# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.AttestationReport

*class* · *dataclass*

```python
class AttestationReport
```

Re-exported from: `ocx_sdk._results`

`ocx package attest` on a single reference — no tag sweep (C-013).

**Payload is enveloped** (D11): `from_json` unwraps `data`. Flat,
thirteen fields; per D7's field-order rule the seven optionals move to
the end even though upstream interleaves `public_key_hint` earlier.

**Attributes**

- `identifier` (`str`) — The identifier that was attested.
- `platform` (`str`) — The attested platform.
- `subject_digest` (`str`) — The manifest digest the attestation covers.
- `predicate_type` (`str`) — The **resolved** predicate type URI — not the `--type` spelling the caller gave `attest(predicate_type=...)`.
- `signed` (`bool`) — Whether the attestation itself was signed.
- `transparency_log_index` (`int | None`) — The Rekor entry index. Always present in the JSON, but `None` when nothing was logged.
- `bundle_digest` (`str | None`) — Digest of the attestation bundle, when produced.
- `referrer_digest` (`str | None`) — Digest under the OCI referrers API, when attached that way.
- `sidecar_digest` (`str | None`) — Digest of the sidecar tag, when attached that way. `--signature-format both` populates both digest fields.
- `certificate_identity` (`str | None`) — The Fulcio certificate's identity, for keyless signing.
- `certificate_oidc_issuer` (`str | None`) — The Fulcio certificate's OIDC issuer, for keyless signing.
- `key_backend` (`str | None`) — Which key backend produced the signature, carried as raw `str` (D8).
- `public_key_hint` (`str | None`) — A hint identifying the verifying key, when supplied.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1744-L1817)

### ocx_sdk.AttestationReport.certificate_identity

*attribute* · *class attribute* · *instance attribute*

```python
certificate_identity: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1785-L1785)

### ocx_sdk.AttestationReport.certificate_oidc_issuer

*attribute* · *class attribute* · *instance attribute*

```python
certificate_oidc_issuer: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1786-L1786)

### ocx_sdk.AttestationReport.identifier

*attribute* · *instance attribute*

```python
identifier: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1776-L1776)

### ocx_sdk.AttestationReport.key_backend

*attribute* · *class attribute* · *instance attribute*

```python
key_backend: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1787-L1787)

### ocx_sdk.AttestationReport.signed

*attribute* · *instance attribute*

```python
signed: bool
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1780-L1780)

### ocx_sdk.AttestationReport.subject_digest

*attribute* · *instance attribute*

```python
subject_digest: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1778-L1778)

### ocx_sdk.AttestationReport.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> AttestationReport
```

Build from a decoded attest report.

Used both for the envelope's `data` (a bare `attest`) and, through
C-017's row-parser seam, for one `SweptTagReport.report` row of a
swept `attest`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1790-L1812)

### ocx_sdk.AttestationReport.from_json

*method* · *classmethod*

```python
def from_json(raw: str) -> AttestationReport
```

Parse `ocx --format json package attest` output (no tag sweep).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1814-L1817)
