smolagents-aer1
Every tool call your smolagents agent makes, recorded as an AER-1 verifiable execution receipt. Five lines of code. No new infrastructure.
AER-1 is an open IETF Internet-Draft (draft-zambo-aer1) defining a small vocabulary for recording one AI agent tool call as a portable, independently checkable receipt. A receipt proves the recorded result was not changed. It does not prove the tool was correct.
For whole-run workflow receipts with a Merkle root (AER-1 Section 8), see aer1-smolagents.
Install
pip install smolagents-aer1
10-minute quickstart
from smolagents import CodeAgent, InferenceClientModel
from smolagents_aer1 import AER1Recorder
recorder = AER1Recorder()
agent = CodeAgent(
tools=[],
model=InferenceClientModel(),
step_callbacks=[recorder],
)
agent.run("What is 17 * 24?")
print(f"{len(recorder.receipts)} receipts recorded")
recorder.save("receipts.jsonl")
That is the whole integration. step_callbacks is smolagents' blessed hook for observing steps (the same pattern tracing integrations use). The recorder watches each action step and emits one receipt per tool call.
What a receipt looks like
{
"id": "3f9a2c1e-7b4d-4f8a-9c2e-1a5b6d7e8f90",
"receipt_schema_version": "0.3",
"created_at": "2026-10-05T21:20:00.123456Z",
"tool": {"name": "python_interpreter", "version": "1.26.0", "scope": "public"},
"provenance_class": "EXECUTED BY SMOLAGENTS",
"canonical_bytes": "eyJpbnB1dHMiOi...",
"output_hash": "sha256:9f2c...",
"verification_status": "verified"
}
The canonical bytes are a deterministic JSON payload (tool, inputs, output). Anyone can base64-decode them, recompute SHA-256, and compare with output_hash. That is the entire verification procedure.
Verify a receipt yourself
from smolagents_aer1 import verify_receipt
failures = verify_receipt(recorder.receipts[0])
assert failures == [], failures
print("receipt checks out")
Or run the full open conformance suite against your receipts: https://gitlab.com/rambozambodotdev/zambo
Notes
- Provenance class is
EXECUTED BY SMOLAGENTS: the recorder runs inside the agent process and records what the agent did. CodeAgentrecords each code execution as onepython_interpretertool call.ToolCallingAgentrecords each named tool call separately.- When one step contains several tool calls, each receipt commits to the step's full observation string.
- The
tool.versionfield records the smolagents runtime version. - Receipts are local JSON. Nothing is sent anywhere. Publishing or anchoring them is your choice.
Links
- Spec: https://datatracker.ietf.org/doc/draft-zambo-aer1/ (IETF Internet-Draft, informational)
- Conformance kit: https://gitlab.com/rambozambodotdev/zambo
- Zambo: https://zambo.dev
License
MIT. See LICENSE.
Metadata
Release files for smolagents-aer1 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| smolagents_aer1-0.1.1.tar.gz | 6.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| smolagents_aer1-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 12.2 kB
Release files / smolagents_aer1-0.1.1.tar.gz
| Download URL | smolagents_aer1-0.1.1.tar.gz |
|---|---|
| Size | 6.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3b4b4e31ba238eb4c3c07f8cf732e687beee6571d0d7df5d46f04f26ae88bba9
|
|
BLAKE2b-256 checksum How to use checksums |
001687454dbd9ff69f57e4a191bd6030e558adf7ece14ed034117d6543e8feb5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|
Release files / smolagents_aer1-0.1.1-py3-none-any.whl
| Download URL | smolagents_aer1-0.1.1-py3-none-any.whl |
|---|---|
| Size | 5.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e8509184117eada6505f6511cb0b69cb758287c7924d367249222ef707eb23bb
|
|
BLAKE2b-256 checksum How to use checksums |
736243294a745d9ae3d15f6416c31a0ed62f3adfd2281a805bcf31e693af6bfd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|