Skip to main content

Trustplane SDK (Python) for generating request proof headers

Project description

Trustplane Python SDK (v0.3.1)

Minimal SDK to generate Trustplane proof headers.

Install

pip install trustplane-sdk

Usage

from trustplane_sdk import sign

out = sign(
    tenant_id="mergematter.io",
    api_id="api_demo",
    client_id="client_demo",
    private_key_b64url="<private_key_b64url>",
    method="GET",
    path="/orders",
    body=""
)

print(out["headers"])

Verify headers (auth plane)

Call the Auth Plane header-native verifier directly (no JSON body):

from trustplane_sdk import verify_headers

res = verify_headers(
    auth_base_url="https://auth.trustplane.mergematter.io",
    tenant_id="mergematter.io",
    api_id="api_demo",
    client_id="client_demo",
    private_key_b64url="<private_key_b64url>",
    method="GET",
    path="/orders",
    body="",
)

print(res["status"], (res.get("data") or {}).get("decision"))

Config file

from trustplane_sdk import from_file

client = from_file("./trustplane.json")
out = client.sign(method="GET", path="/orders", body="", private_key_b64url="<private_key_b64url>")

Auto-enroll (CSR + OIDC / AWS IID)

Auto-enroll with a workload identity token. The SDK will fetch a GCP metadata token if TP_OIDC_TOKEN is not set, or use AWS IID when proof_kind="aws_iid".

from trustplane_sdk import onboard

res = onboard(
    base_url="https://control.trustplane.mergematter.io",
    auth_base_url="https://auth.trustplane.mergematter.io",
    tenant_id="new_tenant",
    client_id="new_tenant_client",
    api_id="api_demo_2",
    scopes=["read:demo"],
    proof_kind="oidc",
    proof_auto=True,
    proof_aud="trustplane-enroll",
    auto_approve=True,
    verify=True,
)

print(res["public_key_b64url"], res["private_key_b64url"])

To use a token explicitly:

from trustplane_sdk import enroll_request

res = enroll_request(
    base_url="https://control.trustplane.mergematter.io",
    tenant_id="new_tenant",
    client_id="new_tenant_client",
    public_key_b64url="<public_key_b64url>",
    scopes=["read:demo"],
    proof_kind="oidc",
    proof_payload="<oidc_jwt>",
    auto_approve=True,
)

# AWS IID (EC2/ECS on EC2)
res = enroll_request(
    base_url="https://control.trustplane.mergematter.io",
    tenant_id="new_tenant",
    client_id="new_tenant_client",
    public_key_b64url="<public_key_b64url>",
    scopes=["read:demo"],
    proof_kind="aws_iid",
    proof_auto=True,
    auto_approve=True,
)

Auto-approve retry: if the response includes `auto_approve_reason` with a token
error, the SDK fetches a fresh proof once and retries automatically.

Blindfold verify (one call)

from trustplane_sdk import blindfold_verify

res = blindfold_verify(
    auth_base_url="https://auth.trustplane.mergematter.io",
    tenant_id="new_tenant",
    api_id="api_demo_2",
    client_id="client_demo",
    private_key_b64url="<private_key_b64url>",
    method="GET",
    path="/orders",
    body="",
)
print(res["status"], res["data"])

Blindfold uses a blind OPRF exchange and only sends a blinded input to the Auth Plane.

Example scripts

TP_PRIVATE_KEY=<private_key_b64url> \
python3 sdk/python/examples/demo_core.py
TP_PRIVATE_KEY=<private_key_b64url> \
python3 sdk/python/examples/demo_blindfold.py

Both scripts read trustplane.json for gateway_url and request_path.

Tests

python3 -m unittest sdk/python/tests/test_vector.py

Integration test (against auth plane)

TP_AUTH_BASE_URL=https://auth.trustplane.mergematter.io \
TP_TENANT_ID=<tenant_id> \
TP_API_ID=<api_id> \
TP_CLIENT_ID=<client_id> \
TP_PRIVATE_KEY=<private_key_b64url> \
TP_VERIFY_HEADERS=true \
TP_MODE=core \
python3 sdk/python/tests/integration_test.py

For blindfold APIs, use TP_MODE=blindfold.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

trustplane_sdk-0.3.3.tar.gz (7.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

trustplane_sdk-0.3.3-py3-none-any.whl (6.4 kB view details)

Uploaded Python 3

File details

Details for the file trustplane_sdk-0.3.3.tar.gz.

File metadata

  • Download URL: trustplane_sdk-0.3.3.tar.gz
  • Upload date:
  • Size: 7.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for trustplane_sdk-0.3.3.tar.gz
Algorithm Hash digest
SHA256 9aac8dbb8464021a9d1b131de71c5349aca0b5263fb6e3fe9bb15f5ece0a56fc
MD5 52f9070a03974581965c283d6f0d44ca
BLAKE2b-256 aeaff7d28b5251f3c4f6185c471a1ba2de01f136487872d3916f31f720010647

See more details on using hashes here.

File details

Details for the file trustplane_sdk-0.3.3-py3-none-any.whl.

File metadata

  • Download URL: trustplane_sdk-0.3.3-py3-none-any.whl
  • Upload date:
  • Size: 6.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.7

File hashes

Hashes for trustplane_sdk-0.3.3-py3-none-any.whl
Algorithm Hash digest
SHA256 4bcbd3074e86e69553e54cf1ff684fa7bb00d405079da4d2f0a7af10c8bd9f38
MD5 1d0957d8b7d73e17ee704eaf665cefc0
BLAKE2b-256 d21e1fa7ffeee98991a59401133df8b5a07af3224ef781e65aec105cfa24df37

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page