Swarrm — signed receipts + transparency log + offline verification for AI agent actions
Project description
Swarrm
Signed receipts, a tamper-evident log, and offline verification for what AI agents do.
Every action an AI agent takes — a model call, a tool run, a refund, a payment — becomes a signed receipt in an append-only, tamper-evident log (RFC 6962 Merkle tree, Ed25519 / DSSE). Any set of receipts exports as a self-contained evidence bundle that anyone you share it with can verify offline — no account, no server, no trust in you or in Swarrm. Payloads stay in your environment; the log holds hashes and operational metadata, never the content.
Ordinary application logs are editable, so they are testimony, not evidence. These records are verifiable: flip a single byte and the bundle fails.
Quickstart
pipx install swarrm # Python 3.11+ (or: pip install swarrm)
swarrm demo # synthetic agent traffic → receipts → bundle → VERIFIED
swarrm verify demo_out/bundle.json # the demo flips one byte → NOT VERIFIED
Two minutes, no account, fully local. One config knob — EVD_PROFILE=dev|trial|edge
— sets every default; swarrm doctor prints what's effective and whether it is
actually recording. The CLI is one word: up (dev stack), demo,
verify BUNDLE, wrap -- CMD (capture an MCP tool), node, incident,
status, doctor.
Verify it yourself — offline, and open
swarrm verify <bundle.json> checks a bundle entirely locally. So does the
in-browser verifier at swarrm.ai/verify —
client-side, nothing leaves the page.
The verifier is open source and independent: a second implementation in Rust
(github.com/capxholding/swarrm-verify,
Apache-2.0) that must agree with this package's Python verifier on a shared
adversarial fixture suite. Two implementations, one answer — the verdict does not
depend on trusting a single codebase. The normative wire-format specifications
(evd/*) are published openly in that repository.
The evidence ladder
Each receipt carries the assurance it has actually earned:
- E0 — signed. The receipt exists and is intact, signed by a known key.
- E1 — in the log. Included in an append-only, checkpointed log; it cannot be silently altered or dropped.
- E2 — anchored. The checkpoint is committed to a public chain and independently timestamped (RFC 3161).
- E3 — co-signed. A counterparty signs the same record — bilateral, non-repudiable proof.
What's in the package
The cryptographic log and receipts; capture surfaces (proxy, recorder, MCP wrapper, SDK, OpenTelemetry); L2 anchoring + RFC 3161 timestamping; the offline verifier; evidence-report rendering; and an out-of-path Evidence Node for independently reading an authoritative source. The wire-format specifications and the second independent verifier are open source (Apache-2.0) in the swarrm-verify repository.
License
The swarrm package is proprietary — © 2026 Capx Holding, all rights reserved.
The published wire-format specifications and the independent verifier are
Apache-2.0.
Homepage: swarrm.ai
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file swarrm-0.3.3.tar.gz.
File metadata
- Download URL: swarrm-0.3.3.tar.gz
- Upload date:
- Size: 235.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4f396ad3ac98e95a1a9adc433fc8766fc2f781a443e5124d5e5e5ad2aa17b9ba
|
|
| MD5 |
aba3b3587510ea8de793dbd097fba7f8
|
|
| BLAKE2b-256 |
2ec09d1c68ea8a2212bb425c96d39c7fa3d231423b759b44457977fdb9d31573
|
File details
Details for the file swarrm-0.3.3-py3-none-any.whl.
File metadata
- Download URL: swarrm-0.3.3-py3-none-any.whl
- Upload date:
- Size: 268.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.14.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8b7328663fbebca796ffef8b10f0f4580a7270a495292128230cad8d5196b4b9
|
|
| MD5 |
442842edbdcb3eb74f1cc40df2fce12e
|
|
| BLAKE2b-256 |
79b468a0d85433741e4d51e5c62df8287859749f51802cafea62fa852429a5b3
|