@assemblyline-agents/provenance
v10.4.0
Published
Official Assembly Line connection plugin for user-scoped Provenance ledgers.
Maintainers
Readme
@assemblyline-agents/provenance
Official Assembly Line connection plugin for Provenance. It lets each authenticated agent user explicitly connect their append-only evidence ledger for reconstruction, audit, and handoff workflows.
Register the Assembly Line OAuth Client
Register one public client with the exact Assembly Line callback URI:
curl https://provenance.artificialillumination.co/api/oauth/clients \
-H "Authorization: Bearer $PROVENANCE_SHARED_SECRET" \
-H "Content-Type: application/json" \
--data '{
"clientId": "my-assembly-line-agent",
"clientName": "My Assembly Line Agent",
"redirectUris": [
"https://YOUR-AGENT-HOST/assembly-line/connections/callback"
]
}'The shared secret is used only by the Provenance operator for registration. It must never be placed in the Assembly Line deployment. Configure the agent with:
PROVENANCE_OAUTH_CLIENT_ID=my-assembly-line-agentOptional identity overrides are PROVENANCE_AGENT_ID,
PROVENANCE_AGENT_NAME, and PROVENANCE_AGENT_RUNTIME. The agent id defaults
to the client id and the runtime defaults to assembly-line.
Self-hosted Provenance deployments can set PROVENANCE_MCP_URL and, when
OAuth is on a different origin, PROVENANCE_OAUTH_ISSUER.
PROVENANCE_OAUTH_REDIRECT_URI overrides Assembly Line's normal callback only when
necessary.
assembly-line add provenance agentThe selected plugin enables every reviewed Provenance tool. Gate its one write-classified action explicitly:
capabilities:
provenance:
connections:
provenance:
approval:
provenance.register_agent: alwaysOAuth uses Authorization Code + PKCE S256 and Provenance's
provenance:ledger scope. The resulting plt_ token is hard-scoped to the
signed-in Provenance user and supplied agent identity, then stored in
Assembly Line's host-side connection grant store.
provenance.register_agent is the only write-classified MCP tool and changes
agent metadata only. OAuth already registers or reactivates the bound agent;
add it to plugins.provenance.connections.provenance.disable when it is not
needed.
Capture Is Separate
This connection exposes reconstruction tools; it does not capture Assembly Line events by itself. Provenance capture must remain ambient through a configured transcript watcher or a native asynchronous adapter. Never ask the model to manually log routine activity.
