Metadata-Version: 2.4
Name: aaes-sdk
Version: 0.1.1
Summary: Python SDK for AAES — the AI governance platform for the action layer: permissions, human approvals, and spending limits on routed agent actions
Author: AAES
License-Expression: LicenseRef-AAES-Proprietary
Project-URL: Homepage, https://aaes.ai/developers/sdks.html
Project-URL: Repository, https://github.com/aaes-ai/aaes
Project-URL: Issues, https://aaes.ai/contact.html
Keywords: aaes,ai-governance,agentic-ai,agent-governance,ai-agents,agent-permissions,human-approval,spending-limits,audit-trail
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Requires-Python: >=3.9
Description-Content-Type: text/markdown

# AAES Python SDK

AAES (Autonomous Agentic Enterprise Systems) is an AI governance platform for the action layer: permissions, approvals by authorized persons, and spending limits on requests routed through it, with a sealed record of each completed decision. This package is its Python client.

Installable distribution `aaes-sdk`, import `aaes`, Python 3.9+, stdlib only (`urllib`). Includes inline annotations and PEP 561 metadata. The source-file import remains supported: `aaes/aaes.py` is self-contained and can still be copied alone. The wheel also ships the LangGraph/CrewAI framework connectors as the `aaes.connectors` subpackage (`aaes_tools`, `langgraph_connect`, `crewai_connect`) — stdlib-only, with crewai/pydantic imported lazily by the caller's own environment.

```bash
python3 -m pip install aaes-sdk
```

The package is publicly available on PyPI. These examples require a running AAES daemon and a token issued by
your deployment operator. Set `AAES_ENDPOINT` and `AAES_TOKEN` first. The request
reads permitted capabilities; it does not execute an agent action.
The customer-run platform evaluation package is included only in the paid design partnership. Installing this SDK does not grant a platform software license or a running deployment.

For local development from a repository checkout:

```bash
python3 -m pip install ./sdk/python
python3 sdk/python/test_aaes.py  # plain assertions; pytest also collects it
```

```python
from aaes import AaesError, Client

try:
    result = Client.from_env().capabilities()
    print(f"{len(result.capabilities)} permitted capabilities")
except AaesError as error:
    raise SystemExit(str(error))
```

Methods: `capabilities`, `catalog`, `health`, `action`, `brokered`,
`resume`, `resume_brokered`, `present_grant`, `request_access`, `access_request`, `observe`, `refresh`,
`federate`, the bounded reads `list_task`, `task`, `list_approvals`,
`approval`, `list_entitlements`, `list_receipts`, `receipt`, the
agent-manager card reads `manager_cards` and `decide_manager_card`, the
person-only `OperatorClient.revoke_access_request`, and
`aaes.verify_hint(export_path, public_key_path)`. Every method above is
covered by this package's tests (`test_aaes.py`, `test_resume.py`, `test_read.py`,
`test_federation.py`).

The tests are a plain `python3` script (functions named `test_*` and a
`main()` runner). Use the documented `python3` command to run the suite without a test framework.

What it deliberately does not do: keyword arguments only, so `url=`,
`method=`, `headers=`, `credential=` and `token=` are `TypeError`s rather
than fields; the payload is checked against the field names the daemon refuses;
tenant and actor come from `GET /v1/capabilities`; receipts are the daemon's
bytes and are verified offline with `aaesctl verify`; a mutating call is
retried only on opt-in, only after a 503, and only under the same effect key.

Public documentation: [SDK guide](https://aaes.ai/developers/sdks.html) and [operation/scope table](https://aaes.ai/developers/sdk-contract.html). Repository recipients can also use [docs/guides/INTEGRATION.md](../../docs/guides/INTEGRATION.md).

A 503 response does not prove that the provider performed no action. Repeat only the identical request with its original effect key; never change the key to force a retry. The daemon retains the reservation and dispatch claim for uncertain outcomes and may answer the repeat with 409. It permits another dispatch only after proving that the previous attempt was never dispatched.

## Published package and expanded contract

See [SDK release policy](../RELEASE.md) and [complete operation/scope table](../CONTRACT.md). Version 0.1.0 is published on PyPI as `aaes-sdk` (import `aaes`), released from the tag `sdk/python/v0.1.0` by the trusted-publisher workflow; check the registry, not this file, for the current version.

Endpoint transport: bearer credentials require HTTPS. HTTP is accepted only
for explicit loopback addresses (`localhost`, `127.0.0.0/8`, or `::1`); DNS
resolution is never used to authorize plaintext transport.
