Skip to main content

KYA (Know Your Agents) — Open-source trust, governance, and evidentiary assurance infrastructure for autonomous systems. Built on KYP (Know Your Principal), a unified trust model for human users, AI agents, service accounts, and machine identities.

Project description

veldt-kya

Verifiable records for AI agent actions.

When an AI agent takes an action, KYA records it in a cryptographically verifiable chain. If anyone modifies the record later, KYA detects it and pinpoints exactly where the chain was broken.

Think of it as Git for agent actions: every action is committed, hash-chained, and independently verifiable by anyone with the key.

Agent acts
      ↓
KYA records
      ↓
Record verified
      ↓
Record tampered
      ↓
KYA detects exactly where it changed
pip install veldt-kya

The 30-second demo

Step 1. An AI agent issues a $50 refund.

import json
from kya import (
    default_session, record_invocation, record_evidence, verify_chain,
)
from sqlalchemy import text

with default_session() as db:
    inv = record_invocation(
        db, tenant_id="acme", agent_key="support_bot",
        principal_kind="agent", principal_id="support_bot",
    )
    record_evidence(
        db, tenant_id="acme", invocation_id=inv,
        evidence_kind="tool_call",
        payload={"tool": "refund", "customer": "alice", "amount_usd": 50},
    )
    db.commit()

Step 2. Verify the audit chain — clean.

    print(verify_chain(db, tenant_id="acme", invocation_id=inv))
    # → {'valid': True, 'broken_at': None, 'checked': 1, 'reason': None}

Step 3. Someone tampers — changes the refund from $50 to $5000 directly in the database.

    tampered = json.dumps({"tool": "refund", "customer": "alice", "amount_usd": 5000})
    db.execute(
        text("UPDATE kya_evidence SET payload = :p WHERE invocation_id = :i"),
        {"i": inv, "p": tampered},
    )
    db.commit()

Step 4. Verify again — KYA pinpoints the modified row.

    print(verify_chain(db, tenant_id="acme", invocation_id=inv))
    # → {'valid': False, 'broken_at': 1, 'checked': 1,
    #    'reason': 'payload_hash mismatch — payload was modified'}

All four steps run inside the same with default_session() as db: block from Step 1.

That's the whole pitch. The rest of this README is what to do next.

What you get out of the box

  • Cryptographically chained evidence — every action HMAC-linked to the previous one
  • Independent verification — any party with the key can re-verify the whole chain
  • Pinpoint tamper detection — exact row identified when the chain breaks
  • Portable storage — SQLite, PostgreSQL, MySQL, or DuckDB; same code, any database
  • Persistent by default — survives process restart, container restart, host failure
  • Framework-agnostic — works with LangChain, CrewAI, LangGraph, OpenAI Agents, Claude SDK, and MCP

Setup

pip install veldt-kya is enough to run the demo above. KYA falls back to sqlite:///~/.kya/kya.db when nothing is configured.

For production, point KYA at your real database and signing key:

export KYA_DB_URL=postgresql://user:pass@host/db
export KYA_EVIDENCE_KEY_PROVIDER=aws-kms://arn:aws:kms:...

Vault, sealed secrets, and HSM-backed keys are supported via the same env var.

Beyond the demo

The 30-second demo shows evidence — the core primitive. The open-source package also includes:

  • Agent identity anchored on W3C DIDs
  • Delegation chains with attribution that carries upstream
  • Runtime policy enforcement at the gateway
  • Per-agent revocation via W3C StatusList 2021

Each one has the same shape as the demo above: a small, composable API you can adopt one piece at a time.

What KYA isn't

KYA isn't an observability tool. Datadog, OpenTelemetry, and your traces explain what happened operationally — latency, cost, exceptions, execution paths.

KYA explains something different: was the action authorized, who was it attributable to, and can the record be trusted weeks or months later?

Links

  • Full documentation — every primitive, with examples
  • arXiv paper — formal model of the seven systems primitives behind KYA
  • veldt-kya-pro — commercial overlay with signed verdicts, regulator pack, and controls mapped to major healthcare, government, and AI governance frameworks

License

Apache License 2.0 — © 2026 Veldt Labs Inc. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

veldt_kya-0.4.0.tar.gz (904.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

veldt_kya-0.4.0-py3-none-any.whl (684.8 kB view details)

Uploaded Python 3

File details

Details for the file veldt_kya-0.4.0.tar.gz.

File metadata

  • Download URL: veldt_kya-0.4.0.tar.gz
  • Upload date:
  • Size: 904.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for veldt_kya-0.4.0.tar.gz
Algorithm Hash digest
SHA256 170324325b97166b176da13ca6b8f69d2ba40a473789b47080acbb5bb0cf206f
MD5 0a165a98299c1493c57356d6a4f8f0bf
BLAKE2b-256 f9b557f71848795e33c26330a022a31f7d3ea64a1fe055be96dd2e847dd51030

See more details on using hashes here.

Provenance

The following attestation bundles were made for veldt_kya-0.4.0.tar.gz:

Publisher: publish.yml on veldtlabs/veldt-kya

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file veldt_kya-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: veldt_kya-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 684.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for veldt_kya-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9f9d3e0569d3db7fdd72367d8503c48645067fdb18278f4c0b39340ac01ce6c9
MD5 c7c6038e46e11c66c7144147a7f4416b
BLAKE2b-256 e34ce8d02ffd4e54182afdecdfe0132c99db58706fa79f61c266f1c61e63ad50

See more details on using hashes here.

Provenance

The following attestation bundles were made for veldt_kya-0.4.0-py3-none-any.whl:

Publisher: publish.yml on veldtlabs/veldt-kya

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page