Rank
65
LangChain/LangGraph tools for AI agent x402 payments on X1
Traction
No public download signal
Freshness
Updated 4mo ago
Crawler Summary
Python SDK for AI agent governance - audit trails, policy enforcement, quantum-safe signatures. Works with LangChain, CrewAI, MCP. <p align="center"> <a href="https://asqav.com"> <img src="https://asqav.com/logo-text-white.png" alt="Asqav" width="200"> </a> </p> <p align="center"> The evidence layer for AI agents. Audit trails, approvals, policy gates, and compliance reports for every action. </p> <p align="center"> <a href="https://pypi.org/project/asqav/"><img src="https://img.shields.io/pypi/v/asqav?style=flat-square&logo=pypi&logoColor=white Capability contract not published. No trust telemetry is available yet. 161 GitHub stars reported by the source. Last updated 5/31/2026.
Freshness
Last checked 5/31/2026
Best For
asqav-sdk is best for crewai, multi-agent workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack
Python SDK for AI agent governance - audit trails, policy enforcement, quantum-safe signatures. Works with LangChain, CrewAI, MCP. <p align="center"> <a href="https://asqav.com"> <img src="https://asqav.com/logo-text-white.png" alt="Asqav" width="200"> </a> </p> <p align="center"> The evidence layer for AI agents. Audit trails, approvals, policy gates, and compliance reports for every action. </p> <p align="center"> <a href="https://pypi.org/project/asqav/"><img src="https://img.shields.io/pypi/v/asqav?style=flat-square&logo=pypi&logoColor=white
Public facts
4
Change events
0
Artifacts
0
Freshness
May 31, 2026
Capability contract not published. No trust telemetry is available yet. 161 GitHub stars reported by the source. Last updated 5/31/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
May 31, 2026
Vendor
Jagmarques
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. 161 GitHub stars reported by the source. Last updated 5/31/2026.
Setup snapshot
git clone https://github.com/jagmarques/asqav-sdk.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Jagmarques
Protocol compatibility
OpenClaw
Adoption signal
161 GitHub stars
Handshake status
UNKNOWN
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
python
bash
pip install asqav
bash
npm install @asqav/sdk
python
import asqav
asqav.init(api_key="sk_...")
agent = asqav.Agent.create("my-agent")
sig = agent.sign("api:call", {"model": "gpt-4"})
print(sig.signature_id, sig.verify_url)ts
import { init, Agent } from "@asqav/sdk";
init({ apiKey: "sk_..." });
const agent = await Agent.create({ name: "my-agent" });
const sig = await agent.sign({
actionType: "api:call",
context: { model: "gpt-4" },
});
console.log(sig.signatureId, sig.verificationUrl);json
{
"signature_id": "sig_a1b2c3",
"agent_id": "agt_x7y8z9",
"action": "api:call",
"algorithm": "ML-DSA-65",
"timestamp": "2026-04-27T18:30:00Z",
"chain_hash": "b94d27b9934d3e08...",
"verify_url": "https://asqav.com/verify/sig_a1b2c3"
}python
# Python asqav.init(api_key="...", base_url="https://api.asqav.com", mode="hash-only")
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB OPENCLEW
Editorial quality
ready
Python SDK for AI agent governance - audit trails, policy enforcement, quantum-safe signatures. Works with LangChain, CrewAI, MCP. <p align="center"> <a href="https://asqav.com"> <img src="https://asqav.com/logo-text-white.png" alt="Asqav" width="200"> </a> </p> <p align="center"> The evidence layer for AI agents. Audit trails, approvals, policy gates, and compliance reports for every action. </p> <p align="center"> <a href="https://pypi.org/project/asqav/"><img src="https://img.shields.io/pypi/v/asqav?style=flat-square&logo=pypi&logoColor=white
The official client SDKs for Asqav, the evidence layer for AI agents. Sign every action with ML-DSA-65 (FIPS 204), enforce policies before execution, and produce regulator-ready audit trails.
This repository ships two SDKs from a single monorepo:
python/ - the original Python SDK, published to PyPI as asqavtypescript/ - the TypeScript SDK, published to npm as @asqav/sdkBoth wrap the same Asqav API. Pick the one that matches your stack.
Python:
pip install asqav
TypeScript / Node.js:
npm install @asqav/sdk
Both packages have zero native dependencies. All ML-DSA cryptography runs server-side.
Python:
import asqav
asqav.init(api_key="sk_...")
agent = asqav.Agent.create("my-agent")
sig = agent.sign("api:call", {"model": "gpt-4"})
print(sig.signature_id, sig.verify_url)
TypeScript:
import { init, Agent } from "@asqav/sdk";
init({ apiKey: "sk_..." });
const agent = await Agent.create({ name: "my-agent" });
const sig = await agent.sign({
actionType: "api:call",
context: { model: "gpt-4" },
});
console.log(sig.signatureId, sig.verificationUrl);
Each signed action returns a receipt like:
{
"signature_id": "sig_a1b2c3",
"agent_id": "agt_x7y8z9",
"action": "api:call",
"algorithm": "ML-DSA-65",
"timestamp": "2026-04-27T18:30:00Z",
"chain_hash": "b94d27b9934d3e08...",
"verify_url": "https://asqav.com/verify/sig_a1b2c3"
}
The agent now has a cryptographic identity, a signed audit trail, and a verifiable action record.
The SDK auto-detects whether you're pointing at the Asqav cloud or a self-hosted deployment, and selects the safer default for each:
*.asqav.com): hash-only by default. The SDK builds a fingerprint of your action context, computes a SHA-256 hash locally, and sends only the hash plus a small metadata bag (action_type, agent_id, session_id, model_name, tool_name). Raw prompts and tool arguments stay on your side.Override anytime:
# Python
asqav.init(api_key="...", base_url="https://api.asqav.com", mode="hash-only")
// TypeScript
await init({ apiKey: "...", baseUrl: "https://api.asqav.com", mode: "hash-only" });
The fingerprint format is RFC 8785-style sorted JSON with no whitespace, hashed with SHA-256. See docs/fingerprint-spec.md and conformance/vectors.json for the spec and cross-language test vectors.
For self-hosted and split-trust deployments, bring-your-own KMS, SCITT and COSE receipt export, and air-gapped mode, see asqav.com/docs.
Asqav's compliance receipts are profiled in IETF Internet-Draft draft-marques-asqav-compliance-receipts, an Independent Submission that profiles draft-farley-acta-signed-receipts for EU AI Act Articles 12 and 26, and DORA Article 17 bindings.
| Without governance | With Asqav | |---|---| | No record of what agents did | Every action signed with ML-DSA (FIPS 204) | | Any agent can do anything | Policies block dangerous actions in real-time | | One person approves everything | Multi-party authorization for critical actions | | Manual compliance reports | Automated EU AI Act and DORA reports | | Reasoning lost after the run | Prompt, trace, and output signed and replayable |
The root README only covers the cross-language story. For language-specific guides - decorators, async clients, framework integrations, CLI commands, local mode, batched signing, three-phase signing, scope tokens, replay, attestations, and more - see:
python/README.mdtypescript/README.mdThe full reference lives at asqav.com/docs.
Both SDKs cover the same core surface: agent identity, signed actions, batched signing, policy enforcement, scope tokens, replay, attestations, three-phase signing, and the user_intent envelope on agent.sign(...) (Ed25519 / ECDSA P-256 / WebAuthn).
The Python SDK additionally ships:
asqav CLI: quickstart, demo, verify, doctor, agents, sync, plus replay, preflight, approve, budget (check/record), and compliance (frameworks/export). See asqav.com/docs/cli.pytest --asqav) that signs every test result and emits a Merkle-rooted compliance bundle on session finish. See asqav.com/docs/pytest-plugin.python/examples/.The TypeScript SDK focuses on the core API and Agent surface for Node 20+ runtimes. It additionally ships:
user_intent envelope on agent.sign(...).@asqav/sdk/extras/vercel-ai that plugs into experimental_telemetry: { tracer } and signs every span the AI SDK opens.AsqavCallbackHandler at @asqav/sdk/extras/langchain that signs each chain step.AsqavMastraHook at @asqav/sdk/extras/mastra that signs each step the Mastra agent emits.AsqavOpenAIAgentsAdapter at @asqav/sdk/extras/openai-agents that signs tool calls on the agent runner.If a feature exists in one SDK but not the other, the language README will mark it explicitly.
asqav-sdk/
python/ Python SDK (pip install asqav)
src/
tests/
pyproject.toml
README.md
typescript/ TypeScript SDK (npm install @asqav/sdk)
src/
tests/
package.json
README.md
conformance/ Cross-language conformance fixtures both SDKs run against
.github/workflows/
ci.yml Path-filtered CI for both languages
publish.yml Tag-based publish (py-v* to PyPI, ts-v* to npm)
CHANGELOG.md
README.md (this file)
The two SDKs are versioned and released independently.
Receipts are portable. Anyone with a signature_id can verify it without an API key:
Python:
import asqav
result = asqav.verify("sig_a1b2c3")
assert result["verified"]
print(result["agent_id"], result["chain_hash"])
TypeScript:
import { verify } from "@asqav/sdk";
const result = await verify("sig_a1b2c3");
console.assert(result.verified);
console.log(result.agentId, result.chainHash);
Or open the receipt's verify_url in a browser. Hashes are reproducible offline from the RFC 8785 (the JSON format spec) payload, so auditors do not need to trust Asqav's servers - the signature speaks for itself.
When two agents hand off a workflow (A signs an action, B acts on it), the SDK lets B emit a protectmcp:acknowledgment receipt that cryptographically binds B's bytes to A's. The bundle carries A's full envelope, B's acknowledgment, and a SHA-256 binding the verifier recomputes offline. A tampered intermediary cannot mutate the bytes without breaking the equality, so a regulator can verify the handoff with one digest comparison.
Python:
from asqav import compute_counterparty_binding, verify_counterparty_binding
binding = compute_counterparty_binding(originating_envelope)
b_payload["counterparty_binding"] = binding.to_wire()
# ... B signs b_payload normally ...
outcome = verify_counterparty_binding(b_envelope, originating_envelope)
assert outcome.valid, outcome.label
TypeScript:
import { computeCounterpartyBinding, verifyCounterpartyBinding } from "@asqav/sdk";
const binding = computeCounterpartyBinding(originatingEnvelope);
bPayload.counterparty_binding = binding;
// ... B signs bPayload normally ...
const outcome = verifyCounterpartyBinding(bEnvelope, originatingEnvelope);
if (!outcome.valid) throw new Error(outcome.label);
The cloud /verify endpoint reports the same outcome on the verification response under counterparty_binding_verified, and /audit-pack/export pulls the originating receipt into the bundle automatically when an acknowledgment in the export window references one outside it.
The conformance/ directory contains shared test fixtures both SDKs run against. Adding a feature means adding a fixture there first, then making both SDKs pass it. CI reruns both matrices whenever conformance/ changes, even if neither python/ nor typescript/ was touched, so cross-language drift is caught at PR time.
CI runs on every push to main and every pull request. It tests only the language whose source changed: pytest on Python 3.10, 3.11, and 3.12, and npm test on Node 20 and 22. A change to conformance/ runs both. The aggregator job ci-ok is the single required status check for branch protection.
asqav doctor validates configuration and connectivity in any environment with ASQAV_API_KEY set, returning non-zero on failure so it gates PRs cleanly. Pair it with asqav.compliance.export_bundle to package signed receipts from your test runs into a self-contained, Merkle-rooted artifact for auditors. See docs/github-actions.md for a copy-paste workflow.
See CONTRIBUTING.md for the full contributor guide. The short version:
cd python && pip install -e ".[all]" pytest && pytest tests -vcd typescript && npm ci && npm testmain. CI must go green for the PR to land.Direct pushes to main are blocked. Every change lands through a PR.
Both SDKs ship to different registries on independent cadences, driven by prefixed git tags: py-v* publishes the Python half to PyPI, ts-v* publishes the TypeScript half to npm. Bump the version in the relevant manifest, update CHANGELOG.md, then tag and push. The publish.yml workflow inspects the tag prefix and runs only the matching publish job. Python uses PyPI's OIDC trusted publisher; TypeScript publishes via the NPM_TOKEN repo secret.
| Package | What it does |
|---|---|
| asqav (PyPI) | Python SDK |
| @asqav/sdk (npm) | TypeScript SDK |
| asqav-mcp | MCP server for Claude Desktop, Claude Code, Cursor |
| asqav-compliance | CI/CD compliance scanner |
Get started at no cost. Free includes 50K signatures/month, 20 agents, 10 policies, 3 team members, OpenTimestamps, MCP server, audit export, and framework integrations. Content scanning, OpenTelemetry, and Replay API on Pro. Quarantine, incident management, multi-party signing, compliance reports, and RFC 3161 timestamps on Business. Managed KMS, SSO, IP allowlist, and bring-your-own KMS on Enterprise. See asqav.com/pricing for the full breakdown.
Machine-readable service descriptor at https://asqav.com/.well-known/governance.json for external tools that want to auto-discover Asqav's endpoints, algorithms, capabilities, and integrations.
MIT - see LICENSE for details.
If Asqav helps you, consider giving the repo a star. It helps others find the project.
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Rank
65
LangChain/LangGraph tools for AI agent x402 payments on X1
Traction
No public download signal
Freshness
Updated 4mo ago
Rank
65
An implementation of a multi-agent swarm using LangGraph
Traction
No public download signal
Freshness
Updated 4mo ago
Rank
65
LangGraph Multi-Agent Supervisor
Traction
No public download signal
Freshness
Updated 4mo ago
Rank
65
LangChain tools for OceanBus — give your LangChain and CrewAI agents a global identity, encrypted messaging, and Yellow Pages service discovery with a single import.
Traction
No public download signal
Freshness
Updated 4mo ago
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-10-08T22:20:24.799Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "crewai",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "multi-agent",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}Facts JSON
[
{
"factKey": "vendor",
"label": "Vendor",
"value": "Jagmarques",
"category": "vendor",
"href": "https://github.com/jagmarques/asqav-sdk",
"sourceUrl": "https://github.com/jagmarques/asqav-sdk",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-31T06:17:57.907Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "protocols",
"label": "Protocol compatibility",
"value": "OpenClaw",
"category": "compatibility",
"href": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-05-31T06:17:57.907Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "traction",
"label": "Adoption signal",
"value": "161 GitHub stars",
"category": "adoption",
"href": "https://github.com/jagmarques/asqav-sdk",
"sourceUrl": "https://github.com/jagmarques/asqav-sdk",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-31T06:17:57.907Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "handshake_status",
"label": "Handshake status",
"value": "UNKNOWN",
"category": "security",
"href": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-jagmarques-asqav-sdk/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true,
"metadata": {}
}
]Change Events JSON
[]
Sponsored
Ads related to asqav-sdk and adjacent AI workflows.