# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.AttestationReport

*class* · *dataclass*

```python
class AttestationReport
```

Re-exported from: `ocx_sdk._results`

`ocx package attest` on a single reference — no tag sweep (C-013).

**Payload is enveloped** (D11): `from_json` unwraps `data`. Flat,
thirteen fields; per D7's field-order rule the seven optionals move to
the end even though upstream interleaves `public_key_hint` earlier.

**Attributes**

- `identifier` (`str`) — The identifier that was attested.
- `platform` (`str`) — The attested platform.
- `subject_digest` (`str`) — The manifest digest the attestation covers.
- `predicate_type` (`str`) — The **resolved** predicate type URI — not the `--type` spelling the caller gave `attest(predicate_type=...)`.
- `signed` (`bool`) — Whether the attestation itself was signed.
- `transparency_log_index` (`int | None`) — The Rekor entry index. Always present in the JSON, but `None` when nothing was logged.
- `bundle_digest` (`str | None`) — Digest of the attestation bundle, when produced.
- `referrer_digest` (`str | None`) — Digest under the OCI referrers API, when attached that way.
- `sidecar_digest` (`str | None`) — Digest of the sidecar tag, when attached that way. `--signature-format both` populates both digest fields.
- `certificate_identity` (`str | None`) — The Fulcio certificate's identity, for keyless signing.
- `certificate_oidc_issuer` (`str | None`) — The Fulcio certificate's OIDC issuer, for keyless signing.
- `key_backend` (`str | None`) — Which key backend produced the signature, carried as raw `str` (D8).
- `public_key_hint` (`str | None`) — A hint identifying the verifying key, when supplied.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1744-L1817)

### ocx_sdk.AttestationReport.bundle_digest

*attribute* · *class attribute* · *instance attribute*

```python
bundle_digest: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1782-L1782)

### ocx_sdk.AttestationReport.platform

*attribute* · *instance attribute*

```python
platform: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1777-L1777)

### ocx_sdk.AttestationReport.predicate_type

*attribute* · *instance attribute*

```python
predicate_type: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1779-L1779)

### ocx_sdk.AttestationReport.public_key_hint

*attribute* · *class attribute* · *instance attribute*

```python
public_key_hint: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1788-L1788)

### ocx_sdk.AttestationReport.referrer_digest

*attribute* · *class attribute* · *instance attribute*

```python
referrer_digest: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1783-L1783)

### ocx_sdk.AttestationReport.sidecar_digest

*attribute* · *class attribute* · *instance attribute*

```python
sidecar_digest: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1784-L1784)

### ocx_sdk.AttestationReport.transparency_log_index

*attribute* · *instance attribute*

```python
transparency_log_index: int | None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1781-L1781)
