# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.Project

*class* · *dataclass*

```python
class Project
```

Re-exported from: `ocx_sdk._client`

A project-tier handle: every call carries `--project <file>`.

Obtained from `Ocx.project(path)`, never constructed directly. Because
the path travels explicitly on every call, no method depends on the
working directory, and an ambient `OCX_PROJECT` can never retarget one.
`init` is the exception, and only because ocx's is: it takes no flags and
writes into the working directory, so the handle sets that instead.

> **Example**
>
> ```python
> from ocx_sdk import Ocx
> 
> project = Ocx().project("/srv/build")
> project.add("ocx.sh/go-task/task:3", group="ci")
> project.lock()
> report = project.env()
> environment = report.compose().mapping
> ```

**Attributes**

- `path` (`Path`) — The absolute project file — the `ocx.toml` itself, which is what ocx's `--project` names.
- `session_config` (`OcxConfig`) — The `OcxConfig` every call spawns under.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L860-L1467)

### ocx_sdk.Project.path

*attribute* · *instance attribute*

```python
path: Path
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L888-L888)

### ocx_sdk.Project.session_config

*property*

```python
session_config: OcxConfig
```

The `OcxConfig` this handle spawns under — see `Ocx.session_config`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L914-L916)

### ocx_sdk.Project.add

*method*

```python
def add(*refs: PackageLike, group: str | None = None, pull: bool | None = None, platform: str | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> tuple[ToolRow, ...]
```

Add tool bindings to `ocx.toml`.

**Parameters**

- `*refs` (`PackageLike`) (default: `()`) — Identifiers, each optionally prefixed `NAME=`.
- `group` (`str | None`) (default: `None`) — The group to add to. `None` uses the implicit `[tools]` table.
- `pull` (`bool | None`) (default: `None`) — Materialize the resolved packages. `None` leaves the choice to ocx's own default.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against, as `os/arch[/variant][+feature]`.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`tuple[ToolRow, ...]`) — The lock rows the call wrote.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L955-L986)

### ocx_sdk.Project.inspect

*method*

```python
def inspect(*names: str, groups: Iterable[str] = (), platform: str | None = None, env: Mapping[str, EnvValue] | None = None, resolve: bool = False, closure: bool = False, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> InspectReport
```

Inspect the toolchain's bindings and their resolution.

**Parameters**

- `*names` (`str`) (default: `()`) — Binding names to inspect. Omitted inspects everything.
- `groups` (`Iterable[str]`) (default: `()`) — Groups to restrict to.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call, as `KEY[:TYPE[:SEP]]=VALUE` flags.
- `resolve` (`bool`) (default: `False`) — Add the pinned identifier, digest, layers, and the resolution chain.
- `closure` (`bool`) (default: `False`) — Add the dependency closure, its surface, and any conflicts. Conflicting entrypoints raise `DataError` with the payload attached to the error's stderr.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`InspectReport`) — The inspected packages and the composed `[env]` entries.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1156-L1194)

### ocx_sdk.Project.status

*method*

```python
def status(timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> StatusReport
```

Report what `ocx.toml` and `ocx.lock` declare, resolving nothing.

A broken or stale lock is payload here, not failure: the call still
exits 0 and the state shows up on the report.

**Parameters**

- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`StatusReport`) — The declared toolchain and the lock's state.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1141-L1154)
