Backend SDK
| Category | Technologies |
|---|---|
| Coverage | |
| Runtime | |
| Auth integration | |
| Testing | |
| Quality | |
| Tools | |
| CI/CD |
Shared backend library for alittlemore.dev: integrations, domain objects, middleware, helpers, utilities, and factories.
Package: alittlemore-backend-sdk · Import: backend_sdk · License: MIT
Python: latest stable minor + its predecessor, all patch releases; currently 3.14.x and 3.13.x.
Tooling: uv, Hatchling, Ruff, mypy, pytest, Bandit, pip-audit, Twine.
Development
Requires uv and GNU Make.
make install # Install dependencies
make quality # Run all checks
make build # Build wheel and sdist
make help # List commands
Auth API integration
Install the Litestar integration:
uv add 'alittlemore-backend-sdk[litestar]'
from backend_sdk.auth import RoleEnum
from backend_sdk.auth.http import AuthApiClientConfig
from backend_sdk.integrations.litestar import AuthPlugin, RequireRole
from litestar import Litestar, get
@get("/health", opt={"auth_public": True})
async def health() -> dict[str, str]:
return {"status": "ok"}
app = Litestar(
route_handlers=[health],
plugins=[
AuthPlugin(
config=AuthApiClientConfig(
verify_url="https://auth.example.com/api/auth/verify",
timeout_seconds=2,
cache_ttl_seconds=15,
max_cache_entries=10_000,
),
),
],
)
Routes require a bearer token by default. Mark anonymous routes with
opt={"auth_public": True} and protect privileged routes with
RequireRole(RoleEnum.ADMIN). Successful checks are cached in each process for
at most 15 seconds; set cache_ttl_seconds=0 to disable this. Services must
still enforce resource ownership in their own domain logic.
The cache is intentionally process-local: it is a short availability and latency optimization, adds no infrastructure dependency, and never becomes an authorization source of truth. Each process can perform one auth-api request per token and TTL.
See examples/litestar_auth.py for public, authenticated,
and administrator routes in one application.
Release files for alittlemore-backend-sdk 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| alittlemore_backend_sdk-0.1.0.tar.gz | 12.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| alittlemore_backend_sdk-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 22.8 kB
Release files / alittlemore_backend_sdk-0.1.0.tar.gz
| Download URL | alittlemore_backend_sdk-0.1.0.tar.gz |
|---|---|
| Size | 12.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c55c8c2e6e7c3daddee25d5f9ccdb2b37cde292a5b8e078e9b24eba5162d14c5
|
|
BLAKE2b-256 checksum How to use checksums |
7e3e7f74689975d58e6759403b3af84e272164ab9563942a5d61fc9952129c26
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 17, 2026.
Transparency logRelease files / alittlemore_backend_sdk-0.1.0-py3-none-any.whl
| Download URL | alittlemore_backend_sdk-0.1.0-py3-none-any.whl |
|---|---|
| Size | 9.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f83dbf4df1246b7a6cff33646cc3df407c68f85e0d4445d4314a72aa5a56c2d5
|
|
BLAKE2b-256 checksum How to use checksums |
0274606e858602b71f47bde7ffe93d6d317e2dde58565eb5e597a244123d47a6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 17, 2026.
Transparency log