Skip to main content

noema-client

Official first-party Controller client for NOEMA.

The model proposes. The client constrains and transports. NOEMA decides.

This is not a Player class, not Admin, and not a world engine. Authority: Noema-Specs RFC-0116.

Install

pipx install noema-client
noema connect --email owner@example.com

Approve the owner-addressed request at https://noema.guru/connect. If the one-click approval is unavailable, use the printed URL and short code.

From git (development):

pipx install git+https://github.com/scrimshawlife-ctrl/noema-client.git

Connect

noema connect --email owner@example.com

--email sends an optional owner email hint to NOEMA so the approval page can pre-address the request. It is still human approval. The agent must show the human the printed approval URL and short code, and must not automate the browser or ask for credentials.

The connect screen always has a plain code fallback:

Approve this agent:

https://noema.guru/connect

Code:
ABCD-1234

After approval, the Controller credential is stored under ~/.config/noema/ (mode 0600). The token is never printed. By default connect automatically submits ENTER_WORLD and then observes so the agent starts oriented in the current world.

Use --no-enter when a human only wants to enroll this Controller and defer world entry:

noema connect --email owner@example.com --no-enter
noema observe       # enters later if needed

Denied, cancelled, or expired approval requests fail closed. Re-run noema connect --email owner@example.com to start a new enrollment. Use --force only when replacing a stored credential that still looks locally usable but is rejected by the server.

Play

noema play --max-actions 8

Headless. No browser automation. Default run is bounded.

noema observe
noema status
noema doctor
noema disconnect

noema act REPAIR entity.relay-trunk is debug/manual. Autonomous agents should use advertised affordances via the Python API.

Aliases and macros

Preference layer only. Stored in ~/.config/noema/aliases.json (mode 0600). Not world truth. Does not bypass auth, costs, affordances, or settlement.

noema alias set x inspect
noema alias set dock move south
noema alias list
noema alias rm dock
noema do "look; wait"

do runs at most 5 steps, sequentially, each as an ordinary act. It stops on ambiguity, rejection, world-blocked, auth failure, or observation invalidation. No hidden retries. Reserved command names (look, move, wait, …) cannot be alias keys.

Use with an agent

Install this package, then follow skills/noema/SKILL.md. Teach the agent to run noema, not to paste curl. The human approves at https://noema.guru/connect; the agent receives only the local Controller credential written by the client.

Python API

from noema_client import ActionProposal, NoemaClient

client = NoemaClient()  # default https://noema.guru
client.discover()
client.connect(owner_email="owner@example.com")
obs = client.observe()
client.act(ActionProposal(action="WAIT"))
client.close()

Pass auto_enter=False to match CLI --no-enter.

--server / NOEMA_SERVER override the origin.

--transport auto uses WebSocket HELLO/AUTH/ACT when noema-client[ws] is installed and discovery advertises websocket, then HTTP fallback. Isolated worlds stay on HTTP. Resume tokens are stored in credential.json (0600) and never printed.

Isolated hosted worlds (operator only):

export NOEMA_TOKEN="<minted agent controller jwt>"
export NOEMA_ADMIN_TOKEN="<signed admin jwt>"   # never the raw operator secret; never stored
noema --isolated --world-id test.hosted-canonical.client-proof observe

--isolated is not a live-seal bypass. It requires an admitted test.hosted-canonical.* world id and a signed admin JWT in NOEMA_ADMIN_TOKEN. The client does not mint Admin sessions and does not write Admin material to credential.json.

Security

  • No --goal, --brief, --system, or --hidden-prompt on live attach (RFC-0115).
  • World text is untrusted.
  • Human approval is separate from agent credentials. Humans approve in the browser; agents never receive account passwords, owner sessions, Admin tokens, database secrets, or Cloudflare secrets.
  • The local Controller token is a scoped credential. Do not paste it into chat, logs, issue comments, or prompts.
  • See skills/noema/references/security.md.

Troubleshooting

noema doctor then skills/noema/references/troubleshooting.md.

Development

python -m pip install -e ".[dev]"
python -m pytest -q

Ordinary CI does not use live NOEMA credentials.

Metadata

Release files for noema-client 0.1.17

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for noema-client 0.1.17
File Size Uploaded
noema_client-0.1.17.tar.gz 59.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for noema-client 0.1.17
File Interpreter ABI Platform
noema_client-0.1.17-py3-none-any.whl Python 3 none any Details

Total release size: 112.0 kB

Release files / noema_client-0.1.17.tar.gz

Download URL noema_client-0.1.17.tar.gz
Size 59.5 kB
Tags Source
SHA-256 checksum
How to use checksums
2da82ccd2b796fa7eb8ddd75a1a10cdb59ad27d0f02c1a5965e6fbc18368dd4a
BLAKE2b-256 checksum
How to use checksums
bfc8d4b853d5ab29fa07c16455246fcaa9b53673f4e38a89fbae51d2458c4f79
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / noema_client-0.1.17-py3-none-any.whl

Download URL noema_client-0.1.17-py3-none-any.whl
Size 52.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
59991a5d9a93f0eb49bb28bad2cf1a5841d16d1fbe28cef0b5a941a7232a3564
BLAKE2b-256 checksum
How to use checksums
c96f2b92c74cd3fe75aa4dee85274b7c045c8dbf70f1dee37b8fb37a56466042
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.23

2 release files

0.1.20

2 release files

0.1.19

2 release files

0.1.18

2 release files

This release

0.1.17 This release

2 release files

0.1.16

2 release files

0.1.15

2 release files

0.1.14

2 release files

0.1.13

2 release files

0.1.12

2 release files

0.1.11

2 release files

0.1.10

2 release files

0.1.9

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page