tai42-identity-redis
The Redis-backed api-key identity provider for the TAI ecosystem — an
installable plugin that registers itself as the "redis" identity provider and
resolves an inbound api key to an authenticated identity.
Importing the package registers the provider in tai42-contract's module-level
identity-provider registry (register_identity_provider("redis", ...)), with no
tai42_app handle involved — so it registers in any process that imports it,
including ones that never start(). A deployment selects it by including
redis in the access-control auth_providers list.
Its only tai-* dependencies are tai42-contract (the identity ABCs and the
registry it registers through) and tai42-kit (the Redis client, the hash typing
seams, and the api-key hash). It never imports the skeleton — the plugin is
contract-facing, and the import is banned by ruff.
The TAI ecosystem
TAI is an open-source runtime for MCP tools, agents, and workflows. An identity provider is how the runtime answers "who is this caller?": it resolves an inbound credential to an authenticated identity, and access control decides what that identity may do. This package is one such provider (api keys over Redis); any package can back the same contract, so this repo is this provider's own full doc home, and the documentation site covers the platform-level story:
- Access-control concept: https://tai42.ai/concepts/access-control
- Build an identity provider (author guide): https://tai42.ai/guides/authors/identity-provider
- Ecosystem catalog: https://tai42.ai/reference/catalog
What it stores
The provider owns the whole api-key identity record in its own plain-Redis storage:
ac:key:{sha256(raw)}— a Redis hash{"user_id", "description"}(the identity a raw key resolves to).ac:management:key:{user_id}— theuser_id -> hashreverse lookup, so a user id resolves to its stored hash for revoke/edit without a scan.
Key material is never stored — only the SHA-256 hash of the raw key.
Surface
The provider implements tai42_contract.access_control.identity.ApiKeyIdentityProvider:
| Method | Does |
|---|---|
validate_token(token) |
Reads ac:key:{hash} and returns the AuthIdentity, or None for an unknown token. A backend error fails closed by raising. |
provision(user_id, description, *, owner_user_id=None) |
Mints a raw sk-… key, writes the identity record + reverse lookup in one transaction, and returns the raw key (surfaced once). When owner_user_id is given, it is stored in the identity record as the owner claim, so validate_token surfaces it for per-request attenuation. |
revoke(user_id) |
Deletes the identity record + reverse lookup; False if the user is unknown. |
update_description(user_id, description) |
Rewrites the record's description; False if the user is unknown. |
list_identities() |
SCANs ac:key:* and returns every stored (user_id, description). |
healthcheck() |
Probes the provider's OWN Redis storage; raises loudly if the record store is unreachable or broken. |
Requirements
Requires Python 3.13+ and any plain Redis — no modules required. The identity
records are plain Redis hashes, so redis, valkey, or any module-less
redis-server works. An unreachable or broken store is caught loudly by
healthcheck() at startup rather than failing per-request.
Install
Requires Python 3.13+. Install from PyPI into the environment that runs the server:
uv add tai42-identity-redis
Or from source — clone this repo and add it as an editable dependency; the
tai42-* dependencies resolve in-tree from the workspace.
git clone https://github.com/tai42ai/tai42 # next to your app checkout
cd /path/to/your/app
uv add --editable ../tai42/plugins/identity-redis
Development
uv venv --python 3.13
uv pip install --no-sources --editable ".[dev]"
uv run --no-sync ruff check .
uv run --no-sync ruff format --check .
uv run --no-sync pyright
uv run --no-sync pytest --cov --cov-report=term-missing
License
Apache-2.0. See LICENSE and NOTICE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file tai42_identity_redis-0.2.2.tar.gz.
File metadata
- Download URL: tai42_identity_redis-0.2.2.tar.gz
- Upload date:
- Size: 12.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
38aae66f2d577e3085a06e58bb0140c2dc1d80d11129a0c766e98861df547b6d
|
|
| MD5 |
e76c23368e335fe35f6dea42e0bc63f0
|
|
| BLAKE2b-256 |
66c35aa1b12bc2e1a808bd5683db11c1db4dfbd4a6d09285f31811b4371bb83f
|
File details
Details for the file tai42_identity_redis-0.2.2-py3-none-any.whl.
File metadata
- Download URL: tai42_identity_redis-0.2.2-py3-none-any.whl
- Upload date:
- Size: 11.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
fd3b21a6c47c3ef6e9ef9dc9b1cfedc8ef0204ff15ff37a86f19ba3d491b434c
|
|
| MD5 |
fd8d5285a6aa56aa9138116e2fb91fc7
|
|
| BLAKE2b-256 |
354066b334c23feae0f09596add5d7c93dea71063c3bc6276e11fb5bf4379f9f
|