Connection Hub
The Python library and client SDK for the Connection Hub product.
Connection Hub gives every agent, automation, and connected application its own delegated-access card. The card records whose authority the caller uses, which resources and operations it may reach, which connected accounts it may use, and when that authority expires. A service resolves the current card and current capability catalog at the operation boundary, so an edit or revocation applies to the next call.
Install
python -m pip install connection-hub
0.0.3 is an alpha release. It contains the portable implementation used by
the Connection Hub application in this repository:
- versioned delegated cards and capability catalogs;
- live card/catalog admission for managed REST, MCP, and named-service calls;
- delegated OAuth client and connected-account policy contracts;
- structured, actionable denial results;
- direct protected-service admission with an opaque delegated bearer and an independent replay-protected workload proof;
- explicit host ports for storage, identity, dispatch, secrets, and live delivery.
The same product is currently hosted in KDCube under the technical app id
connection-hub@1-0. The library
owns portable authority semantics and client contracts; the application host
supplies authenticated sessions, storage, secret resolution, Redis protocol
state, HTTP surfaces, and the user interface.
Direct Protected-Service Admission
An external backend can accept a user's opaque delegated bearer and ask the Connection Hub for a live decision about one concrete operation. The backend also signs the request with its own registered workload secret; possession of the user bearer alone is not service identity.
import secrets
import time
from connection_hub.delegated_credentials.admission import (
AdmissionRequest,
sign_admission_request,
)
request = AdmissionRequest(
resource="https://api.example.test/customers",
operation="customers.search",
)
timestamp = str(int(time.time()))
nonce = secrets.token_urlsafe(24)
signature = sign_admission_request(
secret=service_signing_secret,
service_id="crm-api",
timestamp=timestamp,
nonce=nonce,
delegated_token=user_delegated_bearer,
request=request,
)
The service sends the semantic request body and the four X-Connection-Hub-* proof
headers to the configured Connection Hub admission endpoint, with the opaque
delegated bearer in Authorization: Bearer .... An allow response contains a
service-scoped subject and only the bounded authority relevant to that
operation. It never returns provider credentials or the platform's internal
user id.
See the runnable
direct-admission-service
and the deployment recipe.
Integration Boundaries
- The service registry authenticates workloads and binds each service to resource selectors. It does not duplicate the operation/grant catalog.
- Every decision intersects the delegated bearer with the current card and active catalog. A cached allow is not an authority source.
- Connected-account credential resolution is a separate trusted operation; direct admission does not export provider secrets.
- A protected backend still applies its own domain authorization after Connection Hub admission.
Documentation
- Connection Hub architecture and semantic requirements
- Delegated authority and admission
- Delegated access cards
- OAuth delegated credential protocol
- Package extraction boundary
- Package release procedure
License: MIT. Source: https://github.com/elenaviter/app-ecosystem
Release files for connection-hub 0.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| connection_hub-0.0.3.tar.gz | 259.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| connection_hub-0.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 548.8 kB
Release files / connection_hub-0.0.3.tar.gz
| Download URL | connection_hub-0.0.3.tar.gz |
|---|---|
| Size | 259.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
004bde9f21d3a91c0eccc64f3947b0c4582482de0d8bbcb8ba04683bf9c4fe8a
|
|
BLAKE2b-256 checksum How to use checksums |
c6a53a4bf1d9f577e81d33ee4be5057cf2cae47ac34dc90b222755f730f73756
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.
Transparency logRelease files / connection_hub-0.0.3-py3-none-any.whl
| Download URL | connection_hub-0.0.3-py3-none-any.whl |
|---|---|
| Size | 289.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
14d18dddfac0613627279094f1d124b190f067d7f93f19520d52dab47ea1e71d
|
|
BLAKE2b-256 checksum How to use checksums |
1d0b6f522df640709571ba6885c620a73353d2fa39a83fae3af23f9eac49c39d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 30, 2026.
Transparency log