# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.EnvEntryType

*attribute*

```python
EnvEntryType
```

Re-exported from: `ocx_sdk._results`

The `type` an `ocx env` entry declares. Mirrors ocx's `--env KEY:TYPE=VALUE`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L111-L111)

## ocx_sdk.EnvValue

*attribute*

```python
EnvValue
```

Re-exported from: `ocx_sdk._types`

An `[env]` value. A bare `str` is a `ConstVar`, matching ocx's own grammar.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_types.py#L213-L213)

## ocx_sdk.Forge

*attribute*

```python
Forge
```

Re-exported from: `ocx_sdk._client`

ocx `--forge` values — which forge hosts an index repository. Argv-only, so a `Literal`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L160-L160)

## ocx_sdk.DistSource

*class* · *dataclass*

```python
class DistSource
```

Re-exported from: `ocx_sdk._dist`

Where a dist manifest comes from, and how its body is trusted.

Build one with `url()`, `path()`, or `data()` rather than the constructor.
A source with no location at all is the canonical default: it resolves to
`OCX_INSTALL_DIST_URL` when the environment sets one, and to
`DEFAULT_DIST_URL` otherwise. A source built with an explicit URL never
consults the environment.

**Attributes**

- `manifest_url` (`str | None`) — Explicit manifest URL, or `None` for the default source.
- `manifest_path` (`Path | None`) — Local manifest file.
- `manifest_data` (`bytes | None`) — Manifest bytes the caller already holds.
- `sha256` (`str | None`) — Expected digest of the manifest body. Auto-derived from a `dist/<sha256>.json` URL, and *required* for any URL source that is off-canonical or paired with a mirror.
- `auth` (`Auth | None`) — Credentials for the manifest host, bound to its origin.
- `headers` (`Mapping[str, str]`) — Extra request headers, bound to the same origin.

> **Example**
>
> >>> DistSource.url().manifest_url is None
> True

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L222-L363)

### ocx_sdk.DistSource.url

*method* · *classmethod*

```python
def url(url: str | None = None, sha256: str | None = None, auth: Auth | None = None, headers: Mapping[str, str] | None = None) -> DistSource
```

Fetch the manifest over https.

**Parameters**

- `url` (`str | None`) (default: `None`) — Manifest URL. `None` keeps the default source, which honors `OCX_INSTALL_DIST_URL` from the environment.
- `sha256` (`str | None`) (default: `None`) — Expected digest of the manifest body. Required whenever the host is not `setup.ocx.sh` or a mirror is in play; derived automatically from a `dist/<sha256>.json` URL.
- `auth` (`Auth | None`) (default: `None`) — Credentials for this origin, and this origin only.
- `headers` (`Mapping[str, str] | None`) (default: `None`) — Extra request headers, bound to the same origin.

**Returns**

- (`DistSource`) — The source.

**Raises**

- `DistManifestError` — `sha256` is not 64 lowercase hex digits.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_dist.py#L267-L292)
