Python reference implementation of The Update Framework (TUF)
-
Updated
Oct 6, 2026 - Python
Python reference implementation of The Update Framework (TUF)
Cancelable Biometric Template Protection for Face Recognition - Research prototype demonstrating Ortho+Sign and Perm+LUT transforms with local KMS
Open-source infrastructure and an emerging specification for traceable, revocable, rebuildable, and verifiable persistent learning in AI agents.
Deterministic AI-agent experiment testing runtime authorization when delegated authority is revoked or expires before execution.
ZenithAuth is a professional-grade, high-performance, and secure authentication and authorization library for modern Python applications. It combines the speed of stateless JWTs with the security of stateful Redis-backed revocation.
An AI agent whose every action is authorized by a revocable credential and sealed into a tamper-evident log — and that reconciles actions taken offline on a credential revoked while it couldn't phone home. With a forensics view that shows the recomputed bytes, not just a verdict. A reference implementation on provenance-core.
Production-ready Python library & CLI for Open Badges 3.0 (W3C Verifiable Credentials): issue, verify, and revoke JWT-VC credentials with Bitstring Status Lists and did:web — plus strict OB 2.0 and legacy OB 1.0.
AnonCreds method backed by Archon (did:cid) — an ACA-Py plugin. Issuer-rooted DID URL identifiers, content-addressed objects, revocation carried by a DID's operation log.
A standing monitor over signed sensor readings: tells apart a tampered reading from one it couldn't check, and maps the blast radius of what to distrust.
Stage361: Revocation Proof Injection Gate with Stage360 External Timestamp Binding. Adds OCSP, CRL, and signed revocation metadata receivers into the QSP evidence rail without false verified claims.
Selective-disclosure eligibility credentials: prove you're over 18 and reveal nothing else, with consent signed by the holder and revocation checked at use time. SD-JWT-style salted commitments on plain Ed25519; biometric binding left as an explicit stub. A reference implementation on provenance-core.
A checkpoint that verifies a good's provenance credential offline and decides allow or hold — with a pre-declared posture for when the issuer is unreachable: fail-closed holds, fail-open allows but flags it provisional, never silently. Verifier, not actor. A reference implementation on provenance-core.
A privacy-preserving, revocable, multi-verifier credential system with auditability and unlinkability.
What happens to an AI agent's authority when people, keys, approvals and roles change around it. Invariants with status labels, linked to runnable conformance cases.
Executable enforcement layer connecting prospective AI admission to runtime cross-service access and revocation.
Lo scontrino revocabile per i contenuti AI — un umano autorizza con la passkey, ogni output porta una prova firmata, revoca e muore all'istante. Apache-2.0.
Semantic revocation graph for evidence-dependent decisions powered by GenLayer.
Stage362: Asynchronous Proof Promotion Gate with Stage361 Revocation Proof Binding. Reviews whether pending timestamp or revocation proof can be promoted, kept pending, rejected, or blocked without false verified claims.
The shared trust primitive behind the agent / good / person reference implementations: third-party-issued, revocable, independently verifiable credentials; a tamper-evident hash-chained ledger; deterministic two-log reconciliation. Ed25519 + W3C VCs, with an overhead bench so you can size it. Apache-2.0.
Per-chunk signed provenance with O(1) traceback and source revocation for RAG ingestion — SBSeg 2026 artifact (SeloD/F/S/R)
To associate your repository with the revocation topic, visit your repo's landing page and select "manage topics."