# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.PackageCommands

*class* · *dataclass*

```python
class PackageCommands
```

Re-exported from: `ocx_sdk._client`

The `ocx package` command group — machine tier.

Package operations act on the `$OCX_HOME` store and its candidate and
current symlinks. They take no project path and are CWD-independent by
construction; a path appears only where the CLI itself takes one.

Every method is multi-identifier native, mirroring the CLI's `PKG...`
with one shared resolution.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1470-L3367)

## ocx_sdk.Project

*class* · *dataclass*

```python
class Project
```

Re-exported from: `ocx_sdk._client`

A project-tier handle: every call carries `--project <file>`.

Obtained from `Ocx.project(path)`, never constructed directly. Because
the path travels explicitly on every call, no method depends on the
working directory, and an ambient `OCX_PROJECT` can never retarget one.
`init` is the exception, and only because ocx's is: it takes no flags and
writes into the working directory, so the handle sets that instead.

> **Example**
>
> ```python
> from ocx_sdk import Ocx
> 
> project = Ocx().project("/srv/build")
> project.add("ocx.sh/go-task/task:3", group="ci")
> project.lock()
> report = project.env()
> environment = report.compose().mapping
> ```

**Attributes**

- `path` (`Path`) — The absolute project file — the `ocx.toml` itself, which is what ocx's `--project` names.
- `session_config` (`OcxConfig`) — The `OcxConfig` every call spawns under.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L860-L1467)

### ocx_sdk.Project.env

*method*

```python
def env(groups: Iterable[str] = (), platform: str | None = None, env: Mapping[str, EnvValue] | None = None, pull: bool | None = None, lazy_mode: LazyMode | None = None, show_patches: bool = False, pinned: bool | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> EnvReport
```

Report the environment the toolchain composes.

The report carries this handle's host snapshot, so `compose()` stays
hermetic: a report produced under `HostEnv.clean()` composes against
nothing ambient unless you pass a different base.

Note that ocx's `env` command takes no binding names — narrow with
`groups` instead.

**Parameters**

- `groups` (`Iterable[str]`) (default: `()`) — Groups to compose. Omitted composes the default set.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `env` (`Mapping[str, EnvValue] | None`) (default: `None`) — Extra `[env]` entries for this call.
- `pull` (`bool | None`) (default: `None`) — Materialize missing content first. `None` leaves the choice to ocx's own default.
- `lazy_mode` (`LazyMode | None`) (default: `None`) — When content downloads — now, or on first use.
- `show_patches` (`bool`) (default: `False`) — Include patch-contributed entries.
- `pinned` (`bool | None`) (default: `None`) — Resolve through the rendered toolchain's pinned digests rather than following its links — ocx's `--pinned` / `--no-pinned`. `None` leaves the choice to `ocx.toml`'s `pinned` key, then `OCX_TOOLCHAIN_PINNED`, then ocx's default of following the links.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`EnvReport`) — The typed entries plus the binaries, entrypoints, integrations,
- (`EnvReport`) — and advisories envelope.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1196-L1249)

### ocx_sdk.Project.update

*method*

```python
def update(*names: str, check_only: bool = False, groups: Iterable[str] = (), pull: bool | None = None, platform: str | None = None, timeout: MaybeTimeout = UNSET, retry: MaybeRetry = UNSET) -> tuple[ToolRow, ...] | None
```

Re-resolve declared tags against the registry.

**Parameters**

- `*names` (`str`) (default: `()`) — Binding names to advance; every other pin freezes. Omitted advances the whole file.
- `check_only` (`bool`) (default: `False`) — Compare the candidate lock to its predecessor and write nothing — ocx's `--check`. A changed pin raises `DataError`.
- `groups` (`Iterable[str]`) (default: `()`) — Groups to advance. `default` is the implicit `[tools]` table, `all` expands to every group.
- `pull` (`bool | None`) (default: `None`) — Materialize the resolved packages. `None` leaves the choice to ocx's own default.
- `platform` (`str | None`) (default: `None`) — The platform to resolve against.
- `timeout` (`MaybeTimeout`) (default: `UNSET`) — Seconds per attempt. Omitted takes the config's.
- `retry` (`MaybeRetry`) (default: `UNSET`) — Retry policy. `None` opts out; omitted takes the config's.

**Returns**

- (`tuple[ToolRow, ...] | None`) — The lock rows written, or `None` under `check_only`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_client.py#L1044-L1080)
