Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_signing_hmac Discord

Swarmauri Signing HMAC

An HMAC-based signer implementing the ISigning interface for detached signatures over raw bytes and canonicalized envelopes.

Features

  • JSON canonicalization (always available)
  • Optional CBOR canonicalization via cbor2
  • Detached signatures using standard library hmac
  • Supports raw, hex, environment, and HKDF-derived KeyRef secrets.

Security Notes

  • Supports HMAC-SHA-256/384/512 only.
  • Keys must be at least 32 bytes (256 bits).
  • Tags default to the hash digest size and may be truncated via opts["tag_size"] but not below 16 bytes (128 bits).
  • Secrets shorter than 32 bytes are rejected even when using a longer digest.

Installation

Install the package with your preferred Python packaging tool:

pip install swarmauri_signing_hmac
poetry add swarmauri_signing_hmac
uv pip install swarmauri_signing_hmac

Install cbor2 to enable CBOR canonicalization:

pip install cbor2

Usage

import asyncio
from swarmauri_signing_hmac import HmacEnvelopeSigner
from swarmauri_core.crypto.types import JWAAlg


async def main() -> None:
    signer = HmacEnvelopeSigner()

    # KeyRef with a raw 32-byte secret; see swarmauri_core for more options
    key = {"kind": "raw", "key": "a" * 32}

    # Sign and verify raw bytes
    payload = b"hello"
    sigs = await signer.sign_bytes(key, payload, alg=JWAAlg.HS256, opts={"tag_size": 16})
    assert await signer.verify_bytes(payload, sigs, opts={"keys": [key]})

    # Sign and verify a JSON envelope
    env = {"msg": "hello"}
    sigs_env = await signer.sign_envelope(
        key, env, alg=JWAAlg.HS256, canon="json", opts={"tag_size": 16}
    )
    assert await signer.verify_envelope(env, sigs_env, canon="json", opts={"keys": [key]})


asyncio.run(main())

Verification requires providing one or more keys via opts["keys"].

Key references

HmacEnvelopeSigner accepts multiple KeyRef forms:

  • {"kind": "raw", "key": <bytes-or-str>} ? direct secret material.
  • {"kind": "hex", "key": <hex str>} ? hex encoded secret.
  • {"kind": "env", "name": <ENV_NAME>} ? loads the secret from an environment variable.
  • {"kind": "derived", "key": <bytes-or-str>, "hkdf": {"salt": ..., "info": ...}} ? derives the signing secret with HKDF.

Provide an optional "kid" to control the key identifier or specify "alg" when verifying to override the default HS256 digest for a key entry.

Entry Point

The signer registers under the swarmauri.signings entry point as HmacEnvelopeSigner.

Want to help?

If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.

Metadata

Release files for swarmauri_signing_hmac 0.11.0.dev1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_signing_hmac 0.11.0.dev1
File Size Uploaded
swarmauri_signing_hmac-0.11.0.dev1.tar.gz 9.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_signing_hmac 0.11.0.dev1
File Interpreter ABI Platform
swarmauri_signing_hmac-0.11.0.dev1-py3-none-any.whl Python 3 none any Details

Total release size: 20.6 kB

Release files / swarmauri_signing_hmac-0.11.0.dev1.tar.gz

Download URL swarmauri_signing_hmac-0.11.0.dev1.tar.gz
Size 9.8 kB
Tags Source
SHA-256 checksum
How to use checksums
bf2a68198439d8b654c352f48d39ae1bb26749f9e9e9bb65ea8eadb5f5a7d25a
BLAKE2b-256 checksum
How to use checksums
583cf7d7b92b1ac6b6b0790e2f90275223346b2b3d9113ddfe5f894647e35cf7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_signing_hmac-0.11.0.dev1-py3-none-any.whl

Download URL swarmauri_signing_hmac-0.11.0.dev1-py3-none-any.whl
Size 10.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
34cd658487eaaf432ffb4caad89b5cae3c85ad5fb30968d3fb40f5f05dd3ead4
BLAKE2b-256 checksum
How to use checksums
b5b8f52c1c22fd55a2dfe6d249d062e46536559315161f7c2dc6386ed08a8eb5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page