Standalone Python SDK for Pandora agent discovery, vendored contract access, and MCP execution.
Project description
pandora-agent
pandora-agent is the standalone Python SDK for Pandora's agent-facing contract and MCP execution surfaces.
It is intended to work as a normal installed Python package:
- it ships its own generated contract artifacts inside
pandora_agent/generated - it can execute against local stdio MCP via
pandora mcp - it can execute against operator-hosted remote MCP HTTP via
pandora mcp http - it exposes package-local helpers for the vendored manifest, contract registry, command descriptors, and MCP tool definitions
- it exposes first-class bootstrap helpers so cold agents can start from Pandora's canonical bootstrap contract
What this package is for
Use pandora-agent when Python code needs to:
- inspect the shipped Pandora command and tool catalog without shelling out
- inspect policy scopes and signer-profile metadata before choosing tools
- connect to a local Pandora process over stdio MCP
- connect to a remote Pandora MCP HTTP gateway with a bearer token
Prerequisites
The Python package does not bundle the Pandora CLI runtime itself.
- For local stdio execution, the
pandoraCLI must be installed and available onPATH, or you must pass an explicitcommand=.... - For remote execution, an operator must already be running
pandora mcp http ...and provide the/mcpURL plus a bearer token if auth is enabled.
Installation
Current validated install paths:
Preferred for external consumers:
pip install /path/to/downloaded/pandora_agent-<version>-py3-none-any.whl
Maintainer and repository-checkout flows:
pip install ./sdk/python
Or from a locally built release artifact produced by the repository release flow:
pip install dist/release/sdk/python/*.whl
If you publish manually from sdk/python, clear old build artifacts first:
rm -rf dist build pandora_agent.egg-info
python3 -m build
TWINE_USERNAME=__token__ TWINE_PASSWORD=... python3 -m twine upload dist/*
Use the signed GitHub release wheel or sdist when working outside the repository. Use the repo path only when you intentionally want an in-tree checkout. Public PyPI publication is live as pandora-agent.
Vendored equivalent inside the Pandora CLI package:
PYTHONPATH=/path/to/pandora-cli-skills/sdk/python python
Quickstart
Local stdio MCP
Cold agents should start with bootstrap, not with low-level capabilities or schema calls.
from pandora_agent import create_local_pandora_agent_client
with create_local_pandora_agent_client(command="pandora") as client:
bootstrap = client.get_bootstrap()
print(len(bootstrap["canonicalTools"]), bootstrap["recommendedBootstrapFlow"][0])
Remote MCP HTTP
from pandora_agent import PandoraSdkError, PandoraToolCallError, create_remote_pandora_agent_client
with create_remote_pandora_agent_client(
url="http://127.0.0.1:8787/mcp",
auth_token="replace-me",
) as client:
try:
bootstrap = client.get_bootstrap()
print(bootstrap["canonicalTools"][0])
except PandoraToolCallError as error:
print(error.code, error.details)
except PandoraSdkError as error:
print(error.code, error.details)
Package-local contract inspection
from pandora_agent import (
inspect_generated_command_policy,
load_generated_command_descriptors,
load_generated_manifest,
)
manifest = load_generated_manifest()
trade_descriptor = load_generated_command_descriptors()["trade"]
trade_policy = inspect_generated_command_policy("trade")
print(manifest["packageVersion"])
print(trade_descriptor["canonicalTool"])
print(trade_policy.policy_scopes)
Main API surface
Client constructors
create_local_pandora_agent_client(...)create_remote_pandora_agent_client(...)PandoraAgentClient(...)
PandoraAgentClient supports context-manager usage, so installed consumers can write with ... as client: and avoid manual teardown.
Generated artifact helpers
load_generated_manifest()load_generated_contract_registry()load_generated_capabilities()load_generated_command_descriptors()load_generated_mcp_tool_definitions()get_generated_artifact_path(...)list_generated_artifact_paths()
Policy/profile helpers
load_generated_policy_profiles()inspect_generated_command_policy(command_name)PandoraAgentClient.get_policy_profiles()PandoraAgentClient.inspect_command_policy(command_name)
Error semantics
The SDK raises:
PandoraSdkErrorfor SDK, transport, protocol, process, or HTTP failuresPandoraToolCallErrorfor Pandora tool failure envelopes
Tool-call normalization is intentionally specific:
- when Pandora returns a structured tool error with its own stable code,
PandoraToolCallError.codepreserves that Pandora code directly - examples:
FORBIDDEN,UNKNOWN_TOOL,MCP_INVALID_ARGUMENTS - the generic wrapper code
PANDORA_SDK_TOOL_ERRORis only used when a tool failure envelope does not include a stable Pandora error code
PandoraSdkError.to_dict() and PandoraToolCallError.to_dict() are safe to log or serialize for debugging. PandoraToolCallError also keeps the normalized envelope and raw MCP result payload when available.
Transport notes
Local stdio
- starts
pandora mcp - keeps one subprocess per client instance
- requires
connect()before use unless you use the context-manager form
Remote HTTP
- talks to the streamable HTTP MCP endpoint at
/mcp - supports bearer-token auth via
auth_token=... - preserves gateway-provided MCP session headers when the server emits them
- surfaces HTTP and gateway-side JSON errors as
PandoraSdkError
Examples
Repository examples are kept under:
sdk/python/examples/local_stdio.pysdk/python/examples/remote_http.py
They are source-tree examples, not installed package files in the wheel.
Current boundaries
This package is intentionally standalone at runtime, but the repository and the Pandora CLI package also vendor matching copies and share some integration boundaries:
- the vendored generated JSON artifacts are still produced by the shared contract generator in the main repo
- package versioning and release or publish automation outside
sdk/python/**are still controlled by shared repo release work - the Pandora CLI package also carries a vendored copy under
sdk/pythonfor in-tree consumers and parity checks
That means the installed package is self-contained at runtime, but artifact refresh and coordinated release automation still depend on the repo-level generator and release lanes.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pandora_agent-0.1.0a3.tar.gz.
File metadata
- Download URL: pandora_agent-0.1.0a3.tar.gz
- Upload date:
- Size: 422.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.1
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
75c31a0e1419f13ef98d2f060fbc6e90deacf4e956eb52777142ab25781e4dc6
|
|
| MD5 |
61439508150fdc9ae84461e33a03e088
|
|
| BLAKE2b-256 |
e01baf04ec74c384314eebca847cf287c17684b7e74644a1f9e63fba150fd42f
|
File details
Details for the file pandora_agent-0.1.0a3-py3-none-any.whl.
File metadata
- Download URL: pandora_agent-0.1.0a3-py3-none-any.whl
- Upload date:
- Size: 449.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.11.1
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6454132eec31fd409e9ca7764634be8a3a00b42cce188dcd9ecc909938bb331e
|
|
| MD5 |
1f7ee6a39626f605a5518f36745601ed
|
|
| BLAKE2b-256 |
9db0c246665a3aee615f2123209ae91d7133a454fc9e4c9b739ace12af1015ce
|