# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.AttestationOutcome

*class* · *dataclass*

```python
class AttestationOutcome
```

Re-exported from: `ocx_sdk._results`

The attestation outcome of one `push(..., sign=True)` call (C-019).

`push.rs:161`, internally tagged on `status`. A bare `str` (the usual D8
treatment for a scalar enum) would silently drop `predicate_type` and
`signed`, so this carries every field instead, all but `status`
optional: `succeeded` populates `predicate_type`/`signed` and at least
one of `referrer_digest`/`sidecar_digest`; `failed` populates
`kind`/`message`.

**Attributes**

- `status` (`str`) — `"succeeded"` or `"failed"`.
- `referrer_digest` (`str | None`) — The attestation's referrer-API digest, on success.
- `sidecar_digest` (`str | None`) — The attestation's sidecar-tag digest, on success. `--signature-format both` populates both digest fields.
- `predicate_type` (`str | None`) — The resolved predicate type URI, on success.
- `signed` (`bool | None`) — Whether the attestation was itself signed, on success.
- `kind` (`str | None`) — The machine-branchable failure slug, on failure.
- `message` (`str | None`) — Sanitized prose describing the failure, on failure.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1957-L2012)

### ocx_sdk.AttestationOutcome.kind

*attribute* · *class attribute* · *instance attribute*

```python
kind: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1984-L1984)

### ocx_sdk.AttestationOutcome.message

*attribute* · *class attribute* · *instance attribute*

```python
message: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1985-L1985)

### ocx_sdk.AttestationOutcome.predicate_type

*attribute* · *class attribute* · *instance attribute*

```python
predicate_type: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1982-L1982)

### ocx_sdk.AttestationOutcome.referrer_digest

*attribute* · *class attribute* · *instance attribute*

```python
referrer_digest: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1980-L1980)

### ocx_sdk.AttestationOutcome.sidecar_digest

*attribute* · *class attribute* · *instance attribute*

```python
sidecar_digest: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1981-L1981)

### ocx_sdk.AttestationOutcome.signed

*attribute* · *class attribute* · *instance attribute*

```python
signed: bool | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1983-L1983)

### ocx_sdk.AttestationOutcome.status

*attribute* · *instance attribute*

```python
status: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1979-L1979)

### ocx_sdk.AttestationOutcome.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> AttestationOutcome
```

Build from the decoded `PushResult.attestation` object.

`status` selects the variant, and each variant's own fields carry no
`skip_serializing_if` — so they are read with `_need` under the status
that emits them. `signed` matters most: reading it with `.get` failed
open, turning "nothing vouches for this document" into `None`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1987-L2012)
