Skip to main content

vcp-sdk

Python SDK for the Value Context Protocol (VCP) — portable AI ethics validation — plus the Creed Commons client (vcp CLI) for installing signed value artifacts.

Install

pip install vcp-sdk            # core SDK (stdlib-only)
pip install "vcp-sdk[hub]"     # + the vcp CLI for Creed Commons

SDK — tokens, CSM1, VCP-Lite

from vcp import Token, CSM1Code, validate_lite

token = Token.parse("family.safe.guide@1.0.0")
code = CSM1Code.parse("N5+F+E")
errors = validate_lite({"vcp_version": "lite-1.0", ...})

Creed Commons — signed value artifacts

Creed Commons distributes constitutions, creeds, and detector configs as signed data that a values engine interprets — never executable code. Installing an artifact is a signature-verification decision, not a code-execution one:

vcp search gaslighting
vcp install creed-space/anti_gaslighting     # verify Ed25519 + sha256 + schema, then write
vcp verify                                    # re-check installed tree against vcp.lock

vcp install verifies against a trust root pinned inside this package (the registry cannot vouch for itself), pins name@version + content sha256 + the verifying key in vcp.lock, and never imports, evals, or executes what it fetched.

Community namespaces are delegated, never a new root: the hub's namespace_registry.json binds each namespace to its publisher's Ed25519 keys and is itself signed by the pinned root; artifacts must verify against a key registered to their own namespace. Registration and moderation: GOVERNANCE.md.

Trust tiers: signed proves integrity and origin, not semantics; verified additionally carries a domain-separated root counter-signature (issued after lint + red-team + human review) that the client checks on install and on every vcp verify.

CLI — protocol operations

Alongside the Creed Commons commands, vcp runs the protocol operations directly. These call the same functions the MCP tools do, so scripted CLI output and MCP tool output carry the same fields.

vcp token validate family.safe.guide@1.0.0   # parse a VCP/I token
vcp token parse N5+F+E                       # parse a CSM1 code
vcp lite validate agent.json                 # validate a VCP-Lite document
vcp lite to-csm1 agent.json                  # VCP-Lite document -> CSM1 code
vcp encode --space office --agency peer      # context -> VCP/A wire format
vcp classify "Never endanger a child"        # principle -> Schwartz value
vcp status                                   # versions, capabilities, vocabularies

Output is JSON by default. --quiet prints just the value the command is about, for shell consumption:

$ vcp lite to-csm1 agent.json --quiet
N5+F+E

$ vcp encode --space office --constraints legal --constraints time --quiet
📍office|🔒legal+time

The validate/parse commands exit 0 when valid and 1 when invalid, so they work as a CI gate:

vcp lite validate agent.json --quiet || exit 1

vcp encode takes one flag per context dimension (--space, --agency, --cognitive-state, …); --company and --constraints repeat for multiple values, and each personal dimension has a matching --<dim>-intensity (1-5). Run vcp encode --help for the full list.

MCP Server

vcp-mcp exposes the SDK to any MCP client (Claude Code, Claude Desktop, or anything else that speaks the protocol). It runs over stdio by default and is pure local computation — no network calls, no state between calls, no user data read.

pip install "vcp-sdk[mcp]"
vcp-mcp

Claude Desktop / Claude Code config:

{
  "mcpServers": {
    "vcp": {
      "command": "vcp-mcp"
    }
  }
}

Tools

Tool What it does
vcp_status SDK/spec versions, capabilities, dimension and persona vocabularies
vcp_validate_token Parse a VCP/I token into domain / approach / role / version / namespace
vcp_parse_csm1 Parse a CSM1 code; reports scopes, deprecations, and scope conflicts
vcp_encode_context Encode the 18 VCP/A context dimensions to wire, JSON, and session metadata
vcp_validate_lite Validate a VCP-Lite document; returns the equivalent CSM1 code and token
vcp_lite_to_csm1 Convert VCP-Lite persona/adherence/scopes to a CSM1 code
creed_classify_principle Map a constitution principle to a Schwartz value; flag circular-model tensions

Resource vcp://lite/examples serves the bundled VCP-Lite example documents.

HTTP transport

For hosted deployments, vcp-mcp also speaks Streamable HTTP:

vcp-mcp --transport http --port 8080     # binds 127.0.0.1, endpoint /mcp

--port defaults to $PORT then 8080. The endpoint runs stateless (a fresh transport per request), so a gateway may route any request to any replica. Only POST /mcp is served — GET would otherwise hold an idle event stream open per connection, so it is refused with a clean JSON-RPC 405. A GET /health endpoint returns {"status": "ok"}.

The server has no authentication of its own, so binding beyond loopback requires an explicit opt-in:

VCP_MCP_ALLOW_INSECURE_HTTP=true vcp-mcp --transport http --host 0.0.0.0

Set that only where a gateway or reverse proxy fronts the server and handles client auth.

Development

pip install -e ".[dev]"
pytest tests/

License

Apache-2.0. © Creed Space.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vcp_sdk-0.7.0.tar.gz (84.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vcp_sdk-0.7.0-py3-none-any.whl (72.8 kB view details)

Uploaded Python 3

File details

Details for the file vcp_sdk-0.7.0.tar.gz.

File metadata

  • Download URL: vcp_sdk-0.7.0.tar.gz
  • Upload date:
  • Size: 84.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.13

File hashes

Hashes for vcp_sdk-0.7.0.tar.gz
Algorithm Hash digest
SHA256 472b38cef7869dbede6c2d5c4adb2f54718b1b018d8ffe31b18e15bc06d5cbb3
MD5 d95fa82a349362c9dfcdbaddda5e4526
BLAKE2b-256 33792c300b08b3f7c5b82d7ce0c6511e4145e71471672b1543b4f0ef1e475377

See more details on using hashes here.

File details

Details for the file vcp_sdk-0.7.0-py3-none-any.whl.

File metadata

  • Download URL: vcp_sdk-0.7.0-py3-none-any.whl
  • Upload date:
  • Size: 72.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.13

File hashes

Hashes for vcp_sdk-0.7.0-py3-none-any.whl
Algorithm Hash digest
SHA256 4e3643a339bedfa201f8015d516676f621ef93a34c154c6956e52443b5513e1a
MD5 d66bccf464599e15558df4d3fa579cb1
BLAKE2b-256 2fcae8e5e2dc0bb8455e04be97fd4327c9861ea4905d4e1b0c933216debe1590

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.7.0 This release

2 files

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page