Skip to main content

OpenLatch detection-tool SDK — Standard Webhooks v1 verify/sign + FastAPI decorator.

Project description

openlatch-tool-sdk

Standard Webhooks v1 verify/sign + FastAPI decorator for OpenLatch detection tools (Python). Pairs with openlatch-provider listen (HMAC verification happens there) or stands on its own when the tool server is exposed publicly.

Install

pip install 'openlatch-tool-sdk[fastapi]'

FastAPI

from openlatch_tool_sdk import CloudEvent, Verdict, tool
from fastapi import FastAPI

app = FastAPI()

@tool(app, path="/event", secret=None)  # secret=os.environ["OPENLATCH_WHSEC"] for standalone
async def detect(event: CloudEvent) -> Verdict:
    text = str((event.tool_call.input if event.tool_call else None) or {})
    if "AKIA" in text:
        return Verdict(
            risk_score=99,
            severity_hint="critical",
            verdict_hint="deny",
            rule_id="aws.access_key",
            rationale_summary="AWS access key detected",
        )
    return Verdict(risk_score=5, severity_hint="low", verdict_hint="allow")

Direct API

from openlatch_tool_sdk import compute_signature, sign_response, verify

Verdict shape

Pydantic models are configured with alias_generator=to_camel, so wire JSON uses camelCase (riskScore, severityHint, …) per provider-call.schema.json, while Python code uses snake_case naturally.

Cross-impl HMAC parity

Test fixtures and signed outputs are byte-identical between this SDK, @openlatch/tool-sdk (npm), and runtime/webhook.rs in the openlatch-provider Rust binary. The same whsec_<base64> secret + <id>.<timestamp>.<raw-body> payload + base64(HMAC-SHA256) framing is used by all three.

Releases

openlatch-tool-sdk is released in lock-step with openlatch-provider via release-please. Land conventional-commit PRs against main; release-please opens a Release PR bumping all three packages (openlatch-provider on crates.io + npm, openlatch-tool-sdk on PyPI, @openlatch/tool-sdk on npm). Merging the Release PR creates a v* tag and the unified publish.yml workflow publishes everything via OIDC trusted publishing.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

openlatch_tool_sdk-1.0.0.tar.gz (35.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

openlatch_tool_sdk-1.0.0-py3-none-any.whl (7.4 kB view details)

Uploaded Python 3

File details

Details for the file openlatch_tool_sdk-1.0.0.tar.gz.

File metadata

  • Download URL: openlatch_tool_sdk-1.0.0.tar.gz
  • Upload date:
  • Size: 35.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for openlatch_tool_sdk-1.0.0.tar.gz
Algorithm Hash digest
SHA256 71e401fac72da6fe9fb3db90e0fe8ae0b64ff1b9053624d9fd9f64e1bdb6b133
MD5 0658070d423345e2702f36861ca56fd5
BLAKE2b-256 a6973153adfc06e8e8f54c4bd43fa55bcb71f3ab5c4a57cefa0fcf12727241e1

See more details on using hashes here.

Provenance

The following attestation bundles were made for openlatch_tool_sdk-1.0.0.tar.gz:

Publisher: publish.yml on OpenLatch/openlatch-provider

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file openlatch_tool_sdk-1.0.0-py3-none-any.whl.

File metadata

File hashes

Hashes for openlatch_tool_sdk-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 41b692ce909b4ad06dab2670b8ad94344f06e78b26fb5fd72a6f6decb7164de5
MD5 e0e6b00c3eede006acdbac8b68e85a6d
BLAKE2b-256 f8ef004b68171b0bbc20440c17b38e41d79df17c34b95e9053c34e393699e983

See more details on using hashes here.

Provenance

The following attestation bundles were made for openlatch_tool_sdk-1.0.0-py3-none-any.whl:

Publisher: publish.yml on OpenLatch/openlatch-provider

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page