Metadata-Version: 2.4
Name: mintid-verifier-sdk
Version: 0.1.0
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Rust
Classifier: Topic :: Security :: Cryptography
Classifier: Topic :: Software Development :: Libraries :: Python Modules
License-File: LICENSE
License-File: NOTICE
Summary: MintID Verifier SDK: presentation verification for the relying party's own verifier, with the pinned Rust proof engine compiled in
Keywords: mintid,identity,verifier,verifiable-credentials,zero-knowledge,openid4vp
Author-email: Marc Molas <marc@mintid.net>
License-Expression: Apache-2.0
Requires-Python: >=3.12
Description-Content-Type: text/markdown; charset=UTF-8; variant=GFM
Project-URL: Documentation, https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/02-python-sdk.md
Project-URL: Homepage, https://mintid.net
Project-URL: Issues, https://gitlab.com/mintid/mintid/-/issues
Project-URL: Repository, https://gitlab.com/mintid/mintid
Project-URL: Security, https://gitlab.com/mintid/mintid/-/blob/main/SECURITY.md
Project-URL: Source, https://gitlab.com/mintid/mintid/-/tree/main/verifier-core

# mintid-verifier-sdk

The MintID Verifier SDK (import name `verifier_core`): the single verifying
core of MintID, for the relying party's own verifier. It validates a holder's
presentation against the challenge it answers, either in your own process
(embedded) or behind a thin HTTP service you deploy yourself next to your
backend (service mode, which the TypeScript client and the MCP server talk
to). The Rust proof engine is compiled in at a pinned version, so a supported
install cannot end up with a substituted engine.

## Where it fits

MintID is a network for verifiable, human-backed identity. Accepted issuers
verify people and issue the credentials; the chain publishes their status
roots, their bonds and the registries; each verifier decides on its own
service. MintID itself issues nothing, certifies nothing and verifies nobody.

The verifier is your own service, and the decision is yours: nothing else
validates a presentation, and pointing a client at somebody else's verifier
service would delegate the decision itself. Installing the SDK does not make
you a verifier: your verifier is registered on the chain, with its exact
origins and its request-signing keys, before any presentation can be
accepted (see
[becoming a verifier](https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/10-becoming-a-verifier.md)).

What the SDK enforces, as constants and closed types rather than settings:
every acceptance condition runs in full and in order on every presentation;
a presentation lives 10 seconds; chain reads are proven or they do not count;
and the only thing kept is a minimal decision record, into which proof bytes,
claim values and personal data do not fit.

## Install

```bash
pip install mintid-verifier-sdk   # Python 3.12 or later, no runtime dependencies
```

Where no wheel matches your platform, pip builds it from the source
distribution, which needs a Rust toolchain. Version 0.1.0, published from the
main repository, https://gitlab.com/mintid/mintid (`verifier-core`).

## Example

```python
from verifier_core.build import build_info
from verifier_core.presentation import validate_presentation

print(build_info())  # the pins of this artifact: engine, conformance suite, …

decision = validate_presentation(
    request,            # PresentationRequest — the signed challenge you issued
    envelope,           # PresentationEnvelope — the holder's response
    chain=chain,        # ChainReader        — proven on-chain reads
    nonces=nonces,      # NonceStore         — durable, exactly-once consumption
    proofs=proofs,      # ProofVerifier      — the anonymous-proof engine port
    decisions=log,      # DecisionLog        — the minimal decision sink
    now_unix=now,       # int                — your disciplined clock
)
decision.accepted      # bool
decision.reason_code   # closed vocabulary; a rejection is a decision, not an exception
```

You supply infrastructure (chain access, a nonce store, a decision log, a
clock), never policy.

## Status

The engine is built and in production. An independent audit of its
implementation is scheduled as a milestone; its findings will be published,
and it gates nothing.

## Where to test

On the public testnet and its KYC sandbox, and only there: check the status
line of [its page](https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/17-sandbox-and-testnet.md)
first. Nothing issued on it carries weight. The single-node production chain
is not for third parties and is never a place to test; the local stack of the
main repository runs the same flows on your machine.

## Links

- Documentation: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/02-python-sdk.md
  (service mode: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/03-service-mode.md)
- Source: https://gitlab.com/mintid/mintid (`verifier-core`), where issues and
  merge requests go
- Public testnet: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/17-sandbox-and-testnet.md
- Security: report a vulnerability privately to security@mintid.net, never in
  a public issue; policy: https://gitlab.com/mintid/mintid/-/blob/main/SECURITY.md
- Website: https://mintid.net

## Licence

Apache License 2.0. Author: Marc Molas.

