# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.SignatureReport

*class* · *dataclass*

```python
class SignatureReport
```

Re-exported from: `ocx_sdk._results`

`ocx package sign` on a single reference — no tag sweep (C-011).

**Payload is enveloped** (D11): `from_json` unwraps `data` via
`_envelope` before parsing. A `--signature-format both` run where one leg
lands and one fails exits non-zero carrying a full report — recover it
with `partial_report(err)` and this same `from_json` (D10); `legs` names
which leg died through its `error` field.

Per D7's field-order rule, `public_key_hint` moves to the end even
though upstream orders it before `transparency_log_index` — transcribing
that order verbatim would put a defaulted field before a required one.

**Attributes**

- `identifier` (`str`) — The identifier that was signed.
- `subject_digest` (`str`) — The manifest digest the signature covers.
- `legs` (`tuple[SignatureLegReport, ...]`) — One row per signature format requested.
- `platform` (`str`) — The signed platform.
- `signer` (`str`) — The signing mode label — never an identity and never a key reference. `"keyless-fulcio"` under keyless signing (`signature.rs:159-162`), else `key_backend`'s own backend label (`awskms`, `file`, ...). Deliberately spelled differently from `key_backend`, which reads the plain `"keyless"` in that same case (`signature.rs:155-157`): upstream's own comment notes that reusing `"keyless"` here too would leave no field that actually names the mechanism.
- `certificate_identity` (`str`) — The Fulcio certificate's identity. Plain `String` upstream (`signature.rs:59`) — always emitted, on both the keyless and key-based paths.
- `certificate_oidc_issuer` (`str`) — The Fulcio certificate's OIDC issuer. Always emitted (`signature.rs:61`), same as above.
- `key_backend` (`str`) — Which key backend produced the signature, carried as raw `str` (D8; irregular KMS spellings live here unmodified). Always emitted (`signature.rs:68`); under keyless signing the value is literally `"keyless"`, not absent.
- `transparency_log_index` (`int | None`) — The Rekor entry index. Always present in the JSON, but `None` when nothing was logged.
- `public_key_hint` (`str | None`) — A hint identifying the verifying key, when ocx supplied one.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1568-L1645)

### ocx_sdk.SignatureReport.certificate_identity

*attribute* · *instance attribute*

```python
certificate_identity: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1615-L1615)

### ocx_sdk.SignatureReport.certificate_oidc_issuer

*attribute* · *instance attribute*

```python
certificate_oidc_issuer: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1616-L1616)

### ocx_sdk.SignatureReport.identifier

*attribute* · *instance attribute*

```python
identifier: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1610-L1610)

### ocx_sdk.SignatureReport.key_backend

*attribute* · *instance attribute*

```python
key_backend: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1617-L1617)

### ocx_sdk.SignatureReport.legs

*attribute* · *instance attribute*

```python
legs: tuple[SignatureLegReport, ...]
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1612-L1612)

### ocx_sdk.SignatureReport.platform

*attribute* · *instance attribute*

```python
platform: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1613-L1613)
