Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

harborrag-core

The provider-neutral foundation of HarborRAG: domain models, protocol contracts, storage schemas, and security helpers. It has no provider SDK dependencies, so importing it pulls in nothing heavy and performs no I/O.

Every other HarborRAG package depends on this one. You rarely install it alone - install harborrag instead - but you import from it whenever you write an adapter or type a function signature against HarborRAG data.

pip install harborrag-core

What it exports

from harborrag_core import Document, HarborError, RetrievalQuery, RetrievalResult
Group Names
Documents Document, DocumentElement, DocumentProvenance, DocumentRelation, RawDocument, SourceRecord
Retrieval RetrievalQuery, RetrievalResult
Errors HarborError - the base of every HarborRAG exception
Security URLPolicy, URLPolicyError, redact_secrets, redact_mapping

Deeper contracts stay in submodules rather than the package root:

Submodule Contains
harborrag_core.ports.* protocols adapters implement - ports.model_clients, ports.memory, ports.conversation, and the repository ports
harborrag_core.domain.* domain models shared by more than one package
harborrag_core.contracts.errors the full exception family re-exported as HarborError and its subclasses
harborrag_core.base StrictModel and ExtensibleModel, the validated-model base classes

Contributing to this package

  • Add only stable, dependency-light contracts here.
  • Keep provider SDKs out of this package.
  • Add protocols in harborrag_core.ports.* when adapters need a shared model contract; model-client protocols live in harborrag_core.ports.model_clients.
  • Add domain models in harborrag_core.domain.* only when multiple packages need them.
  • Reuse StrictModel or ExtensibleModel from harborrag_core.base for validated models.
  • Add package-wide exceptions to harborrag_core.contracts.errors; keep subsystem error families near their subsystem.

Hard rule: harborrag-core must never import harborrag-adapters, harborrag-engine, harborrag-runtime, harborrag-app, harborrag-mcp-server, or the harborrag meta-package. scripts/check_dependency_direction.py enforces this in CI.

Development

Tests for this package live in packages/harborrag-core/tests/. Run them from the repository root:

uv run pytest packages/harborrag-core/tests

See Extending HarborRAG for how contracts here relate to adapter implementations.

Licensed under the Apache License 2.0.

Release files for harborrag-core 2.0.0a1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for harborrag-core 2.0.0a1
File Size Uploaded
harborrag_core-2.0.0a1.tar.gz 99.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for harborrag-core 2.0.0a1
File Interpreter ABI Platform
harborrag_core-2.0.0a1-py3-none-any.whl Python 3 none any Details

Total release size: 213.2 kB

Release files / harborrag_core-2.0.0a1.tar.gz

Download URL harborrag_core-2.0.0a1.tar.gz
Size 99.1 kB
Tags Source
SHA-256 checksum
How to use checksums
d843c0ddc1169922dcef6301d3aeaeabdb748b1a3ea558f0769944db02dd3421
BLAKE2b-256 checksum
How to use checksums
0144132d5f7be5666e3840677782158a39a520e45c49c7cd05eceaf0e2fe145d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release files / harborrag_core-2.0.0a1-py3-none-any.whl

Download URL harborrag_core-2.0.0a1-py3-none-any.whl
Size 114.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3d0cdc844b7e66fe0395c57460989bc6684dbdeb13485610ac964f1aabc76f16
BLAKE2b-256 checksum
How to use checksums
8c02c160a57862a6dd383a323a7938288b7a0fcafcabca59ae7392ec1684e628
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 9, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

2.0.0a1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page