knowledge proofs, and authenticate to enterprises via NOSTR and OIDC.

Installation

pip install signedby

Quick Start

from signedby import AgentIdentity, EncryptedFileStorage, MembershipProver, NostrClient

# Initialize secure storage
storage = EncryptedFileStorage("./agent_data")

# Create agent identity (one-time setup)
identity = AgentIdentity(storage)
state = identity.initialize()

print(f"Agent npub: {state.agent_npub}")
print(f"Leaf commitment: {state.leaf_commitment}")

# Generate Groth16 proof for authentication
prover = MembershipProver.from_circuits_dir("./circuits")

leaf_secret = identity.get_leaf_secret()
witness = load_witness(storage, "acme")

proof = prover.generate_proof(leaf_secret, witness)
print(f"Proof generated in {proof.proof_time_ms}ms")

# Publish proof to NOSTR (async)
client = await NostrClient.connect(identity)
await client.publish_proof_event(proof_data)

Features

  • DID Generation: secp256k1 keypair in secure storage (OS keyring, Keychain, DPAPI), never extractable
  • Groth16 ZK Proofs: BN254 curve, ~101K constraints, <3s on ARM64 via native Rust core (PyO3)
  • Bitcoin-Backed: Identity fused with Lightning payment at creation via NWC (NIP-47)
  • NOSTR Integration: Publish kinds 28101 (proof), 28102 (delegation ack), 28103 (revocation ack); poll for kinds 28200/28250/28251; NIP-42 relay authentication; decentralized audit trail on public relays
  • Witness Caching: Merkle path cached locally, auto-refresh when root rotates out of 30-root window

Modules

Module Purpose
signedby.AgentIdentity DID generation, leaf_secret derivation
signedby.EncryptedFileStorage Encrypted storage with OS keyring (ChaCha20-Poly1305)
signedby.MembershipProver Groth16 proof generation via native Rust
signedby.NostrClient NOSTR relay client with NIP-42 auth
signedby.EnrollmentBootstrap Three-gate genesis flow
signedby.DelegationValidator Delegation validation (kind 28250/28251)
signedby.NwcWallet NWC wallet integration (NIP-47)

SDK Lifecycle

One-Time Initialization

  1. Generate DID in secure storage
  2. Derive leaf_secret (5 BN254 field elements)
  3. Compute leaf_commitment = Poseidon2(leaf_secret)
  4. Load Groth16 proving key (~88MB)
  5. Initialize NWC wallet for Lightning

Enrollment per Enterprise

Three-gate genesis flow — runs once per enterprise:

  • Gate 1: Email + token verification via kind 28202
  • Gate 2: Human signs kind 28250 delegation
  • Gate 3: Leaf appended to Merkle tree

Authentication

  1. Generate Groth16 proof from leaf_secret + cached witness
  2. Publish kind 28101 to NOSTR
  3. Enterprise validates and calls API
  4. Agent receives OIDC id_token

Requirements

  • Python 3.9+
  • Native libraries bundled for supported platforms

Supported Platforms

  • Linux x64 (glibc)
  • Linux ARM64 (glibc)
  • macOS x64 (Intel)
  • macOS ARM64 (Apple Silicon)
  • Windows x64

Documentation

License

SSAL-1.0 (SIGNEDBYME Source-Available License)

Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

signedby-0.1.0b9.tar.gz (12.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

signedby-0.1.0b9-cp311-cp311-manylinux_2_34_x86_64.whl (288.2 kB view details)

Uploaded CPython 3.11manylinux: glibc 2.34+ x86-64

File details

Details for the file signedby-0.1.0b9.tar.gz.

File metadata

  • Download URL: signedby-0.1.0b9.tar.gz
  • Upload date:
  • Size: 12.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: maturin/1.13.3

File hashes

Hashes for signedby-0.1.0b9.tar.gz
Algorithm Hash digest
SHA256 1967694e67c9909eda8f1dfacaa5ec3ea7978af6eeeb96cef221e14e9b53049c
MD5 fe3574cd17825820bd9ac4604a7539ca
BLAKE2b-256 125771ca961d68ff8113a81928c91b6389edfc881042af4e75bd178739ecf786

See more details on using hashes here.

File details

Details for the file signedby-0.1.0b9-cp311-cp311-manylinux_2_34_x86_64.whl.

File metadata

File hashes

Hashes for signedby-0.1.0b9-cp311-cp311-manylinux_2_34_x86_64.whl
Algorithm Hash digest
SHA256 642650588265d11d73bbee5f86a5fec9c3a43d139f75bc8a589b9fbfbb92d6f8
MD5 5dec8612a98f27350b936c40ccf2017e
BLAKE2b-256 b290cd822ef7e54cd04a486058f2a8fdb823b11332ef4fec7ebdf0359b93b859

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page