Python SDK for Quome sandboxes
Project description
quome
The official Python SDK for Quome sandboxes — isolated, ephemeral compute environments you can spin up, run commands in, exchange files with, and expose a preview URL from, all from a few lines of Python.
pip install quome
Streaming exec (run(..., on_stdout=...)) needs the ws extra:
pip install quome[ws]
Requires Python 3.10+.
Quickstart
import quome
sbx = quome.Sandbox.create(template="Code Write") # blocks until running
result = sbx.run("pytest -q")
print(result.exit_code, result.stdout)
sbx.files.write("report.txt", "all green\n")
print(sbx.files.read("report.txt"))
url = sbx.preview_url(8000, public=True) # see "Preview URLs" below
print(url)
sbx.stop()
Async
Every sync call has an async/await mirror under AsyncQuome /
AsyncSandbox, with identical method names and semantics:
import asyncio
import quome
async def main() -> None:
sbx = await quome.AsyncSandbox.create(template="Code Write")
result = await sbx.run("pytest -q")
print(result.exit_code, result.stdout)
await sbx.stop()
asyncio.run(main())
Note that org_id is an async method on AsyncQuome (await client.org_id()),
not a property — resolving it makes a network call the first time it's used.
Authentication
The SDK reads your API key from the QUOME_API_KEY environment variable (or
pass api_key= explicitly to quome.Quome(...) / quome.AsyncQuome(...)):
export QUOME_API_KEY=qk_...
Use a service-account key with sandbox grants, not your org-owner key. Create one under Settings → Service Accounts → API keys and grant it only the sandbox permissions it needs, rather than reusing the full-owner key from the general Settings → API Keys page. A service-account key is scoped to exactly the resources you grant it (least privilege); an org-owner key can do anything in the org, so a leaked owner key is a much bigger blast radius than a leaked, narrowly-scoped one.
The org id for the key is resolved automatically (GET /api/v1/api-keys/self,
cached on the client) — you normally don't need to set it. QUOME_ORG_ID is
available as an override for multi-org service accounts.
base_url defaults to https://api.quome.studio; override with
QUOME_BASE_URL or base_url= for self-hosted / dev environments.
Secrets
Never put secret values inline in a command string passed to run() — exec
commands are audit-logged verbatim, so anything in the command text ends up
in the audit trail in plaintext. Pass secrets through env= instead (or
inject a secret binding into the sandbox ahead of time):
# Wrong — the API key literal lands in the audit log
sbx.run(f"curl -H 'Authorization: Bearer {api_key}' https://example.com")
# Correct — env values are not part of the logged command text
sbx.run("curl -H \"Authorization: Bearer $API_KEY\" https://example.com", env={"API_KEY": api_key})
Preview URLs
url = sbx.preview_url(8000, public=True)
public=True is required (keyword-only) — there is no way to call
preview_url without explicitly opting in. The returned URL is publicly
internet-reachable: anyone who has the link can hit the exposed port with
no further authentication. An unguessable subdomain is not access control —
don't put anything behind it that requires real auth unless the app itself
enforces it.
Streaming exec
def on_chunk(text: str) -> None:
print(text, end="")
result = sbx.run("some-long-build.sh", on_stdout=on_chunk)
Streaming requires the quome[ws] extra (pip install quome[ws]) — without
it, run(..., on_stdout=...) raises a clear QuomeError telling you to
install it. The streaming protocol carries incremental stdout only: it has no
exit-code channel and no separate stderr, so a streamed ExecResult always
has exit_code=None and stderr="". If you need the exit code, call
run() without on_stdout (a normal synchronous or job-polled exec, which
does return exit_code).
Files
sbx.files.write("app.py", source_code) # str or bytes; creates or overwrites
data = sbx.files.read("app.py") # raw bytes
names = sbx.files.list("/workspace") # entry names in a directory
sbx.files.delete("app.py")
Errors
All SDK exceptions derive from quome.QuomeError. HTTP errors from the API
map to typed subclasses of quome.QuomeAPIError:
| Exception | When |
|---|---|
AuthenticationError |
401/403, or no API key configured |
NotFoundError |
404 |
QuotaExceededError |
429 (carries retry_after when the server sends one) |
SandboxNotRunningError |
409 against a sandbox that isn't running |
SandboxProvisioningError |
a sandbox lands in a terminal failure state while Sandbox.create(wait=True) is waiting for running |
QuomeAPIError |
any other non-2xx response (fallback) |
None of these ever carry the API key — only HTTP status codes and server-provided detail strings.
API stability
The SDK wraps a specific, documented subset of the Quome REST API (sandbox
lifecycle, exec, files, preview URLs, templates, key introspection). That
subset is the SDK's stable public contract — changes to it are additive
only, and breaking changes ship as an SDK major version bump. Everything else
under /api/v1 is internal to the Quome web app and may change without
notice; don't call undocumented endpoints directly and expect stability. See
docs/developer-guide/python-sdk.md in the main repo for the full endpoint
table.
License
Apache-2.0
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file quome-0.1.0.tar.gz.
File metadata
- Download URL: quome-0.1.0.tar.gz
- Upload date:
- Size: 35.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.12.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
073e5de960a7087d9ca095936909876dcf37deb00454532b5fb137533dfb0aea
|
|
| MD5 |
7ab565094d15ce9247a5629b92c87435
|
|
| BLAKE2b-256 |
bc802a38e0355e9eaddf5ee3e03832e075ffd6f134d9b6e24db8e3e59694b847
|
Provenance
The following attestation bundles were made for quome-0.1.0.tar.gz:
Publisher:
release.yml on quome-cloud/quome-sdk-python
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
quome-0.1.0.tar.gz -
Subject digest:
073e5de960a7087d9ca095936909876dcf37deb00454532b5fb137533dfb0aea - Sigstore transparency entry: 2112426016
- Sigstore integration time:
-
Permalink:
quome-cloud/quome-sdk-python@eedf1c36d4524e11380967a7cec263232e108082 -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/quome-cloud
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@eedf1c36d4524e11380967a7cec263232e108082 -
Trigger Event:
push
-
Statement type:
File details
Details for the file quome-0.1.0-py3-none-any.whl.
File metadata
- Download URL: quome-0.1.0-py3-none-any.whl
- Upload date:
- Size: 31.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.12.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c9c6485925e5a84c89661481e3c7253b5036afc7c3c413afa13b63c362891072
|
|
| MD5 |
70986b4abf814d598f2a78bff08251e2
|
|
| BLAKE2b-256 |
22d1829cb6b86fadafb2dc716e395dad9723550f964f35595d668e8557fc92d1
|
Provenance
The following attestation bundles were made for quome-0.1.0-py3-none-any.whl:
Publisher:
release.yml on quome-cloud/quome-sdk-python
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
quome-0.1.0-py3-none-any.whl -
Subject digest:
c9c6485925e5a84c89661481e3c7253b5036afc7c3c413afa13b63c362891072 - Sigstore transparency entry: 2112426057
- Sigstore integration time:
-
Permalink:
quome-cloud/quome-sdk-python@eedf1c36d4524e11380967a7cec263232e108082 -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/quome-cloud
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@eedf1c36d4524e11380967a7cec263232e108082 -
Trigger Event:
push
-
Statement type: