# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.RefusedEntry

*class* · *dataclass*

```python
class RefusedEntry
```

Re-exported from: `ocx_sdk._results`

One candidate `sbom` examined and rejected (C-014).

All three fields always present (`sbom.rs:192-205`).

**Attributes**

- `referrer_digest` (`str`) — The rejected candidate's own digest.
- `reason` (`str`) — English prose explaining the refusal — free to be reworded upstream (PKG-25); branch on `reason_kind`, never on this text.
- `reason_kind` (`str`) — The frozen, machine-branchable slug to switch on.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2117-L2141)

### ocx_sdk.RefusedEntry.reason

*attribute* · *instance attribute*

```python
reason: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2131-L2131)

### ocx_sdk.RefusedEntry.reason_kind

*attribute* · *instance attribute*

```python
reason_kind: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2132-L2132)

### ocx_sdk.RefusedEntry.referrer_digest

*attribute* · *instance attribute*

```python
referrer_digest: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2130-L2130)

### ocx_sdk.RefusedEntry.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> RefusedEntry
```

Build from one decoded entry of `SbomListingReport.refused`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L2134-L2141)
