Aksara
An async PostgreSQL backend framework that generates REST APIs and authorized MCP tools from the same model and policy boundary.
What is Aksara?
Aksara is a Python 3.11+ framework for async PostgreSQL applications. Define an
ORM model and a ModelViewSet, then use the same schema and application policy
for generated REST routes and MCP tools.
The v0.6 stable contract covers the ORM, migrations, generated REST,
authentication and server-owned Principal, permissions and PolicyEngine,
tenant isolation, core CLI and Doctor, PostgreSQL background tasks, and MCP
Streamable HTTP execution at /mcp/.
Planner behavior, provider-specific quality, process-local investigation sessions, autonomous workflows, memory, and Studio AI internals remain experimental. Aksara is pre-1.0; read the exact stability contract before production adoption.
Why Aksara?
REST callers and AI agents often reach the same data through separate code and security paths. Aksara generates both surfaces from one model/ViewSet definition and rechecks identity, permissions, policy, tenant, and field-write rules when a tool actually runs. The production tenant claim also depends on a restricted PostgreSQL role and forced RLS.
10-Minute Quickstart
Aksara requires PostgreSQL.
python -m venv .venv
source .venv/bin/activate
pip install "aksara-framework==0.6.1"
aksara startproject opsdesk
cd opsdesk
aksara dbsetup
Open app/models.py and define a model:
from aksara import Model, fields
class Incident(Model):
title = fields.String(max_length=200, ai_description="Short summary")
resolved = fields.Boolean(
default=False,
ai_description="Resolution state",
ai_agent_writable=False,
)
notes = fields.Text(nullable=True, ai_sensitive=True)
class Meta:
table_name = "incidents"
ai_agent_exposed = True
Open app/views.py:
from aksara import ModelViewSet
from .models import Incident
class IncidentViewSet(ModelViewSet):
model = Incident
prefix = "/api/incidents"
ai_exposed = True
Then import IncidentViewSet in app/urls.py, add it to urlpatterns, and run:
aksara makemigrations --app app.models
aksara migrate
aksara doctor launch-check
aksara dev
Open http://127.0.0.1:8000/docs for generated REST OpenAPI. The scaffold keeps MCP, provider-backed AI, and Studio disabled until you configure them.
REST and MCP
The two MCP-related paths have different meanings:
| Path | Purpose |
|---|---|
/mcp/ |
MCP Streamable HTTP protocol endpoint used by official clients |
/ai/tools/mcp |
Permission-filtered HTTP JSON inspection catalog of generated tool metadata |
MCP requires trusted server-side authentication that resolves the bearer
credential into a Principal; enabling the route does not verify credentials
for your application. Follow the
complete MCP quickstart
for the copy-pasteable model → migration → REST → Principal → official client →
persisted invocation path.
Core Features
| Classification | Surface |
|---|---|
| Stable v0.6 | Async PostgreSQL ORM, relations and migrations |
| Stable v0.6 | Generated REST CRUD, validation, filters and pagination |
| Stable v0.6 | Principal, permissions, PolicyEngine, tenant and field enforcement |
| Stable v0.6 | MCP Streamable HTTP, generated tools, approval boundary, audit events, structured failures and runtime limits |
| Stable v0.6 | Core CLI, Doctor production policy, and PostgreSQL task queue |
| Functional but evolving | Admin details, storage backends, email, search, SDK generation and DurableStep |
| Experimental | Studio/Studio AI, planners, prompt providers, investigation sessions, code patches, memory and autonomous workflows |
MCP replay state, approval workflow storage, and audit retention are bounded or application-owned in v0.6. Cross-worker durable operations are planned for v0.7 and are not part of v0.6.1.
Security boundary
Applications verify credentials and resolve a server-owned Principal. Aksara
then applies covered permission, object, policy, field, tenant, ORM transaction,
and RLS checks to REST and MCP execution. Schemas and hidden UI controls are
helpful descriptions; they are not authorization controls.
For production:
aksara doctor security-check
aksara doctor production-check --release
Read the Security Overview and Production Hardening guide. Release gates and security tests provide repository evidence; they are not an external audit or certification.
Configuration
The global aksara.conf.settings object is the runtime source of truth. Use
environment variables for deploy-time values and configure(...) for explicit
Python overrides. Precedence is explicit configuration, AKSARA_* environment
variables, supported aliases such as DATABASE_URL, then defaults.
DATABASE_URL=postgresql://user:password@localhost:5432/opsdesk
AKSARA_DEBUG=true
AKSARA_MCP_ENABLED=false
AKSARA_AI_ENABLED=false
AKSARA_ENABLE_STUDIO=false
An AKSARA = {...} dictionary does not configure the runtime. See the
Settings Reference.
Open Studio
Studio is an experimental inspection and AI surface at /studio/ui. It is
disabled in new projects. Enabling it requires its secret/authentication and
production exposure settings; see the
Studio guide.
Use AI
Provider-backed prompt execution is optional and experimental. Configure the current AI Hub path when you need it:
aksara ai-hub configure
aksara ai-hub status
aksara ai-hub doctor
There is no public AgentRuntime or Planner class in v0.6.1. The documented
real primitives remain experimental and are described in the
AI Mode guide.
Use MCP
Set AKSARA_MCP_ENABLED=true only after adding server-side Principal
resolution, then connect an official MCP client to
http://127.0.0.1:8000/mcp/. MCP does not require an AI model provider.
Examples
From a source checkout, validate bundled examples with:
aksara examples validate --format json
Documentation
Roadmap
v0.6.1 aligns documentation, scaffolding, configuration, package metadata, and installed-wheel validation with the v0.6 product. It does not add the v0.7 durable-operation architecture. See the Roadmap.
Contributing
Read the Contributing Guide and Code of Conduct. Run the relevant tests and strict documentation build before opening a pull request.
License
Release files for aksara-framework 0.6.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aksara_framework-0.6.1.tar.gz | 3.5 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aksara_framework-0.6.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 4.4 MB
Release files / aksara_framework-0.6.1.tar.gz
| Download URL | aksara_framework-0.6.1.tar.gz |
|---|---|
| Size | 3.5 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d2d05e2dc925f6d73e454bd66050c32632c76a44b7f6fd5e0a962fa405ecd443
|
|
BLAKE2b-256 checksum How to use checksums |
de56b08d1c3db8dc9fe89fc07c4189dbd996841a2fd29d797a003c204f4e4f0e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.
Transparency logRelease files / aksara_framework-0.6.1-py3-none-any.whl
| Download URL | aksara_framework-0.6.1-py3-none-any.whl |
|---|---|
| Size | 925.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4efadd612db62c3c19494b467ead427b34ab1ebd938b53f40dd89e94aa4bdb5b
|
|
BLAKE2b-256 checksum How to use checksums |
7658d7b7d9cb80b94fdc7f90780ca8b0d2a615b0223b9af23e12ef1f4d7fe742
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 10, 2026.
Transparency log