Quickstart

Get Writ in front of your first write in five minutes.

Have an existing codebase? Skip the manual steps: run ./writ scan ./your-repo to find every write, map it to a verb, and generate the instrumentation diff. See Scanner.

1. Install the CLI

pip install pywrit
writ key --email you@company.com

This prints your sponsor token once. Save it.

2. Wrap your first endpoint

Add one line of middleware in front of the write:

from writ import check
@app.post("/refunds")
def refund(order_id: str):
decision = check(verb="payments.refund", principal="api")
if decision != "ALLOW":
raise HTTPException(403, "Denied by Writ")
# ... your refund logic

3. See the decision

./writ check --verb payments.refund --principal api
# ALLOW tenant=acme receipt=wr_8f3a2b1c chain=verified

Every decision writes a receipt to your tamper-evident audit log.

4. Kill a token

./writ revoke --principal api
# REVOKED 3 tokens killed receipt=wr_9e4c7d2a

One click. No key rotation, no redeploy.

5. Verify the chain

./writ verify-chain
# ✓ 1,247 receipts verified, chain intact

For AI agents

Give this prompt to your coding agent to instrument your codebase:

Instrument this repository with Writ. For every function that writes
to a system of record (database, API, file, queue), wrap it with a
writ check call before the write. Use verb names like
<domain>.<action> (e.g. payments.refund, users.delete).
The pattern is:
decision = writ_check(verb="...", principal="...")
if decision != "ALLOW": deny the write
Do not modify the write logic itself, only add the gate in front.

Next steps