# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.SignatureEntry

*class* · *dataclass*

```python
class SignatureEntry
```

Re-exported from: `ocx_sdk._results`

One signature `verify` found on the inspected object (C-012).

Field list verified against `verification.rs:50-85`.

**Attributes**

- `signature_format` (`str`) — Which format this entry is, carried as raw `str` (D8).
- `discovery_method` (`str`) — How ocx found it — referrer API or sidecar tag, carried as raw `str` (D8).
- `key_backend` (`str`) — Which key backend verified it, carried as raw `str` (D8).
- `referrer_digest` (`str`) — This signature's own digest. **Not always a manifest digest** — for a simplesigning sidecar it is a layer blob digest; feeding it to a manifest fetch 404s.
- `certificate_identity` (`str | None`) — The Fulcio certificate's identity, when the signature is keyless.
- `certificate_oidc_issuer` (`str | None`) — The Fulcio certificate's OIDC issuer, when the signature is keyless.
- `signed_at` (`str | None`) — When the signature was produced, as ocx spelled it, when present.
- `rekor_log_index` (`int | None`) — The Rekor entry index, when present. **Named differently from `SignatureReport`/`AttestationReport`'s `transparency_log_index`** — same concept, two wire names, and unlike those two structs this field is absent rather than always-present-nullable. Do not unify the handling.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1648-L1698)

### ocx_sdk.SignatureEntry.certificate_identity

*attribute* · *class attribute* · *instance attribute*

```python
certificate_identity: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1681-L1681)

### ocx_sdk.SignatureEntry.certificate_oidc_issuer

*attribute* · *class attribute* · *instance attribute*

```python
certificate_oidc_issuer: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1682-L1682)

### ocx_sdk.SignatureEntry.discovery_method

*attribute* · *instance attribute*

```python
discovery_method: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1678-L1678)

### ocx_sdk.SignatureEntry.key_backend

*attribute* · *instance attribute*

```python
key_backend: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1679-L1679)

### ocx_sdk.SignatureEntry.referrer_digest

*attribute* · *instance attribute*

```python
referrer_digest: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1680-L1680)

### ocx_sdk.SignatureEntry.rekor_log_index

*attribute* · *class attribute* · *instance attribute*

```python
rekor_log_index: int | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1684-L1684)

### ocx_sdk.SignatureEntry.signed_at

*attribute* · *class attribute* · *instance attribute*

```python
signed_at: str | None = None
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1683-L1683)

### ocx_sdk.SignatureEntry.from_dict

*method* · *classmethod*

```python
def from_dict(data: Mapping[str, Any]) -> SignatureEntry
```

Build from one decoded entry of `VerificationReport.signatures`.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1686-L1698)
