This release has been yanked by its maintainers, and will be ignored by installers, except when explicitly specified.
Reason given by maintainers: Early build, no longer supported. Use 0.1.2 or later.
devora-fastapi
Recording, masking and activity preferences are configured in Devora Settings. SDK initialization overrides are ignored. New sessions retain the server's policy snapshot across exchange and resume. Developer privacy labels take effect only when selected in Settings; sensitive-field protection remains mandatory. See migration details.
FastAPI adapter for the Devora Python backend SDK.
Requirements
- Python
>=3.10,<4.0 - FastAPI
>=0.100.0,<1.0.0
Install
pip install devora-python devora-fastapi
Quick Start
from fastapi import FastAPI
from devora_sdk import DEVORA_ENDPOINTS, devora_sdk
from devora_sdk_fastapi import fastapi_router
sdk = devora_sdk(
api_key="pk_server_live_...",
secret_key="sk_server_live_...",
org_id="org_...",
)
@sdk.register(DEVORA_ENDPOINTS.USER_SEARCH)
async def search_users(req):
return {"users": await search_customer_users(req.query.get("term", ""))}
app = FastAPI()
app.include_router(fastapi_router(sdk), prefix="/devora")
For protected application routes, install the guard middleware and extract a trusted impersonation context from authenticated request state.
from devora_sdk import ImpersonationContext
from devora_sdk_fastapi import DevoraImpersonationGuardMiddleware
def get_impersonation_context(request) -> ImpersonationContext | None:
devora = getattr(request.state, "devora", None)
if not devora:
return None
return ImpersonationContext(
is_impersonation=devora["isImpersonation"],
scope=devora["scope"],
session_id=devora["sessionId"],
expires_at=devora["expiresAt"],
actor=devora["actor"],
subject=devora["subject"],
auth_method=devora["authMethod"],
authorization_source=devora["authorizationSource"],
recording_allowed=devora["recordingAllowed"],
impersonator=devora.get("impersonator"),
)
app.add_middleware(
DevoraImpersonationGuardMiddleware,
sdk=sdk,
get_impersonation_context=get_impersonation_context,
)
Register your own authentication middleware after this call — Starlette
runs middleware in the reverse of its registration order, so it must be the
outer layer that runs first for request.state to carry verified claims by
the time the guard reads them.
Resolve method overrides and route rewrites before the guard as well
(register that middleware after this call too, so it runs first). The guard
also judges every X-HTTP-Method-Override, X-HTTP-Method and
X-Method-Override value and any _method query parameter, but it cannot see a
_method field inside a request body, and it judges the path it receives.
expires_at must be a Unix timestamp in milliseconds. If your JWT stores Unix
seconds, multiply by 1000 when building the impersonation context. actor,
subject, auth_method, authorization_source, and recording_allowed are
all required — the guard rejects the context as invalid without them, even
though the dataclass marks them optional for construction convenience.
Metadata
Release files for devora-fastapi 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| devora_fastapi-0.1.0.tar.gz | 8.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| devora_fastapi-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.5 kB
Release files / devora_fastapi-0.1.0.tar.gz
| Download URL | devora_fastapi-0.1.0.tar.gz |
|---|---|
| Size | 8.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6014cc509916e94804f62d768b25ebfbd2dcc2821bdc4db2fb9213726f22017a
|
|
BLAKE2b-256 checksum How to use checksums |
60b56a842b8de3ef64c8ffd27c4e5c9b0e6dd13c01b47e4012618c780846b8c1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / devora_fastapi-0.1.0-py3-none-any.whl
| Download URL | devora_fastapi-0.1.0-py3-none-any.whl |
|---|---|
| Size | 9.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
32f67231136a805c483c50d475793c25cf52d84e23a292e8c2b4e5434038f0cb
|
|
BLAKE2b-256 checksum How to use checksums |
c078fb47911b81dc6bf3ccf2b8fce687a1fe6ca00316e0a80d19dce63674be4a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log