trustatom
Verify Ed25519 signed TrustAtom decision receipts (ML-DSA-65 post-quantum gate planned).
A TrustAtom is a signed decision receipt: who decided, what policy governed, what evidence supported it, when. This package verifies them. It does not mint them -- minting requires the Trust Gate backend with OPA policy evaluation and key management.
Install
pip install trustatom
Usage
from trustatom import TrustAtom, verify_receipt
atom = TrustAtom(
agent_id="analyst-01",
action="tool_call:database_query",
policy="opa://compliance/data-access-v2",
decision="ALLOW",
evidence={"role": "analyst", "scope": "read_only"},
timestamp="2026-06-30T00:00:00Z",
signature=signature_bytes,
public_key=public_key_bytes,
pq_cosig=pq_cosig_bytes, # optional; required when TRUST_GATE_REQUIRE_PQ=1 (default)
)
assert verify_receipt(atom)
print(atom.receipt_id) # 128-bit content address, sha256[:32]
H3: PQ-required verify
By default, verify_receipt rejects any receipt missing pq_cosig (defends against
signature-stripping). Set TRUST_GATE_REQUIRE_PQ=0 or pass require_pq=False to
accept legacy Ed25519-only receipts.
ML-DSA-65 cosignature verification itself is not yet implemented in this package --
it checks that pq_cosig is present, not that it cryptographically verifies. A real
ML-DSA-65 check ships when a NIST-compliant ML-DSA-65 Python library is available.
Links
License
Apache-2.0
Release files for trustatom 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| trustatom-0.1.0.tar.gz | 5.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| trustatom-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 9.7 kB
Release files / trustatom-0.1.0.tar.gz
| Download URL | trustatom-0.1.0.tar.gz |
|---|---|
| Size | 5.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
67f25240c16287eadd7097d4342391720a2e4921ba45eb2d54a6e8b9eb62edfe
|
|
BLAKE2b-256 checksum How to use checksums |
b236a58af7869ead4941dc69f4e1a0168f4039423c65243b01ca7edf2cd2a167
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 10, 2026.
Transparency logRelease files / trustatom-0.1.0-py3-none-any.whl
| Download URL | trustatom-0.1.0-py3-none-any.whl |
|---|---|
| Size | 4.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e10bdab9741a3b4d8a2e8d0e2634258e24b2ab9c0f87a4bcc751e1228f8c5841
|
|
BLAKE2b-256 checksum How to use checksums |
9f19d787155b0e1cbe4480ffae7972f9238eda8c2b407d2e7fee96c5d61eb035
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 10, 2026.
Transparency log