tappass — Zero Trust Control Plane for Agentic AI (Python SDK)
Runtime governance for your LLM, agent, and tool calls. Embed in your code, get a typed audit trail, surface governance decisions as Python exceptions.
What this SDK is for:
- Governing LLM calls, agent runs, and tool executions at runtime.
- Emitting structured audit events with correlation IDs.
- Handling governance decisions (block, redact, approve, trust-tier, break-glass) as typed exceptions in your code.
What this SDK is NOT for:
- Policy CRUD, compliance report generation, Verified credential issuance, retention config, break-glass invocation, tool-integrity approval. Those live in the TapPass dashboard — not in your agent code.
Requirements
- Python ≥ 3.11.
tappassserver ≥ 0.6.0. (The SDK rejects older servers at construction time.)
Install
pip install tappass
Quickstart — a governed chat call
from tappass import Agent
agent = Agent("https://tappass.example.com", api_key="tp_...")
r = agent.chat("Summarize Q4 revenue")
print(r.content)
print(r.session_id, r.audit_url) # correlation IDs, deep link to dashboard
Quickstart — govern a CrewAI run
from crewai import Agent, Task, Crew
from tappass.integrations.crewai import guard_crew
crew = Crew(agents=[...], tasks=[...])
with guard_crew(crew, tappass_url="https://tappass.example.com", api_key="tp_...") as session:
result = session.kickoff()
print(session.id, session.audit_url)
Telemetry kill-switch
The SDK delivers audit events to your TapPass server asynchronously via a background reporter. To disable that delivery entirely, set either of:
export TAPPASS_DISABLE_TELEMETRY=1
export DO_NOT_TRACK=1 # community convention — consoledonottrack.com
This only suppresses audit-event delivery. It does not disable
governance — govern() calls still run, decisions are still enforced,
blocks still raise GovernanceBlocked. The distinction is deliberate:
governance is the product you're paying for; telemetry is observability
of your own usage.
Decisions are typed exceptions
from tappass import GovernanceDecision, PolicyBlockError, ApprovalRequired
try:
r = agent.chat("Show me all customer SSNs")
except PolicyBlockError as e:
print(f"Blocked by {e.blocked_by}: {e.reason}. See {e.audit_url}")
except ApprovalRequired as e:
print(f"Awaiting approval: {e.approval_url}")
except GovernanceDecision as e:
print(f"Governance decision: {e}")
What's new in 0.6
See CHANGELOG.md. Breaking changes — no back-compat with 0.5.x. See the migration guide.
Publishing a release
Releases ship to PyPI via GitHub Actions using OIDC Trusted Publishing — no long-lived API token is stored anywhere. The workflow is .github/workflows/release.yml.
One-time PyPI configuration
Only needed once per project (or whenever the workflow name / environment changes):
- Log in to https://pypi.org/manage/account/publishing/.
- Under Add a new pending publisher (if the project isn't on PyPI yet) or the existing project's Publishing tab, add a GitHub publisher with:
- PyPI Project Name:
tappass - Owner:
tappass - Repository name:
tappass-sdk - Workflow name:
release.yml - Environment name:
pypi
- PyPI Project Name:
- In the GitHub repo, go to Settings → Environments and create an environment named
pypi. Optionally add a required-reviewers protection rule so a human approves each release.
That's it — no secrets, no tokens.
Cutting a release
- Bump
versioninpyproject.toml(and__version__intappass/__init__.py). - Update
CHANGELOG.md: flip## [X.Y.Z] — Unreleasedto## [X.Y.Z] — YYYY-MM-DD. - Commit:
git commit -am "release: X.Y.Z". - Tag and push:
git tag vX.Y.Z git push origin main --tags
The workflow then:
- Verifies the tag matches
pyproject.tomlversion (fails the release if not). - Builds wheel + sdist.
- Runs
twine check. - Publishes to PyPI via OIDC.
- Creates a GitHub Release with the wheel + sdist attached and auto-generated notes.
Dry run
To build the artifacts without publishing, use Actions → Release to PyPI → Run workflow with dry_run checked. The publish and github_release jobs are skipped; the build job's artifacts are retained for inspection.
License
Apache-2.0. See LICENSE.
Metadata
Release files for tappass 0.12.53
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tappass-0.12.53.tar.gz | 362.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tappass-0.12.53-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 840.4 kB
Release files / tappass-0.12.53.tar.gz
| Download URL | tappass-0.12.53.tar.gz |
|---|---|
| Size | 362.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a482c467859d1daf10b3b1cf7998f9170e996a6c9471d5e4213a4f30e33c8935
|
|
BLAKE2b-256 checksum How to use checksums |
ca6e6a5ea78de3f9381134bdef16890262659ca913ce0dcca6f22d122fbe77fa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / tappass-0.12.53-py3-none-any.whl
| Download URL | tappass-0.12.53-py3-none-any.whl |
|---|---|
| Size | 478.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b45b43ebb5adc2f6856c03a2bad097bfff316b215defbc969b79921ae937ca64
|
|
BLAKE2b-256 checksum How to use checksums |
4493f120a197d32e45960817375caa10dc34aae2e1f048431dd357fcf7012e69
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log