Skip to main content

adbc-driver-gizmosql

A Python ADBC driver for GizmoSQL with OAuth/SSO support

adbc-driver-gizmosql-ci Supported Python Versions PyPI version PyPI Downloads

Overview

adbc-driver-gizmosql is a lightweight Python wrapper around adbc-driver-flightsql that adds GizmoSQL-specific features:

  • OAuth/SSO browser flow — Authenticate via your identity provider (Google, Okta, etc.) with a single parameter change
  • DBAPI 2.0 interface — Drop-in replacement for adbc_driver_flightsql.dbapi
  • Minimal dependencies — Only requires adbc-driver-flightsql and pyarrow; the OAuth flow uses only Python stdlib
  • OpenTelemetry tracing & structured logging — Inherited from adbc-driver-flightsql ≥ 1.12.0 (see Observability)

Setup (to run locally)

Install Python package

You can install adbc-driver-gizmosql from PyPi or from source.

Option 1 - from PyPi

# Create the virtual environment
python3 -m venv .venv

# Activate the virtual environment
. .venv/bin/activate

pip install adbc-driver-gizmosql

Option 2 - from source - for development

git clone https://github.com/gizmodata/adbc-driver-gizmosql

cd adbc-driver-gizmosql

# Create the virtual environment
python3 -m venv .venv

# Activate the virtual environment
. .venv/bin/activate

# Upgrade pip, setuptools, and wheel
pip install --upgrade pip setuptools wheel

# Install adbc-driver-gizmosql - in editable mode with dev and test dependencies
pip install --editable ".[dev,test]"

Usage

Start a GizmoSQL server

First — start a GizmoSQL server in Docker (mounts a small TPC-H database by default):

docker run --name gizmosql \
           --detach \
           --rm \
           --tty \
           --init \
           --publish 31337:31337 \
           --env TLS_ENABLED="1" \
           --env GIZMOSQL_USERNAME="gizmosql_user" \
           --env GIZMOSQL_PASSWORD="gizmosql_password" \
           --env PRINT_QUERIES="1" \
           --pull missing \
           gizmodata/gizmosql:latest

Password authentication

from adbc_driver_gizmosql import dbapi as gizmosql

with gizmosql.connect("gizmosql://localhost:31337",
                      username="gizmosql_user",
                      password="gizmosql_password",
                      tls_skip_verify=True,
                      ) as conn:
    with conn.cursor() as cur:
        cur.execute("SELECT n_nationkey, n_name FROM nation WHERE n_nationkey = ?",
                    parameters=[24])
        table = cur.fetch_arrow_table()
        print(table)

URI schemes

The preferred way to connect is the gizmosql:// URI scheme, which is secure by default (gRPC with TLS):

URI Meaning
gizmosql://host:31337 gRPC with TLS (default)
gizmosql://host:31337?transport=tls gRPC with TLS (explicit)
gizmosql://host:31337?transport=tcp gRPC plaintext (no TLS)
grpc+tls://host:31337 Legacy TLS spelling (still supported)
grpc+tcp://host:31337 / grpc://host:31337 Legacy plaintext spellings (still supported)
with gizmosql.connect("gizmosql://localhost:31337",  # TLS by default
                      username="gizmosql_user",
                      password="gizmosql_password",
                      tls_skip_verify=True,
                      ) as conn:
    ...

Note: gizmosql:// requires adbc-driver-flightsql ≥ 1.12.0 (this package's floor) — it maps onto the underlying driver's flightsql:// scheme. In connection profile TOML files, the uri is consumed directly by the underlying driver, so use grpc+tls:// or flightsql:// there.

DDL/DML — auto-detected and executed immediately

cursor.execute() automatically detects DDL/DML statements and executes them immediately on the server, matching the behavior of the GizmoSQL JDBC and ODBC drivers. No special API is needed — just use execute() for everything:

from adbc_driver_gizmosql import dbapi as gizmosql

with gizmosql.connect("gizmosql://localhost:31337",
                      username="gizmosql_user",
                      password="gizmosql_password",
                      tls_skip_verify=True,
                      ) as conn:
    with conn.cursor() as cur:
        # DDL and DML work with regular execute()
        cur.execute("CREATE TABLE t (a INT)")
        cur.execute("INSERT INTO t VALUES (1)")

        # SELECT works as usual
        cur.execute("SELECT * FROM t")
        print(cur.fetch_arrow_table())

        # Cleanup
        cur.execute("DROP TABLE t")

Note: cursor.execute_update(query) is still available if you need the rows-affected count returned directly: rows = cur.execute_update("INSERT ...").

OAuth/SSO authentication

When your GizmoSQL server is configured with OAuth, simply change auth_type:

from adbc_driver_gizmosql import dbapi as gizmosql

with gizmosql.connect("gizmosql://gizmosql.example.com:31337",
                      auth_type="external",
                      tls_skip_verify=True,
                      ) as conn:
    with conn.cursor() as cur:
        cur.execute("SELECT CURRENT_USER AS user")
        print(cur.fetch_arrow_table())

This will:

  1. Auto-discover the OAuth server endpoint
  2. Open your browser to the identity provider login page
  3. Poll for completion and retrieve the identity token
  4. Connect to GizmoSQL using the token via Basic Auth (username="token")

Connection profiles

This driver supports ADBC connection profiles (requires adbc-driver-manager >= 1.11.0) — reusable TOML files that bundle the server URI and options so connection code stays credential-free.

Create a profile, e.g. ~/.config/adbc/profiles/gizmosql_dev.toml on Linux, ~/Library/Application Support/ADBC/Profiles/gizmosql_dev.toml on macOS, or any directory listed in the ADBC_PROFILE_PATH environment variable:

profile_version = 1

[Options]
uri = "grpc+tls://gizmosql.example.com:31337"
username = "gizmosql_username"
# Keep secrets out of the file — substituted from the environment at connect time
password = "{{ env_var(GIZMOSQL_PASSWORD) }}"

Then connect by profile name (no uri needed):

from adbc_driver_gizmosql import dbapi as gizmosql

with gizmosql.connect(profile="gizmosql_dev") as conn:
    with conn.cursor() as cur:
        cur.execute("SELECT 1 AS value")
        print(cur.fetch_arrow_table())

Notes:

  • connect("profile://gizmosql_dev") and connect(profile="/abs/path/to/profile.toml") work too.
  • The profile does not need a driver entry — the Flight SQL driver bundled with this package is supplied automatically.
  • Options passed explicitly to connect() (e.g. username=, password=, db_kwargs=) take precedence over the profile's [Options].
  • Boolean/typed driver options are plain strings in profiles, e.g. "adbc.flight.sql.client_option.tls_skip_verify" = "true" (dotted keys must be quoted in TOML).

Advanced: Standalone OAuth token retrieval

from adbc_driver_gizmosql import get_oauth_token

result = get_oauth_token(
    host="gizmosql.example.com",
    port=31339,           # OAuth HTTP port (default)
    tls_skip_verify=True, # Skip TLS cert verification
    timeout=300,          # Seconds to wait for user to complete auth
)

print(f"Token: {result.token}")
print(f"Session: {result.session_uuid}")

Bulk ingest (load Arrow data into a table)

The ADBC adbc_ingest method on the cursor lets you load Arrow tables, record batches, or record batch readers directly into GizmoSQL — no row-by-row INSERT needed:

import pyarrow as pa
from adbc_driver_gizmosql import dbapi as gizmosql

# Build an Arrow table
table = pa.table({
    "id": [1, 2, 3],
    "name": ["Alice", "Bob", "Charlie"],
    "score": [95.0, 87.5, 91.2],
})

with gizmosql.connect("gizmosql://localhost:31337",
                      username="gizmosql_user",
                      password="gizmosql_password",
                      tls_skip_verify=True,
                      ) as conn:
    with conn.cursor() as cur:
        # Create a new table and insert the data
        cur.adbc_ingest("students", table, mode="create")

        # Verify
        cur.execute("SELECT * FROM students")
        print(cur.fetch_arrow_table())

Supported modes: "create", "append", "replace", "create_append".

Observability: OpenTelemetry tracing & logging

Starting with adbc-driver-flightsql 1.12.0 (the floor for this package), the underlying Flight SQL driver emits OpenTelemetry trace spans for the core operations — Database.Open, Prepare, ExecuteQuery, and ExecuteUpdate — and supports structured logging.

Tracing

Enable a trace exporter via db_kwargs (per-connection) or the standard OTEL_* environment variables (process-wide):

from adbc_driver_gizmosql import dbapi as gizmosql

with gizmosql.connect("gizmosql://localhost:31337",
                      username="gizmosql_user",
                      password="gizmosql_password",
                      tls_skip_verify=True,
                      db_kwargs={
                          # one of: none | otlp | console | adbcfile
                          "adbc.telemetry.traces_exporter": "otlp",
                      },
                      ) as conn:
    ...
Option key (db_kwargs) Description
adbc.telemetry.traces_exporter Exporter: none, otlp, console, or adbcfile
adbc.telemetry.traces_folder_path Output directory when using the adbcfile exporter
adbc.telemetry.trace_parent W3C Trace Context traceparent — join your application's existing distributed trace

With the otlp exporter, the standard OpenTelemetry environment variables (OTEL_EXPORTER_OTLP_ENDPOINT, OTEL_EXPORTER_OTLP_HEADERS, ...) configure the collector endpoint. OTEL_TRACES_EXPORTER may also be used instead of the database option (the option wins when both are set).

Driver logging

Set the log level for the underlying Flight SQL driver via an environment variable (great for debugging connection/TLS/auth issues):

export ADBC_DRIVER_FLIGHTSQL_LOG_LEVEL=debug   # debug | info | warn | error

See the Flight SQL driver telemetry docs for full details.

Pandas integration

import pandas as pd
from adbc_driver_gizmosql import dbapi as gizmosql

with gizmosql.connect("gizmosql://localhost:31337",
                      username="gizmosql_user",
                      password="gizmosql_password",
                      tls_skip_verify=True,
                      ) as conn:
    df = pd.read_sql("SELECT * FROM nation ORDER BY n_nationkey", conn)
    print(df)

API Reference

dbapi.connect()

Parameter Type Default Description
uri str None Server URI (e.g., "gizmosql://host:31337" — TLS by default; grpc+tls://, grpc+tcp://, and flightsql:// also accepted); optional if profile supplies it. "profile://<name>" is also accepted
profile str None ADBC connection profile — a bare name resolved via the standard search paths (incl. ADBC_PROFILE_PATH) or an absolute path to a .toml file. At least one of uri/profile is required
username str None Username for password auth
password str None Password for password auth
tls_skip_verify bool False Skip TLS cert verification
auth_type str "password" "password" or "external" (OAuth)
oauth_port int 31339 OAuth HTTP server port
oauth_url str None Explicit OAuth base URL
oauth_tls_skip_verify bool None TLS skip for OAuth (defaults to tls_skip_verify)
oauth_timeout int 300 Seconds to wait for OAuth
open_browser bool True Auto-open browser for OAuth
db_kwargs dict None Extra ADBC database options
conn_kwargs dict None Extra ADBC connection options
autocommit bool True Enable autocommit

cursor.execute_update()

Execute a DDL/DML statement immediately and return the rows-affected count. This is an alternative to cursor.execute() when you need the rows-affected count as the return value.

Parameter Type Default Description
query str required SQL DDL or DML statement to execute

Returns: int — number of rows affected (0 for DDL statements that do not affect rows)

Note: cursor.execute() now auto-detects DDL/DML and executes it immediately, so execute_update() is only needed when you want the rows-affected count returned directly. The module-level gizmosql.execute_update(cursor, query) function is still available for backward compatibility.

get_oauth_token()

Parameter Type Default Description
host str required GizmoSQL server hostname
port int 31339 OAuth HTTP port
tls_skip_verify bool True Skip TLS cert verification
timeout int 300 Seconds to wait
poll_interval float 1 Seconds between polls
open_browser bool True Auto-open browser
oauth_url str None Explicit OAuth base URL

Returns: OAuthResult(token=str, session_uuid=str)

How the OAuth flow works

Python Client              GizmoSQL OAuth Server         Identity Provider
     |                            |                            |
     +-- GET /oauth/initiate ---->|                            |
     |<-- {uuid, auth_url} -------|                            |
     |                            |                            |
     +-- Open browser to auth_url-|--------------------------->|
     |                            |                            |
     |                            |<-- callback (auth code) ---|
     |                            |-- exchange code for token ->|
     |                            |<-- id_token ---------------|
     |                            |                            |
     +-- GET /oauth/token/{uuid}->|                            |
     |<-- {status: complete,      |                            |
     |     token: <id_token>}     |                            |
     |                            |                            |
     +-- Flight BasicAuth ------->|                            |
     |   user="token"             | (verify token via JWKS,    |
     |   pass=<id_token>          |  issue server JWT)         |
     |<-- Server Bearer token ----|                            |

Handy development commands

Version management

Bump the version of the application - (you must have installed from source with the [dev] extras)

bumpver update --patch

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

adbc_driver_gizmosql-1.3.0.tar.gz (36.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

adbc_driver_gizmosql-1.3.0-py3-none-any.whl (21.4 kB view details)

Uploaded Python 3

File details

Details for the file adbc_driver_gizmosql-1.3.0.tar.gz.

File metadata

  • Download URL: adbc_driver_gizmosql-1.3.0.tar.gz
  • Upload date:
  • Size: 36.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for adbc_driver_gizmosql-1.3.0.tar.gz
Algorithm Hash digest
SHA256 a28e3bb59c9a264a77b965fc6e57ccdaccb52023f37c808f1d71eafa7d0310fc
MD5 de3df6b705f6de07ad5b777384cd0d3f
BLAKE2b-256 05955d6b329e89feba868169203b0f87d4eba5b64fed92c4293d4deb15caff27

See more details on using hashes here.

Provenance

The following attestation bundles were made for adbc_driver_gizmosql-1.3.0.tar.gz:

Publisher: ci.yml on gizmodata/adbc-driver-gizmosql

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file adbc_driver_gizmosql-1.3.0-py3-none-any.whl.

File metadata

File hashes

Hashes for adbc_driver_gizmosql-1.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 6d641f47dbadb2613e370a834f905dc8f18e7e0d3b19ad58dd92e485bca95cc8
MD5 537dba75533f7e90e09f38c529e9c6cb
BLAKE2b-256 98b4b24f9b621380bc1ab13840097033eb43614e8a24f98f1d5d4a47ed1f8b2d

See more details on using hashes here.

Provenance

The following attestation bundles were made for adbc_driver_gizmosql-1.3.0-py3-none-any.whl:

Publisher: ci.yml on gizmodata/adbc-driver-gizmosql

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

2.0.13

6 files

2.0.12

6 files

2.0.11

6 files

2.0.10

6 files

2.0.9

6 files

2.0.8

6 files

2.0.7

6 files

2.0.6

6 files

2.0.5

6 files

2.0.4

6 files

2.0.3

6 files

2.0.2

6 files

2.0.1

6 files

2.0.0

6 files

This release

1.3.0 This release

2 files

1.2.0

2 files

1.1.7

2 files

1.1.6

2 files

1.1.5

2 files

1.1.4

2 files

1.1.3

2 files

1.1.2

2 files

1.1.1

2 files

1.1.0

2 files

1.0.5

2 files

1.0.4

2 files

1.0.3

2 files

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

0.1.1

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page