Metadata-Version: 2.4
Name: mintid-proof-core
Version: 0.3.0
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Rust
Classifier: Topic :: Security :: Cryptography
Classifier: Topic :: Software Development :: Libraries :: Python Modules
License-File: LICENSE
License-File: NOTICE
Summary: MintID proof core for Python: the headless holder library and the issuance side of the anonymous-credential core, with the Rust core compiled in
Keywords: mintid,identity,anonymous-credentials,zero-knowledge,selective-disclosure,revocation
Author-email: Marc Molas <marc@mintid.net>
License-Expression: Apache-2.0
Requires-Python: >=3.12
Description-Content-Type: text/markdown; charset=UTF-8; variant=GFM
Project-URL: Documentation, https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/08-credentials-and-holders.md
Project-URL: Homepage, https://mintid.net
Project-URL: Issues, https://gitlab.com/mintid/mintid/-/issues
Project-URL: Repository, https://gitlab.com/mintid/mintid
Project-URL: Security, https://gitlab.com/mintid/mintid/-/blob/main/SECURITY.md
Project-URL: Source, https://gitlab.com/mintid/mintid/-/tree/main/identity-proof-core

# mintid-proof-core

Python bindings of the MintID proof core: the anonymous-credential core,
written in Rust and compiled into this package, with the headless **holder
library** (`proof_core.holder`) and the issuance side that an issuer service
uses. A holder obtains a credential blind (the issuer never sees it in the
clear), keeps its witnesses current, and answers a verifier's challenge with
a zero-knowledge presentation that proves predicates such as "over 18",
"grade at least A3" or "still active", and nothing else. The holder can also
revoke its own credential without revealing which one it is (holder
self-revocation, the holder's kill switch).

## Where it fits

MintID is a network for verifiable, human-backed identity. Accepted issuers
verify people and issue the credentials; the chain publishes their status
roots, their bonds and the registries; each verifier decides on its own
service. MintID itself issues nothing, certifies nothing and verifies nobody.

The holder library is headless: it runs in the holder's own
infrastructure, next to the keys the holder already custodies. The Python agent
client (`mintid-agent`) builds on it. Verification is not in this package:
it is in the verifier SDK (`mintid-verifier-sdk`), on the relying party's own
service.

## Install

```bash
pip install mintid-proof-core   # Python 3.12 or later
```

The Rust core is compiled in; where no wheel matches your platform, pip
builds it from the source distribution, which needs a Rust toolchain.
Version 0.3.0, published from the main repository,
https://gitlab.com/mintid/mintid (`identity-proof-core/python`).

## Example

```python
import proof_core
from proof_core.holder import Holder

print(proof_core.core_version())       # the Rust core compiled into this package

holder = Holder.issue(offer)           # the holder half of issuance, from the operator's credential offer
holder.refresh_witness()               # right before presenting; material that does not verify is refused
envelope = holder.present(challenge)   # one bound, 10-second presentation, or nothing is sent
custody = holder.storage_bytes()       # holds the link secret: encrypt it under your own key
```

There is no export: the custody encoding is the only serialisation, and a
lost key is recoverable by nobody (you verify again and get a fresh
credential, unlinkable to the old one).

## Status

Built and in production on the single-node production chain. An independent
audit of the implementation is scheduled as a milestone; its findings will be
published, and it gates nothing.

## Where to test

On the public testnet and its KYC sandbox, and only there: check the status
line of [its page](https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/17-sandbox-and-testnet.md)
first. Nothing issued on it carries weight. The single-node production chain
is not for third parties and is never a place to test.

## Links

- Documentation: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/08-credentials-and-holders.md
- Source: https://gitlab.com/mintid/mintid (`identity-proof-core`), where
  issues and merge requests go
- Public testnet: https://gitlab.com/mintid/mintid/-/blob/main/docs/sdk/17-sandbox-and-testnet.md
- Security: report a vulnerability privately to security@mintid.net, never in
  a public issue; policy: https://gitlab.com/mintid/mintid/-/blob/main/SECURITY.md
- Website: https://mintid.net

## Licence

Apache License 2.0. Author: Marc Molas.

