Shared MeshFlow platform contracts.
Project description
MeshFlow Contracts
Shared Pydantic contracts used by Core, Gateway, and MeshFlow apps.
Rule of thumb: if a model is only used by one app, it does not belong here.
Installation
This package is preparing for public PyPI publication. After the release is
published, install the supported 0.2 line with pip install "meshflow-contracts~=0.2.3".
Until then, consumers must not assume the distribution is available on PyPI.
Maintainers: use the package-specific release and adoption runbook.
It describes release gates without implying that 0.2.3 is already published.
External ingress manifests
Apps may declare optional generic external ingress capabilities through
AppManifest.external_ingress. Each entry fixes the audience, private upstream
path, methods, content types, scopes, body limit, and rate policy that platform
services may snapshot and enforce. The contract describes policy only; it does
not route traffic or authorize grants.
Manifests that omit external_ingress remain valid and declare no external
ingress capabilities.
External ingress policy is intentionally conservative for Core/Gateway
snapshots: internal upstream paths must be canonical absolute app-internal
paths, capability ids are unique per manifest, methods are limited to GET,
POST, PUT, and DELETE, and numeric limits are strict integers. Contract
safety caps are 100 MiB per request body, 1,000 requests per window, and 3,600
seconds per rate window.
Integration request tokens
IntegrationRequestClaims defines the shared internal JWT payload Gateway sends
only to private app ingress after Core has validated an integration grant. The
contract adds token_type="integration_request" without changing existing
app_request or lifecycle token claims.
The claims model requires workspace, installation, app/audience, capability,
grant, subject user, request, jti, immutable scopes, and strict integer iat
/ exp values. App id and audience must match, token lifetime is capped at
3,600 seconds, undeclared claims are rejected, and validated copies re-run the
same invariants. JWT registered claims keep their JWT semantics: iss accepts a
case-sensitive non-empty StringOrURI, including HTTPS URIs and arbitrary
human-readable no-colon issuer strings, while sub and jti are case-sensitive
opaque URL-safe strings rather than MeshFlow identifiers. This package validates
claim shape only; cryptographic verification and equality to the configured
issuer remain runtime responsibilities alongside signing, minting, JWKS
validation, replay handling, routing, lifecycle status, error taxonomy, and grant
persistence.
0.2.3 recovery rollout notes
The failed v0.2.0, v0.2.1, and v0.2.2 tags are immutable unpublished history. They
must never be moved, reused, published, or turned into GitHub Releases. 0.2.3
is the recovery candidate, and consumers must wait for its public package verification. Core
adopts the verified package before Gateway; the schema upgrade alone does not
enable runtime capabilities.
- Apps that omit
external_ingresspreserve0.1.0parse/serialize behavior; omission grants no public ingress. - Registration and runtime rollout depend on Core/Gateway adopting their own snapshot, introspection, routing, and policy-enforcement behavior.
- Core/Gateway must ignore
external_ingressuntil their own snapshot, introspection, routing, and policy-enforcement work lands. - Apps must ignore
integration_requestuntil they implement private external ingress consumers; existing browser and lifecycle paths keep usingapp_requestandlifecyclesemantics. - No Core, Gateway, or app domain behavior is enabled solely by upgrading this package.
Packaging metadata, licensing, source-level checks, strict artifact inspection, and wheel/sdist smoke tests are enforced by release CI before consumer adoption.
License
Licensed under the Apache License 2.0. See LICENSE.
Copyright 2026 MeshFlow contributors.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file meshflow_contracts-0.2.3.tar.gz.
File metadata
- Download URL: meshflow_contracts-0.2.3.tar.gz
- Upload date:
- Size: 9.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a1c8d0e9a4b0fe645ba0edd506bc9e8ee8cf46307ca9c5a2cd322a66e5bbd813
|
|
| MD5 |
5d2b0c031cd25de9fd338c711ad54ead
|
|
| BLAKE2b-256 |
59951e9d7421a6bbd3a04348559e8c407f4db069abe266bc4fc911c9e67e66b5
|
Provenance
The following attestation bundles were made for meshflow_contracts-0.2.3.tar.gz:
Publisher:
release.yml on MeshFlow-os/meshflow-contracts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
meshflow_contracts-0.2.3.tar.gz -
Subject digest:
a1c8d0e9a4b0fe645ba0edd506bc9e8ee8cf46307ca9c5a2cd322a66e5bbd813 - Sigstore transparency entry: 2168299184
- Sigstore integration time:
-
Permalink:
MeshFlow-os/meshflow-contracts@784fdd56ff7177010fc84861618596f4e6994b90 -
Branch / Tag:
refs/tags/v0.2.3 - Owner: https://github.com/MeshFlow-os
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@784fdd56ff7177010fc84861618596f4e6994b90 -
Trigger Event:
push
-
Statement type:
File details
Details for the file meshflow_contracts-0.2.3-py3-none-any.whl.
File metadata
- Download URL: meshflow_contracts-0.2.3-py3-none-any.whl
- Upload date:
- Size: 11.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f9c7f7caeb3c495f86e49b53b0e7afb6afbc75a27a762947170af790c186606d
|
|
| MD5 |
c05bb4e27c5847c79f643b61f07b7a49
|
|
| BLAKE2b-256 |
84e159f35aa0caba1655797abd51b1c8a503404bd2af90d811a0676720134bd8
|
Provenance
The following attestation bundles were made for meshflow_contracts-0.2.3-py3-none-any.whl:
Publisher:
release.yml on MeshFlow-os/meshflow-contracts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
meshflow_contracts-0.2.3-py3-none-any.whl -
Subject digest:
f9c7f7caeb3c495f86e49b53b0e7afb6afbc75a27a762947170af790c186606d - Sigstore transparency entry: 2168299201
- Sigstore integration time:
-
Permalink:
MeshFlow-os/meshflow-contracts@784fdd56ff7177010fc84861618596f4e6994b90 -
Branch / Tag:
refs/tags/v0.2.3 - Owner: https://github.com/MeshFlow-os
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@784fdd56ff7177010fc84861618596f4e6994b90 -
Trigger Event:
push
-
Statement type: