Skip to main content

A minimalist Python web framework with minimal external dependencies.

Project description

Asok Framework Logo

GitHub Stars License PyPI Version Python Version Tests

Full-stack Python. Zero runtime dependencies.


Asok is a batteries-included Python web framework built entirely on the standard library. It gives you routing, ORM, templates, admin interface, REST and GraphQL APIs, WebSockets, background tasks, and SSG/ISR โ€” all from a single pip install, with nothing else required at runtime.

Built for developers who want a complete stack without assembling one.

๐ŸŒ Documentation ยท ๐Ÿ’ฌ Discord ยท ๐ŸŽฅ Tutorials


When to choose Asok

Flask Django Asok
Runtime dependencies ~6 ~20+ transitive 0
ORM built-in โœ— โœ“ โœ“
Admin interface โœ— โœ“ โœ“
File-based routing โœ— โœ— โœ“
GraphQL built-in โœ— โœ— โœ“
WebSockets built-in โœ— โœ— โœ“
Reactive components โœ— โœ— โœ“
SSG / ISR โœ— โœ— โœ“
Auto OpenAPI docs โœ— โœ— โœ“
Background tasks โœ— โœ— โœ“

Choose Asok when you want a full stack out of the box, dependency auditability matters (security-critical environments, embedded deployments, strict supply chain policies), or you're a solo developer or small team who doesn't want to assemble and maintain a stack of integrations.


A complete app in one file

# wsgi.py
from asok import Asok, Field, Model, Admin

app = Asok(__name__)

class Post(Model):
    title   = Field.String(nullable=False)
    body    = Field.Text()
    author  = Field.String()

admin = Admin(app)
# src/pages/page.py
from asok import Request
from src.models.post import Post

def render(request: Request):
    posts = Post.query().order_by("-id").limit(10).get()
    return request.render("page.html", posts=posts)

That's a working app with database, admin interface, and a paginated index page. Run it:

pip install asok
asok create my-blog && cd my-blog
asok migrate
asok dev

Live Interactivity & Reactivity (No Client JS Needed)

Asok provides two built-in options for building interactive frontends, both operating on Zero-Eval Security (strict CSP compliance, no 'unsafe-eval' required).

1. Live Stateful Components (Real-time WebSockets)

Create reactive, server-side components that synchronize state automatically over WebSockets using the @exposed decorator.

# src/components/counter.py
from asok import Component
from asok.component import exposed

class Counter(Component):
    """Reusable UI component for Counter."""
    count = 0

    @exposed
    def increment(self):
        self.count += 1

    def render(self):
        return self.html("counter.html")
<!-- src/components/counter.html -->
<div>
    <h3>Count: {{ count }}</h3>
    <button ws-click="increment">Add 1</button>
</div>
<!-- In any page template (e.g., src/pages/page.html) -->
{{ component('Counter', count=10) }}

2. Client-Side Reactive Directives

For offline or local state updates, use native lightweight reactive directives directly in your HTML markup (~5KB client runtime, zero build step):

<div asok-state="{ count: 0 }">
  <h3>Count: <span asok-text="count"></span></h3>
  <button asok-on:click="count++">Add 1</button>
</div>

Features

Routing & Templates

  • File-based routing โ€” src/pages/blog/[slug]/page.py maps to /blog/hello-world
  • Dynamic parameters โ€” [id], [slug:slug], catch-all patterns
  • Template engine โ€” Jinja-compatible with inheritance, macros, and auto-escaping
  • HTML streaming โ€” chunked responses for instant TTFB

ORM

  • Multi-database โ€” SQLite (default), PostgreSQL, MySQL with connection pooling
  • Relations โ€” HasMany, BelongsTo, BelongsToMany, MorphTo, self-referencing
  • Migrations โ€” automatic schema diffing, rollback, multi-DB
  • Security โ€” parameterized queries, column whitelisting, mass-assignment protection, encrypted fields (Fernet AES-256)
  • Password fields โ€” PBKDF2-SHA256 with 600,000 iterations

API

  • REST โ€” decorator-based routes with automatic OpenAPI 3.0 generation and live Swagger UI
  • GraphQL โ€” schema auto-generated from ORM models, playground in development, WS subscriptions
  • API versioning โ€” URL-based and header-based, deprecation sunset headers
  • Bearer token auth โ€” HMAC-signed, configurable expiry

Real-time

  • WebSockets โ€” rooms, presence tracking, typing indicators, direct messages
  • Live components โ€” server-driven reactive UI over WebSockets
  • Client reactivity โ€” asok-state, asok-on:click, asok-text directives (~3KB, no build step)

Admin interface

  • Auto-generated CRUD for every model
  • Role-based access control (RBAC)
  • Two-factor authentication (TOTP + backup codes)
  • Audit logs, inline editing, advanced filters
  • Fully customizable templates

Infrastructure

  • WSGI + ASGI โ€” run on Gunicorn or Uvicorn
  • Background tasks โ€” thread pool (local) or Redis queue (asok worker) with HMAC-signed job envelopes
  • Caching โ€” in-memory, Redis, fragment caching
  • Sessions โ€” HMAC-signed, Redis-backed, HttpOnly + SameSite=Strict
  • Static site generation โ€” SSG for static routes, ISR with background cache warming
  • Islands architecture โ€” selective hydration for performance-critical pages
  • Email โ€” SMTP with templates, async dispatch via Redis
  • S3 storage โ€” AWS S3 integration with automatic mime-type detection

Security (audited)

  • CSRF protection with auto-rotation and HMAC validation
  • Content Security Policy with per-request nonces
  • HSTS, X-Frame-Options, X-Content-Type-Options, Permissions-Policy
  • HTML and SVG sanitizer (two-pass whitelist)
  • Path traversal prevention on file uploads
  • SQL injection protection (parameterized queries + identifier validation)
  • Rate limiting (per-IP, per-user, configurable windows)
  • GraphQL mutations blocked by default without GRAPHQL_AUTHORIZE

Developer experience

  • CLI โ€” asok create, asok dev, asok migrate, asok make model, asok build
  • Production build โ€” bytecode compilation, JS/CSS minification, WebP conversion
  • Testing โ€” built-in test client, TestClient, fixture helpers
  • Developer toolbar โ€” request inspector, query analyzer, cache stats in-browser
  • i18n โ€” {{ __('key') }} with JSON locale files, translation management UI
  • Extensions โ€” community plugin system with secure path sandboxing
  • VSCode extension โ€” syntax highlighting, IntelliSense, route navigation

Installation

pip install asok

Asok has zero runtime dependencies. SQLite works out of the box. Add extras only if you need them:

pip install "asok[postgres]"        # PostgreSQL
pip install "asok[mysql]"           # MySQL
pip install "asok[redis]"           # Redis (caching, sessions, background tasks)
pip install "asok[async]"           # ASGI / async support
pip install "asok[postgres,redis]"  # Combined

Quick start

asok create my-project
cd my-project
asok dev

Open http://localhost:8000. Edit src/pages/page.html to start.


Project structure

my-project/
โ”œโ”€โ”€ src/
โ”‚   โ”œโ”€โ”€ components/       # Reactive components
โ”‚   โ”œโ”€โ”€ locales/          # Translations (en.json, fr.json, ...)
โ”‚   โ”œโ”€โ”€ middlewares/      # Request interceptors
โ”‚   โ”œโ”€โ”€ models/           # ORM models
โ”‚   โ”œโ”€โ”€ pages/            # Routes (page.py + page.html)
โ”‚   โ””โ”€โ”€ partials/         # css, js, images, uploads
โ””โ”€โ”€ wsgi.py               # Entry point

Production

# WSGI
gunicorn wsgi:app

# ASGI
uvicorn asgi:app

Required environment variables:

DEBUG=false
SECRET_KEY=your-64-character-key   # generate: python -c "import secrets; print(secrets.token_hex(32))"
APP_URL=https://yourdomain.com
DATABASE_URL=sqlite:///data/prod.db

Generate a deployment config:

asok deploy   # outputs Gunicorn + Nginx + SystemD configs
asok build    # optimized production build (bytecode + minification)

Roadmap

Version Status Focus
v0.4.0 โœ… Released (June 2026) GraphQL, extensions, SSG/ISR, advanced WebSockets
v0.5.0 โœ… Released (June 2026) Security hardening, GraphQL auth, signed Redis jobs, offline GraphiQL
v1.0.0 ๐Ÿ“‹ Q3 2026 Stable API, monitoring, multi-tenancy, CDN pipeline

Full details in ROADMAP.md.


Contributing

git clone https://github.com/asok-framework/asok.git
cd asok
python -m venv venv && source venv/bin/activate
pip install -e .
python -m pytest

License

MIT โ€” see LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

asok-0.5.0.tar.gz (787.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

asok-0.5.0-py3-none-any.whl (855.6 kB view details)

Uploaded Python 3

File details

Details for the file asok-0.5.0.tar.gz.

File metadata

  • Download URL: asok-0.5.0.tar.gz
  • Upload date:
  • Size: 787.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for asok-0.5.0.tar.gz
Algorithm Hash digest
SHA256 6892fb6fd96d149ac7bd894f4dcc2528a5e426a7978b934fc49b5a921ba58cde
MD5 d4aa021ec9b35a82fd569a150eca804c
BLAKE2b-256 80f57202eae011bc7e7043ec77a5629dbb33548b74a05146c7b6d9c7e834944a

See more details on using hashes here.

Provenance

The following attestation bundles were made for asok-0.5.0.tar.gz:

Publisher: release.yml on asok-framework/asok

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file asok-0.5.0-py3-none-any.whl.

File metadata

  • Download URL: asok-0.5.0-py3-none-any.whl
  • Upload date:
  • Size: 855.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for asok-0.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 fac1e998d20059d1cbd0af1cb412f85c3a41847011dd8a209950606f3413638f
MD5 d76d364bab555168dfe951a96e28da2f
BLAKE2b-256 8d0b81c128596f3240a5b714fe84ba58251101b22679ac2e1a98756135f1624e

See more details on using hashes here.

Provenance

The following attestation bundles were made for asok-0.5.0-py3-none-any.whl:

Publisher: release.yml on asok-framework/asok

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page