Vitnify your agents
Logs tell you what your agent did. Vitnify proves it — a cryptographic, independently-reconstructable record of what an agent computed and did.
Contain what an agent may do, deterministically reconstruct the model behind every decision, and seal the whole run into one bit-for-bit receipt anyone can verify offline — long after it happened.
vitnify (v.) — to turn an agent run into a receipt anyone can reproduce and verify, offline.
vitnify isn't detection. It gives you the primitives to prove exactly what an agent
did: a vitnify-receipt v2 binds the model's computation, the granted capabilities,
every tool call and result, the entropy, and the order into a single ed25519-signed,
self-verifying object.
Install
pip install vitnify
Quickstart
from vitnify.events import EventLog, Kind
from vitnify.engine import Engine, prompt_hash
from vitnify.certificate import issue_certificate, verify_certificate, gen_ed25519
eng = Engine("model.gguf", model_id="my-model") # deterministic backend
log = EventLog()
step = eng.run(prompt_tokens=[1, 2, 3], n_new=20) # a model step
log.append_llm_call(prompt_hash([1, 2, 3]), step["tokens"], seed=0,
model_digest=step["model_digest"]) # bind the model computation
log.append(Kind.TOOL_CALL, {"tool": "read_docs", "decision": "allow"})
log.append(Kind.TOOL_CALL, {"tool": "send_email", "decision": "deny"}) # ungranted → blocked
priv, pub = gen_ed25519()
cert, _ = issue_certificate("program_hash", ["read_docs"], log, priv=priv)
verify_certificate(cert, log) # level 1: offline integrity — no model, no secret
# level 2: re-run each step through the engine; every model_digest reproduces bit-for-bit
See vitnify-receipt-v2.md for the receipt format, and
examples/demo_receipt_e2e.py for the full loop.
What you get
- Capability containment — ungranted tools are structurally unreachable.
- Deterministic replay — re-run any past run and get the identical result.
- Bit-for-bit receipts — the model's exact computation, bound and signed.
- Offline verification — anyone verifies with no model, network, or secret.
- Drop-in — wraps existing LangGraph and MCP agents (
pip install vitnify[langgraph]/[mcp]).
The deterministic engine is vitni-tensor;
the vitni-receipt binary is the model backend (point VITNI_RECEIPT_BIN at it).
License
Apache-2.0. "vitnify" and "vitnify-verified" are trademarks — see TRADEMARKS.md. A fork may use the code, but not the name or issue vitnify-verified receipts.
Part of Vitnify
This SDK is one of three open repos:
- vitni-tensor — the deterministic,
no_stdengine that produces the bit-identical model-computation digest this SDK binds. - vitnify-receipt-spec — the
canonical
vitnify-receipt v2format the SDK implements. - vitnify.com — the project.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vitnify-0.2.4.tar.gz.
File metadata
- Download URL: vitnify-0.2.4.tar.gz
- Upload date:
- Size: 40.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4b0fa751ac9e7de2b0e16338096ffe3be2078f9ad662a42cc3c794cec512fd43
|
|
| MD5 |
636c99169874b5b47e7c17ad031a2ba8
|
|
| BLAKE2b-256 |
67dbe12a4e1931dd67702e8d8f202d1911923999be10e2e4e2a514d11c2ec588
|
Provenance
The following attestation bundles were made for vitnify-0.2.4.tar.gz:
Publisher:
publish.yml on vitnify/vitnify
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vitnify-0.2.4.tar.gz -
Subject digest:
4b0fa751ac9e7de2b0e16338096ffe3be2078f9ad662a42cc3c794cec512fd43 - Sigstore transparency entry: 2525589916
- Sigstore integration time:
-
Permalink:
vitnify/vitnify@7b8e2fb2a90d81142ed6626075bea1d05482a470 -
Branch / Tag:
refs/tags/v0.2.4 - Owner: https://github.com/vitnify
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@7b8e2fb2a90d81142ed6626075bea1d05482a470 -
Trigger Event:
release
-
Statement type:
File details
Details for the file vitnify-0.2.4-py3-none-any.whl.
File metadata
- Download URL: vitnify-0.2.4-py3-none-any.whl
- Upload date:
- Size: 32.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
38a5575fc000de096daadb9b7003838592dd70022d391c57f8a5a21e941ac39b
|
|
| MD5 |
a1a97a676caae3d22aef4fa632056693
|
|
| BLAKE2b-256 |
ed66d55d10233dddacb1ad09a95f8b34875a91e58f93ad3e279efc910e1a10fb
|
Provenance
The following attestation bundles were made for vitnify-0.2.4-py3-none-any.whl:
Publisher:
publish.yml on vitnify/vitnify
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
vitnify-0.2.4-py3-none-any.whl -
Subject digest:
38a5575fc000de096daadb9b7003838592dd70022d391c57f8a5a21e941ac39b - Sigstore transparency entry: 2525590019
- Sigstore integration time:
-
Permalink:
vitnify/vitnify@7b8e2fb2a90d81142ed6626075bea1d05482a470 -
Branch / Tag:
refs/tags/v0.2.4 - Owner: https://github.com/vitnify
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@7b8e2fb2a90d81142ed6626075bea1d05482a470 -
Trigger Event:
release
-
Statement type: