phlatline-core
OpenAPI-driven API diagnostic CLI.
Point it at a spec, get a report of boundary failures, fuzz hits, and schema drift — in minutes.
Quickstart
pip install 'phlatline-core[fuzz]'
phlatline scan https://petstore3.swagger.io/api/v3/openapi.json
That's it. Phlatline loads the spec, generates boundary and fuzz test cases, runs them against the
live API, and writes an HTML report to ./phlatline_results/.
The [fuzz] extra pulls in Schemathesis for the fuzz
stage. Plain pip install phlatline-core works too — every other stage runs, and the fuzz stage
reports itself as skipped.
With a local spec
phlatline scan my-api.yaml
phlatline scan ./openapi.json --output-dir ./reports
With authentication
Create auth.yaml:
type: bearer
token: "your-token-here"
Then pass it:
phlatline scan my-api.yaml --config auth.yaml
For more auth options (API key, Basic, OAuth2) see INSTALL.md.
Multi-target project
Create phlatline.yaml:
name: my-project
targets:
- name: prod
schema: https://api.example.com/openapi.json
base_url: https://api.example.com
- name: staging
schema: https://staging.example.com/openapi.json
base_url: https://staging.example.com
Run all targets:
phlatline project phlatline.yaml
What it checks
| Category | What it does |
|---|---|
| Happy path | Verifies 2xx responses for valid inputs |
| Boundary | Tests min/max integers, empty strings, max-length strings, MAX_INT32 |
| Fuzz | Random valid inputs via Hypothesis — finds unexpected 500s (needs the [fuzz] extra) |
| Auth missing | Confirms the API rejects unauthenticated requests (401/403) |
CLI reference
phlatline scan SCHEMA [OPTIONS]
SCHEMA Path to an OpenAPI/Swagger file, or a URL.
--base-url TEXT Override base URL from the schema servers block.
--config FILE Path to auth config (JSON or YAML).
--output-dir TEXT Where to write reports (default: ./phlatline_results).
--no-fuzz Skip the fuzzing stage (faster).
--fuzz-examples INT Hypothesis examples per operation (default: 10).
--no-verify-ssl Skip TLS certificate verification.
-h, --help Show this message and exit.
phlatline project FILE [OPTIONS]
FILE Path to a phlatline.yaml multi-target project file.
--output-dir TEXT Where to write reports.
-h, --help Show this message and exit.
Supported formats
- OpenAPI 3.1 (JSON and YAML)
- OpenAPI 3.0 (JSON and YAML)
- Swagger 2.0 (JSON and YAML)
- Local files and HTTPS URLs
Development
git clone https://github.com/snoodleboot-io/phlatline-core
cd phlatline-core
python -m venv .venv && source .venv/bin/activate
pip install -e .[dev]
pytest
Tests use strict ATDD + TDD per ADR-002. Coverage target: 85%.
License
Business Source License 1.1 — free to use for non-production purposes.
Auto-converts to Apache 2.0 after 4 years (Change Date: 2029-05-01).
See LICENSE and NOTICE for the full text and Additional Use Grant.
Metadata
Release files for phlatline-core 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| phlatline_core-0.1.0.tar.gz | 85.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| phlatline_core-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 139.4 kB
Release files / phlatline_core-0.1.0.tar.gz
| Download URL | phlatline_core-0.1.0.tar.gz |
|---|---|
| Size | 85.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f8ed39a67579bb07fa3d9d105fe5fc2d504eb73d003215c482f1962b56e3753e
|
|
BLAKE2b-256 checksum How to use checksums |
57ffd7819422af1dec4032b44a3b91c025221e45fec86f1833176963d2e1b983
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 23, 2026.
Transparency logRelease files / phlatline_core-0.1.0-py3-none-any.whl
| Download URL | phlatline_core-0.1.0-py3-none-any.whl |
|---|---|
| Size | 53.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
89ba3c6ad3554a439dda70007009df4e43475a2954874b8b8b87005f7949f64d
|
|
BLAKE2b-256 checksum How to use checksums |
b2feb82c3c644d81fd4170bc17f8f581d09f9293314efb0e2b574ae920349076
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 23, 2026.
Transparency log