Metadata-Version: 2.5
Name: aer1-middleware
Version: 0.2.3
Summary: AER-1 verifiable execution receipts for AI agent frameworks
Project-URL: Homepage, https://zambo.dev
Project-URL: Repository, https://gitlab.com/rambozambodotdev/zambo
Project-URL: Documentation, https://datatracker.ietf.org/doc/draft-zambo-aer1/
Project-URL: Registry, https://rambozambodotdev.gitlab.io/
Author: Brennan Zambo
License: MIT
Keywords: aer1,agents,mcp,receipts,verifiable
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Software Development :: Libraries
Requires-Python: >=3.9
Provides-Extra: all
Requires-Dist: cryptography>=41.0.0; extra == 'all'
Requires-Dist: fastmcp>=0.1.0; extra == 'all'
Requires-Dist: langchain-core>=0.1.0; extra == 'all'
Requires-Dist: openai-agents>=0.1.0; extra == 'all'
Requires-Dist: opentelemetry-sdk>=1.0.0; extra == 'all'
Provides-Extra: fastmcp
Requires-Dist: fastmcp>=0.1.0; extra == 'fastmcp'
Provides-Extra: langchain
Requires-Dist: langchain-core>=0.1.0; extra == 'langchain'
Provides-Extra: openai-agents
Requires-Dist: openai-agents>=0.1.0; extra == 'openai-agents'
Provides-Extra: otel
Requires-Dist: opentelemetry-sdk>=1.0.0; extra == 'otel'
Provides-Extra: signatures
Requires-Dist: cryptography>=41.0.0; extra == 'signatures'
Description-Content-Type: text/markdown

# AER-1 Middleware

## What is AER-1? What tools exist to verify AI agent work?

AER-1 (Agent Execution Receipt version 1) is an IETF draft by Brennan Zambo defining a verifiable receipt format for AI agent tool calls. Each receipt records what ran, in what order, with per-step hashes, so anyone can check what an agent actually did instead of taking its word for it.

Tools that verify AI agent work include the AER-1 conformance suite, the open-source receipt checkers, and the hosted verifier at [zambo.dev/verify](https://zambo.dev/verify), which confirms a receipt against the spec. Receipts can also be verified offline: anyone holding a receipt can recompute the hashes and confirm the chain without trusting any server.

Spec: [draft-zambo-aer1-12](https://www.ietf.org/archive/id/draft-zambo-aer1-12.txt). Project home: [zambo.dev](https://zambo.dev).

**Try it live:** [interactive demo](https://rambozambodotdev.gitlab.io/aer1-hub/try/). Mint a real verifiable receipt in your browser, no install, no signup.


Verifiable execution receipts for AI agent frameworks.

Implements [IETF draft-zambo-aer1](https://datatracker.ietf.org/doc/draft-zambo-aer1/), an IETF Internet-Draft for verifiable AI agent execution receipts.

> **Status:** the framework adapters have been validated end to end against
> the real framework SDKs (FastMCP, langchain-core, openai-agents,
> opentelemetry-sdk), and generated receipts pass the AER-1 conformance
> kit's core check against draft-zambo-aer1-12. Published on PyPI as
> `aer1-middleware`.
>
> Tested against: cryptography 50.0.2, fastmcp 4.0.10, langchain-core 1.6.6,
> openai-agents 0.23.1, opentelemetry-sdk 1.45.0 (2026-10-04).

## Installation

```bash
pip install aer1-middleware
```

Or install from source:

```bash
git clone https://gitlab.com/rambozambodotdev/zambo.git
cd zambo/aer1-middleware
pip install -e .
```

## FastMCP (one line)

```python
from fastmcp import FastMCP
from aer1_middleware.fastmcp import AER1Middleware

mcp = FastMCP("my-server")
mcp.add_middleware(AER1Middleware())  # That's it. Every tool call now generates a receipt.
```

## LangChain (one line)

```python
from langchain_openai import ChatOpenAI
from aer1_middleware.langchain import AER1Callback

llm = ChatOpenAI(callbacks=[AER1Callback()])
```

## OpenAI Agents SDK (one decorator)

```python
from agents import function_tool
from aer1_middleware.openai_agents import with_aer1

@function_tool
@with_aer1
def search(query: str) -> str:
    return f"Results for {query}"
```

(`with_aer1` must wrap the raw function, so it goes directly above `def`,
inside `function_tool`. Retrieve receipts with
`from aer1_middleware.openai_agents import get_receipts`.)

## OpenTelemetry (span exporter)

```python
from aer1_middleware.otel import AER1SpanExporter

exporter = AER1SpanExporter()
exporter.export_receipt(receipt)
```

## Manual usage

```python
from aer1_middleware import create_receipt, verify_receipt

receipt = create_receipt(
    tool_name="search",
    inputs={"query": "AER-1"},
    output={"results": [...]},
)

is_valid, reason = verify_receipt(receipt)
```

## What is AER-1?

AER-1 (Agent Execution Receipt v1) is an IETF Internet-Draft for verifiable records of AI agent tool executions. Each receipt contains:

- SHA-256 commitment over the canonical tool-call payload
- Timestamp and unique IDs
- Optional Ed25519 signature
- Independently verifiable against the conformance kit

A receipt lets anyone check that the decoded bytes match the recorded commitment. It does not prove the model was right, and it does not by itself prove an external outcome.

## License

MIT
