Skip to main content

vouch-safetensors

Embed Vouch Credentials in a .safetensors file's existing __metadata__ header, with zero changes to the safetensors format.

This is deliberately complementary to OpenSSF Model Signing (OMS). OMS proves an artifact is intact and signed by a key. Vouch adds the agent and delegation dimension: which principal or pipeline produced the weights, traceable back to an accountable human. The credential is bound to a SHA-256 of the tensor data buffer, so any weight tampering breaks verification. Standard loaders (including Hugging Face) ignore the extra metadata key, so signed files load normally.

Install

pip install vouch-safetensors

Sign a model

from vouch import Signer
from vouch_safetensors import sign_safetensors

signer = Signer(private_key=PRIV_JWK, did="did:web:ml.acme.com")
credential = sign_safetensors(signer, "model.safetensors", name="fraud-detector")
# Writes the credential into model.safetensors __metadata__ (in place by default;
# pass out_path=... to write a copy).

Verify a model

from vouch_safetensors import verify_safetensors

ok, passport = verify_safetensors("model.safetensors", public_key=producer_pubkey)
if not ok:
    raise RuntimeError("Unsigned, invalid signature, or weights changed since signing")

verify_safetensors checks both the signature and that the tensor data still matches the digest the credential was bound to.

License

Apache-2.0.

Metadata

Release files for vouch-safetensors 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vouch-safetensors 0.1.0
File Size Uploaded
vouch_safetensors-0.1.0.tar.gz 3.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vouch-safetensors 0.1.0
File Interpreter ABI Platform
vouch_safetensors-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 6.0 kB

Release files / vouch_safetensors-0.1.0.tar.gz

Download URL vouch_safetensors-0.1.0.tar.gz
Size 3.4 kB
Tags Source
SHA-256 checksum
How to use checksums
91338f9f3971eadc2d79079801ec483c3fd47730557d9e42fe69c636059c2ed0
BLAKE2b-256 checksum
How to use checksums
c69c48efa09adbe35702e4543a863e8dfb4885850d21f6913d889baf90cfb609
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.9

Release files / vouch_safetensors-0.1.0-py3-none-any.whl

Download URL vouch_safetensors-0.1.0-py3-none-any.whl
Size 2.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3364861b978dd84578441d3ddc41af61425b99f08e5deb5ac68d794ccd0e2baa
BLAKE2b-256 checksum
How to use checksums
a8840d9024172417e66303cada2705d2ceba10f0aef65bdd85665a8e547735f8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.9

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page