Skip to main content

Client library for SpiceDB.

Project description

Authzed Python Client

PyPI License Build Status Mailing List Discord Server Twitter

This repository houses the Python client library for Authzed.

Authzed is a database and service that stores, computes, and validates your application's permissions.

Developers create a schema that models their permissions requirements and use a client library, such as this one, to apply the schema to the database, insert data into the database, and query the data to efficiently check permissions in their applications.

Supported client API versions:

  • v1 - Core SpiceDB API for permissions checks, schema management, and relationship operations
  • materialize/v0 - Materialize API for building materialized permission views

You can find more info on each API on the Authzed API reference documentation. Additionally, Protobuf API documentation can be found on the Buf Registry Authzed API repository.

See CONTRIBUTING.md for instructions on how to contribute and perform common tasks like building the project and running tests.

Getting Started

We highly recommend following the Protecting Your First App guide to learn the latest best practice to integrate an application with Authzed.

If you're interested in examples of a specific version of the API, they can be found in their respective folders in the examples directory.

Basic Usage

Installation

This project is packaged as the wheel authzed on the Python Package Index.

If you are using pip, the command to install the library is:

pip install authzed

Initializing a client

With the exception of gRPC utility functions found in grpcutil, everything required to connect and make API calls is located in a module respective to API version.

In order to successfully connect, you will have to provide a Bearer Token with your own API Token from the Authzed dashboard in place of t_your_token_here_1234567deadbeef in the following example:

from authzed.api.v1 import Client
from grpcutil import bearer_token_credentials


client = Client(
    "grpc.authzed.com:443",
    bearer_token_credentials("t_your_token_here_1234567deadbeef"),
)

Performing an API call

from authzed.api.v1 import (
    CheckPermissionRequest,
    CheckPermissionResponse,
    ObjectReference,
    SubjectReference,
)


post_one = ObjectReference(object_type="blog/post", object_id="1")
emilia = SubjectReference(object=ObjectReference(
    object_type="blog/user",
    object_id="emilia",
))

# Is Emilia in the set of users that can read post #1?
resp = client.CheckPermission(CheckPermissionRequest(
    resource=post_one,
    permission="reader",
    subject=emilia,
))
assert resp.permissionship == CheckPermissionResponse.PERMISSIONSHIP_HAS_PERMISSION

Insecure Client Usage

When running in a context like docker compose, because of Docker's virtual networking, the gRPC client sees the SpiceDB container as "remote." It has built-in safeguards to prevent calling a remote client in an insecure manner, such as using client credentials without TLS.

However, this is a pain when setting up a development or testing environment, so we provide the InsecureClient as a convenience:

from authzed.api.v1 import InsecureClient

client = InsecureClient(
    "spicedb:50051",
    "my super secret token"
)

Materialize API

The authzed-py supports Authzed Materialize API. The Materialize API allows you to build and maintain materialized views of your permissions data in your own systems for high-performance lookups.

Learn more in the Materialize API Quickstart Guide that can be found the examples directory.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

authzed-1.24.4.tar.gz (143.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

authzed-1.24.4-py3-none-any.whl (181.3 kB view details)

Uploaded Python 3

File details

Details for the file authzed-1.24.4.tar.gz.

File metadata

  • Download URL: authzed-1.24.4.tar.gz
  • Upload date:
  • Size: 143.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for authzed-1.24.4.tar.gz
Algorithm Hash digest
SHA256 eb427c266170787684d1202fa0aca6af7edb752489363a832cc40c6cf9e6bbf4
MD5 2c3dd5e8af1a5cd4b1f1859123d95b13
BLAKE2b-256 625990c13e155bdb9dc31a8484e50147aa1103b7040912cd058429562f3f7666

See more details on using hashes here.

Provenance

The following attestation bundles were made for authzed-1.24.4.tar.gz:

Publisher: publish-to-pypi.yml on authzed/authzed-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file authzed-1.24.4-py3-none-any.whl.

File metadata

  • Download URL: authzed-1.24.4-py3-none-any.whl
  • Upload date:
  • Size: 181.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for authzed-1.24.4-py3-none-any.whl
Algorithm Hash digest
SHA256 02c9dd7ff27246a5497af484ac7af50024fdbef1814bd3dc0596e7429ae6b82e
MD5 077d2c16f6fa6cc4e99337a8e27057ff
BLAKE2b-256 c364a1fdff538c12e4dc57e25ef9d3584cf7c3ba2955cba07ab9dcd1ee4f5ad9

See more details on using hashes here.

Provenance

The following attestation bundles were made for authzed-1.24.4-py3-none-any.whl:

Publisher: publish-to-pypi.yml on authzed/authzed-py

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page