> ## Documentation Index
> Fetch the complete documentation index at: https://praison.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Resolve Ingress Attribution • AI Agent SDK

> resolve_ingress_attribution: Resolve the real client attribution for an inbound request.

# resolve\_ingress\_attribution

<div className="flex items-center gap-2">
  <Badge color="teal">Function</Badge>
</div>

> This function is defined in the [**protocols**](../modules/protocols) module.

Resolve the real client attribution for an inbound request.

Pure and side-effect-free so it is unit-testable in isolation and every
seam (rate limiters, connection budget, operator id) consults the same
decision.

## Signature

```python theme={"theme":{"light":"vitesse-light","dark":"vitesse-dark"}}
def resolve_ingress_attribution() -> IngressAttribution
```

### Returns

<ResponseField name="Returns" type="IngressAttribution">
  class:`IngressAttribution`. The real client IP is resolved *only*
  across hops in `trusted_proxies`; anything proxy-shaped but
  unattributable fails closed to the socket peer.

  Resolution rules:

  * No proxy headers → `direct-local` (loopback peer) or
    `direct-remote`; `client_ip` is the peer, never fail-closed.
  * Proxy headers present but the socket peer is not a trusted hop →
    `unattributable-proxy`, `fail_closed=True`, `client_ip` = peer
    (a spoofable header is never trusted on a directly-reachable
    gateway).
  * Socket peer is a trusted hop → walk the forwarded chain right→left,
    peeling trusted hops, and stop at the first untrusted address: that
    address is the real client. If the chain is empty, fall back to
    `real_ip` then the peer. The resolved client must be a literal IP —
    a malformed/non-IP hop fails closed to the peer. A loopback trusted
    hop is classified `tunnel`; otherwise `trusted-proxy`.
</ResponseField>

## Uses

* `is_loopback`
* `IngressAttribution`

## Source

<Card title="View on GitHub" icon="github" href="https://github.com/MervinPraison/PraisonAI/blob/main/src/praisonai-agents/praisonaiagents/gateway/protocols.py#L2680">
  `praisonaiagents/gateway/protocols.py` at line 2680
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.