# ocx_sdk

*module*

Python SDK for [OCX](https://github.com/ocx-sh/ocx).

`ocx-sdk` drives the ocx binary rather than reimplementing it: ocx owns
resolution, verification, and the identifier grammar, and this package gives
you typed, CWD-independent handles over the commands it exposes.

```python
from ocx_sdk import Ocx, bootstrap

ocx = Ocx(exe=bootstrap.ensure())
project = ocx.project("/srv/build")
project.pull()
project.exec(["task", "verify"])
```

**This module is the API.** Everything listed in `__all__` is the stable
surface; every other module is underscored and package-private, and the one
public submodule is `ocx_sdk.bootstrap`. Reaching into an underscored path
means the next release may move it without notice — pre-1.0, breaking
changes ship without shims.

Start at `Ocx` for the runtime API and `bootstrap.ensure` for provisioning.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/__init__.py#L1-L1)

## ocx_sdk.VerificationReport

*class* · *dataclass*

```python
class VerificationReport
```

Re-exported from: `ocx_sdk._results`

`ocx package verify` (C-012).

**Payload is enveloped** (D11): `from_json` unwraps `data`.

**Attributes**

- `subject_digest` (`str`) — The manifest digest that was verified.
- `referrer_digest` (`str`) — The verified object's own digest. **Not always a manifest digest** — see `SignatureEntry.referrer_digest`.
- `certificate_identity` (`str`) — The keyless identity pinned for verification. Plain `String` upstream (`verification.rs:115`) — always emitted, on both the keyless and key-based paths.
- `certificate_oidc_issuer` (`str`) — The keyless OIDC issuer pinned for verification. Always emitted (`verification.rs:117`), same as above.
- `signed_at` (`str`) — When the signature was produced, as ocx spelled it. Always emitted (`verification.rs:119`).
- `signatures` (`tuple[SignatureEntry, ...]`) — Matching signatures found. Absent, not empty, when there were none (D7).

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1701-L1741)

### ocx_sdk.VerificationReport.certificate_identity

*attribute* · *instance attribute*

```python
certificate_identity: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1725-L1725)

### ocx_sdk.VerificationReport.certificate_oidc_issuer

*attribute* · *instance attribute*

```python
certificate_oidc_issuer: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1726-L1726)

### ocx_sdk.VerificationReport.referrer_digest

*attribute* · *instance attribute*

```python
referrer_digest: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1724-L1724)

### ocx_sdk.VerificationReport.signatures

*attribute* · *class attribute* · *instance attribute*

```python
signatures: tuple[SignatureEntry, ...] = ()
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1728-L1728)

### ocx_sdk.VerificationReport.signed_at

*attribute* · *instance attribute*

```python
signed_at: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1727-L1727)

### ocx_sdk.VerificationReport.subject_digest

*attribute* · *instance attribute*

```python
subject_digest: str
```

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1723-L1723)

### ocx_sdk.VerificationReport.from_json

*method* · *classmethod*

```python
def from_json(raw: str) -> VerificationReport
```

Parse `ocx --format json package verify` output.

[View source](https://github.com/ocx-sh/ocx-sdk-python/blob/main/src/ocx_sdk/_results.py#L1730-L1741)
