Skip to main content

Swarrm — signed receipts + transparency log + offline verification for AI agent actions

Project description

Swarrm

Signed receipts, a tamper-evident log, and offline verification for what AI agents do.

Every action an AI agent takes — a model call, a tool run, a refund, a payment — becomes a signed receipt in an append-only, tamper-evident log (RFC 6962 Merkle tree, Ed25519 / DSSE). Any set of receipts exports as a self-contained evidence bundle that anyone you share it with can verify offline — no account, no server, no trust in you or in Swarrm. Payloads stay in your environment; the log holds hashes and operational metadata, never the content.

Ordinary application logs are editable, so they are testimony, not evidence. These records are verifiable: flip a single byte and the bundle fails.

Quickstart

pipx install swarrm                   # Python 3.11+  (or: pip install swarrm)
swarrm demo                           # synthetic agent traffic → receipts → bundle → VERIFIED
swarrm verify demo_out/bundle.json    # the demo flips one byte → NOT VERIFIED

Two minutes, no account, fully local. One config knob — EVD_PROFILE=dev|trial|edge — sets every default; swarrm doctor prints what's effective and whether it is actually recording. The CLI is one word: up (dev stack), demo, verify BUNDLE, wrap -- CMD (capture an MCP tool), node, incident, status, doctor.

Verify it yourself — offline, and open

swarrm verify <bundle.json> checks a bundle entirely locally. So does the in-browser verifier at swarrm.ai/verify — client-side, nothing leaves the page.

The verifier is open source and independent: a second implementation in Rust (github.com/capxholding/swarrm-verify, Apache-2.0) that must agree with this package's Python verifier on a shared adversarial fixture suite. Two implementations, one answer — the verdict does not depend on trusting a single codebase. The normative wire-format specifications (evd/*) are published openly in that repository.

The evidence ladder

Each receipt carries the assurance it has actually earned:

  • E0 — signed. The receipt exists and is intact, signed by a known key.
  • E1 — in the log. Included in an append-only, checkpointed log; it cannot be silently altered or dropped.
  • E2 — anchored. The checkpoint is committed to a public chain and independently timestamped (RFC 3161).
  • E3 — co-signed. A counterparty signs the same record — bilateral, non-repudiable proof.

What's in the package

The cryptographic log and receipts; capture surfaces (proxy, recorder, MCP wrapper, SDK, OpenTelemetry); L2 anchoring + RFC 3161 timestamping; the offline verifier; evidence-report rendering; and an out-of-path Evidence Node for independently reading an authoritative source. The wire-format specifications and the second independent verifier are open source (Apache-2.0) in the swarrm-verify repository.

License

The swarrm package is proprietary — © 2026 Capx Holding, all rights reserved. The published wire-format specifications and the independent verifier are Apache-2.0.

Homepage: swarrm.ai

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

swarrm-0.4.0.tar.gz (238.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

swarrm-0.4.0-py3-none-any.whl (272.8 kB view details)

Uploaded Python 3

File details

Details for the file swarrm-0.4.0.tar.gz.

File metadata

  • Download URL: swarrm-0.4.0.tar.gz
  • Upload date:
  • Size: 238.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0

File hashes

Hashes for swarrm-0.4.0.tar.gz
Algorithm Hash digest
SHA256 6135c9a3203f12ff98ac16bf305a3f73ae3e2ff152f9f6a7e858a5cdd1df4220
MD5 f053ed26879d6a9fa8d2f6b0b4fd68fb
BLAKE2b-256 298cac9260e5c6d4bc16053d1da13aacc27d198ab462df320d1cb264b56ab709

See more details on using hashes here.

File details

Details for the file swarrm-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: swarrm-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 272.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.0

File hashes

Hashes for swarrm-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9a733892c39aed7819b26c5377d99b5a710aea561c0baf9d5fcb9662eb5d6ada
MD5 52b8b97529901aab40bf58d257fa1de3
BLAKE2b-256 6c8369a1e59a089f1c41a2506c4f53367fde593676c7cd0f6626c5001f36101f

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page