Python client and CLIs for TrueSight DAO / Edgar (edgar.truesight.me).
Project description
๐ New to the DAO? Start with the Integration Guide โ โ a developer-friendly overview of all Edgar protocols, event types, and the digital signature system.
dao_client
Python client library + CLI for TrueSight DAO's contribution server, Edgar (edgar.truesight.me, source: TrueSightDAO/dao_client (Python/FastAPI, formerly dao_protocol)).
Every public DAO action โ contribution, inventory movement, notarization, QR update, tree planting, proposal vote, sale โ is submitted as an RSA-signed event payload to Edgar's POST /dao/submit_contribution endpoint. The browser-side reference implementation lives in TrueSightDAO/dapp (each HTML page under dapp.truesight.me/). This repo is the terminal / script / automation equivalent: same signing, same payload shape, same endpoint โ just from Python instead of a browser tab.
Contents
- What this repo gives you
- Installation
- Quick start (three commands)
- Onboarding a key โ
truesight_dao_client.auth - Submitting signed events โ
truesight_dao_client.modules/ - Reading DAO data โ
truesight_dao_client.cache/ - AI-agent contributions โ
report_ai_agent_contribution - Using the library from your own Python
- Environment variables (
.env) - Architecture โ one picture
- Security notes
- Related repos
What this repo gives you
| Location | Purpose |
|---|---|
truesight_dao_client/edgar_client.py |
Core library. Key generation (RSA-2048, SPKI / PKCS#8 base64 โ byte-identical to WebCrypto exports), canonical payload formatting, RSASSA-PKCS1-v1_5 / SHA-256 signing, the multipart POST /dao/submit_contribution, and build_event_cli(...) for zero-boilerplate per-event wrappers. Python port of dapp/scripts/edgar_payload_helper.js. |
truesight_dao_client/auth.py |
OAuth-loopback CLI to onboard this machine's keypair. login signs [EMAIL REGISTERED EVENT] with a 127.0.0.1:<port>/verify callback, spins up a one-shot listener, captures em+vk when the email link is clicked, auto-submits [EMAIL VERIFICATION EVENT]. Fallbacks: verify, status, rotate. Installed as truesight-dao-auth. |
truesight_dao_client/modules/ |
Thin CLI wrappers, one per signed page on dapp.truesight.me/. Named flags for canonical attributes + --attr 'Label=Value' escape hatch + --dry-run. See table. |
truesight_dao_client/cache/ |
Read-side wrappers over the DAO's four public data sources (treasury snapshot, freight lanes, repackaging receipts, contributor voting rights). Each module has a library API and python -m truesight_dao_client.cache.<name> (plus truesight-dao-cache-* console scripts). Swappable backends (GithubRawBackend / GithubContentsBackend / GasBackend) so GASโGitHub flips are one-liners. |
truesight_dao_client/modules/ping_sophia.py |
Ping Sophia (the autopilot) with a governor-signed one-shot message โ the reusable trigger for the local-LLM โ Sophia execution handoff (e.g. "open a Telegram topic for <plan> and post a kickoff"). Signs the RSA payload Sophia's /chat-blocking expects and POSTs with X-Public-Key. Governor-only โ enforced by Sophia (non-governor keys get HTTP 403). Installed as truesight-dao-ping-sophia. Any LLM/CLI on a governor's machine (with that governor's ./.env keys) can use it. |
dapp_digital_signature_onboarding/ |
Operator read-mostly demo mirroring Edgar's Google-Sheets side of the onboarding flow (append VERIFYING row, call the mailer, flip to ACTIVE). Previously lived in TrueSightDAO/tokenomics under python_scripts/examples/. |
requirements.txt |
Mirrors runtime deps from pyproject.toml for pip install -r workflows. |
pyproject.toml |
Installable package truesight-dao-client (import name truesight_dao_client) and console entry points (truesight-dao-auth, per-event CLIs, cache readers). |
.env |
Never committed (0600, gitignored). Holds EMAIL, PUBLIC_KEY (SPKI base64), PRIVATE_KEY (PKCS#8 base64). Written by truesight-dao-auth login (or python -m truesight_dao_client.auth login). Looked up from the current working directory (./.env) unless you pass an explicit path to EdgarClient.from_env(path=...). |
auth.py, edgar_client.py (repo root) |
Thin shims for older scripts; prefer truesight_dao_client imports or the truesight-dao-* commands after pip install. |
Installation
From PyPI (once published):
python3 -m venv .venv && source .venv/bin/activate
pip install truesight-dao-client
From a git checkout (editable install keeps truesight-dao-* on your PATH):
git clone git@github.com:TrueSightDAO/dao_client.git ~/Applications/dao_client
cd ~/Applications/dao_client
python3 -m venv .venv && source .venv/bin/activate
pip install -e .
# or: pip install -r requirements.txt # library only, no console scripts
Python 3.10+ (uses list[str]-style type hints in several modules).
Quick start (three commands)
# 1. Generate a keypair, register it with Edgar, finalise via email click.
truesight-dao-auth login --email you@example.com
# 2. Confirm Edgar agrees you're active.
truesight-dao-auth status
# 3. Emit any signed event โ e.g. log 30 min of contribution work.
truesight-dao-report-contribution \
--type "Time (Minutes)" --amount 30 \
--description "Closing out Townhall" \
--contributors "Your Name" --tdg-issued "N/A"
Dry-run the third command with --dry-run first if you want to see the signed share text without hitting the wire.
Onboarding a key โ truesight_dao_client.auth / truesight-dao-auth
How the loopback flow works
โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโ
โ your CLI โ [EMAIL REGISTERED โ Edgar (Python/FastAPI) โ
โ auth.py โโโโโโโโโ EVENT]โโโโโโถโ edgar.truesight.me โ
โ โ gen_src=127.0.0.1 โ โ
โ โ โโโโโโโโโโโโฌโโโโโโโโโโโ
โ โ โ
โ โ โโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโ
โ โ โ GAS edgar_send_email_verif.gs โ
โ โ โ GmailApp.sendEmail(โฆ&vk=โฆ) โ
โ โ โโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโ
โ โ โ
โ โ (you receive an email) โ
โ โ โผ
โ โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โโโโโem,vkโโโผโโโค browser: http://127.0.0.1:PORT/verifyโ
โ โ โ ?em=โฆ&vk=โฆ โ
โ โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ โ โโโโโโโโโโโโโโโโโโโโโโโ
โ โ [EMAIL VERIFICATIONโ Edgar writes โ
โ โโโโโโโโ EVENT]โโโโโโโถโ Contributors Digitalโ
โ โ vk + pubkey โ Signatures row: โ
โ โ โ Status=ACTIVE, โ
โ โ โ col H = now โ
โ โ โโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโ
The generation-source URL encoded in the signed payload is the only thing that tells the mailer where to point the link โ the auth CLI exploits that by setting it to an ephemeral 127.0.0.1 port bound a moment before the EMAIL REGISTERED EVENT POST. The listener captures em+vk the instant you click, signs [EMAIL VERIFICATION EVENT] with the same keypair, and POSTs it to Edgar. Column H ("Verification Key Consumed", added in sentiment_importer#1024) enforces single-use.
Subcommands
truesight-dao-auth login --email you@example.com # loopback register+verify; default path
truesight-dao-auth verify --vk <value-from-email-url> # manual fallback if you click on a phone
truesight-dao-auth status # GET /dao/check_digital_signature
truesight-dao-auth rotate --email you@example.com # wipe .env keys + generate fresh
truesight-dao-auth login is idempotent โ if the stored key is already ACTIVE on Edgar it exits with a short message. If the key is mid-verification it says so and points you at verify / rotate.
Constraints & troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Gmail shows "preview this link" warning | Link is http://127.0.0.1:โฆ (not HTTPS). |
Click through โ it's a local URL. |
| Email link opens but nothing happens in terminal | You clicked on a different device, or the listener timed out (10 min default). | truesight-dao-auth verify --vk <value> (paste the vk= query param from the URL). |
HTTP 422 โฆ No matching pending verification row |
The vk already consumed, or the pub_key doesn't match the row the vk was minted for. | truesight-dao-auth rotate --email you@example.com then log in again. |
HTTP 200 โฆ email_registration.skipped=true |
This browser key is already pending/active โ Edgar won't re-send. | Click the previous email, or rotate. |
ReadTimeout on status / contributors |
GAS cold start. | Retry once; GasBackend default is 45 s. |
Submitting signed events โ truesight_dao_client.modules/
Every signed page on dapp.truesight.me/ has a matching module under truesight_dao_client/modules/. Each one hardcodes the event name, exposes canonical attributes as named CLI flags (dashes; e.g. --type, --amount), and accepts --attr 'Label=Value' (repeatable) for anything not covered. All modules support --dry-run and --generation-source <URL>.
After pip install -e . or pip install truesight-dao-client, use the truesight-dao-* console commands (see pyproject.toml [project.scripts]). You can also run python -m truesight_dao_client.modules.<name> โฆ.
truesight-dao-report-contribution \
--type "Time (Minutes)" --amount 30 \
--description "Closing out Townhall" \
--contributors "Gary Teh" \
--tdg-issued 50.00
# โ HTTP 200, {"status":"success","signature_verification":"success",...}
Example when the contribution is USD-denominated under the 1 TDG per 1 USD rule. The DApp maps the USD picker to payload - Type: USD (dapp/report_contribution.html); Amount is the USD number; TDG Issued should match it (e.g. 607.00 TDG for 607.00 USD).
truesight-dao-report-contribution \
--type "USD" \
--amount 607.00 \
--description "Flight tickets for DAO logistics (USD 607.00)." \
--contributors "Gary Teh" \
--tdg-issued 607.00
TDG Issued โ match the scoring rubric (time or USD)
Do not use N/A for TDG Issued when a numeric rubric applies. Tokenomics TDG scoring encodes two headline rules in google_app_scripts/tdg_scoring/grok_scoring_for_telegram_and_whatsapp_logs.gs (checkTdgIssued): 100 TDG per 1 hour of human effort, and 1 TDG per 1 USD of contribution treated as liquidity / dollar outlay. The sheet Intiatives Scoring Rubric summarizes categories (tokenomics/SCHEMA.md โ Intiatives Scoring Rubric). Pass --tdg-issued so CLI rows stay consistent with Telegram-scored lines.
Clock time (Time (Minutes), human effort)
Classification analogue: 100TDG For every 1 hour of human effort. Compute TDG as 100 * <minutes> / 60 (e.g. 30 minutes โ 50.00 TDG).
USD (dollar amount โ liquidity injected / spend the rubric scores per-USD)
Classification analogue: 1TDG For every 1 USD of liquidity injected. Use --type "USD" to mirror the DAppโs USD branch (not Time (Minutes)). Set --amount to the USD number and --tdg-issued to the same numeric total โ e.g. 607.00 USD outlay โ --tdg-issued 607.00 (Grok example in the same checkTdgIssued string). Proof and context still go in --description (and attachments / destination fields when applicable).
Other types (capital injection events, inventory, AI-agent sessions, โฆ) use the rubric line that applies to that Type / event. The AI-agent contribution CLI defaults Amount / TDG to 0 by convention; see agentic_ai_context/DAO_CLIENT_AI_AGENT_CONTRIBUTIONS.md. Capital and other dedicated events may use truesight-dao-report-capital-injection (or the matching module) instead of truesight-dao-report-contribution when that is the correct Edgar event.
| Module | Console script (examples) | Event tag | Browser equivalent |
|---|---|---|---|
truesight_dao_client/modules/batch_qr_generator.py |
truesight-dao-batch-qr-generator |
[BATCH QR CODE REQUEST] |
batch_qr_generator.html |
truesight_dao_client/modules/create_proposal.py |
truesight-dao-create-proposal |
[PROPOSAL CREATION] |
create_proposal.html |
truesight_dao_client/modules/notarize.py |
truesight-dao-notarize |
[NOTARIZATION EVENT] |
notarize.html |
truesight_dao_client/modules/register_farm.py |
truesight-dao-register-farm |
[FARM REGISTRATION] |
register_farm.html |
truesight_dao_client/modules/repackaging_planner.py |
truesight-dao-repackaging-planner |
[REPACKAGING BATCH EVENT] |
repackaging_planner.html |
truesight_dao_client/modules/report_capital_injection.py |
truesight-dao-report-capital-injection |
[CAPITAL INJECTION EVENT] โ external investors wiring into AGL contracts only |
report_capital_injection.html |
truesight_dao_client/modules/report_contribution.py |
truesight-dao-report-contribution |
[CONTRIBUTION EVENT] โ time or out-of-pocket expenses |
report_contribution.html |
truesight_dao_client/modules/report_ai_agent_contribution.py |
truesight-dao-report-ai-agent-contribution |
[CONTRIBUTION EVENT] (AI agent โ PR URLs required) |
Convention: agentic_ai_context/DAO_CLIENT_AI_AGENT_CONTRIBUTIONS.md |
truesight_dao_client/modules/report_dapp_permission_change.py |
truesight-dao-report-dapp-permission-change |
[DAPP PERMISSION CHANGE EVENT] (governor-only โ edits permissions.json on treasury-cache) |
Spec: agentic_ai_context/DAPP_PERMISSION_CHANGE_FLOW.md |
truesight_dao_client/modules/report_dao_expenses.py |
truesight-dao-report-dao-expenses |
[DAO Inventory Expense Event] |
report_dao_expenses.html |
truesight_dao_client/modules/report_inventory_movement.py |
truesight-dao-report-inventory-movement |
[INVENTORY MOVEMENT] |
report_inventory_movement.html |
truesight_dao_client/modules/report_sales.py |
truesight-dao-report-sales |
[SALES EVENT] |
report_sales.html |
truesight_dao_client/modules/report_tree_planting.py |
truesight-dao-report-tree-planting |
[TREE PLANTING EVENT] |
report_tree_planting.html |
truesight_dao_client/modules/review_proposal.py |
truesight-dao-review-proposal |
[PROPOSAL VOTE] |
review_proposal.html |
truesight_dao_client/modules/scanner.py |
truesight-dao-scanner |
[QR CODE EVENT] |
scanner.html |
truesight_dao_client/modules/update_qr_code.py |
truesight-dao-update-qr-code |
[QR CODE UPDATE EVENT] |
update_qr_code.html |
truesight_dao_client/modules/withdraw_voting_rights.py |
truesight-dao-withdraw-voting-rights |
[VOTING RIGHTS WITHDRAWAL REQUEST] |
withdraw_voting_rights.html |
Read the browser-equivalent HTML for the canonical attribute list and value-format expectations (dates, coordinates, currency). Pages that don't emit a signed event (read-only dashboards โ index.html, stores_nearby.html, stores_by_status.html, store_interaction_history.html, submit_feedback.html, verify_request.html, view_open_proposals.html, restock_recommender.html, shipping_planner.html) aren't mirrored here โ they'd need a different client surface (GET helpers).
Reading DAO data โ truesight_dao_client.cache/
Four wrappers over the DAO's read-only data sources. Each one has a library API, python -m truesight_dao_client.cache.<name>, and a truesight-dao-cache-* console script.
| Module | Source | CLI example |
|---|---|---|
truesight_dao_client.cache.treasury |
TrueSightDAO/treasury-cache/dao_offchain_treasury.json (GitHub raw) โ DAO off-chain inventory snapshot, regenerated on every Telegram-logged inventory movement + safety-net cron. |
truesight-dao-cache-treasury --ledger AGL4 |
truesight_dao_client.cache.freight |
TrueSightDAO/agroverse-freight-audit/pointers/freight_lanes.json (GitHub raw) โ freight lane registry. |
truesight-dao-cache-freight --to "San Francisco" |
truesight_dao_client.cache.compositions |
TrueSightDAO/agroverse-inventory/currency-compositions/{uuid}.json โ per-UUID repackaging receipts (GitHub raw fetch + GitHub contents API for listing, rate-limited to 60/hr unauthenticated). |
truesight-dao-cache-compositions --list |
truesight_dao_client.cache.contributors |
GAS assetVerify (default) + GitHub-raw dao_members.json (live) โ auto-detects shape, either works. See below. |
truesight-dao-cache-contributors ยท --github ยท --list ยท --totals |
truesight_dao_client.cache.contributors โ two live backends
The snapshot shipped by tokenomics#237's dao_members_cache_publisher.gs is live now at raw.githubusercontent.com/TrueSightDAO/treasury-cache/main/dao_members.json. Refresh triggers:
sentiment_importer#1028โ Perch (Rails) enqueuesDaoMembersCacheRefreshWorker(Sidekiq worker in sentiment_importer) on every successful[EMAIL VERIFICATION EVENT]activation. The worker GETs?action=refresh_dao_members_cache&secret=โฆon the publisher, which rebuilds the snapshot and commits to the treasury-cache repo.installDaoMembersCacheDailyTrigger()โ safety-net daily cron in the GAS. Cache self-heals if a Sidekiq enqueue drops.- Manual operator call:
publishDaoMembersCacheNow()in the Apps Script editor.
Snapshot shape (schema_version: 2, contributor-keyed because one contributor has N simultaneously-active RSA keys โ see project_edgar_multiple_active_keys memory):
{
"generated_at": "2026-04-22TโฆZ",
"schema_version": 2,
"dao_totals": {
"voting_rights_circulated": 2341222.10,
"total_assets": 15086.58,
"asset_per_circulated_voting_right": 0.00644,
"usd_provisions_for_cash_out": 32.42
},
"contributors": [
{ "name": "Gary Teh", "voting_rights": 955414.06,
"public_keys": [{"public_key": "MIIBโฆ", "status": "ACTIVE",
"created_at": "โฆ", "last_active_at": "โฆ"}] }
]
}
Contributors.for_public_key(pk) auto-detects which shape the backend returned (GAS ships a single {contributor_name, voting_rights, โฆ} dict; GitHub ships the snapshot above and we scan contributors[*].public_keys[*] locally) and returns an identical-shaped record either way โ just with _source: "gas" | "github_cache" appended so callers can tell which path answered. Default remains GAS for zero-surprise migration; flip to GitHub explicitly via Contributors.from_github() or the --github CLI flag, or globally by editing _default_lookup_source in truesight_dao_client/cache/contributors.py.
Library usage
from truesight_dao_client.cache.treasury import TreasuryCache
tc = TreasuryCache.fetch()
print(tc.totals()) # {item_types, total_units, total_value_usd, ...}
print(tc.manager("Gary Teh")) # one manager's holdings
print(tc.for_ledger("AGL4")) # contents of AGL4
print(tc.item("ceremonial-cacao-500g")) # where a SKU lives
from truesight_dao_client.cache.contributors import Contributors
me = Contributors().for_self() # default GAS backend
print(me["voting_rights"]) # e.g. 955414.06
me_fast = Contributors.from_github().for_self() # fast path โ ~50โ150ms TTFB vs 2โ5s GAS cold start
print(me_fast["_source"], me_fast["_generated_at"])
roster = Contributors.from_github().list_all() # every contributor + their public keys
print(Contributors.from_github().dao_totals()) # DAO-wide aggregates block
Backend-swappable architecture
Every cache module delegates reads to a DataSource in truesight_dao_client/cache/_source.py. Three implementations ship:
GithubRawBackend(raw_url)โ CDN-fast, auth-free, git-history audit trail. Default for treasury / freight / compositions; opt-in for contributors.GithubContentsBackend(contents_url)โ for directory listings thatraw.githubusercontent.comcan't enumerate. Rate-limited to 60 req/hr per IP unauthenticated; surfaces a readable error when throttled.GasBackend(exec_url, params=...)โ for GAS web apps. 45 s timeout so cold starts don't spuriously fail. Default fortruesight_dao_client.cache.contributors.
Downstream โ dapp uses the same cache
TrueSightDAO/dapp shares the same dao_members.json snapshot via scripts/dao_members_cache.js:
tdg_balance.jsrenders the voting-rights badge from the cache (GAS fallback on miss) โ typical 20ร latency win vs GAS cold start (dapp#170).create_signature.htmlrenders "Welcome back" optimistically from the cache while Edgar'scheck_digital_signaturecall is in flight (dapp#171).
So a verification landing in Edgar propagates to: Sidekiq worker โ GAS publisher โ GitHub raw โ both the dapp browser badge and any Python scripts using truesight_dao_client.cache.contributors. One snapshot, three consumers.
AI-agent contributions โ truesight_dao_client/modules/report_ai_agent_contribution.py
Special-cased wrapper for [CONTRIBUTION EVENT] submissions that record work done by an AI agent on behalf of a contributor (e.g. Claude Code pairing sessions). Requires at least one https://github.com/TrueSightDAO/.../pull/N URL and an explicit description so the ledger entry is verifiable against a merged PR.
Full convention, format, and review checklist: agentic_ai_context/DAO_CLIENT_AI_AGENT_CONTRIBUTIONS.md.
Using the library from your own Python
Every additional DAO event is a three-line call:
from truesight_dao_client import EdgarClient
client = EdgarClient.from_env()
resp = client.submit(
"CONTRIBUTION EVENT",
{
"Type": "Time (Minutes)",
"Amount": "30",
"Description": "Closing out Townhall",
"Contributor(s)": "Gary Teh",
},
)
print(resp.status_code, resp.text)
Or sign without sending (handy for testing or for pasting into a manual workflow):
payload, request_txn_id, share_text = client.sign(
"CONTRIBUTION EVENT",
{"Type": "Time (Minutes)", "Amount": "30", "Description": "โฆ", "Contributor(s)": "โฆ"},
)
print(share_text)
The attribute dict matches the - Label: value lines emitted by the browser-side edgar_payload_helper.js + each dapp/*.html, so read that file as the canonical event contract.
Environment variables (.env)
| Key | Purpose | Set by |
|---|---|---|
EMAIL |
The email address this identity registered with (used for EMAIL REGISTERED + EMAIL VERIFICATION events). |
truesight-dao-auth login / rotate |
PUBLIC_KEY |
RSA-2048 SPKI base64, no PEM headers. Byte-identical to crypto.subtle.exportKey('spki', ...) + btoa. |
truesight-dao-auth login / rotate |
PRIVATE_KEY |
RSA-2048 PKCS#8 base64, no PEM headers, unencrypted. Keep this file mode 0600. |
truesight-dao-auth login / rotate |
The .gitignore covers .env, .env.*, and an exception for an optional .env.example. If you ever commit a private key by mistake, rotate immediately (truesight-dao-auth rotate) โ multiple active keys per contributor are fine; old leaked keys can be marked inactive in the sheet by an operator.
Architecture โ one picture
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ your shell / script โ
โ โ
โ auth.py modules/*.py cache/*.py โ
โ โ โ โ โ
โ โโโโโโsigned POSTโโโโโโโโ โ โ
โ โ โ โ
โ โผ โผ โ
โ edgar_client.EdgarClient cache/_source.py โ
โ (RSA-2048, PKCS1v15/SHA256, โโโโโโโโโโโโฌโโโโโโโโโโโโ โ
โ SPKI pub / PKCS8 priv) โ Github โ Gas โ โ
โ โ โ Raw / โ Backend โ โ
โ โ โ Contents โ โ โ
โ โผ โโโโโโฌโโโโโโดโโโโโโฌโโโโโโ โ
โ POST https://edgar.truesight.me/ โ โ โ
โ dao/submit_contribution โ โ โ
โ โ โ โ โ
โโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโผโโโโโโโโโ
โ โ โ
โผ โผ โผ
โโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโ
โ sentiment_ โ โ TrueSightDAO/ โ โ script. โ
โ importer (Railsโ โ treasury-cacheโ โ google. โ
โ on EC2) โ โ /โฆ JSON files โ โ com/macrosโ
โ โ Edgar โ โ (GitHub raw) โ โ /s/โฆ/exec โ
โโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโ
โ
โผ
Google Sheet tabs:
Contributors Digital Signatures,
Contributors voting weight,
TDG ledger, etc.
Security notes
- Key storage.
PRIVATE_KEYlives in.envmode 0600, gitignored. Don't check it in. If a key leaks,truesight-dao-auth rotateโ Edgar allows multiple active keys so revoking an old one is an operator action on the sheet, not a hard lockout. - Loopback URLs. The email verification link is
http://127.0.0.1:<port>/verify?em=โฆ&vk=โฆ. Anyone with network access to your loopback interface during the 10 min window could hit it; in practice that's you + anything else running on your laptop. Not a concern on a single-user machine. - Single-use verification keys. Column H on Contributors Digital Signatures enforces single-use per (
sentiment_importer#1024): a second click with the same vk returnsalready_consumed: trueif the same public key is signing, or a hard reject if a different key is. - No secrets in signed payloads. Everything in the signed share text is world-readable (Edgar logs it to the Telegram raw-logs sheet). Don't put API keys, sensitive notes, or internal URLs in attribute values.
- GitHub cache. The forthcoming
dao_members.jsonmust publish only governance-public fields (name, public keys, voting weight). Emails fromContributors contact information(column D) are onboarding data and must not leak โ the publisher script projects columns explicitly.
Related repos
TrueSightDAO/dappโ browser-side reference implementation; one HTML page per signed event.TrueSightDAO/sentiment_importerโ the Rails Perch (sentiment_importer, formerly called "Edgar"). Signature verify + sheet write logic:app/services/dao_email_registration_service.rb,app/models/gdrive/contributors_digital_signatures.rb.TrueSightDAO/tokenomicsโ canonicalSCHEMA.md+ Apps Script projects (tdg_identity_management,tdg_inventory_management, etc.) that maintain the Google Sheets ledger and publish the GitHub JSON caches.TrueSightDAO/treasury-cacheโ pre-computed JSON snapshot of DAO off-chain treasury. Consumed bycache.treasury.TrueSightDAO/agroverse-freight-auditโ freight lane registry consumed bycache.freightanddapp/shipping_planner.html.TrueSightDAO/agroverse-inventoryโ per-request repackaging receipts consumed bycache.compositionsanddapp/repackaging_planner.html.TrueSightDAO/agentic_ai_contextโ AI-agent operating conventions, includingDAO_CLIENT_AI_AGENT_CONTRIBUTIONS.mdandPROJECT_INDEX.md.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file truesight_dao_client-0.2.0.tar.gz.
File metadata
- Download URL: truesight_dao_client-0.2.0.tar.gz
- Upload date:
- Size: 150.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6270e0c108b415b5cec0e6887b51964f2ff248c3af45cd60add24f688b5ad039
|
|
| MD5 |
f01006a3f15f2b53389161d411071875
|
|
| BLAKE2b-256 |
46a255eb6873db6545dbf4d8397b54148093b5731c5641de29e79fc836b2e1f9
|
Provenance
The following attestation bundles were made for truesight_dao_client-0.2.0.tar.gz:
Publisher:
pypi-publish-dao-client.yml on TrueSightDAO/dao_protocol
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
truesight_dao_client-0.2.0.tar.gz -
Subject digest:
6270e0c108b415b5cec0e6887b51964f2ff248c3af45cd60add24f688b5ad039 - Sigstore transparency entry: 1863475304
- Sigstore integration time:
-
Permalink:
TrueSightDAO/dao_protocol@f5a97f5c95e3e2f571e52a3650c2df24493022a5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/TrueSightDAO
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
pypi-publish-dao-client.yml@f5a97f5c95e3e2f571e52a3650c2df24493022a5 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file truesight_dao_client-0.2.0-py3-none-any.whl.
File metadata
- Download URL: truesight_dao_client-0.2.0-py3-none-any.whl
- Upload date:
- Size: 160.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
28a97d8c923882c41c3d94856cab99f97a11be01c641722cb9aaf67d67382bad
|
|
| MD5 |
15b037f259097afb8aeeaacf5a413fb3
|
|
| BLAKE2b-256 |
d8b32979a30a3cf0227fbb2b3f09a344e1840ce7bd43165e208742639007567d
|
Provenance
The following attestation bundles were made for truesight_dao_client-0.2.0-py3-none-any.whl:
Publisher:
pypi-publish-dao-client.yml on TrueSightDAO/dao_protocol
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
truesight_dao_client-0.2.0-py3-none-any.whl -
Subject digest:
28a97d8c923882c41c3d94856cab99f97a11be01c641722cb9aaf67d67382bad - Sigstore transparency entry: 1863475943
- Sigstore integration time:
-
Permalink:
TrueSightDAO/dao_protocol@f5a97f5c95e3e2f571e52a3650c2df24493022a5 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/TrueSightDAO
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
pypi-publish-dao-client.yml@f5a97f5c95e3e2f571e52a3650c2df24493022a5 -
Trigger Event:
workflow_dispatch
-
Statement type: