# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.Project

*class* · *dataclass*

```python
class Project
```

Re-exported from: `ocx_sdk._client`

A project-tier handle: every call carries `--project <file>`.

Obtained from `Ocx.project(path)`, never constructed directly. Because
the path travels explicitly on every call, no method depends on the
working directory, and an ambient `OCX_PROJECT` can never retarget one.
`init` is the exception, and only because ocx's is: it takes no flags and
writes into the working directory, so the handle sets that instead.

> **Example**
>
> ```python
> from ocx_sdk import Ocx
> 
> project = Ocx().project("/srv/build")
> project.add("ocx.sh/go-task/task:3", group="ci")
> project.lock()
> report = project.env()
> environment = report.compose().mapping
> ```

**Attributes**

- `path` (`Path`) — The absolute project file — the `ocx.toml` itself, which is what ocx's `--project` names.
- `session_config` (`OcxConfig`) — The `OcxConfig` every call spawns under.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L860-L1467)

### ocx_sdk.Project.remove

*method*

```python
def remove(*names: PackageLike, group: str | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> tuple[ToolRow, ...]
```

Remove tool bindings from `ocx.toml`.

**Parameters**

- `*names` (`PackageLike`) (default: `()`) — Binding names or fully-qualified identifiers.
- `group` (`str | None`) (default: `None`) — The group to target. `None` searches every group and fails when a name appears in more than one.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`tuple[ToolRow, ...]`) — The lock rows the call wrote — empty when nothing changed.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L988-L1008)

### ocx_sdk.Project.spawn_async

*method* · *async*

```python
async def spawn_async(argv: Sequence[str], *, names: Iterable[str] = (), groups: Iterable[str] = (), clean: bool = False, env: Mapping[str, EnvValue] | None = None, lazy_mode: LazyMode | None = None, pinned: bool | None = None, records_dir: str | Path | None = None, records_name: str | None = None, **popen_kw: Any) -> asyncio.subprocess.Process
```

Start a command in the project's environment, on the event loop.

**Parameters**

- `argv` (`Sequence[str]`) — The command and its arguments. Must not be empty.
- `names` (`Iterable[str]`) (default: `()`) — Bindings to compose.
- `groups` (`Iterable[str]`) (default: `()`) — Groups to compose.
- `clean` (`bool`) (default: `False`) — Strip the ambient parent environment before composing.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `pinned` (`bool | None`) (default: `None`) — Resolve through pinned digests — see `exec`.
- `records_dir` (`str | Path | None`) (default: `None`) — Write an execution record here — see `exec`.
- `records_name` (`str | None`) (default: `None`) — The record's filename template — see `exec`.
- `**popen_kw` (`Any`) (default: `{}`) — Forwarded to the subprocess factory. `args`, `shell`, and `executable` are rejected.

**Returns**

- (`asyncio.subprocess.Process`) — The running child.

**Raises**

- `ValueError` — `argv` is empty, or a rejected keyword was passed.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1395-L1432)
