Swarmauri Signing DSSE
DSSESigner layers the in-toto DSSE envelope format on top of any existing Swarmauri
signer. It computes the Pre-Authentication Encoding (PAE) defined by the spec, delegates raw signing and verification to the
wrapped provider, and exposes helpers for serializing envelopes in the DSSE JSON representation.
Features
- Adds the
dsse-paecanonicalization surface to anySigningBaseprovider. - Supports detached signature workflows for bytes, digests, streams, and envelopes.
- Includes a strict JSON codec with typed helpers for building and inspecting DSSE envelopes.
- Maintains the inner signer's capability matrix while declaring DSSE-specific features (
detached_only,multi).
Installation
Install the package with your preferred Python packaging tool:
Using uv
uv add swarmauri_signing_dsse
Using pip
pip install swarmauri_signing_dsse
Usage
import base64
from swarmauri_signing_dsse import DSSESigner, DSSEEnvelope
from swarmauri_signing_ed25519 import Ed25519EnvelopeSigner
# Wrap an existing Swarmauri signer.
inner_signer = Ed25519EnvelopeSigner()
dsse_signer = DSSESigner(inner_signer)
# Prepare a DSSE envelope.
payload = b"example payload"
payload_b64 = base64.urlsafe_b64encode(payload).decode("ascii").rstrip("=")
envelope = DSSEEnvelope(payload_type="text/plain", payload_b64=payload_b64)
# Sign and verify using DSSE PAE over the payload.
key_ref = {"kind": "raw_ed25519_sk", "bytes": b"\x01" * 32}
signatures = await dsse_signer.sign_envelope(key_ref, envelope)
assert await dsse_signer.verify_envelope(envelope, signatures)
DSSESigner accepts existing DSSE JSON mappings or bytes anywhere an envelope is expected. The helper methods
encode_envelope() and decode_envelope() let you round-trip envelopes without reimplementing JSON handling.
License
This project is licensed under the Apache License 2.0.
Metadata
Release files for swarmauri_signing_dsse 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_signing_dsse-0.2.0.tar.gz | 9.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_signing_dsse-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 21.2 kB
Release files / swarmauri_signing_dsse-0.2.0.tar.gz
| Download URL | swarmauri_signing_dsse-0.2.0.tar.gz |
|---|---|
| Size | 9.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ffc4c6f1b71b04017247f69bd330fd056202dbe8ec886b48ed207f989261d9dc
|
|
BLAKE2b-256 checksum How to use checksums |
812fa2199f0f4ab6c6335f472c361e285d785da7edaf9f6bb446069121e23ce1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_signing_dsse-0.2.0-py3-none-any.whl
| Download URL | swarmauri_signing_dsse-0.2.0-py3-none-any.whl |
|---|---|
| Size | 11.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d26f55424a63e7ad1d578d2b5079d64112a6197b0ac371a8de17f1c82ddf5b47
|
|
BLAKE2b-256 checksum How to use checksums |
9e5750c9965bd46d5d9e98b40016dd436d36c5d7e90e275604af32901bfe457e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|