ophix-client-management
Know which fleet clients need attention, before a stale token becomes a security problem.
Client tokens don't rotate themselves, and a forgotten one sitting unrotated for months (or years) is exactly the kind of thing that only surfaces during an audit — or an incident. ophix-client-management gives you a fleet-wide status dashboard showing every client's token age and reported software version at a glance, lets you request rotation or lock out a client directly from the admin, and enforces a hard rotation deadline automatically once you've configured one.
Installation
pip install ophix-client-management
ophix-manage migrate
The plugin registers itself automatically via the ophix.plugins entry point — no changes
to INSTALLED_APPS or MIDDLEWARE are needed.
What this plugin provides
- Status dashboard at
/client-management/— linked from the admin left-hand nav under Client Management - Per-client status bars with six states: OK / Warning / Rotation Required / Locked / Never Rotated / Operator Requested
- Per-client actions: Request Rotation, Clear Request, Unlock Client
- Bulk Request Rotation — All Overdue action
X-Token-Rotation-Warning: trueresponse header injected for clients in the warn stateX-Token-Rotation-Required: trueresponse header injected for clients past the require threshold or operator-flagged- Hard lockout enforcement in
ClientTokenAuthentication— clients pastTOKEN_LOCKOUT_DAYSare denied API access until an operator unlocks them from the dashboard - Client version tracking — captures the
X-*-Client-Versionrequest header on every successful API call and displays the last-seen version per client in the dashboard
Dashboard states
| State | Meaning |
|---|---|
| OK | Token age below warn threshold — no action needed |
| Warning | Token age between warn and require thresholds — X-Token-Rotation-Warning sent |
| Rotation Required | Token age past require threshold — X-Token-Rotation-Required sent |
| Locked | Token age past lockout threshold — API access blocked until operator unlocks |
| Never Rotated | No rotation recorded — lockout does not apply |
| Operator Requested | Flagged manually via the dashboard — X-Token-Rotation-Required sent |
Configuration (.env)
| Variable | Default | Purpose |
|---|---|---|
TOKEN_WARN_DAYS |
30 |
Age (days) at which the warning signal is sent |
TOKEN_REQUIRE_DAYS |
90 |
Age (days) at which the required signal is sent |
TOKEN_LOCKOUT_DAYS |
180 |
Age (days) at which API access is blocked. Set to 0 to disable lockout. A value below TOKEN_REQUIRE_DAYS is invalid and will be ignored with a log warning. |
Recommended values are shown above. TOKEN_LOCKOUT_DAYS must be greater than or equal to
TOKEN_REQUIRE_DAYS to take effect.
Client signalling and automatic rotation
Tier 1 clients built on ophix-client-core check the rotation signal headers automatically
on every API response. Two env vars in each client's domain env file control the behaviour:
| Variable | Default | Purpose |
|---|---|---|
ROTATE_ON_WARNING |
true |
Rotate automatically when X-Token-Rotation-Warning is received |
ROTATE_ON_REQUIRED |
true |
Rotate automatically when X-Token-Rotation-Required is received |
Set either to false to suppress automatic rotation and handle it manually instead.
With both defaults in place, tokens rotate silently as they age — no operator intervention
required under normal circumstances.
Lockout and recovery
When a client reaches TOKEN_LOCKOUT_DAYS, every API request returns 403 until an operator
intervenes. To recover a locked client:
- Open the Status dashboard in the admin under Client Management.
- Click Unlock Client on the locked row.
This sets the lockout override and the rotation-required flag. On the client's next successful
API call, X-Token-Rotation-Required is sent and ophix-client-core rotates the token
automatically. Normal operation resumes without any manual token handling.
Clients that have never rotated (last_token_rotation is null) are not subject to lockout.
Requirements
ophix-server-base >= 2026.06.08.01
Metadata
Release files for ophix-client-management 2026.10.4.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ophix_client_management-2026.10.4.1.tar.gz | 20.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ophix_client_management-2026.10.4.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 45.1 kB
Release files / ophix_client_management-2026.10.4.1.tar.gz
| Download URL | ophix_client_management-2026.10.4.1.tar.gz |
|---|---|
| Size | 20.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
52d20922482dfe761abd8b3abe5013c89fde149a91f849f1ffaf846343320e0c
|
|
BLAKE2b-256 checksum How to use checksums |
f849e2dc9ab72f11327f5d240cb90731919644aaef3091aff168d221eadbeb2e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.3
|
Release files / ophix_client_management-2026.10.4.1-py3-none-any.whl
| Download URL | ophix_client_management-2026.10.4.1-py3-none-any.whl |
|---|---|
| Size | 24.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7d51952e0b84cc925e060dc16b25286378f64d2742b720cc32446e21f1c11a6a
|
|
BLAKE2b-256 checksum How to use checksums |
b2714593c17c877d19165dd03085d40cbd5f815390a3e15f97ce89f9547c6f8f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.3
|