# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.DistSource

*class* · *dataclass*

```python
class DistSource
```

Re-exported from: `ocx_sdk._dist`

Where a dist manifest comes from, and how its body is trusted.

Build one with `url()`, `path()`, or `data()` rather than the constructor.
A source with no location at all is the canonical default: it resolves to
`OCX_INSTALL_DIST_URL` when the environment sets one, and to
`DEFAULT_DIST_URL` otherwise. A source built with an explicit URL never
consults the environment.

**Attributes**

- `manifest_url` (`str | None`) — Explicit manifest URL, or `None` for the default source.
- `manifest_path` (`Path | None`) — Local manifest file.
- `manifest_data` (`bytes | None`) — Manifest bytes the caller already holds.
- `sha256` (`str | None`) — Expected digest of the manifest body. Auto-derived from a `dist/<sha256>.json` URL, and *required* for any URL source that is off-canonical or paired with a mirror.
- `auth` (`Auth | None`) — Credentials for the manifest host, bound to its origin.
- `headers` (`Mapping[str, str]`) — Extra request headers, bound to the same origin.

> **Example**
>
> >>> DistSource.url().manifest_url is None
> True

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L222-L363)

### ocx_sdk.DistSource.auth

*attribute* · *class attribute* · *instance attribute*

```python
auth: Auth | None = field(default=None, repr=False)
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L251-L251)

### ocx_sdk.DistSource.headers

*attribute* · *class attribute* · *instance attribute*

```python
headers: Mapping[str, str] = field(default=_NO_HEADERS, repr=False)
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L252-L252)

### ocx_sdk.DistSource.credentials

*method*

```python
def credentials(env: Mapping[str, str] | None = None) -> Credentials
```

Return this source's credentials, bound to its resolved origin.

**Parameters**

- `env` (`Mapping[str, str] | None`) (default: `None`) — Environment used to resolve the URL, as in `resolve_url`.

**Returns**

- (`Credentials`) — Credentials whose origin is the resolved URL's, or an unbound empty
- (`Credentials`) — set for a local or in-memory source.

**Raises**

- `DistManifestError` — The resolved URL is not usable — not https, or
carrying userinfo.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L346-L363)

### ocx_sdk.DistSource.data

*method* · *classmethod*

```python
def data(raw: bytes, sha256: str | None = None) -> DistSource
```

Use manifest bytes the caller already has.

The vendoring path: ship a `dist/<sha256>.json` snapshot as package data
and read it back with `importlib.resources`, which works from a zipped
wheel where a filesystem path does not.

**Parameters**

- `raw` (`bytes`) — The manifest body.
- `sha256` (`str | None`) (default: `None`) — Expected digest of `raw`.

**Returns**

- (`DistSource`) — The source.

**Raises**

- `DistManifestError` — `sha256` is not 64 lowercase hex digits.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L310-L328)

### ocx_sdk.DistSource.path

*method* · *classmethod*

```python
def path(path: Path | str, sha256: str | None = None) -> DistSource
```

Read the manifest from a local file.

**Parameters**

- `path` (`Path | str`) — File holding the manifest JSON.
- `sha256` (`str | None`) (default: `None`) — Expected digest of the file contents.

**Returns**

- (`DistSource`) — The source.

**Raises**

- `DistManifestError` — `sha256` is not 64 lowercase hex digits.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L294-L308)

### ocx_sdk.DistSource.resolve_url

*method*

```python
def resolve_url(env: Mapping[str, str] | None = None) -> str | None
```

Return the URL this source fetches from.

**Parameters**

- `env` (`Mapping[str, str] | None`) (default: `None`) — Environment consulted for `OCX_INSTALL_DIST_URL`; only a source without an explicit location reads it.

**Returns**

- (`str | None`) — The manifest URL, or `None` for a local or in-memory source.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L330-L344)
