AgentBuck Python SDK
agentbuck is the public Python SDK for AgentBuck runtime validation.
Install
pip install agentbuck
Import
import agentbuck
api_key = "<api key provided by caller>"
client = agentbuck.AgentBuckClient(api_key=api_key)
result = client.validate_bulk(
agent_id="agent-123",
idApp=456,
data=[{"email": "user@example.com"}],
)
Successful validation returns a dictionary with engine status, message, and decisions:
{
"status": "success",
"message": "",
"decisions": ["PROCEED", "BLOCK"],
}
Authorization failures are returned by the engine in the same response shape:
{
"status": "failed",
"message": "idApp not accessible",
"decisions": [],
}
The SDK endpoint can be provided directly, loaded from a custom env file, or
read from AGENTBUCK_GRPC_TARGET in the process environment. If no endpoint or
custom env file is provided, the SDK also loads a standard .env file from the
current working directory when present.
Examples:
AGENTBUCK_GRPC_TARGET=tcp://127.0.0.1:50051
client = agentbuck.AgentBuckClient(
api_key=api_key,
endpoint="tcp://127.0.0.1:50051",
)
client = agentbuck.AgentBuckClient(
api_key=api_key,
env_file="/path/to/custom.env",
)
Endpoint lookup order:
- Explicit
endpoint=... - Explicit
env_file=... AGENTBUCK_GRPC_TARGETfrom the process environment or.envin the current working directory
Endpoint values must use tcp://host:port format.
Authentication
Pass an API key when creating the client:
api_key = "<api key provided by caller>"
client = agentbuck.AgentBuckClient(api_key=api_key)
The API key must be provided by the caller through api_key=....
Public API
agentbuck.AgentBuckClientagentbuck.HealthResultagentbuck.ValidateBulkResult
License
The SDK is licensed under Apache-2.0. Copyright 2026 AgentBuck.
Build and verify a release
From a clean checkout, install the release tools and build both distribution formats:
python -m pip install build twine
python -m build
python -m twine check --strict dist/*
python scripts/verify_release.py dist
verify_release.py checks that the wheel and source distribution have matching
versions, Apache-2.0 metadata, the license files, the type marker, and the
generated gRPC modules. It also checks that the source distribution contains
validation.proto and the generator script. The generated Python modules are
checked in; installing the SDK does not run the generator or need
grpcio-tools.
GitHub Actions runs these checks and installs both archives in clean environments on Python 3.10, 3.11, 3.12, and 3.13.
Verify against a running engine
On Windows, install the built wheel into a fresh environment, then run the interactive check:
py -3.12 -m venv .venv-pypi-check
.\.venv-pypi-check\Scripts\python.exe -m pip install .\dist\agentbuck-0.1.0-py3-none-any.whl
.\.venv-pypi-check\Scripts\python.exe .\scripts\verify_live.py --csv "C:\path\to\data.csv" --endpoint "tcp://host:port" --agent-id "agent-123" --idapp 370
The script prompts for api_key without echoing it. If omitted, --csv and
--endpoint are prompted for too. The defaults are agent-123 and 370 for
--agent-id and --idapp. It reads CSV records using the same header handling
as the SDK, times validate_bulk, and shows each row whose decision is BLOCK.
It checks the decision count before pairing decisions with rows. A successful
live check ends with Live SDK validation succeeded. The server must be
running and the API key must be allowed to validate the chosen idapp and
agent_id.
Publish to PyPI
One-time setup:
- Publish this repository at the public
FirstEigen-Labs/agentbuck_sdk
path and update this checkout's
originURL to that repository. - In that repository's Settings → Environments, create
pypi. Require a reviewer before deployment and allow release tags matchingv*. - In PyPI's publishing settings,
register a pending GitHub trusted publisher with project
agentbuck, ownerFirstEigen-Labs, repositoryagentbuck_sdk, workflowrelease.yml, and environmentpypi. A pending publisher does not reserve the project name.
For the first release, keep pyproject.toml and agentbuck.__version__ at
0.1.0. After CI passes, push the v0.1.0 tag:
git tag v0.1.0
git push origin v0.1.0
The release workflow checks the tag against
the distribution version, rebuilds and verifies the archives, and waits for
approval in the pypi environment before uploading through trusted
publishing. For later releases, update both version values before tagging.
Metadata
Release files for agentbuck 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agentbuck-0.1.0.tar.gz | 16.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agentbuck-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 33.1 kB
Release files / agentbuck-0.1.0.tar.gz
| Download URL | agentbuck-0.1.0.tar.gz |
|---|---|
| Size | 16.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1fb73ff382ee5d3ff697f669af30fb69daf88eac960c6c1bd32fdefe8513c181
|
|
BLAKE2b-256 checksum How to use checksums |
69179c428bf5511b0d8ef2f017b961f96c17124b6bf7a12d71a4017d98a4bc26
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / agentbuck-0.1.0-py3-none-any.whl
| Download URL | agentbuck-0.1.0-py3-none-any.whl |
|---|---|
| Size | 16.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
dceeb236930940e6936a5232431b5452adf4c3050c917ab90d59aae9c872d904
|
|
BLAKE2b-256 checksum How to use checksums |
9a7aa2c261d4dd75a329f4bcb51eb8e6780bd1a496c5cd094bdf07c8cd6013d4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log