This release is a pre-release and may not be stable for production use.
Swarmauri Signing JWS
Composite JSON Web Signature (JWS) signer and verifier that orchestrates multiple Swarmauri signing providers behind a single asynchronous API.
Features
- Async helpers for both compact and general JSON JWS serialization
- Algorithm routing across HMAC (HS256/384/512), RSA (RS*/PS*), ECDSA
(ES256/384/512), Ed25519 (EdDSA), and optional secp256k1 (ES256K when the
secp256k1extra is installed) - Works with direct key material, Swarmauri signer objects, or a JWKS resolver
while returning the protected header and payload via
JwsResult
Installation
pip
pip install swarmauri_signing_jws
Poetry
poetry add swarmauri_signing_jws
uv
To add the dependency to a pyproject.toml managed by uv:
uv add swarmauri_signing_jws
Or install it into the active environment:
uv pip install swarmauri_signing_jws
Optional extras:
secp256k1enables ES256K support throughswarmauri_signing_secp256k1
Usage
import asyncio
from swarmauri_signing_jws import JwsSignerVerifier
async def main() -> None:
signer = JwsSignerVerifier()
key = {"kind": "raw", "key": "0" * 32}
compact = await signer.sign_compact(
payload={"msg": "hi"},
alg="HS256",
key=key,
)
result = await signer.verify_compact(
compact,
hmac_keys=[key],
)
print(result.payload.decode("utf-8"))
if __name__ == "__main__":
asyncio.run(main())
The public methods accept either raw strings or JWAAlg enum values for the
alg parameter. Compact verification returns a JwsResult dataclass containing
the parsed header and payload bytes so applications can safely forward or decode
the authenticated message.
API highlights
sign_compact(...)/verify_compact(...)wrap the standard compact serialization, including optional allowlists and JWKS resolvers.sign_general_json(...)/verify_general_json(...)operate on the general JSON serialization and support multi-signer verification withmin_signersthresholds.- Each algorithm family accepts dedicated key collections (
hmac_keys,rsa_pubkeys,ec_pubkeys,ed_pubkeys,k1_pubkeys) or ajwks_resolvercallback for dynamic key retrieval.
HMAC key requirements
All HMAC-based operations require a secret of at least 32 bytes (256 bits).
Shorter keys are rejected to avoid truncation mistakes and to keep forgery
probabilities negligible even after many verification attempts.
Rationale:
- Forgery success scales with tag length; a 256-bit tag keeps the chance negligible even after many tries (NIST SP 800-107 Rev.1).
- RFC 7518 already mandates HS256 keys >= 256 bits; using the full HMAC-SHA-256 output avoids inadvertent strength reduction.
- A full 32-byte tag preserves approximately 128-bit security even under generic quantum search speedups (NIST IR 8547).
- Fixed-length tags simplify constant-time verification and prevent configuration mismatches.
Entry Point
The signer registers under the swarmauri.signings entry point as
JwsSignerVerifier.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_signing_jws 0.11.0.dev1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_signing_jws-0.11.0.dev1.tar.gz | 15.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_signing_jws-0.11.0.dev1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 30.4 kB
Release files / swarmauri_signing_jws-0.11.0.dev1.tar.gz
| Download URL | swarmauri_signing_jws-0.11.0.dev1.tar.gz |
|---|---|
| Size | 15.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2b5481fc53c25447daf24d6fac267f46baf5b7664aee45f7fd564de20df9d14c
|
|
BLAKE2b-256 checksum How to use checksums |
dc199df4c1e676d63ba74799c3f33ef6b7767b8e589ffafaa977cde529ac8edd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_signing_jws-0.11.0.dev1-py3-none-any.whl
| Download URL | swarmauri_signing_jws-0.11.0.dev1-py3-none-any.whl |
|---|---|
| Size | 15.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d3ad33db4b9d12d9b223a99dc6b890adca9d551e14a7378e3d0926551f882e60
|
|
BLAKE2b-256 checksum How to use checksums |
c1d5e1e54ac9866ac0f953028009e327dc0dead3edc274c32b8d36107cab0a34
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|