Metadata-Version: 2.4
Name: aaes-sdk
Version: 0.1.0
Summary: Scoped, dependency-free AAES daemon client
Author: AAES
License-Expression: LicenseRef-AAES-Proprietary
Project-URL: Homepage, https://github.com/aaes-ai/aaes/tree/main/sdk/python
Project-URL: Repository, https://github.com/aaes-ai/aaes
Project-URL: Issues, https://github.com/aaes-ai/aaes/issues
Keywords: aaes,agent-governance,ai-agents
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Requires-Python: >=3.9
Description-Content-Type: text/markdown

# AAES Python SDK

Installable distribution `aaes-sdk`, import `aaes`, Python 3.9+, stdlib only (`urllib`). Includes inline annotations and PEP 561 metadata. The source-file import remains supported: `aaes/aaes.py` is self-contained and can still be copied alone. The wheel also ships the LangGraph/CrewAI framework connectors as the `aaes.connectors` subpackage (`aaes_tools`, `langgraph_connect`, `crewai_connect`) — stdlib-only, with crewai/pydantic imported lazily by the caller's own environment.

```bash
python3 -m pip install ./sdk/python  # build/install local candidate
python3 sdk/python/test_aaes.py  # plain assertions; pytest also collects it
```

These examples require SDK access, a running AAES daemon, and a token issued by
your deployment operator. Set `AAES_ENDPOINT` and `AAES_TOKEN` first. The request
reads permitted capabilities; it does not execute an agent action.

```python
from aaes import AaesError, Client

try:
    result = Client.from_env().capabilities()
    print(f"{len(result.capabilities)} permitted capabilities")
except AaesError as error:
    raise SystemExit(str(error))
```

Methods: `capabilities`, `catalogue`, `health`, `action`, `brokered`,
`resume`, `resume_brokered`, `present_grant`, `request_access`, `access_request`, `observe`, `refresh`,
`federate`, the bounded reads `list_task`, `task`, `list_approvals`,
`approval`, `list_entitlements`, `list_receipts`, `receipt`, the
agent-manager card reads `manager_cards` and `decide_manager_card`, the
person-only `OperatorClient.revoke_access_request`, and
`aaes.verify_hint(export_path, public_key_path)`. Every method above is
covered by this package's tests (`test_aaes.py`, `test_resume.py`, `test_read.py`,
`test_federation.py`).

The tests are a plain `python3` script (functions named `test_*` and a
`main()` runner). Use the documented `python3` command to run the suite without a test framework.

What it deliberately does not do: keyword arguments only, so `url=`,
`method=`, `headers=`, `credential=` and `token=` are `TypeError`s rather
than fields; the payload is checked against the field names the daemon refuses;
tenant and actor come from `GET /v1/capabilities`; receipts are the daemon's
bytes and are verified offline with `aaesctl verify`; a mutating call is
retried only on opt-in, only after a 503, and only under the same effect key.

Full guide: [docs/guides/INTEGRATION.md](../../docs/guides/INTEGRATION.md).

A 503 response does not prove that the provider performed no action. Repeat only the identical request with its original effect key; never change the key to force a retry. The daemon retains the reservation and dispatch claim for uncertain outcomes and may answer the repeat with 409. It permits another dispatch only after proving that the previous attempt was never dispatched.

## Candidate package and expanded contract

See [SDK release policy](../RELEASE.md) and [complete operation/scope table](../CONTRACT.md). Version 0.1.0 is a local candidate; no registry publication is claimed.
