Skip to content

client.provenance

client.provenance — the provenance operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
limit: int | None = None,
cursor: str | None = None,
run_id: str | None = None,
agent_id: str | None = None,
created_after: str | None = None,
timeout: float | None = None,
) -> ProvenanceCollectionPage

List provenance records. GET /v1/provenance

Cursor-paginated. Metadata rows only — clients fetch the DAG payload via GET /v1/provenance/{runId}. Fixed sort: createdAt desc, id desc. Filters: ?runId=, ?agentId=, ?createdAfter=.

get(*, timeout: float | None = None) -> ProvenanceRecord

Fetch the full provenance DAG for a run. GET /v1/provenance/{runId}

Returns the full DAG (nodes + edges) plus record metadata. 404 when no provenance was emitted for the run (e.g. the deployment does not run the emitter, or the run was pre-provenance).

export(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> ExportProvenanceResult

Export a signed provenance bundle for a run. POST /v1/provenance/{runId}/export

Canonicalizes the record + optional messages as sorted-key JSON and signs with the deployment's Ed25519 key looked up by signingKeyId. Verification is a pure client-side operation: verifyEd25519(publicKey, bundleBytes, signature). Deployments without a signingKey binding mounted return 404 signing-not-configured.