Skip to main content

Shared MeshFlow platform contracts.

Project description

MeshFlow Contracts

Shared Pydantic contracts used by Core, Gateway, and MeshFlow apps.

Rule of thumb: if a model is only used by one app, it does not belong here.

Installation

This package is preparing for public PyPI publication. After the release is published, install the supported 0.2 line with pip install "meshflow-contracts~=0.2.3". Until then, consumers must not assume the distribution is available on PyPI.

Maintainers: use the package-specific release and adoption runbook. It describes release gates without implying that 0.2.3 is already published.

External ingress manifests

Apps may declare optional generic external ingress capabilities through AppManifest.external_ingress. Each entry fixes the audience, private upstream path, methods, content types, scopes, body limit, and rate policy that platform services may snapshot and enforce. The contract describes policy only; it does not route traffic or authorize grants.

Manifests that omit external_ingress remain valid and declare no external ingress capabilities.

External ingress policy is intentionally conservative for Core/Gateway snapshots: internal upstream paths must be canonical absolute app-internal paths, capability ids are unique per manifest, methods are limited to GET, POST, PUT, and DELETE, and numeric limits are strict integers. Contract safety caps are 100 MiB per request body, 1,000 requests per window, and 3,600 seconds per rate window.

Integration request tokens

IntegrationRequestClaims defines the shared internal JWT payload Gateway sends only to private app ingress after Core has validated an integration grant. The contract adds token_type="integration_request" without changing existing app_request or lifecycle token claims.

The claims model requires workspace, installation, app/audience, capability, grant, subject user, request, jti, immutable scopes, and strict integer iat / exp values. App id and audience must match, token lifetime is capped at 3,600 seconds, undeclared claims are rejected, and validated copies re-run the same invariants. JWT registered claims keep their JWT semantics: iss accepts a case-sensitive non-empty StringOrURI, including HTTPS URIs and arbitrary human-readable no-colon issuer strings, while sub and jti are case-sensitive opaque URL-safe strings rather than MeshFlow identifiers. This package validates claim shape only; cryptographic verification and equality to the configured issuer remain runtime responsibilities alongside signing, minting, JWKS validation, replay handling, routing, lifecycle status, error taxonomy, and grant persistence.

0.2.3 recovery rollout notes

The failed v0.2.0, v0.2.1, and v0.2.2 tags are immutable unpublished history. They must never be moved, reused, published, or turned into GitHub Releases. 0.2.3 is the recovery candidate, and consumers must wait for its public package verification. Core adopts the verified package before Gateway; the schema upgrade alone does not enable runtime capabilities.

  • Apps that omit external_ingress preserve 0.1.0 parse/serialize behavior; omission grants no public ingress.
  • Registration and runtime rollout depend on Core/Gateway adopting their own snapshot, introspection, routing, and policy-enforcement behavior.
  • Core/Gateway must ignore external_ingress until their own snapshot, introspection, routing, and policy-enforcement work lands.
  • Apps must ignore integration_request until they implement private external ingress consumers; existing browser and lifecycle paths keep using app_request and lifecycle semantics.
  • No Core, Gateway, or app domain behavior is enabled solely by upgrading this package.

Packaging metadata, licensing, source-level checks, strict artifact inspection, and wheel/sdist smoke tests are enforced by release CI before consumer adoption.

License

Licensed under the Apache License 2.0. See LICENSE.

Copyright 2026 MeshFlow contributors.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

meshflow_contracts-0.2.3.tar.gz (9.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

meshflow_contracts-0.2.3-py3-none-any.whl (11.8 kB view details)

Uploaded Python 3

File details

Details for the file meshflow_contracts-0.2.3.tar.gz.

File metadata

  • Download URL: meshflow_contracts-0.2.3.tar.gz
  • Upload date:
  • Size: 9.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for meshflow_contracts-0.2.3.tar.gz
Algorithm Hash digest
SHA256 a1c8d0e9a4b0fe645ba0edd506bc9e8ee8cf46307ca9c5a2cd322a66e5bbd813
MD5 5d2b0c031cd25de9fd338c711ad54ead
BLAKE2b-256 59951e9d7421a6bbd3a04348559e8c407f4db069abe266bc4fc911c9e67e66b5

See more details on using hashes here.

Provenance

The following attestation bundles were made for meshflow_contracts-0.2.3.tar.gz:

Publisher: release.yml on MeshFlow-os/meshflow-contracts

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file meshflow_contracts-0.2.3-py3-none-any.whl.

File metadata

File hashes

Hashes for meshflow_contracts-0.2.3-py3-none-any.whl
Algorithm Hash digest
SHA256 f9c7f7caeb3c495f86e49b53b0e7afb6afbc75a27a762947170af790c186606d
MD5 c05bb4e27c5847c79f643b61f07b7a49
BLAKE2b-256 84e159f35aa0caba1655797abd51b1c8a503404bd2af90d811a0676720134bd8

See more details on using hashes here.

Provenance

The following attestation bundles were made for meshflow_contracts-0.2.3-py3-none-any.whl:

Publisher: release.yml on MeshFlow-os/meshflow-contracts

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page