Skip to main content

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_signing_dpop

Swarmauri Signing DPoP

DPoP proof signer/verifier implementing RFC 9449 for proof-of-possession over HTTP requests.

Features:

  • Creates and validates dpop+jwt proofs with embedded public JWK thumbprints.
  • Supports ES256, RS256, and EdDSA algorithms through the SigningBase interface.
  • Optional access-token hash binding (ath), nonce enforcement, and replay-protection hooks.

Installation

The package is published on PyPI together with the dependencies required to sign and verify DPoP proofs.

pip

pip install swarmauri_signing_dpop

uv

uv add swarmauri_signing_dpop

Poetry

poetry add swarmauri_signing_dpop

Usage

DpopSigner implements the asynchronous SigningBase / ISigning interface. Signing requires the HTTP method and URL (opts['htm'] and opts['htu']), and verification requires the same data passed via require.

Signing and verifying a request

import asyncio

from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.primitives.asymmetric import ed25519

from swarmauri_signing_dpop import DpopSigner


async def main() -> None:
    signer = DpopSigner()

    private_key = ed25519.Ed25519PrivateKey.generate()
    priv_pem = private_key.private_bytes(
        encoding=serialization.Encoding.PEM,
        format=serialization.PrivateFormat.PKCS8,
        encryption_algorithm=serialization.NoEncryption(),
    )
    key = {"kind": "pem", "priv": priv_pem, "alg": "EdDSA"}

    signatures = await signer.sign_bytes(
        key,
        b"",
        opts={"htm": "GET", "htu": "https://api.example/x"},
    )

    is_valid = await signer.verify_bytes(
        b"",
        signatures,
        require={"htm": "GET", "htu": "https://api.example/x"},
    )
    assert is_valid
    print("DPoP proof valid:", is_valid)


asyncio.run(main())

Signature format

sign_bytes and sign_envelope return a sequence with a single detached signature entry:

{
    "alg": "EdDSA",            # JWS algorithm used
    "format": "dpop+jwt",      # proof media type
    "sig": "<compact JWT>",    # DPoP proof token containing the claims
    "jkt": "<thumbprint>",     # SHA-256 JWK thumbprint for cnf.jkt binding
}

Use the jkt helper when comparing against cnf.jkt values embedded in access tokens.

Key references

Keys are provided using the KeyRef mapping expected by other Swarmauri signing packages:

  • { "kind": "pem", "priv": <PEM bytes|str> } — RSA/EC keys and Ed25519 PKCS8 PEM.
  • { "kind": "jwk", "priv": <private JWK dict> } — accepts EC, RSA, or OKP keys with private fields.

For Ed25519 material, both formats are supported; the signer derives and embeds the public JWK automatically.

Options reference

  • opts['htm'] / opts['htu']: HTTP method and URL that will be bound in the proof (required for signing).
  • opts['nonce']: Optional server-issued DPoP-Nonce to include in the proof.
  • opts['access_token']: Optional access token to derive the ath confirmation hash.
  • require['htm'] / require['htu']: Expected method and URL (required for verification).
  • require['max_skew_s']: IAT skew tolerance (defaults to 300 seconds).
  • require['algs']: Allowed signing algorithms. Defaults to all supported values.
  • require['nonce']: Expected nonce when enforcing a server challenge.
  • require['access_token']: Expected bearer token when validating ath.
  • require['replay']: Mapping with seen(jti) -> bool and mark(jti, ttl_s) callables for replay prevention.

sign_envelope and verify_envelope reuse the same logic after canonicalizing the envelope to bytes (raw or json). Payload bytes are otherwise unused because the DPoP proof binds request metadata instead of message content.

Entry Point

The signer registers under the swarmauri.signings entry point as DpopSigner.

Want to help?

If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.

Metadata

Release files for swarmauri_signing_dpop 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for swarmauri_signing_dpop 0.1.1
File Size Uploaded
swarmauri_signing_dpop-0.1.1.tar.gz 11.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for swarmauri_signing_dpop 0.1.1
File Interpreter ABI Platform
swarmauri_signing_dpop-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 24.9 kB

Release files / swarmauri_signing_dpop-0.1.1.tar.gz

Download URL swarmauri_signing_dpop-0.1.1.tar.gz
Size 11.6 kB
Tags Source
SHA-256 checksum
How to use checksums
9bd6689c36128f748b19e03a0bd5e4da39b7ec64d06ba683de18fdcc1b7d0bcd
BLAKE2b-256 checksum
How to use checksums
d006474b4e4087aa5ec976fbe0d479c19e7c11e5c9c1c324d7105a3809b5f4b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.27 {"installer":{"name":"uv","version":"0.9.27","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / swarmauri_signing_dpop-0.1.1-py3-none-any.whl

Download URL swarmauri_signing_dpop-0.1.1-py3-none-any.whl
Size 13.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
987d87140ab962a673ec9558649cdb7e96d8c76f473aa91ae5289c1c8bfb2d6b
BLAKE2b-256 checksum
How to use checksums
d892cd40eb6c36a8a3181747fb16aac93cdd590afd333f84bfe5545a36a7c073
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.27 {"installer":{"name":"uv","version":"0.9.27","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page