This release is a pre-release and may not be stable for production use.
Swarmauri Signing SigV4
AWS Signature Version 4 (SigV4) signer and verifier that implements the ISigning interface for HTTP requests and raw byte payloads.
Features
- Canonicalizes HTTP request envelopes according to AWS SigV4 rules
- Derives SigV4 signing keys from AWS credentials and scope information
- Supports both request signing and raw payload HMAC generation/verification
- Returns structured signature metadata (scope, signed headers, canonical hash) for downstream Authorization headers
Security Notes
- Requires valid AWS-style credentials (
access_key,secret_key, optionalsession_token) - Verification requires access to the shared secret material; compare signatures externally when AWS performs verification
- Payload canonicalization expects callers to supply the appropriate SHA-256 hash or the
UNSIGNED-PAYLOADmarker
Installation
Install the package with your preferred Python packaging tool:
pip install swarmauri_signing_sigv4
uv pip install swarmauri_signing_sigv4
poetry add swarmauri_signing_sigv4
Usage
import asyncio
from swarmauri_signing_sigv4 import SigV4Signing
envelope = {
"method": "GET",
"uri": "/",
"query": {"Action": ["ListUsers"], "Version": ["2010-05-08"]},
"headers": {
"host": "iam.amazonaws.com",
"x-amz-date": "20150830T123600Z",
"content-type": "application/x-www-form-urlencoded; charset=utf-8",
},
"payload_hash": "UNSIGNED-PAYLOAD",
"amz_date": "20150830T123600Z",
"scope": {"date": "20150830", "region": "us-east-1", "service": "iam"},
}
key = {"access_key": "AKIDEXAMPLE", "secret_key": "wJalrXUtnFEMI/K7MDENG+bPxRfiCYEXAMPLEKEY"}
async def main() -> None:
signer = SigV4Signing()
signatures = await signer.sign_envelope(key, envelope)
print(signatures[0]["signature"])
asyncio.run(main())
When verifying signatures you must provide the shared secret via opts["secret_key"] or require["secret_key"].
Byte payload signing
Use sign_bytes / verify_bytes when you only need a SigV4-derived HMAC:
payload = b"example"
opts = {"date": "20150830", "region": "us-east-1", "service": "iam"}
signatures = await signer.sign_bytes(key, payload, opts=opts)
assert await signer.verify_bytes(payload, signatures, opts={**opts, "secret_key": key["secret_key"]})
Entry Point
The signer registers under the swarmauri.signings entry point as SigV4Signing.
Want to help?
If you want to contribute to swarmauri-sdk, read up on our guidelines for contributing that will help you get started.
Metadata
Release files for swarmauri_signing_sigv4 0.11.0.dev1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_signing_sigv4-0.11.0.dev1.tar.gz | 9.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_signing_sigv4-0.11.0.dev1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 20.7 kB
Release files / swarmauri_signing_sigv4-0.11.0.dev1.tar.gz
| Download URL | swarmauri_signing_sigv4-0.11.0.dev1.tar.gz |
|---|---|
| Size | 9.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e45f05ab73758905d26fbe2457f1b5082543037d87428f27f0376390d6f6f07a
|
|
BLAKE2b-256 checksum How to use checksums |
1603c6d729d1d9ca05b0fcf0b1e98f72cb1f5490fe39013d53104966ba8eca97
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_signing_sigv4-0.11.0.dev1-py3-none-any.whl
| Download URL | swarmauri_signing_sigv4-0.11.0.dev1-py3-none-any.whl |
|---|---|
| Size | 10.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
57418f9ceb70f254fa0728a67e06c4b317a24659a565fba21b1805a8289d1ed2
|
|
BLAKE2b-256 checksum How to use checksums |
eb2f0c6369ed90e52c777a715a2bd2e861d3764e602c0979f53612c60b222ac2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.26 {"installer":{"name":"uv","version":"0.11.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|