Skip to main content

Type-safe Python SDK for the Endor Labs REST API — resource facades, operational workflows, and optional agent-context bootstrap

Project description

Endor Labs SDK

Endor Labs

AURI by Endor Labs — agentic application security platform (CLI, API, MCP, Skills, Web UI)

AURI platform · Platform docs · Quick start

Python CI

Type-safe, resource-oriented Python client for the Endor Labs REST API. List, get, create, update, and delete resources (projects, findings, scan results, policies, namespaces, and the rest of the registry-backed resource set) with consistent patterns for filtering, pagination, namespace traversal, and IDE-friendly typed facades.

Start here

You want to… Go to
Use the SDK (API scripts, CI) InstallationQuick startno init() required
Bootstrap an AI agent (skills, offline OpenAPI) AGENTS.md
Try the SDK on a real tenant docs/guides/examples.md · Try it with skills
SDK contracts and deep reference docs/README.md
Contribute to this repo CONTRIBUTORS.md

Installation

pip install endorlabs

Or with uv:

uv add endorlabs

From the repository (editable):

git clone https://github.com/endorlabs/endorlabs-sdk.git
cd endorlabs-sdk
uv sync
# or: pip install -e .

Verify: uv run python -c "import endorlabs; print(endorlabs.__version__)"

Source repo: endorlabs/endorlabs-sdk — PyPI distribution name is endorlabs (import endorlabs).

Optional extras

Extra Install Enables
docs pip install 'endorlabs[docs]' User-docs sync (include_user_docs=True); OpenAPI download works on the base install
analytics pip install 'endorlabs[analytics]' DataFrame / Parquet export and estate graph metrics — see docs/estate/README.md

CSV export from workflows.estate.analyze.cardinality.tabular works without extras (utils.tabular re-exports the same API). In this repo: uv sync --extra docs --extra analytics.

Quick start

SDK-only — examples below do not call endorlabs.init(). For agent bootstrap, see AGENTS.md.

Entry point: endorlabs.Client(tenant=...). Resources are PascalCase facades (client.Project, client.Finding, …) matching endorctl api … --resource <Kind>.

Basic usage

import os
import endorlabs

client = endorlabs.Client(
    tenant=os.getenv("ENDOR_NAMESPACE", "your-tenant.namespace"),
    logging_level="ERROR",
)

namespaces = client.Namespace.list(traverse=True)
projects = client.Project.list(traverse=True, max_pages=1)

if projects:
    project = client.Project.get(projects[0].uuid)
    print(project.meta.name)

List field masks: a non-empty mask= on list() returns list[dict] wire JSON rows, not full Pydantic models. Omit mask when you need typed resources end-to-end. See docs/guides/consumer-ux-list-update.md.

Large estate lists: for project-scoped resources at scale, use endorlabs.tools.list_sharding or the endor-estate workflow CLI (see docs/contributing/list-query-performance.md).

Requesting a scan and waiting for results

repo_url = "https://github.com/tgowan-endor/BenchmarkJava.git"
project = client.Project.lookup(traverse=True, filter=f"meta.name=={repo_url}")

client.Project.update(project, scan_state="SCAN_STATE_REQUEST_FULL_RESCAN")

client.wait_until(
    lambda: (
        (p := client.Project.get(project))
        and p.processing_status.scan_state == "SCAN_STATE_IDLE"
    ),
    timeout=300,
)

scans = client.ScanResult.list(
    parent=project,
    max_pages=1,
    sort_by="meta.create_time",
    desc=True,
)

More patterns (filters, F(), masks, namespace scoping): docs/guides/consumer-ux-list-update.md, docs/guides/retrieving-scan-results.md.

Transport-only APIClient

from endorlabs import APIClient

client = APIClient()
response = client.get("v1/namespaces/tenant.namespace/projects")

Prefer endorlabs.Client for typed models and namespace handling.

Configuration

The SDK uses environment variables only (no config file loading). Precedence: constructor arguments → environment variables → built-in defaults.

Variable Purpose
ENDOR_API API base URL (default: https://api.endorlabs.com)
ENDOR_API_CREDENTIALS_KEY API key
ENDOR_API_CREDENTIALS_SECRET API secret
ENDOR_TOKEN Bearer token; validated first when set
ENDOR_NAMESPACE Default tenant namespace (e.g. tenant.namespace)
ENDOR_LOG_LEVEL Optional: DEBUG, INFO, WARNING, ERROR, CRITICAL
ENDOR_MAX_RETRIES Optional: retry count (default: 5)

Canonical naming is tenant.namespace.child; do not use UUIDs in namespace paths. Full semantics: docs/contracts.md.

Example .env for local runs:

ENDOR_API_CREDENTIALS_KEY=your-api-key
ENDOR_API_CREDENTIALS_SECRET=your-api-secret
ENDOR_NAMESPACE=your-tenant.namespace
ENDOR_LOG_LEVEL=INFO

Browser auth, SSO setup, and skill walkthroughs: docs/guides/examples.md.

Try it with skills

Guided tenant sessions use shipped agent skills — start with docs/guides/examples.md and AGENTS.md. Skills ship in the wheel (endorlabs.agent_knowledge_index_path()) or .endorlabs-context/sdk/skills/ after init().

Further reading

License

MIT. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

endorlabs-0.2.0.tar.gz (1.8 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

endorlabs-0.2.0-py3-none-any.whl (1.1 MB view details)

Uploaded Python 3

File details

Details for the file endorlabs-0.2.0.tar.gz.

File metadata

  • Download URL: endorlabs-0.2.0.tar.gz
  • Upload date:
  • Size: 1.8 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for endorlabs-0.2.0.tar.gz
Algorithm Hash digest
SHA256 c3c1c392d2f2603be63a7cb3f604961ff2dbd7c5bf5c24ba2cc31770a0aa1f6e
MD5 bb63d7604361f31fc08cb8ffbecc117d
BLAKE2b-256 04ba8a7f02c67aadd78fa55ec83fc2f4c02e1e9ddaf541baf360c0719dffa656

See more details on using hashes here.

Provenance

The following attestation bundles were made for endorlabs-0.2.0.tar.gz:

Publisher: release-tag-publish.yml on endorlabs/endorlabs-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file endorlabs-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: endorlabs-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for endorlabs-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ecae8fe1f38104ce5bdd0c6f4c134bbdabda2c707f80edff072649bef688b870
MD5 54cd33c29620b940b95ec701cc32eff8
BLAKE2b-256 5d7563f969202037b21eae027179eebd76ed5ead1676320a809f49cfc615b546

See more details on using hashes here.

Provenance

The following attestation bundles were made for endorlabs-0.2.0-py3-none-any.whl:

Publisher: release-tag-publish.yml on endorlabs/endorlabs-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page