Skip to main content

tersign (Python)

pip install tersign

Tersign — the evidence layer for the agent economy. This package is the verification-first Python SDK: zero dependencies, standard library only — the verify path a tribunal, examiner, or CI job can run with nothing installed.

python3 -m tersign verify receipt.json            # offline — no network, ever
python3 -m tersign verify 0x<digest> --ledger …   # chain lookup (explicit network)
from tersign import verify_receipt, digest_of, chain_link_digest, verify_link, verify_commitment

result = verify_receipt(signed_receipt)        # {'valid': True, 'signer': '0x…', 'digest': '0x…'}

What it covers (v0.1):

  • RFC 8785 (JCS) canonical form + the Tersign artifact digest (keccak256(utf8(JCS(v)))) and chain-link constructor — byte-compatible with the TypeScript reference, pinned by shared cross-implementation vectors.
  • EIP-712 recovery for the upstream x402 receipt domain (the merged offer-receipt extension) — pure-python secp256k1, canonical low-s only.
  • Counter-signature verification (verify_link): EIP-191 over the raw 32-byte chain-link digest, recovered against the published ledger signer (https://tersign.ai/v1/ledger).
  • Chain commitment recompute (verify_commitment): since 2026-08-28 each anchor stamps a chain commitment — an accumulator over every counter-signed link — so one anchored digest covers the whole prefix; rows anchored earlier bind the head record only and say so (subjectSchema).

The bundled copy is a convenience, not a trust root. A frozen bundle ships this verify core inside itself, which is fine for a worked example and wrong for evidence handed to you by an interested party — a bundle can ship a checker that blesses it. For adversarial input fetch the checker out-of-band from https://tersign.ai/verify/v1/ (digests at SHA256SUMS beside it) and diff it against the bundled copy; a difference is itself the finding.

Check this package against the public corpus yourself. Since 0.1.4 the sdist carries the subset of the two-sided conformance corpus these primitives decide — 19 vectors across canonical bytes, digest recompute, chain link and chain commitment, both accept and reject arms. python3 -m unittest discover -s tests runs them. A package whose job is letting you check us without trusting us should ship the means to check the package.

Issuing/signing lives in the TypeScript SDK (npm tersign); this package is the independent second implementation of the verification surface — cross-implementation by construction. Frozen evidence bundles (tersign-evidence-bundle-v1) ship their own copy of this verify core inside the artifact, so bundle verification never depends on an install.

No console script on purpose: the tersign bin name belongs to the npm package; the Python surface is python3 -m tersign.

Metadata

Release files for tersign 0.1.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tersign 0.1.6
File Size Uploaded
tersign-0.1.6.tar.gz 28.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tersign 0.1.6
File Interpreter ABI Platform
tersign-0.1.6-py3-none-any.whl Python 3 none any Details

Total release size: 42.6 kB

Release files / tersign-0.1.6.tar.gz

Download URL tersign-0.1.6.tar.gz
Size 28.1 kB
Tags Source
SHA-256 checksum
How to use checksums
8241cde1c091f78e103ebdd3a5940c3163547d826ff150a9ea33103c77c64454
BLAKE2b-256 checksum
How to use checksums
8cea043c2bac94c9d5881992e7c2acfad2290b1122e6f86b40667ca21fec4374
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release files / tersign-0.1.6-py3-none-any.whl

Download URL tersign-0.1.6-py3-none-any.whl
Size 14.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5fcdd75bd2d60774c5b1a03cd09b667c6630b76aba8ede0ad42de1dba00e838c
BLAKE2b-256 checksum
How to use checksums
3bd7e9076256131d74b45dfc49cbfa98fb51df6bb31479a8e818536ba0d0f3b5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release history Release notifications | RSS feed

0.2.1

2 release files

0.2.0

2 release files

0.1.7

2 release files

This release

0.1.6 This release

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

0.0.2

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page