LupisLabs Python SDK for AI application tracing and monitoring
Project description
LupisLabs Labs Python SDK
Spin up tracing for any Python workflow in minutes.
Installation
pip install --upgrade lupislabs
Download the LupisLabs desktop app for macOS or Windows. No separate CLI authentication is required—once the app is running you are ready to stream traces.
Features
- 🔍 Automatic HTTP Tracing: Captures requests from
requests,http.client,urllib3,httpx, andaiohttp - 💬 Session Support: Group traces by conversation/session
- ⚡ Batching: Automatically batches events for efficient transmission
- 🐍 Python Support: Full Python 3.8+ support with async/await
- 🔒 Privacy-First: Never collects request/response bodies, only analytics data
Quick Start
1. Initialize a global LupisLabs client
Create a single LupisLabs instance when your app boots and reuse it everywhere:
# lupis_client.py
from lupislabs import LupisLabs
lupis = LupisLabs(workspace="local-dev")
2. Enable the SDK
The SDK is disabled by default. You must explicitly enable it to start collecting traces:
# Enable the SDK
export LUPIS_SDK_ENABLED=true
# Or in your .env file
LUPIS_SDK_ENABLED=true
This opt-in approach ensures no unexpected data collection occurs. When disabled, the SDK will not instrument HTTP clients, collect traces, or send data to the collector.
3. Use in your code
Import that module anywhere you need to record sessions:
# agent.py
from lupis_client import lupis
def summarize():
with lupis.session("summarize") as session:
session.log_input(prompt="Summarize the latest run logs")
result = agent.run()
session.log_output(result)
return result
4. Open the desktop app and Session Monitor
Start the LupisLabs desktop app and switch to Session Monitor. Keep it open while you develop—every session.log_* call will stream into that view immediately.
5. Run your agent and inspect traces
Execute your script or service normally (python app.py, uvicorn main:app, notebooks, etc.). As soon as the global client records a session you will see:
- Prompts and model outputs
- Tool invocations and latency
- Custom metrics or artifacts
Supported HTTP Clients
The SDK automatically captures outbound calls made with:
requests.Sessionhttp.client.HTTPConnection/HTTPSConnectionurllib3connection poolshttpx.Clientandhttpx.AsyncClientaiohttp.ClientSession
Nested client usage (for example requests → urllib3 → http.client) is deduplicated so only a single trace is emitted per HTTP call.
Advanced Configuration
The SDK automatically connects to the LupisLabs desktop app at http://127.0.0.1:9009. For advanced use cases, you can customize the configuration:
from lupislabs import LupisLabs
lupis = LupisLabs(
workspace="local-dev", # Required: workspace identifier
enabled=True, # Optional: enable/disable tracking
service_name="my-service", # Optional: service name for traces
service_version="1.0.0", # Optional: service version
filter_sensitive_data=True, # Optional: enable sensitive data filtering
sensitive_data_patterns=[...], # Optional: custom regex patterns to filter
redaction_mode="mask", # Optional: 'mask', 'remove', or 'hash'
)
Or enable via configuration:
from lupislabs import LupisLabs
lupis = LupisLabs(
workspace="local-dev",
enabled=True, # SDK will start collecting data
)
When disabled, the SDK will not instrument HTTP clients, collect traces, or send data to the collector.
Event Batching
Events are automatically batched and sent to the server:
- Batch Size: Up to 50 events per batch
- Flush Interval: Every 5 seconds
- Auto-flush: Background worker + process exit hook
Sensitive Data Filtering
The SDK automatically filters sensitive data in production to protect API keys, tokens, and other sensitive information. This feature is enabled by default for security.
Default Filtering
The SDK automatically filters these common sensitive patterns:
API Keys & Tokens
sk-[a-zA-Z0-9]{20,}- OpenAI API keyspk_[a-zA-Z0-9]{20,}- Paddle API keysak-[a-zA-Z0-9]{20,}- Anthropic API keysBearer [a-zA-Z0-9._-]+- Bearer tokensx-api-key,authorization- API key headers
Authentication
password,passwd,pwd- Password fieldstoken,access_token,refresh_token,session_token- Various tokenssecret,private_key,api_secret- Secret fields
Personal Data
ssn,social_security- Social Security Numberscredit_card,card_number- Credit card numberscvv,cvc- Security codes
Redaction Modes
Choose how sensitive data is replaced when initializing the SDK:
Mask Mode (Default)
lupis = LupisLabs.init(LupisConfig(
project_id="your-project-id",
redaction_mode="mask", # Default
))
# Examples:
# sk-1234567890abcdef1234567890abcdef12345678 → sk-1***5678
# Bearer sk-1234567890abcdef1234567890abcdef12345678 → Bear***5678
# password: 'secret-password' → password: '***'
Remove Mode
lupis = LupisLabs.init(LupisConfig(
project_id="your-project-id",
redaction_mode="remove",
))
# Examples:
# sk-1234567890abcdef1234567890abcdef12345678 → [REDACTED]
# password: 'secret-password' → password: [REDACTED]
Hash Mode
lupis = LupisLabs.init(LupisConfig(
project_id="your-project-id",
redaction_mode="hash",
))
# Examples:
# sk-1234567890abcdef1234567890abcdef12345678 → [HASH:2dd0e9d5]
# password: 'secret-password' → password: [HASHED]
Custom Patterns
Add your own sensitive data patterns during initialization:
lupis = LupisLabs.init(LupisConfig(
project_id="your-project-id",
filter_sensitive_data=True,
sensitive_data_patterns=[
"sk-[a-zA-Z0-9]{20,}", # OpenAI API keys
"Bearer [a-zA-Z0-9._-]+", # Bearer tokens
"custom_secret", # Your custom field
"my_api_key", # Your custom field
"email", # Email addresses
],
redaction_mode="mask",
))
What Gets Filtered
The SDK filters sensitive data in:
- Request Headers: Authorization, API keys, tokens
- Span Attributes: All OpenTelemetry span attributes
- Custom Events: Event properties containing sensitive data
Note: Request and response bodies are never collected, so no filtering is needed for them.
Disable Filtering (Development Only)
⚠️ Warning: Only disable filtering in development environments:
lupis = LupisLabs.init(LupisConfig(
project_id="your-project-id",
filter_sensitive_data=False, # ⚠️ Sensitive data will be exposed!
))
Production Security
- ✅ Enabled by default - No configuration needed
- ✅ Comprehensive coverage - Common sensitive patterns included
- ✅ Configurable - Add custom patterns as needed
- ✅ Performance optimized - Minimal impact when enabled
- ✅ Debugging friendly - Mask mode preserves partial data for debugging
Examples
See the examples/ directory for more usage examples:
anthropic_example.py- Anthropic API integrationopenai_example.py- OpenAI API integrationstreaming_example.py- Streaming responsescomprehensive_tracking.py- Complete workflow demonstrationsensitive_data_example.py- Sensitive data filtering examples
Requirements
- Python 3.8+
- requests
- opentelemetry-api
- opentelemetry-sdk
- opentelemetry-exporter-otlp-proto-http
- opentelemetry-instrumentation-requests
License
Made with ❤️ by the LupisLabs team
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file lupislabs-1.0.4.tar.gz.
File metadata
- Download URL: lupislabs-1.0.4.tar.gz
- Upload date:
- Size: 23.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b95253162de2812af8ef84db9b31f4afee184761a0e9f1286cdeb2704d892ca4
|
|
| MD5 |
6d6de2a39113c5eab243e3d29a34e6f5
|
|
| BLAKE2b-256 |
4d97fa964232f92a5c76dc6e7e92fe5328a0cac153b5186b629eb2a568da6719
|
Provenance
The following attestation bundles were made for lupislabs-1.0.4.tar.gz:
Publisher:
publish-python.yml on henchiyb/lupis-labs
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lupislabs-1.0.4.tar.gz -
Subject digest:
b95253162de2812af8ef84db9b31f4afee184761a0e9f1286cdeb2704d892ca4 - Sigstore transparency entry: 686222848
- Sigstore integration time:
-
Permalink:
henchiyb/lupis-labs@72fb2ab6ccefa81fca3cf9c91e25747c82ca50ac -
Branch / Tag:
refs/heads/main - Owner: https://github.com/henchiyb
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-python.yml@72fb2ab6ccefa81fca3cf9c91e25747c82ca50ac -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file lupislabs-1.0.4-py3-none-any.whl.
File metadata
- Download URL: lupislabs-1.0.4-py3-none-any.whl
- Upload date:
- Size: 24.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1d1c6704e9e1a5bbf5f0efce6959085d23609c943d3a2a2d2119bbc4940c577d
|
|
| MD5 |
e8f1ac475858191f99cac27b35b039e3
|
|
| BLAKE2b-256 |
78029a01c6c750adc5b55f9066fd66f38c7935c8b9ea66e34b866d37566455ce
|
Provenance
The following attestation bundles were made for lupislabs-1.0.4-py3-none-any.whl:
Publisher:
publish-python.yml on henchiyb/lupis-labs
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lupislabs-1.0.4-py3-none-any.whl -
Subject digest:
1d1c6704e9e1a5bbf5f0efce6959085d23609c943d3a2a2d2119bbc4940c577d - Sigstore transparency entry: 686222851
- Sigstore integration time:
-
Permalink:
henchiyb/lupis-labs@72fb2ab6ccefa81fca3cf9c91e25747c82ca50ac -
Branch / Tag:
refs/heads/main - Owner: https://github.com/henchiyb
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-python.yml@72fb2ab6ccefa81fca3cf9c91e25747c82ca50ac -
Trigger Event:
workflow_dispatch
-
Statement type: