The official Python SDK for the Creduent Protocol, a federated, open trust-verification layer and cryptographic identity infrastructure for autonomous AI agents.
Creduent is an open application-layer protocol for cryptographic identity and trust verification of autonomous AI agents, originally created by Kashish Kanojia and stewarded by IDevSec. The official Python SDK is developed and maintained by IDevSec.
Creduent enables autonomous agents to cryptographically sign metadata, verify identities across administrative domains via DNS bindings, and interact with the Creduent registry for secure, machine-to-machine trust checks.
- Cryptographic Identity Management: Generate secure Ed25519 keypairs for AI agents (multi-key support enabled).
- RFC 8785 Canonical Signatures: Compute cryptographic signatures over JSON agent documents using JCS and Ed25519.
- DNS Trust Binding: Verify cryptographic bindings between
agent://identifiers and web domains. - Registry Integration: Register agents and resolve signed attestations from the Creduent Registry.
- Discovery API: Directly fetch and parse an agent's
agent.jsonfrom their well-known endpoint without needing the registry. - Framework Integrations: Native middleware/tools for CrewAI, LangGraph, and AutoGen.
- Unified CLI
creduent: Out-of-the-box CLI commands for CRD scaffolding, signing, and capability discovery.
pip install creduentTo install with specific framework integration support:
pip install "creduent[crewai]"
pip install "creduent[langgraph]"
pip install "creduent[autogen]"
pip install "creduent[all]"Creduent provides native verification adapters for major AI agent frameworks, ensuring you can verify another agent's identity before interacting with it.
from creduent.integrations.crewai import CreduentVerificationTool
from crewai import Agent, Task, Crew
verify_tool = CreduentVerificationTool()
security_agent = Agent(
role='Security Verifier',
goal='Verify the identity of external agents before interacting',
backstory='You are a strict security officer enforcing the Creduent protocol.',
tools=[verify_tool]
)from creduent.integrations.langgraph import create_verification_node
from langgraph.graph import StateGraph
def my_agent_node(state):
# your logic
pass
workflow = StateGraph(MyState)
# Insert verification middleware before interaction
workflow.add_node("verify_agent", create_verification_node("agent://example/target_agent"))
workflow.add_node("interact", my_agent_node)
workflow.add_edge("verify_agent", "interact")from creduent.integrations.autogen import CreduentAgentMiddleware
import autogen
# Wrap your assistant to automatically verify incoming/outgoing agent messages
secure_assistant = CreduentAgentMiddleware(
autogen.AssistantAgent(name="assistant", llm_config=llm_config)
)The new unified creduent CLI uses a YAML-first CRD (Custom Resource Definition) approach to manage your agent identities.
creduent initCreates a draft agent.yaml in the current directory.
creduent keygenGenerates Ed25519 keys inside .creduent/keys/ and prints your public key.
creduent buildReads agent.yaml and .creduent/keys/private.pem (or CREDUENT_PRIVATE_KEY env var) and compiles a fully canonicalized, signed agent.json ready for deployment.
# Public discovery
creduent discover agent://idevsec/steward
# Authenticated discovery (presents your agent identity)
creduent discover agent://idevsec/steward --as agent://my_org/my_agentdiscover(target_agent_id: str, my_agent_id: str = None, private_key_pem: str = None) -> DiscoveryResult
Resolves an agent's URL from the registry, fetches their agent.json, verifies its cryptographic signature and DNS bindings offline, and returns their capabilities. Can optionally perform authenticated discovery using your own key.
Signs a draft agent document using JCS canonicalization (RFC 8785) + Ed25519. Returns signed document with the keys and signature fields.
Verifies a self-signed agent.json. Accepts dict, HTTPS URL, domain, local path, or agent:// URI.
result.valid: boolresult.agent_id,result.keys,result.endpoint,result.capabilitiesresult.error: str or None
Registers an agent with the Creduent registry.
result.success: boolresult.attestation: dict (level, issued_at, expires_at, ...)
Fetches attestation status for an agent from the registry.
Bugs, feature requests, and pull requests welcome via GitHub Issues.
The Creduent Python SDK enforces key safety and signature verification practices:
- Strict Key Storage Permissions: Key generation commands (
creduent keygenin the CLI andcreduent-sign generate-keysin the signing tool) automatically restrict the saved private key file's permissions to0o600(read/write by owner only) on Unix-based systems. - Fail-Closed Verification: Any validation parsing error or timestamp format discrepancy defaults to marking the verification or attestation status as invalid, guarding against format injection attacks.
Licensed under the Apache License 2.0. See the LICENSE file for the full legal text.