JARVIS PDP
First-party OSS reference implementation of the ARP Policy Decision Point (PDP) service.
This reference implementation uses only the SDK packages:
arp-standard-server, arp-standard-model, and arp-standard-client, plus arp-policy and arp-auth.
It is designed to be a thin adapter to your real governance system (rules, OPA, internal policy services), while keeping a stable, spec-aligned request/response schema.
Implements: ARP Standard spec/v1 PDP API (contract: ARP_Standard/spec/v1/openapi/pdp.openapi.yaml).
Requirements
- Python >= 3.11
Install
python3 -m pip install -e .
Local configuration (optional)
For local dev convenience, copy the example env file:
cp .env.example .env.local
src/scripts/dev_server.sh auto-loads .env.local (or .env).
Run
- PDP listens on
http://127.0.0.1:8086by default.
python3 -m pip install -e .
python3 -m jarvis_pdp
[!TIP] Use
bash src/scripts/dev_server.sh --host ... --port ... --reloadfor dev convenience.
Using this repo
To build your own PDP, fork this repository and replace the decision logic while preserving request/response semantics.
If all you need is to change policy behavior, edit:
src/jarvis_pdp/service.py
Default behavior
- Deny-by-default when no profile or policy file is configured.
JARVIS_POLICY_PROFILE=dev-allowenables allow-all behavior for local dev.JARVIS_POLICY_PATHloads anarp-policyJSON policy file.- When a policy file is configured and a request includes
node_type_ref, PDP fetches theNodeTypefrom Node Registry and enriches the policy context (so callers do not need to embed NodeType metadata in the request).
Example policy: first-party atomic only
This repo includes an example arp-policy file that allows:
- composite nodes (e.g.
jarvis.composite.planner.general) - atomic nodes only when
jarvis.trust_tier == "first_party"
See: src/scripts/policy.first_party_atomic_only.json
To use it:
export JARVIS_POLICY_PATH=src/scripts/policy.first_party_atomic_only.json
Quick health check
curl http://127.0.0.1:8086/v1/health
Configuration
CLI flags:
--host(default127.0.0.1)--port(default8086)--reload(dev only)
Environment variables (Node Registry hydration):
JARVIS_NODE_REGISTRY_URL(enables NodeType metadata hydration for node-type policy decisions)JARVIS_NODE_REGISTRY_AUDIENCE(defaultarp-jarvis-noderegistry)- Outbound STS credentials (required when
JARVIS_NODE_REGISTRY_URLis set):ARP_AUTH_CLIENT_IDARP_AUTH_CLIENT_SECRETARP_AUTH_TOKEN_ENDPOINT(orARP_AUTH_ISSUER+ discovery)
Validate conformance (arp-conformance)
python3 -m pip install arp-conformance
arp-conformance check pdp --url http://127.0.0.1:8086 --tier smoke
arp-conformance check pdp --url http://127.0.0.1:8086 --tier surface
Helper scripts
-
src/scripts/dev_server.sh: run the server (flags:--host,--port,--reload). -
src/scripts/send_request.py: send a policy decision request from a JSON file.python3 src/scripts/send_request.py --request src/scripts/request.json
Authentication
Auth is enabled by default (JWT). To disable for local dev, set ARP_AUTH_PROFILE=dev-insecure.
To enable local Keycloak defaults, set:
ARP_AUTH_PROFILE=dev-secure-keycloakARP_AUTH_AUDIENCE=arp-pdpARP_AUTH_ISSUER=http://localhost:8080/realms/arp-dev
Upgrading
When upgrading to a new ARP Standard SDK release, bump pinned versions in pyproject.toml (arp-standard-*==...) and re-run conformance.
Release files for arp-jarvis-pdp 0.3.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| arp_jarvis_pdp-0.3.8.tar.gz | 12.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| arp_jarvis_pdp-0.3.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:24.6 kB
Release files / arp_jarvis_pdp-0.3.8.tar.gz
| Download URL | arp_jarvis_pdp-0.3.8.tar.gz |
|---|---|
| Size | 12.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6ddfe398add0fa3398ea4361b3cd199c3d36732e5774be24f6404db7ab7b5ba3
|
|
BLAKE2b-256 checksum How to use checksums |
6560d802bf28be8cd1b51fac23546ce1cd7169a3851923c3cda3df49cf2028a7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 4, 2026.
Transparency logRelease files / arp_jarvis_pdp-0.3.8-py3-none-any.whl
| Download URL | arp_jarvis_pdp-0.3.8-py3-none-any.whl |
|---|---|
| Size | 12.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
03288b4614b8393697eb0e44505b79cc90879faf64cc80581da87c14fe3f33b0
|
|
BLAKE2b-256 checksum How to use checksums |
c79c0e50d6cd30503910a4cea993bf9239bf905108de0c432dfd7a40ae1ea185
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jan 4, 2026.
Transparency log