# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PermissionDeniedError

*class*

```python
class PermissionDeniedError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

ocx was denied access to a resource (exit 77).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L202-L205)

## ocx_sdk.PolicyBlockedError

*class*

```python
class PolicyBlockedError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

ocx refused the operation under an offline or frozen policy (exit 81).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L236-L239)

## ocx_sdk.ReferrersUnsupportedError

*class*

```python
class ReferrersUnsupportedError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

The registry served neither the OCI 1.1 Referrers API nor the Referrers Tag Schema fallback (exit 84).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L259-L266)

## ocx_sdk.TempFailError

*class*

```python
class TempFailError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

A transient failure ocx marked as retry-safe (exit 75).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L196-L199)

## ocx_sdk.TransparencyLogUnavailableError

*class*

```python
class TransparencyLogUnavailableError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

Rekor was unreachable during a signing or verification operation (exit 83).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L248-L256)

## ocx_sdk.UnavailableError

*class*

```python
class UnavailableError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

A resource is unavailable and ocx classified it as non-transient (exit 69).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L184-L187)

## ocx_sdk.UnsupportedKeyBackendError

*class*

```python
class UnsupportedKeyBackendError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

ocx recognized the key backend scheme but has not implemented it (exit 85).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L269-L276)

## ocx_sdk.UnsupportedPlatformError

*class*

```python
class UnsupportedPlatformError(BootstrapError)
```

Bases: `ocx_sdk._errors.BootstrapError`

Re-exported from: `ocx_sdk._errors`

No ocx release matches the host platform.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L342-L345)

## ocx_sdk.UsageError

*class*

```python
class UsageError(OcxProcessError)
```

Bases: `ocx_sdk._errors.OcxProcessError`

Re-exported from: `ocx_sdk._errors`

ocx rejected the command line (exit 64).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_errors.py#L172-L175)
