vouch-safetensors
Embed Vouch Credentials in a .safetensors file's
existing __metadata__ header, with zero changes to the safetensors format.
This is deliberately complementary to OpenSSF Model Signing (OMS). OMS proves an artifact is intact and signed by a key. Vouch adds the agent and delegation dimension: which principal or pipeline produced the weights, traceable back to an accountable human. The credential is bound to a SHA-256 of the tensor data buffer, so any weight tampering breaks verification. Standard loaders (including Hugging Face) ignore the extra metadata key, so signed files load normally.
Install
pip install vouch-safetensors
Sign a model
from vouch import Signer
from vouch_safetensors import sign_safetensors
signer = Signer(private_key=PRIV_JWK, did="did:web:ml.acme.com")
credential = sign_safetensors(signer, "model.safetensors", name="fraud-detector")
# Writes the credential into model.safetensors __metadata__ (in place by default;
# pass out_path=... to write a copy).
Verify a model
from vouch_safetensors import verify_safetensors
ok, passport = verify_safetensors("model.safetensors", public_key=producer_pubkey)
if not ok:
raise RuntimeError("Unsigned, invalid signature, or weights changed since signing")
verify_safetensors checks both the signature and that the tensor data still
matches the digest the credential was bound to.
License
Apache-2.0.
Metadata
Release files for vouch-safetensors 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vouch_safetensors-0.1.0.tar.gz | 3.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vouch_safetensors-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 6.0 kB
Release files / vouch_safetensors-0.1.0.tar.gz
| Download URL | vouch_safetensors-0.1.0.tar.gz |
|---|---|
| Size | 3.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
91338f9f3971eadc2d79079801ec483c3fd47730557d9e42fe69c636059c2ed0
|
|
BLAKE2b-256 checksum How to use checksums |
c69c48efa09adbe35702e4543a863e8dfb4885850d21f6913d889baf90cfb609
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.9
|
Release files / vouch_safetensors-0.1.0-py3-none-any.whl
| Download URL | vouch_safetensors-0.1.0-py3-none-any.whl |
|---|---|
| Size | 2.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3364861b978dd84578441d3ddc41af61425b99f08e5deb5ac68d794ccd0e2baa
|
|
BLAKE2b-256 checksum How to use checksums |
a8840d9024172417e66303cada2705d2ceba10f0aef65bdd85665a8e547735f8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.9
|