Skip to main content

Type-safe Python SDK for the Endor Labs REST API — resource facades, operational workflows, and optional agent-context bootstrap

Project description

Endor Labs SDK

Endor Labs

AURI by Endor Labs — agentic application security platform (CLI, API, MCP, Skills, Web UI)

AURI platform · Platform docs · Quick start

Python CI

Type-safe, resource-oriented Python client for the Endor Labs REST API. List, get, create, update, and delete resources (projects, findings, scan results, policies, namespaces, and the rest of the registry-backed resource set) with consistent patterns for filtering, pagination, namespace traversal, and IDE-friendly typed facades.

Start here

You want to… Go to
Use the SDK (API scripts, CI) InstallationQuick startno init() required
Bootstrap an AI agent (skills, offline OpenAPI) AGENTS.md
Try the SDK on a real tenant docs/guides/examples.md · Try it with skills
SDK contracts and deep reference docs/README.md
Contribute to this repo CONTRIBUTORS.md

Installation

pip install endorlabs

Or with uv:

uv add endorlabs

From the repository (editable):

git clone https://github.com/endorlabs/endorlabs-sdk.git
cd endorlabs-sdk
uv sync
# or: pip install -e .

Verify: uv run python -c "import endorlabs; print(endorlabs.__version__)"

Source repo: endorlabs/endorlabs-sdk — PyPI distribution name is endorlabs (import endorlabs).

Optional extras

Extra Install Enables
docs pip install 'endorlabs[docs]' User-docs sync (include_user_docs=True); OpenAPI download works on the base install
analytics pip install 'endorlabs[analytics]' DataFrame / Parquet export and estate graph metrics — see docs/estate/README.md

CSV export from workflows.estate.analyze.cardinality.tabular works without extras. In this repo: uv sync --extra docs --extra analytics.

Quick start

SDK-only — examples below do not call endorlabs.init(). For agent bootstrap, see AGENTS.md.

Entry point: endorlabs.Client(tenant=...). Resources are PascalCase facades (client.Project, client.Finding, …) matching endorctl api … --resource <Kind>.

Basic usage

import os
import endorlabs

client = endorlabs.Client(
    tenant=os.getenv("ENDOR_NAMESPACE", "your-tenant.namespace"),
    logging_level="ERROR",
)

namespaces = client.Namespace.list(traverse=True)
projects = client.Project.list(traverse=True, max_pages=1)

if projects:
    project = client.Project.get(projects[0].uuid)
    print(project.meta.name)

List field masks: a non-empty mask= on list() returns list[dict] wire JSON rows, not full Pydantic models. Omit mask when you need typed resources end-to-end. See docs/guides/consumer-ux-list-update.md.

Large estate lists: for project-scoped resources at scale, use endorlabs.tools.list_sharding or the endor-estate workflow CLI (see docs/contributing/list-query-performance.md).

Requesting a scan and waiting for results

repo_url = "https://github.com/tgowan-endor/BenchmarkJava.git"
projects = client.Project.search_by_name(repo_url, traverse=True, max_pages=2)
project = projects[0] if projects else None

client.Project.update(project, scan_state="SCAN_STATE_REQUEST_FULL_RESCAN")

client.wait_until(
    lambda: (
        (p := client.Project.get(project))
        and p.processing_status.scan_state == "SCAN_STATE_IDLE"
    ),
    timeout=300,
)

scans = client.ScanResult.list(
    parent=project,
    max_pages=1,
    sort_by="meta.create_time",
    desc=True,
)

More patterns (filters, F(), masks, namespace scoping): docs/guides/consumer-ux-list-update.md, docs/guides/retrieving-scan-results.md.

Transport-only APIClient

from endorlabs import APIClient

client = APIClient()
response = client.get("v1/namespaces/tenant.namespace/projects")

Prefer endorlabs.Client for typed models and namespace handling.

Configuration

The SDK uses environment variables only (no config file loading). Precedence: constructor arguments → environment variables → built-in defaults.

Variable Purpose
ENDOR_API API base URL (default: https://api.endorlabs.com)
ENDOR_API_CREDENTIALS_KEY API key
ENDOR_API_CREDENTIALS_SECRET API secret
ENDOR_TOKEN Bearer token; validated first when set
ENDOR_NAMESPACE Default tenant namespace (e.g. tenant.namespace)
ENDOR_LOG_LEVEL Optional: DEBUG, INFO, WARNING, ERROR, CRITICAL
ENDOR_MAX_RETRIES Optional: retry count (default: 5)

Canonical naming is tenant.namespace.child; do not use UUIDs in namespace paths. Full semantics: docs/contracts.md.

Example .env for local runs:

ENDOR_API_CREDENTIALS_KEY=your-api-key
ENDOR_API_CREDENTIALS_SECRET=your-api-secret
ENDOR_NAMESPACE=your-tenant.namespace
ENDOR_LOG_LEVEL=INFO

Browser auth, SSO setup, and skill walkthroughs: docs/guides/examples.md.

Try it with skills

Guided tenant sessions use shipped agent skills — start with docs/guides/examples.md and AGENTS.md. Skills ship in the wheel (endorlabs.agent_knowledge_index_path()) or .endorlabs-context/sdk/skills/ after init().

Further reading

License

MIT. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

endorlabs-0.3.0.tar.gz (1.8 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

endorlabs-0.3.0-py3-none-any.whl (1.1 MB view details)

Uploaded Python 3

File details

Details for the file endorlabs-0.3.0.tar.gz.

File metadata

  • Download URL: endorlabs-0.3.0.tar.gz
  • Upload date:
  • Size: 1.8 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for endorlabs-0.3.0.tar.gz
Algorithm Hash digest
SHA256 ab0f9426a710f9383e57d8e085a0f96d4a86901d2dc5b3d53bbb57db4ea0d1df
MD5 f69165da92cd76bde83d239d17ef8714
BLAKE2b-256 6578e29215e43a022c2ca288948d0fe7276be01a8cfceccf233564c7bab1785f

See more details on using hashes here.

Provenance

The following attestation bundles were made for endorlabs-0.3.0.tar.gz:

Publisher: release-tag-publish.yml on endorlabs/endorlabs-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file endorlabs-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: endorlabs-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for endorlabs-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 d9b53c3e4d76316f4ad92aa078bea0a7b6b62d598e8177e89d32346126251a02
MD5 c8e4faaa47460bfcb9964b9be45b706c
BLAKE2b-256 bcf9ea6916d2c13b48f714c67d459dadc5ee1eed4546eb4bde4c7cb69c333043

See more details on using hashes here.

Provenance

The following attestation bundles were made for endorlabs-0.3.0-py3-none-any.whl:

Publisher: release-tag-publish.yml on endorlabs/endorlabs-sdk

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page