veltro-suite-auth
Veltro-owned suite session and service-token contracts with signed-realm compatibility.
This package is derived from the AGPL-3.0-or-later veltro-suite-auth 1.3.0 implementation originally maintained in VectorFlow. See NOTICE for provenance.
Authority envelope v2
verify_authority_envelope_v2 verifies and consumes short-lived ES256
veltro-suite-service+jwt envelopes. The receiver supplies the exact issuer,
exact audience, active generation, that audience's public P-256 JWK ring, required
scope, and an atomic synchronous or asynchronous replay consumer. The consumer
runs exactly once after all stateless checks and must return literal True.
This package deliberately provides no v2 minting/signing API, private-key type, key generator, JWKS/network fetcher, settings/environment adapter, or consumer runtime wiring. Existing HS256 v1 compatibility remains separate and unchanged.
Browser request assertion verifier
verify_browser_request_assertion verifies and consumes short-lived ES256
veltro-browser-request+jwt request assertions minted by Veltro identity. The
receiver supplies the exact issuer, exact audience, active generation, that
audience's public P-256 JWK ring, the request being authorized (request with
method and path), and an atomic synchronous or asynchronous replay consumer.
The verifier enforces every binding the mint records: exact typ, alg=ES256
allowlist, audience key ring and kid, signature, issuer/audience, active
generation, nbf/iat/expiry capped at 60s, fixed realm default, grant-product
consistency, and — the point of the artifact — that the signed method and
canonical path match the request being authorized, using the same shared
normalize_request_path contract the mint uses. An assertion minted for
GET /chad/api/alerts never authorizes POST /chad/api/rules.
One-use semantics are the receiver's: after all stateless checks, the verifier
calls the replay consumer exactly once with a frozen {issuer, audience, generation, jti, expires_at} tuple. The consumer must return literal True
only if it has not previously seen that tuple; a replayed jti is rejected when
the consumer returns False. The consumer must persist at least
{issuer, audience, generation, jti} until expires_at to enforce one-use
semantics across the token's validity window.
This package deliberately provides no request-assertion minting/signing API, private-key type, key generator, JWKS/network fetcher, settings/environment adapter, or consumer runtime wiring.
Release files for veltro-suite-auth 2.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| veltro_suite_auth-2.3.0.tar.gz | 34.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| veltro_suite_auth-2.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 77.4 kB
Release files / veltro_suite_auth-2.3.0.tar.gz
| Download URL | veltro_suite_auth-2.3.0.tar.gz |
|---|---|
| Size | 34.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
673304ef3834811fc8eb2d1903b2e1f17d4f7eccc3fb7c1447ef5f884f5c8afd
|
|
BLAKE2b-256 checksum How to use checksums |
55c4d164f79c752a54278b8b1ff39458f3a37b857f92195c60baf9e45abba3a8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.
Transparency logRelease files / veltro_suite_auth-2.3.0-py3-none-any.whl
| Download URL | veltro_suite_auth-2.3.0-py3-none-any.whl |
|---|---|
| Size | 43.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
21688d13d6f6355e2199783a32b25978875620cb0bef8bdb028fd866a250ee68
|
|
BLAKE2b-256 checksum How to use checksums |
97accf7354d0c240392892d1b0e6f57ce0c9f147a69ac24bc252a95805db63c1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.
Transparency log