attestation-spec

mcp
Guvenlik Denetimi
Uyari
Health Uyari
  • License — License: Apache-2.0
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 8 GitHub stars
Code Uyari
  • fs module — File system access in .github/workflows/test.yml
Permissions Gecti
  • Permissions — No dangerous permissions requested

Bu listing icin henuz AI raporu yok.

SUMMARY

Open specification and reference verifiers for Seal records: ATTESTATION-v1 for AI model-call decisions, ACTION-v1 for agent actions. Ed25519, canonical JSON, checked offline against a published key.

README.md

Seal

ATTESTATION-v1

Open format and reference verifiers for Seal enforcement receipts.
Ed25519. Offline-verifiable. No call to the issuer required.

CI
PyPI
npm
Spec CC-BY-4.0
Code Apache-2.0

Check a receipt in the browser ·
Spec ·
5-minute walkthrough

What this is

A signed receipt that an AI gateway decided whether a model call was allowed
to run. Anyone with the issuer's published public key can verify it offline.

This repo is the format, two reference verifiers, a stand-alone
reference issuer, and test vectors. It is not the managed Seal
gateway (app.aqta.ai).

A valid signature proves what the gateway said, not what the provider's
compute did. Details: WHAT-RECEIPTS-PROVE.md,
THREAT-MODEL.md.

Verify (pin the key)

pip install aqta-verify-receipt
# or: npm install aqta-verify-receipt
from aqta_verify_receipt import verify_receipt, fetch_published_public_key

trusted = fetch_published_public_key()  # once, then pin
result = verify_receipt(receipt, trusted_public_key=trusted)
print(result.valid)

From v1.0.4, a pinned trusted_public_key is required by default.
Verifying against the key embedded in the receipt alone only proves
integrity, not issuer identity. CLI: --key <pinned> or --integrity-only.

Current production key (also at
/v1/attestation/public-key):

9Y3Eiq6V8QjRDUM5nPqSwKIOPQaoEU4SbagfYFdvWa4

Keys rotate; receipts do not. A receipt verifies against the key that was
current when it was signed. The permanent key record, including retired keys
and their validity windows, is at
app.aqta.ai/security/issuer-keys.txt.

What you'll see

Default output is one compact line. Words carry the verdict; colour is optional.

$ aqta-verify-receipt test-vectors/valid/001-allowed.json --integrity-only
✓ valid  ALLOWED  0000…0001  untrusted embedded key (integrity only)

Tampered signature:

$ aqta-verify-receipt test-vectors/invalid/001-tampered-signature.json --integrity-only
✕ invalid  signature mismatch  0000…ffff

Exit 0 valid, 1 invalid, 2 usage/IO. --json for automation. --pretty
adds a short flourish (seal intact · verified offline); it is never the proof.

--integrity-only checks the receipt against the key embedded in it, which
proves internal consistency but not who issued it. Pass --key with the
published key above to bind it to the issuer.

Contents

Path What
spec/ATTESTATION-v1.md Wire format (CC-BY-4.0)
packages/verify-receipt-py Python verifier (PyPI)
packages/verify-receipt TypeScript verifier (npm)
examples/ Reference issuer and sample receipt
test-vectors/ Known-good and known-bad receipts
CONFORMANCE.md Issuer and verifier expectations
RELATIONSHIP-TO-SCITT.md Where this sits against RFC 9943, and where it is weaker

Run the whole suite from a clean checkout. Each block is independent, so you can
paste them one at a time or all together.

# Python verifier: 38 tests
pip install -e packages/verify-receipt-py
pip install pytest cryptography
pytest packages/verify-receipt-py/tests/ -q

# TypeScript verifier: 11 tests. The build step is required, dist/ is not committed.
(cd packages/verify-receipt && npm ci && npm run build && npm test)

# Cross-implementation check: every test vector, both verifiers, same verdict.
node scripts/make-interop-fixture.mjs

Attribution

Please credit the authors when you implement, fork, cite, or redistribute.

Specification (spec/): CC-BY-4.0. You must give
appropriate credit to Aqta Technologies Ltd, link the licence, and note
if you changed the text. Suggested credit line:

ATTESTATION-v1 by Aqta Technologies Ltd,
https://github.com/Aqta-ai/attestation-spec
(CC-BY-4.0)

Code (packages/, examples/, scripts/, test-vectors/):
Apache-2.0. Keep copyright and licence notices when you
redistribute.

Machine-readable citation: CITATION.cff
(GitHub → Cite this repository).

ATTESTATION-v1 is adjacent to SCITT/COSE, W3C Verifiable Credentials, and
in-toto/SLSA. It is not a conforming profile of those standards.

Links

Yorumlar (0)

Sonuc bulunamadi