# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.EnvReport

*class* · *dataclass*

```python
class EnvReport
```

Re-exported from: `ocx_sdk._results`

`ocx env` and `ocx package env` — the same five-array envelope, both tiers.

Iterating the report iterates `entries`: composing an environment is what
it is for, and the other four arrays are description.

**Attributes**

- `entries` (`tuple[EnvEntry, ...]`) — The `[env]` contributions, in declaration order.
- `binaries` (`tuple[PackageBinding, ...]`) — Executables the packages put on PATH. Pre-1.0, may break.
- `entrypoints` (`tuple[PackageBinding, ...]`) — Named entrypoints the packages declare. Pre-1.0, may break.
- `integrations` (`tuple[Integration, ...]`) — Tool integrations, payloads untyped. Pre-1.0, may break.
- `advisories` (`tuple[Advisory, ...]`) — Warnings about the composition. Pre-1.0, may break.

The four non-entry arrays carry ocx's `package which`-style caveat: they
are not on ocx's durable-anchor list, so their shape may change in a minor
release. `entries` is the part the SDK depends on.

> **Example**
>
> ```pycon
> >>> wire = '{"entries": [{"key": "TOOL", "type": "constant", "value": "1"}],'
> >>> wire += ' "binaries": [], "entrypoints": [], "integrations": [], "advisories": []}'
> >>> [entry.key for entry in EnvReport.from_json(wire)]
> ['TOOL']
> 
> ```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L979-L1067)

### ocx_sdk.EnvReport.compose

*method*

```python
def compose(base: Mapping[str, str] | None = None) -> ComposedEnv
```

Fold these entries onto an environment.

**Parameters**

- `base` (`Mapping[str, str] | None`) (default: `None`) — What to fold onto. Defaults to the environment the producing call ran under, so composing a report from a hermetic handle stays hermetic.

**Returns**

- (`ComposedEnv`) — The merged environment. `.mapping` is the non-invasive form;
- (`ComposedEnv`) — `.activate()` applies it to the whole process.

**Raises**

- `ValueError` — Two list contributions to one key disagree about the
separator, or a value is edged by the one it folds with
(`_envmodel.merge`). ocx validates its own `[env]` before
emitting it, so a report parsed from `ocx env` should not
reach that; a hand-built one can.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1023-L1047)

### ocx_sdk.EnvReport.from_json

*method* · *classmethod*

```python
def from_json(raw: str, *, base: Mapping[str, str] = _EMPTY) -> EnvReport
```

Parse `ocx --format json env` (or `package env`) output.

**Parameters**

- `raw` (`str`) — Captured stdout.
- `base` (`Mapping[str, str]`) (default: `_EMPTY`) — The environment the call ran under, carried for `compose`. Snapshotted, so a later mutation of the source cannot rewrite what an already-parsed report composes onto.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1049-L1067)

## ocx_sdk.ErrorEnvelope

*class* · *dataclass*

```python
class ErrorEnvelope
```

Re-exported from: `ocx_sdk._results`

The structured failure ocx prints under `--format json` (C-S1-1).

`{schema_version, command, exit_code, error: {kind, detail?, message,
remediation?, context}}` — a contract frozen separately from the reports
schema, and printed on stdout only when the failing command wrote no
report of its own. `error_envelope(err)` is how a caller reaches it.

The exit code is still the category (`_errors`): `kind` restates it as
ocx's own vocabulary, and `detail` — when present — is the fine-grained
slug to branch on. `message` is prose, free to be reworded.

**Attributes**

- `schema_version` (`int`) — The envelope's own version; `1` for every 0.6 binary.
- `command` (`str`) — The canonical command string, e.g. `"package claim"`.
- `exit_code` (`int`) — The exit status the process returned.
- `kind` (`str`) — The coarse category, snake_case (`"data_error"`, `"auth_error"`, ...).
- `message` (`str`) — The outermost message of the error chain.
- `detail` (`str | None`) — The fine-grained variant slug, when ocx assigned one.
- `remediation` (`str | None`) — A remediation hint. Reserved upstream and never emitted by a 0.6 binary; carried so a consumer treating it as optional keeps working when it appears.
- `context` (`Mapping[str, Any]`) — Structured context (identifiers, digests, URLs), untyped.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L329-L377)

### ocx_sdk.ErrorEnvelope.command

*attribute* · *instance attribute*

```python
command: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L356-L356)

### ocx_sdk.ErrorEnvelope.context

*attribute* · *class attribute* · *instance attribute*

```python
context: Mapping[str, Any] = _EMPTY
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L362-L362)
