Skip to main content

postkit SDK

Python client for postkit.

Installation

pip install postkit

Usage

import psycopg
from postkit.authz import AuthzClient
from postkit.authn import AuthnClient

conn = psycopg.connect("postgresql://...")
cursor = conn.cursor()

# Authorization
authz = AuthzClient(cursor, namespace="my-app")
authz.set_hierarchy("repo", "admin", "write", "read")
authz.grant("admin", resource=("repo", "api"), subject=("user", "alice"))
if authz.check(("user", "alice"), "read", ("repo", "api")):
    print("Access granted")

# Authentication
authn = AuthnClient(cursor, namespace="my-app")
user_id = authn.create_user("alice@example.com", password_hash="argon2...")
session_id = authn.create_session(user_id, token_hash="sha256...")

Tenant Context and Transactions

Constructing a client calls {module}.set_tenant(namespace) immediately. The setting is transaction-scoped, so inside an open transaction the constructor taints that transaction's context for the module until commit or rollback; an unrelated client built mid-transaction can therefore change which rows a later raw SQL statement sees.

Every SDK call needs a transaction for that context. On autocommit connections each call runs in its own transaction and commits immediately. On non-autocommit connections each call joins the connection's open transaction: nothing is durable until you commit, and a rollback takes it all with it, including a queue claim from pull(). That is the intended model for transactional consumers; nack/fail accept the pending job a rollback leaves behind.

In CI, call client.assert_rls_active() during setup. A suite connecting as a superuser or BYPASSRLS role (the docker default) bypasses every RLS policy and exercises none of the tenancy model.

Requirements

  • PostgreSQL 14+
  • The postkit SQL schema installed in your database

See the main repository for SQL installation instructions.

Release files for postkit 0.11.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for postkit 0.11.0
File Size Uploaded
postkit-0.11.0.tar.gz 276.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for postkit 0.11.0
File Interpreter ABI Platform
postkit-0.11.0-py3-none-any.whl Python 3 none any Details

Total release size: 338.3 kB

Release files / postkit-0.11.0.tar.gz

Download URL postkit-0.11.0.tar.gz
Size 276.2 kB
Tags Source
SHA-256 checksum
How to use checksums
99ac99cd9d346a52b5ada5277daf3dee91b6943f58d0f032bde823b54017b7ee
BLAKE2b-256 checksum
How to use checksums
fb9e0d3dd5e1ce1b5d2f64b0f04d4f295b738401ceb2476ddb52ea13d7dfd60f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 20, 2026.

Transparency log

Release files / postkit-0.11.0-py3-none-any.whl

Download URL postkit-0.11.0-py3-none-any.whl
Size 62.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d225c7f29de4e0f67649aac49dceb343b3f3bdc88f64d885d71fdac2f727e7cd
BLAKE2b-256 checksum
How to use checksums
aa803deace5ca96056837fd3c40014e267a5bfc9aa659a720bf17e06d0a6d237
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 20, 2026.

Transparency log

Release history Release notifications | RSS feed

0.12.1

2 release files

0.12.0

2 release files

This release

0.11.0 This release

2 release files

0.10.0

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page