Skip to main content

Build PyPi version PyPi status

SEAR Logo

Security API for RACF (SEAR)

A standardized JSON interface for RACF that enables seamless exploitation by programming languages that have a foreign language interface for C/C++ and native JSON support.

Description

As automation becomes more and more prevalent, the need to manage the security environment programmatically increases. On z/OS that means managing a security product like the IBM Resource Access Control Facility (RACF). RACF is the primary facility for managing identity, authority, and access control for z/OS. There are more than 50 callable services with assembler interfaces that are part of the RACF API. The complete set of interfaces can be found in the IBM documentation.

While there are a number of languages that can be used to manage RACF, (from low level languages like Assembler to higher level languages like REXX), the need to be able to easily exploit RACF management functions using existing industry standard programming languages and even programming languages that don't exist yet is paramount. The SEAR project is focused on making RACF management functions available to all programming languages that have native JSON support and a foreign language interface for C/C++. This will make it easier to pivot to new tools and programming languages as technology, skills, and business needs continue to evolve in the foreseeable future.

Minimum z/OS & Language Versions

All versions of z/OS and the IBM Open Enterprise SDK for Python that are fully supported by IBM are supported by SEAR.

Dependencies

  • R_SecMgtOper (IRRSMO00): Security Management Operations.
  • R_Admin (IRRSEQ00): RACF Administration API.
  • R_Datalib (IRRSDL64): RACF Certificate data library.
  • RACF Subsystem Address Space: This is a dependency for both IRRSMO00 and IRRSEQ00.
  • z/OS Language Environment Runtime Support: SEAR is compiled using the IBM Open XL C/C++ 2.1 compiler, which is still fairly new and requires z/OS Language Environment service updates for runtime support.

Getting started

:bulb: Note: You can also Download & Install SEAR from GitHub

pip install pysear

Make sure you have the right authorizations, detailed in the full documentation.

How to create a simple userid using SEAR in Python:

from sear import sear

result = sear(
    {
        "operation": "add",
        "admin_type": "user",
        "userid": "FDEGILIO",
        "traits": {
            "base:name": "FRANK D",
        },
    },
)

print(result.result)

Further examples are located under examples in the documentation.

Additional help can be found in the following communities:

Build from source

Alternatively to installing from Pip, SEAR can be built from source on a z/OS system. SEAR uses a CMake build system, and can be built via a two-step process:

cmake --preset <preset>
cmake --build --preset <preset> --target <sear,pysear>

The first command will configure the build environment and generate build scripts in a directory named build/<preset>, then the second command builds the given target.

A complete list of available CMake presets can be found in CMakePresets.json, but the most useful are:

  • default - Does not apply any special platform handling, and should work on most platforms.

  • zos - Applies the cmake/ibm-clang.cmake toolchain to the build process. This compiles the project using the IBM-Clang compiler, and works only on z/OS systems.

  • zos-pysear - Inherits from the zos preset. Used internally as part of the Python package build process, and not generally used by hand.

Build artifacts are located within the build directory.

The CMake build process builds static libraries by default. If you instead wish to build shared libraries, append -DBUILD_SHARED_LIBS=on to the CMake configure step command (the first of the two) shown above.

Maintainers

  • Bobby Tjassens Keiser
  • Emma Skovgård

Authors of RACFu

This is a fork of RACFu

Metadata

Release files for pysear 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pysear 0.7.0
File Size Uploaded
pysear-0.7.0.tar.gz 630.0 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for pysear 0.7.0
File Interpreter ABI Platform
pysear-0.7.0-py314-none-any.whl Python 3.14 none any Details
pysear-0.7.0-py313-none-any.whl Python 3.13 none any Details

Total release size: 11.3 MB

Release files / pysear-0.7.0.tar.gz

Download URL pysear-0.7.0.tar.gz
Size 630.0 kB
Tags Source
SHA-256 checksum
How to use checksums
d6ad7a80e600f4562489452d9a1bb9c2e12a70979589a3ad46398b48dc80eae9
BLAKE2b-256 checksum
How to use checksums
6e3ecf5ae06650ce5f9eff5f84459e57ed5363c0a42bb0ffc882673e73f92081
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / pysear-0.7.0-py314-none-any.whl

Download URL pysear-0.7.0-py314-none-any.whl
Size 5.3 MB
Tags Python 3.14
SHA-256 checksum
How to use checksums
3b8377e7b6b41d1383c16f680f52e68a40d0d71156b6296bbb836fcd2a2f0097
BLAKE2b-256 checksum
How to use checksums
fd8310348fc306c2c2dd562716c1f2b444ef24b0a8834468ff6c242de8b5b3a3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / pysear-0.7.0-py313-none-any.whl

Download URL pysear-0.7.0-py313-none-any.whl
Size 5.3 MB
Tags Python 3.13
SHA-256 checksum
How to use checksums
198ae678065e3ddc90ccaa710f83d6be972cbcf4ba604ff8af268a706df2a5d3
BLAKE2b-256 checksum
How to use checksums
127b86349f87487e569b50ed7fc86f07281d5ec31f4a59e7a54872316024e8df
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.7.0 This release

3 release files

0.6.0

4 release files

0.5.0

4 release files

0.4.0

3 release files

0.3.1

3 release files

0.3.0

3 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page