MeshFlow Contracts
Shared Pydantic contracts used by Core, Gateway, and MeshFlow apps.
Rule of thumb: if a model is only used by one app, it does not belong here.
Installation
0.2.3 is published on PyPI and is the currently supported line:
pip install "meshflow-contracts~=0.2.3".
0.3.0 is prepared but not yet published. Consumers must not assume it is
available, and must not adopt it before its public wheel, sdist, hashes, and
provenance are verified.
Maintainers: use the package-specific release and adoption runbook.
External ingress manifests
Apps may declare optional generic external ingress capabilities through
AppManifest.external_ingress. Each entry fixes the audience, private upstream
path, methods, content types, scopes, body limit, and rate policy that platform
services may snapshot and enforce. The contract describes policy only; it does
not route traffic or authorize grants.
Manifests that omit external_ingress remain valid and declare no external
ingress capabilities.
External ingress policy is intentionally conservative for Core/Gateway
snapshots: internal upstream paths must be canonical absolute app-internal
paths, capability ids are unique per manifest, methods are limited to GET,
POST, PUT, and DELETE, and numeric limits are strict integers. Contract
safety caps are 100 MiB per request body, 1,000 requests per window, and 3,600
seconds per rate window.
Integration request tokens
IntegrationRequestClaims defines the shared internal JWT payload Gateway sends
only to private app ingress after Core has validated an integration grant. The
contract adds token_type="integration_request" without changing existing
app_request or lifecycle token claims.
The claims model requires workspace, installation, app/audience, capability,
grant, subject user, request, jti, immutable scopes, and strict integer iat
/ exp values. App id and audience must match, token lifetime is capped at
3,600 seconds, undeclared claims are rejected, and validated copies re-run the
same invariants. JWT registered claims keep their JWT semantics: iss accepts a
case-sensitive non-empty StringOrURI, including HTTPS URIs and arbitrary
human-readable no-colon issuer strings, while sub and jti are case-sensitive
opaque URL-safe strings rather than MeshFlow identifiers. This package validates
claim shape only; cryptographic verification and equality to the configured
issuer remain runtime responsibilities alongside signing, minting, JWKS
validation, replay handling, routing, lifecycle status, error taxonomy, and grant
persistence.
0.3.0 rollout notes
0.3.0 removes service.base_url from AppManifest. The manifest now describes
app identity only; the upstream address is a deployment binding supplied
separately at registration time. Consumers must migrate their own manifest
producers before adopting.
ServiceDefinition stays tolerant of unknown keys on purpose. Registry manifest
snapshots are immutable and hashed at write time, and Core parses them on the
read path, so a snapshot written by 0.2.x has to keep parsing. Refusing a newly
submitted manifest that still carries base_url is a registration-time policy
check in Core, not a contract-level rule.
Core adopts the verified package before Gateway; the schema upgrade alone does not enable runtime capabilities.
The failed v0.2.0, v0.2.1, and v0.2.2 tags are immutable unpublished
history. They must never be moved, reused, published, or turned into GitHub
Releases.
- Apps that omit
external_ingresspreserve0.1.0parse/serialize behavior; omission grants no public ingress. - Registration and runtime rollout depend on Core/Gateway adopting their own snapshot, introspection, routing, and policy-enforcement behavior.
- Core/Gateway must ignore
external_ingressuntil their own snapshot, introspection, routing, and policy-enforcement work lands. - Apps must ignore
integration_requestuntil they implement private external ingress consumers; existing browser and lifecycle paths keep usingapp_requestandlifecyclesemantics. - No Core, Gateway, or app domain behavior is enabled solely by upgrading this package.
Packaging metadata, licensing, source-level checks, strict artifact inspection, and wheel/sdist smoke tests are enforced by release CI before consumer adoption.
License
Licensed under the Apache License 2.0. See LICENSE.
Copyright 2026 MeshFlow contributors.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file meshflow_contracts-0.3.0.tar.gz.
File metadata
- Download URL: meshflow_contracts-0.3.0.tar.gz
- Upload date:
- Size: 11.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
eb81e30245b14b259c93f20e42f02b5118d67cb68923b4bbf293999903c55215
|
|
| MD5 |
f5ae6f739ab91933e643357b74878dbf
|
|
| BLAKE2b-256 |
90777eeebbe7ec0aca0800923a0219a756a4d48334c93912e76b74f49cb94b0d
|
Provenance
The following attestation bundles were made for meshflow_contracts-0.3.0.tar.gz:
Publisher:
release.yml on MeshFlow-os/meshflow-contracts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
meshflow_contracts-0.3.0.tar.gz -
Subject digest:
eb81e30245b14b259c93f20e42f02b5118d67cb68923b4bbf293999903c55215 - Sigstore transparency entry: 2296001910
- Sigstore integration time:
-
Permalink:
MeshFlow-os/meshflow-contracts@e1a59ef98a0ae406257467478906d65d70cd232f -
Branch / Tag:
refs/tags/v0.3.0 - Owner: https://github.com/MeshFlow-os
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@e1a59ef98a0ae406257467478906d65d70cd232f -
Trigger Event:
push
-
Statement type:
File details
Details for the file meshflow_contracts-0.3.0-py3-none-any.whl.
File metadata
- Download URL: meshflow_contracts-0.3.0-py3-none-any.whl
- Upload date:
- Size: 13.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
718c863733c668a8be934517828c0e7f7f5b11d0b56fb4eb1552b069b042c715
|
|
| MD5 |
99aa8bdc8fceee3e9626437ad495af7a
|
|
| BLAKE2b-256 |
ae6de107c63adb4fd123bf909ffc686ecd6f7ea6309eeb1b9d624e7388128fb9
|
Provenance
The following attestation bundles were made for meshflow_contracts-0.3.0-py3-none-any.whl:
Publisher:
release.yml on MeshFlow-os/meshflow-contracts
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
meshflow_contracts-0.3.0-py3-none-any.whl -
Subject digest:
718c863733c668a8be934517828c0e7f7f5b11d0b56fb4eb1552b069b042c715 - Sigstore transparency entry: 2296001945
- Sigstore integration time:
-
Permalink:
MeshFlow-os/meshflow-contracts@e1a59ef98a0ae406257467478906d65d70cd232f -
Branch / Tag:
refs/tags/v0.3.0 - Owner: https://github.com/MeshFlow-os
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@e1a59ef98a0ae406257467478906d65d70cd232f -
Trigger Event:
push
-
Statement type: