Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

hull — shared core for the wet / crg / mnemo self-hosted stack

CI CodeQL

Python License

hull is the shared monorepo core for the wet, crg and mnemo self-hosted stack.

It owns everything the three products share — token auth, per-task model configuration, per-user rate limiting, local SQLite storage, the HTTP MCP server lifecycle, web scraping/search infrastructure, and a local embedding daemon — for wet (search), crg (code graph) and mnemo (memory).

Install

hull ships as one PyPI dist, hull-core. The wheel carries all three import packages; the heavy stacks are opt-in extras:

pip install hull-core               # hull_core only (crg, mnemo)
pip install "hull-core[web]"        # + hull_web scraping/browser stack (wet)
pip install "hull-core[embedding]"  # + hull_embedding_daemon server stack

import hull_web without the [web] extra raises ImportError naming the missing modules and the install command.

Packages

Source dir Import package Extra Purpose
packages/core-py hull_core (base) Auth (3 modes), per-task model cells, limiter, ~/.hull/ SQLite WAL storage, server start + /mcp endpoint, CLI, SSRF-safe HTTP, lifecycle lock
packages/embedding-daemon hull_embedding_daemon [embedding] Local ONNX/GGUF embedding server (FastAPI)
packages/web hull_web [web] Search (SearXNG), scraping strategies, stealth browsers, fingerprinting, HTTP/SSRF security

Runtime model

  • Python 3.13. Dev with uv, always-on with docker.
  • hull server start is the only way to run a server; MCP is an HTTP endpoint at http://host:port/mcp — never a spawned subprocess.
  • The CLI is the control plane + consumer. With the server down the CLI tells you to start it first; there is no hidden local-core mode.
  • Provider calls are plain OpenAI-spec HTTP (httpx). OpenRouter is the pre-wired default. Each task (embed, rerank, chat, jev_score) has its own base_url + api_key + model cell — change provider by editing config, never code.
  • Storage is local SQLite (WAL) under ~/.hull/. Backup/sync is rclone outside this repo.

Auth — one mechanism, three modes

Mode is a config state ([server] auth in ~/.hull/config.toml):

  1. no-auth — localhost-only bind enforced, one shared namespace.
  2. token — one shared token (token_hash in config), still one shared namespace.
  3. multi — users.toml maps uid → {token_hash, enabled, namespace, allowed_roots, limits}; one process serves N users, each isolated to their namespace. Admin is host-side only: edit users.toml, restart.

Token hashes are scrypt (hull token hash). Wrong token → 401; disabled user → 403; over-limit → 429.

Quick start

uv sync
uv run hull config init          # write ~/.hull/config.toml (OpenRouter defaults)
uv run hull token hash mysecret  # mint a token_hash for users.toml / config
uv run hull server start         # serves http://127.0.0.1:8000/mcp

Development

uv sync --all-extras
uv run pytest -q
uv run ruff check .
uv build

License

Apache-2.0

Metadata

Release files for hull-core 0.1.0b1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hull-core 0.1.0b1
File Size Uploaded
hull_core-0.1.0b1.tar.gz 437.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hull-core 0.1.0b1
File Interpreter ABI Platform
hull_core-0.1.0b1-py3-none-any.whl Python 3 none any Details

Total release size: 550.6 kB

Release files / hull_core-0.1.0b1.tar.gz

Download URL hull_core-0.1.0b1.tar.gz
Size 437.9 kB
Tags Source
SHA-256 checksum
How to use checksums
82427427063c6f7511cf617831e98e57ef5253e036ad76d3fa3e75a992abfcf2
BLAKE2b-256 checksum
How to use checksums
ab5ffacc8613cc436402c8cb26ef90be9253d238701fcd74f1fab8558a7036ff
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release files / hull_core-0.1.0b1-py3-none-any.whl

Download URL hull_core-0.1.0b1-py3-none-any.whl
Size 112.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dbdea6d99398190dc3f93371e3198df3f5b0c0ae17466074b63c1af4184985c2
BLAKE2b-256 checksum
How to use checksums
117919c54f07981dcdf54c641ab19e49d5355474d0b96ed36ab285da2cdf7ba7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0b1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page