Metadata-Version: 2.4
Name: veltro-suite-auth
Version: 2.0.2
Summary: Veltro-owned suite authentication contracts.
Project-URL: Repository, https://github.com/veltrosecurity/veltro
Author: Veltro Security
License-Expression: AGPL-3.0-or-later
License-File: LICENSE
License-File: NOTICE
Classifier: License :: OSI Approved :: GNU Affero General Public License v3 or later (AGPLv3+)
Classifier: Typing :: Typed
Requires-Python: >=3.11
Requires-Dist: cryptography>=43.0.0
Requires-Dist: python-jose[cryptography]>=3.5.0
Description-Content-Type: text/markdown

# veltro-suite-auth

Veltro-owned suite session and service-token contracts with signed-realm compatibility.

This package is derived from the AGPL-3.0-or-later `veltro-suite-auth` 1.3.0 implementation originally maintained in VectorFlow. See `NOTICE` for provenance.

## Authority envelope v2

`verify_authority_envelope_v2` verifies and consumes short-lived ES256
`veltro-suite-service+jwt` envelopes. The receiver supplies the exact issuer,
exact audience, active generation, that audience's public P-256 JWK ring, required
scope, and an atomic synchronous or asynchronous replay consumer. The consumer
runs exactly once after all stateless checks and must return literal `True`.

This package deliberately provides no v2 minting/signing API, private-key type,
key generator, JWKS/network fetcher, settings/environment adapter, or consumer
runtime wiring. Existing HS256 v1 compatibility remains separate and unchanged.
