Backend SDK
| Category | Technologies |
|---|---|
| Coverage | |
| Runtime | |
| Auth integration | |
| Testing | |
| Quality | |
| Tools | |
| CI/CD |
Shared backend library for alittlemore.dev: integrations, domain objects, middleware, helpers, utilities, and factories.
Package: alittlemore-backend-sdk · Import: backend_sdk · License: MIT
Python: latest stable minor + its predecessor, all patch releases; currently 3.14.x and 3.13.x.
Tooling: uv, Hatchling, Ruff, mypy, pytest, Bandit, pip-audit, Twine.
Development
Requires uv and GNU Make.
make install # Install dependencies
make quality # Run all checks
make build # Build wheel and sdist
make help # List commands
Auth API integration
Install the Litestar integration:
uv add 'alittlemore-backend-sdk[litestar]'
from backend_sdk.auth import Principal, RoleEnum
from backend_sdk.auth.http import AuthApiClientConfig
from backend_sdk.integrations.litestar import AuthContext, AuthPlugin, RequireRole
from litestar import Litestar, Request, get
from litestar.datastructures import State
@get("/health", opt={"auth_public": True})
async def health() -> dict[str, str]:
return {"status": "ok"}
@get("/activity", opt={"auth_optional": True})
async def activity(
request: Request[Principal, AuthContext | None, State],
) -> dict[str, str]:
return {"username": request.user.username}
app = Litestar(
route_handlers=[health, activity],
plugins=[
AuthPlugin(
config=AuthApiClientConfig(
verify_url="https://auth.example.com/api/auth/verify",
timeout_seconds=2,
cache_ttl_seconds=15,
max_cache_entries=10_000,
),
),
],
)
Routes require a bearer token by default. Mark anonymous routes with
opt={"auth_public": True}. Use opt={"auth_optional": True} when a route accepts
anonymous requests but should authenticate a bearer token when one is present; this also
overrides an inherited auth_public option. Malformed or invalid supplied credentials still
return 401, and an unavailable verifier returns 503. Protect privileged routes with
RequireRole(RoleEnum.ADMIN). Successful checks are cached in each process for at most 15
seconds; set cache_ttl_seconds=0 to disable this. Services must still enforce resource
ownership in their own domain logic.
The cache is intentionally process-local: it is a short availability and latency optimization, adds no infrastructure dependency, and never becomes an authorization source of truth. Each process can perform one auth-api request per token and TTL.
See examples/litestar_auth.py for public, authenticated,
and administrator routes in one application.
Release files for alittlemore-backend-sdk 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| alittlemore_backend_sdk-0.2.0.tar.gz | 13.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| alittlemore_backend_sdk-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 24.0 kB
Release files / alittlemore_backend_sdk-0.2.0.tar.gz
| Download URL | alittlemore_backend_sdk-0.2.0.tar.gz |
|---|---|
| Size | 13.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
531227edd5fb01eb4919fc47c04d615e94be9c72210e3deb4b8b13a193d033ba
|
|
BLAKE2b-256 checksum How to use checksums |
6e6a5ca67b81ff9dbb976950c74fcd9ebb46bbf52c255cd529870b80cd3f17f4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 17, 2026.
Transparency logRelease files / alittlemore_backend_sdk-0.2.0-py3-none-any.whl
| Download URL | alittlemore_backend_sdk-0.2.0-py3-none-any.whl |
|---|---|
| Size | 10.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ea06ecd911857280593f447d610ca99b9a113fbe3e9f1eede11aec0de4710922
|
|
BLAKE2b-256 checksum How to use checksums |
dee5b23a2cf01b80b5909e292a5c1b9d8a45c4f16ab27ef67d707dec823b529c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 17, 2026.
Transparency log