Skip to main content

Connection Hub

The Python library and client SDK for the Connection Hub product.

Connection Hub gives every agent, automation, and connected application its own delegated-access card. The card records whose authority the caller uses, which resources and operations it may reach, which connected accounts it may use, and when that authority expires. A service resolves the current card and current capability catalog at the operation boundary, so an edit or revocation applies to the next call.

Install

python -m pip install connection-hub

0.0.3 is an alpha release. It contains the portable implementation used by the Connection Hub application in this repository:

  • versioned delegated cards and capability catalogs;
  • live card/catalog admission for managed REST, MCP, and named-service calls;
  • delegated OAuth client and connected-account policy contracts;
  • structured, actionable denial results;
  • direct protected-service admission with an opaque delegated bearer and an independent replay-protected workload proof;
  • explicit host ports for storage, identity, dispatch, secrets, and live delivery.

The same product is currently hosted in KDCube under the technical app id connection-hub@1-0. The library owns portable authority semantics and client contracts; the application host supplies authenticated sessions, storage, secret resolution, Redis protocol state, HTTP surfaces, and the user interface.

Direct Protected-Service Admission

An external backend can accept a user's opaque delegated bearer and ask the Connection Hub for a live decision about one concrete operation. The backend also signs the request with its own registered workload secret; possession of the user bearer alone is not service identity.

import secrets
import time

from connection_hub.delegated_credentials.admission import (
    AdmissionRequest,
    sign_admission_request,
)

request = AdmissionRequest(
    resource="https://api.example.test/customers",
    operation="customers.search",
)
timestamp = str(int(time.time()))
nonce = secrets.token_urlsafe(24)
signature = sign_admission_request(
    secret=service_signing_secret,
    service_id="crm-api",
    timestamp=timestamp,
    nonce=nonce,
    delegated_token=user_delegated_bearer,
    request=request,
)

The service sends the semantic request body and the four X-Connection-Hub-* proof headers to the configured Connection Hub admission endpoint, with the opaque delegated bearer in Authorization: Bearer .... An allow response contains a service-scoped subject and only the bounded authority relevant to that operation. It never returns provider credentials or the platform's internal user id.

See the runnable direct-admission-service and the deployment recipe.

Integration Boundaries

  • The service registry authenticates workloads and binds each service to resource selectors. It does not duplicate the operation/grant catalog.
  • Every decision intersects the delegated bearer with the current card and active catalog. A cached allow is not an authority source.
  • Connected-account credential resolution is a separate trusted operation; direct admission does not export provider secrets.
  • A protected backend still applies its own domain authorization after Connection Hub admission.

Documentation

License: MIT. Source: https://github.com/elenaviter/app-ecosystem

Release files for connection-hub 0.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for connection-hub 0.0.3
File Size Uploaded
connection_hub-0.0.3.tar.gz 259.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for connection-hub 0.0.3
File Interpreter ABI Platform
connection_hub-0.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 548.8 kB

Release files / connection_hub-0.0.3.tar.gz

Download URL connection_hub-0.0.3.tar.gz
Size 259.1 kB
Tags Source
SHA-256 checksum
How to use checksums
004bde9f21d3a91c0eccc64f3947b0c4582482de0d8bbcb8ba04683bf9c4fe8a
BLAKE2b-256 checksum
How to use checksums
c6a53a4bf1d9f577e81d33ee4be5057cf2cae47ac34dc90b222755f730f73756
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log

Release files / connection_hub-0.0.3-py3-none-any.whl

Download URL connection_hub-0.0.3-py3-none-any.whl
Size 289.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
14d18dddfac0613627279094f1d124b190f067d7f93f19520d52dab47ea1e71d
BLAKE2b-256 checksum
How to use checksums
1d0b6f522df640709571ba6885c620a73353d2fa39a83fae3af23f9eac49c39d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page