This release is a pre-release and may not be stable for production use.
Dogwood Policy Python SDK
Python SDK and PyO3 binding for the Dogwood policy language. Dogwood supports fine-grained authorization decisions that depend on history or patterns of events over time, then lowers policies back to Cedar for evaluation.
For full documentation, see dogwood-py.abhishek-tiwari.com.
⚠️⚠️⚠️ Current Dogwood reference interpreter is not intended for production use; therefore, this Python SDK and PyO3 binding is experimental in nature.
Note: This is an unofficial Python SDK and port for Dogwood Policy. Support is provided on a best effort basis with community help.
Install
pip install dogwood-py
Optional extras:
pip install "dogwood-py[examples]" # FastAPI and general examples
pip install "dogwood-py[strands]" # Strands integration and shopping-agent example
pip install "dogwood-py[examples,strands]"
The package installs as dogwood:
from dogwood import native
assert native.available()
What It Provides
The public API follows the Rust dogwood-language lifecycle:
- Build a
ServiceSchemaandPolicySchema. - Parse and lower policy source into a
LoweredPolicySet. - Validate it.
- Feed
Eventvalues to a statefulAuthorizer.
The native path uses PyO3/maturin to call the Rust Dogwood reference implementation for schema-backed lowering, validation, trace replay, augmented Cedar schema export, and authorization. A temporary pure-Python fallback remains only for limited schema-less examples.
The Python SDK includes a PolicyEnforcer wrapper with mode="enforce" and mode="log_only" for rollout and audit behavior. Dogwood still evaluates the policy; the SDK mode controls whether a denied decision blocks the operation or is reported as would_have_denied.
dogwood-py also provides optional Strands Agents support. Dogwood policies can be attached as Strands interventions so tool calls are checked before execution, with typed outcomes such as proceed, deny, guide, confirm, and transform.
Strands integrations use the same SDK-level enforce and log_only modes on top of the Rust Dogwood policy decision.
Documentation
- Installation
- Getting Started
- Native Rust Binding
- Strands Agents Integration
- PolicyEnforcer API
- Examples
- API Reference
Dogwood language documentation is available at dogwood-policy.github.io/dogwood.
Examples
Checked-in examples are documented at Examples. After installing the package and optional dependencies, run examples directly:
python -m examples.api_usage
python -m examples.cli
python -m uvicorn examples.fastapi_simple.app:app --host 127.0.0.1 --port 8000
python -m examples.strands_shopping_agent.agent --user alice
Development
make setup
make develop
make test
make docs
make build
Useful targets:
make docs-ciinstalls docs-only dependencies and builds Sphinx HTML docs.make docs-watchserves live-reloading docs athttp://127.0.0.1:8001.make perf-testruns the opt-in native-vs-Python replay regression check.
The docs-only Cloudflare Pages build command is:
make docs-ci PYTHON=python
Build output directory:
docs/build/html
Current Scope
Rust-backed operations cover schema-backed lowering, validation, authorization, and trace replay. The Python fallback is temporary and schema-less only. The intended end state is to remove it once the Rust-backed SDK objects cover the same ergonomic surface.
Metadata
Release files for dogwood-py 0.0.7.dev27
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dogwood_py-0.0.7.dev27.tar.gz | 42.5 kB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| dogwood_py-0.0.7.dev27-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| dogwood_py-0.0.7.dev27-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ x86-64 | Details |
| dogwood_py-0.0.7.dev27-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl | CPython 3.10 | abi3 | Linux glibc 2.17+ ARM64 | Details |
| dogwood_py-0.0.7.dev27-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
| dogwood_py-0.0.7.dev27-cp310-abi3-macosx_10_12_x86_64.whl | CPython 3.10 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 28.6 MB
Release files / dogwood_py-0.0.7.dev27.tar.gz
| Download URL | dogwood_py-0.0.7.dev27.tar.gz |
|---|---|
| Size | 42.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a256153532a117f102686f6ea613fcee36c277dc54417ac5870a645bd525897c
|
|
BLAKE2b-256 checksum How to use checksums |
d210d0d3a9d3ec05c17a56ab0d0cd554f9dea6540b3b08036a7c9bc86898e49a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency logRelease files / dogwood_py-0.0.7.dev27-cp310-abi3-win_amd64.whl
| Download URL | dogwood_py-0.0.7.dev27-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 5.4 MB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
5ab397c35b04489dfe3509d4391c3bc8d8021293f18425f0c80e2509512d10b0
|
|
BLAKE2b-256 checksum How to use checksums |
8274e053dae68101a7d85ec3e6bc2bf5b655cc6f8e031fd9b2f68d9835c9f1d8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency logRelease files / dogwood_py-0.0.7.dev27-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | dogwood_py-0.0.7.dev27-cp310-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 6.2 MB |
| Tags | CPython 3.10 Linux glibc 2.17+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
f7e9b3d43add26ca7f811afa7c975c9c4701a3d9ef85c5ab09999b894038e020
|
|
BLAKE2b-256 checksum How to use checksums |
323c523a5438f9a685a21b3cb51d707b5625399a1979b4362ba0023d8f95e228
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency logRelease files / dogwood_py-0.0.7.dev27-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
| Download URL | dogwood_py-0.0.7.dev27-cp310-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl |
|---|---|
| Size | 6.0 MB |
| Tags | CPython 3.10 Linux glibc 2.17+ ARM64 abi3 |
|
SHA-256 checksum How to use checksums |
df70f4bade5d59079cfe1d95b5f2e80ea183b3d6f9c34bccfeadd59de5255f47
|
|
BLAKE2b-256 checksum How to use checksums |
a7e8184810af8a102053e44a8e5af08a1562eb8140cf982948f4e20f3237ebd3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency logRelease files / dogwood_py-0.0.7.dev27-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | dogwood_py-0.0.7.dev27-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 5.4 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
1ba244b04cf0dee127c57076b0a0831a13faebc47d0855d1abcf678c0aef4dfe
|
|
BLAKE2b-256 checksum How to use checksums |
5906d4c08b7b52a5c66ac05604a95699301becce3aa065acee1322d9c01e79bb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency logRelease files / dogwood_py-0.0.7.dev27-cp310-abi3-macosx_10_12_x86_64.whl
| Download URL | dogwood_py-0.0.7.dev27-cp310-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 5.6 MB |
| Tags | CPython 3.10 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
59c801cf5a5f41e6a272c553b4bcd3e86f77c2b77919d9a8393cf3e2298bf990
|
|
BLAKE2b-256 checksum How to use checksums |
d778d478ae9bae0da80132dd167c039294365d2c931cad6670dfb405606c1481
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 15, 2026.
Transparency log