You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 0a66175
Browse filesBrowse the repository at this point in the historyBrowse files
## Summary
`GET /v1/reputation` was retired on 2026-09-30 along with the
transaction pipeline, and the API now answers 404 on it. This removes
`get_reputation()` / `aget_reputation()` and the types only they
returned, and releases 2.7.0.
- `get_reputation()` and `aget_reputation()` are removed.
- The reputation response types are removed from `agentscore.types` and
the package exports: `ReputationResponse`, `Reputation`, `Score`,
`ChainScore`, `ChainEntry`, `Classification`, `RedactedClassification`,
`Subject`, `Identity`, `Activity`, `EvidenceSummary`, `OperatorScore`,
`AgentSummary`, `Grade`, `EntityType`, `ReputationStatus`.
`AssessResponse` is unchanged.
- The `create_session` docstrings no longer call it "an assessment
session for deferred scoring".
- README, `.claude/CLAUDE.md` and the package keywords no longer
describe a reputation lookup.
- Dependencies: ruff 0.16.10, python-dotenv 1.2.4, lefthook 2.1.16.
Workflows move to uv 0.12.22.
Versioned as a minor on purpose: the method has returned 404 since the
endpoint was retired, so no working call changes behavior. Code that
still references it raises `AttributeError` after upgrading.
## Type of change
- [ ] Bug fix (no breaking change)
- [ ] New feature (no breaking change)
- [x] Breaking change (existing callers must update)
- [ ] Docs, tests, or internal maintenance only
## Public API
`AgentScore.get_reputation()`, `AgentScore.aget_reputation()` and the
reputation types listed above are removed. Migration: drop the call. The
endpoint behind it no longer exists, so there is no replacement;
`assess()` / `aassess()` remain the identity and compliance check.
## Test plan
- The generic request tests (error mapping, context managers,
concurrency, retries) used `get_reputation` as their vehicle and now run
through `list_credentials()` / `alist_credentials()`, so that coverage
is kept.
- The assess and session-poll fixtures now carry the shapes the API
returns, not score and chain bodies. A policy test that sent a
nonexistent `min_score` key now sends `require_kyc`.
- A new test pins that both methods are absent from the client.
- `uv run pytest` (177 passed, 2 integration skipped without
credentials, 99.8% coverage), `ruff check`, `ruff format --check`, `ty
check` and `vulture` all pass locally. The OSV scan of `uv.lock` is
clean.
Worked with Varun.
## Checklist
- [x] Tests cover the new behavior, and the suite passes locally
- [x] Lint, format, and type checks pass
- [x] Docs and README examples updated if the public surface changed
- [x] No secrets, credentials, or personal data in the diff or the tests
- `assess` / `aassess` — identity gate with policy (paid). Accepts `operator_token` for non-wallet agents. Response includes `linked_wallets[]` and `resolved_operator`. Optional `signer: { address, network }` opts into server-side wallet-signer-match AND OFAC SDN wallet-address screening — the response then carries both a `signer_match` block (wallet-binding verdict: `pass` / `wallet_signer_mismatch` / `wallet_auth_requires_wallet_signing`) and a `signer_sanctions` block (discriminated union: `{status: "clear"}` | `{sanctioned: True, ofac_label, sdn_uid, listed_at}` | `{status: "unavailable"}`). Wallet-OFAC SDN enforcement on the `signer` block is unconditional whenever a signer is supplied — no `policy.require_sanctions_clear` opt-in required. A `sanctioned: True` OR `status: "unavailable"` verdict flips the response `decision` to `deny` with `decision_reasons` including `sanctions_flagged` or `sanctions_check_unavailable` respectively (fail-closed; OFAC strict-liability). `policy.require_sanctions_clear` is the separate NAME-based screen on the resolved operator's KYC identity.
@@ -75,7 +67,7 @@ client.create_session(kind="sign_in") # registration-only: account sign-in, no
75
67
76
68
### Wallet resolution
77
69
78
-
`assess()` responses include `resolved_operator` and `linked_wallets`, all same-operator sibling wallets (claimed via SIWE or captured via prior `associate_wallet`). The list may mix EVM addresses (`0x...` lowercased) and Solana addresses (base58, case-preserved) for cross-chain operators; merchants doing wallet-signer-match checks should accept a payment signed by any address in the list, regardless of chain. The `address` parameter on `assess()`and `get_reputation()`accepts either format; the network is auto-detected from the address shape.
70
+
`assess()` responses include `resolved_operator` and `linked_wallets`, all same-operator sibling wallets (claimed via SIWE or captured via prior `associate_wallet`). The list may mix EVM addresses (`0x...` lowercased) and Solana addresses (base58, case-preserved) for cross-chain operators; merchants doing wallet-signer-match checks should accept a payment signed by any address in the list, regardless of chain. The `address` parameter on `assess()` accepts either format; the network is auto-detected from the address shape.
0 commit comments