This release has been yanked by its maintainers, and will be ignored by installers, except when explicitly specified.
Reason given by maintainers: Early build, no longer supported. Use 0.1.2 or later.
devora-python
Recording, masking and activity preferences are configured in Devora Settings. SDK initialization overrides are ignored. New sessions retain the server's policy snapshot across exchange and resume. Developer privacy labels take effect only when selected in Settings; sensitive-field protection remains mandatory. See migration details.
Python backend core SDK for Devora customer integrations.
Requirements
- Python
>=3.10,<4.0
Install
pip install devora-python
Quick Start
from devora_sdk import DEVORA_ENDPOINTS, devora_sdk
sdk = devora_sdk(
api_key="pk_server_live_...",
secret_key="sk_server_live_...",
org_id="org_...",
)
@sdk.register(DEVORA_ENDPOINTS.USER_SEARCH)
def search_users(req):
return {"users": search_customer_users(req.query.get("term", ""))}
@sdk.register(DEVORA_ENDPOINTS.IMPERSONATE)
def impersonate(req):
context = req.devora_context
token = create_customer_token(context.target_user["id"], context)
return {"token": token}
Use process_request() for sync frameworks, async_process_request() for
async frameworks, or use the Django and FastAPI adapter packages.
Production replay store
Every signed request carries a single-use id. In production the SDK needs a
shared, atomic replay_store so a captured request cannot be replayed against
another worker or instance; the in-memory store is for
environment="development" or "test" only, and any other environment refuses
to start without one.
import os
import redis
from devora_sdk import devora_sdk
client = redis.Redis.from_url(os.environ["REDIS_URL"])
class RedisReplayStore:
def consume(self, namespace: str, request_id: str, expires_at: int) -> bool:
# Atomic insert-if-absent that lives until expires_at (Unix ms).
# Exceptions propagate: the SDK then fails closed with a 503.
return bool(
client.set(f"devora:replay:{namespace}:{request_id}", b"1", nx=True, pxat=expires_at)
)
sdk = devora_sdk(
api_key=os.environ["DEVORA_API_KEY"],
secret_key=os.environ["DEVORA_SECRET_KEY"],
org_id=os.environ["DEVORA_ORG_ID"],
replay_store=RedisReplayStore(),
)
consume is called synchronously, including from async_process_request;
keep it a single short round trip. Do not let the store evict these keys
before they expire. A unique-key database insert with an expiry column works
too.
The guard's session-liveness checker caches at most 1,024 results and permits at most 64 distinct concurrent lookups per checker. Requests for the same session share a lookup. Live/ended results use the configured TTL (five seconds by default); unavailable results use at most one second. Cache hits never extend a verdict's lifetime. Capacity exhaustion follows the configured unavailable policy, which denies access by default.
Cold-start latency
The impersonation guard's scope policy is fetched lazily on first use, so the
first request handled by a freshly started worker process pays for that fetch
synchronously (and any request racing it gets a 503 IMPERSONATION_POLICY_UNAVAILABLE rather than waiting). If your deployment
runs multiple worker processes (gunicorn, uWSGI, etc.), pass
prefetch_scope_config=True to warm the cache in the background as soon as
devora_sdk(...) is constructed, before the process starts serving traffic:
sdk = devora_sdk(
api_key="pk_server_live_...",
secret_key="sk_server_live_...",
org_id="org_...",
prefetch_scope_config=True,
)
Metadata
Release files for devora-python 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| devora_python-0.1.0.tar.gz | 27.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| devora_python-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 63.1 kB
Release files / devora_python-0.1.0.tar.gz
| Download URL | devora_python-0.1.0.tar.gz |
|---|---|
| Size | 27.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bbaf99d0758e8a2fee33ff6f91e937d8ce14d7e8e4cfad6cdc6da108bcb17e6c
|
|
BLAKE2b-256 checksum How to use checksums |
107959af59ca260ed872e160f4fd5c68a743fa8b97c73707f13472609c004ed9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / devora_python-0.1.0-py3-none-any.whl
| Download URL | devora_python-0.1.0-py3-none-any.whl |
|---|---|
| Size | 35.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e24c173b9cc51cb8cb84838ed04e6df1794f48f8b6ab7a15622d544ec0d6803e
|
|
BLAKE2b-256 checksum How to use checksums |
7210a507eb625666f62fe8658aefa400f6dbd8ab5c869d9b6d5bc3de0ebfe6a9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log