This release is a pre-release and may not be stable for production use.
dpdpkit-fastapi
FastAPI adapter for dpdpkit. It adds consent, versioned notices, rights requests and retention to your FastAPI app, with tables in your own database. This is the reference implementation of the dpdpkit REST contract.
Disclaimer. dpdpkit is software that helps you implement obligations under India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It does not provide legal advice and does not guarantee compliance. Decisions about notices, purposes, retention and incident reporting must be made by you or your counsel.
Install
pip install "dpdpkit[fastapi]" # or: pip install dpdpkit-fastapi
pip install "dpdpkit-fastapi[scheduler,postgres]" # APScheduler + psycopg
Quickstart
dpdpkit init # writes dpdpkit.yaml: purposes, notice text, contact details
from fastapi import Depends, FastAPI
from dpdpkit.fastapi import DPDPKit, require_consent
app = FastAPI()
dpdp = DPDPKit(
db_url=settings.DATABASE_URL,
config="dpdpkit.yaml", # policy pack, purposes, notice
principal_resolver=lambda request: request.state.user.id, # stable id, no personal data
admin_guard=lambda request: "admin" if request.state.user.is_staff else None,
signing_key=settings.DPDPKIT_SIGNING_KEY, # signs consent receipts
contact_resolver=lookup_contact, # principal -> Contact(email=..., phone=...)
notifier=SmtpNotifier("smtp.example.in", sender="privacy@example.in"),
)
dpdp.install(app, prefix="/dpdp") # router + error handlers + activity middleware + admin
@dpdp.kit.retention.register_handler
def erase(principal: str, purposes: list[str]) -> None: ... # delete or anonymise your own rows
@app.post("/offers/send", dependencies=[Depends(require_consent("marketing"))])
async def send_offer(): ...
dpdpkit migrate --db-url "$DATABASE_URL" # Alembic migrations shipped in the package
Run the scheduler in one process (or call dpdpkit retention run from cron):
dpdp.start_scheduler(retention_minutes=15) # retention run + daily ledger verification
What you get
| Component | Detail |
|---|---|
SqlAlchemyRepository |
SQLAlchemy 2.0; Postgres, MySQL, SQLite; microsecond timestamps so ledger hashes survive round trips |
| Migrations | Alembic, forward-only, shipped in the package (dpdpkit migrate) |
| Router | Full REST contract from dpdpkit-spec |
require_consent() |
Dependency returning 403 consent_required with the purpose |
| Roles | admin_guard returns viewer, handler or admin |
| Scheduler | APScheduler ([scheduler] extra); Celery and Arq entry points in v0.5 |
| Activity middleware | Records activity, restarting inactivity clocks and cancelling warned erasures |
| Admin mount | Serves the admin dashboard bundle (placeholder page until v0.4) |
Example
examples/fastapi_shop is a small shop with consent, requests and erasure
handlers. It passes the conformance suite:
cd examples/fastapi_shop
uvicorn app:app --reload # http://localhost:8000/docs
DPDPKIT_CONFORMANCE=1 DPDPKIT_ASGI_APP=app:app dpdpkit-conformance
Licence
Apache-2.0.
Metadata
Release files for dpdpkit-fastapi 0.1.0a1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dpdpkit_fastapi-0.1.0a1.tar.gz | 26.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dpdpkit_fastapi-0.1.0a1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 51.6 kB
Release files / dpdpkit_fastapi-0.1.0a1.tar.gz
| Download URL | dpdpkit_fastapi-0.1.0a1.tar.gz |
|---|---|
| Size | 26.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
707f629bb733b3b1aa254ed6d419baa4b855cefdac9f076c134dc220df7694b1
|
|
BLAKE2b-256 checksum How to use checksums |
e8a68a47a9c3b00620c6aadaf24f2e0731d24cb055cc14de6323318d21c9749b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / dpdpkit_fastapi-0.1.0a1-py3-none-any.whl
| Download URL | dpdpkit_fastapi-0.1.0a1-py3-none-any.whl |
|---|---|
| Size | 25.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0930e9e2c02614d3c7c6f145036b6897ba4162543f6ae05a384be27deb42dcb1
|
|
BLAKE2b-256 checksum How to use checksums |
a016c4ae3b526a867bcac571bdb8d07a3e7c016e833041badd8e9d938260650b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log