Metadata-Version: 2.5
Name: langchain-alex
Version: 0.1.0
Summary: Verify signed ALEX evidence bundles in LangChain and LangGraph workflows.
Project-URL: Documentation, https://github.com/Alex-Proof/alex-core/tree/main/packages/langchain-alex#readme
Project-URL: Repository, https://github.com/Alex-Proof/alex-core
Project-URL: Issues, https://github.com/Alex-Proof/alex-core/issues
Author: Bewusst.Ki
License: Copyright 2026 Bewusst.Ki
        
        Licensed under the Apache License, Version 2.0 (the "License");
        you may not use this file except in compliance with the License.
        You may obtain a copy of the License at
        
            http://www.apache.org/licenses/LICENSE-2.0
        
        Unless required by applicable law or agreed to in writing, software
        distributed under the License is distributed on an "AS IS" BASIS,
        WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
        See the License for the specific language governing permissions and
        limitations under the License.
License-File: LICENSE
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Requires-Python: >=3.10
Requires-Dist: langchain-core<2.0,>=1.0
Provides-Extra: dev
Requires-Dist: build>=1.2.2; extra == 'dev'
Requires-Dist: langgraph<2.0,>=1.0; extra == 'dev'
Requires-Dist: pytest>=8.3; extra == 'dev'
Requires-Dist: ruff>=0.11; extra == 'dev'
Description-Content-Type: text/markdown

# langchain-alex

Verify signed ALEX Evidence Packages inside LangChain and LangGraph workflows. The verifier checks
the package against a public key obtained separately from the evidence bundle and fails closed on
unsupported schemas, signature failures, incomplete evidence, or inconsistent declared outcomes.

`valid=True` means that the evidence package passed verification and carries a verified outcome.
Authentic bundles documenting failed or inconclusive runs remain rejected; inspect `reason` and
`outcome` separately.

## Requirements

- Python 3.10 or newer
- OpenSSL available as `openssl` on `PATH`

## Install

```bash
pip install langchain-alex
```

## Verify an Evidence Package

```python
from langchain_alex import AlexEvidenceVerifier

verifier = AlexEvidenceVerifier.from_key_files("alex-public-key.pem")
result = verifier.verify_file("evidence-bundle.json")

print(result.valid, result.reason, result.outcome)
```

The trust anchor is intentionally supplied separately. A public key embedded only in the bundle is
not trusted.

## LangChain tool

```python
tool = verifier.as_tool()
result = tool.invoke({"bundle": evidence_bundle})
```

The tool returns a JSON-serializable object with `valid`, `reason`, `bundle_id`, `schema_version`,
`outcome`, and `claim_ladder`.

## LangGraph node

```python
from typing_extensions import TypedDict
from langgraph.graph import END, START, StateGraph


class State(TypedDict):
    evidence_bundle: dict
    alex_verification: dict


graph = StateGraph(State)
graph.add_node("alex_verify", verifier.as_langgraph_node())
graph.add_edge(START, "alex_verify")
graph.add_edge("alex_verify", END)
app = graph.compile()

result = app.invoke({"evidence_bundle": evidence_bundle})
assert result["alex_verification"]["valid"] is True
```

The node returns a state update and does not mutate its input state. Route on both `valid` and
`outcome` when the graph controls a consequential action.

## Development

```bash
python -m pip install -e ".[dev]"
python -m pytest
ruff check .
python -m build
```

The verifier implementation is also used by the repository's standalone Python CLI at
`tools/verify-bundle/verify.py`; the integration does not maintain a second verdict algorithm.
