Recipe 1
Create, verify and sign with an ENTITY identity
from pathlib import Path
import importlib.util, json
ROOT = Path.cwd()
def load_source(path, name):
spec = importlib.util.spec_from_file_location(name, ROOT / path)
mod = importlib.util.module_from_spec(spec); spec.loader.exec_module(mod); return mod
m = load_source("src/01_Core_Runtime/identity/canonical_identity.py", "entity_identity")
STATE = ROOT / ".recipe-state" / "identity"
vault = m.EntityIdentityVault(STATE)
manifest = vault.create(
"Recipe Organization",
"organization",
aliases=["recipe-org"],
)
assert vault.verify_manifest(manifest)
entity_id = manifest["entity_id"]
print(entity_id)
payload = {"action":"demo", "object":"sample"}
signature_record = vault.sign(entity_id, payload)
print(json.dumps(signature_record, indent=2))
rotated = vault.rotate_signing_key(entity_id)
assert vault.verify_manifest(rotated)
assert rotated["manifest_revision"] == 2
print(rotated["active_signing_key_id"])What this proves
You created a persistent ent2- identity with distinct operational and recovery verification methods, verified the signed manifest, produced an ENTITY signature record and rotated the operational key with continuity evidence.
Do not use this disposable state directory for production keys. Production custody, backup and hardware-key policy are deployment concerns.