Metadata-Version: 2.4
Name: pywrit
Version: 0.1.2
Summary: Ask Writ before an agent writes — allow/deny gate with a tamper-evident audit log
Project-URL: Homepage, https://withwrit.com
Project-URL: Documentation, https://docs.withwrit.com
Keywords: agents,audit-log,authorization,api-keys
Classifier: Programming Language :: Python :: 3
Classifier: Operating System :: OS Independent
Classifier: Topic :: Security
Classifier: Topic :: System :: Systems Administration
Requires-Python: >=3.9
Description-Content-Type: text/markdown
License-File: LICENSE
Dynamic: license-file

# pywrit 🏴‍☠️

*Arrr!* The Writ CLI — ask before yer agent writes.

```bash
pip install pywrit
writ key --email you@company.com
```

Writ is an allow/deny gate that sits in front of every write your AI agent makes. Each check writes a tamper-evident receipt to your audit log. No more wondering who called what, or when.

Shiver me timbers, it's that simple.

## What it does

- `writ key` — Get a free API key (1,000 receipts/month, no card)
- `writ check` — Ask the gate before a write (ALLOW or DENY)
- `writ revoke` — Kill switch: revoke a principal's tokens in one click
- `writ receipts` — See your audit log
- `writ scan` — Find every write in your repo and instrument it

## Docs

Full docs at [docs.withwrit.com](https://docs.withwrit.com). Quickstart at [docs.withwrit.com/quickstart](https://docs.withwrit.com/quickstart).

---

## Packaging notes (for maintainers)

Installable distribution of the Writ CLI. `pip install pywrit` gives you the
`writ` command — no `curl` + `chmod` dance.

### Layout

- `pyproject.toml` — package metadata, `writ` console-script entry point
- `writ_cli/__init__.py` — version
- `writ_cli/cli.py` — the CLI itself (stdlib-only: argparse, json, urllib)

### Relationship to `gate/web/writ`

`gate/web/writ` is the **self-contained single-file script** served by the Lambda
at `/writ` (the `curl -fsSL ... -o writ` download path). It must stay a single
file with no install step.

`writ_cli/cli.py` is the **PyPI package source**. The two files are currently
byte-identical by copy. If you change CLI behavior, update **both** and keep
them in sync — the download path and the pip path must behave the same.

### Build & test locally

```bash
cd cli
python -m build                    # needs `pip install build`
pip install -e .                   # editable install, creates the `writ` command
writ --help
```

### Publish

```bash
cd cli
python -m build
twine upload dist/*
```
