Skip to main content

Ranbval: load .ranbval* config, decrypt vault tokens, optional telemetry (BYO HTTP/vendor SDK)

Project description

Ranbval Python SDK

Load layered .ranbval* into the environment, decrypt ranbval.* tokens when you call safe_decrypt, and optionally emit_telemetry so your password-manager sees usage — with any HTTP client or vendor SDK you already use.

No vendor SDKs are bundled. OpenAI / Stripe / custom requests flows are all the same story: load env → call your API → ping telemetry if you want the Live Monitor.

Install

pip install ranbval-sdk

Then in your project (examples):

pip install openai
# or: pip install anthropic stripe …

Config: layered .ranbval*

Call load_ranbval() yourself (not on import).

from ranbval_sdk import load_ranbval

load_ranbval()

Merge order (later overrides earlier): .ranbval.ranbval.{mode}.ranbval.local.ranbval.{mode}.local. Mode from load_ranbval(mode="production") or RANBVAL_ENV / ENVIRONMENT / ENV (default development).

See .ranbval.example. Add .ranbval.local to .gitignore.

Quick start — env load + your own client + telemetry

.ranbval keeps ranbval.* tokens as-is in the environment (not decrypted at load time). You decrypt right before the call, then tell Ranbval a request happened:

import os
import openai
from ranbval_sdk import load_ranbval, safe_decrypt, emit_telemetry

load_ranbval()
raw = os.environ["OPENAI_API_KEY"]
secret = os.environ["RANBVAL_VAULT_SECRET"]
api_key = safe_decrypt(raw, secret) if raw.startswith("ranbval.") else raw

client = openai.OpenAI(api_key=api_key)
resp = client.chat.completions.create(
    model="gpt-4o-mini",
    messages=[{"role": "user", "content": "hi"}],
)
emit_telemetry(
    vault_token_env="OPENAI_API_KEY",
    model_used="openai.chat.completions",
    prompt_tokens=resp.usage.prompt_tokens,
    completion_tokens=resp.usage.completion_tokens,
    background=True,
)

Same idea with requests, httpx, or an internal microservice: decrypt (if needed) → call → emit_telemetry(...) with a label in model_used. If the env var is not a ranbval.* token, pass client_salt="..." explicitly instead of vault_token_env.

Optional — auto-wrap any SDK class

If you prefer Ranbval to inject the key and optionally patch one method for background telemetry:

import openai
from ranbval_sdk import load_ranbval, secure_client

load_ranbval()
client = secure_client(
    openai.OpenAI,
    env_var="OPENAI_API_KEY",
    key_kwarg="api_key",
    method_path_to_patch="chat.completions.create",  # optional: telemetry after each call
)
client.chat.completions.create(
    model="gpt-4o-mini",
    messages=[{"role": "user", "content": "hi"}],
)
import anthropic
from ranbval_sdk import load_ranbval, secure_client

load_ranbval()
claude = secure_client(
    anthropic.Anthropic,
    env_var="ANTHROPIC_API_KEY",
    key_kwarg="api_key",
    method_path_to_patch="messages.create",
)
import stripe
from ranbval_sdk import load_ranbval, secure_client

load_ranbval()
stripe_client = secure_client(
    stripe.StripeClient,
    env_var="STRIPE_SECRET_KEY",
    key_kwarg="api_key",
)

Lower-level: build_secure_client(SDKClass, env_var_name, key_kwarg, method_path_to_patch=None) returns a class you can reuse or subclass.

Low-level decrypt

from ranbval_sdk import safe_decrypt

plain = safe_decrypt("ranbval.noise.blob.ahsan", os.environ["RANBVAL_VAULT_SECRET"])

Telemetry

emit_telemetry and secure_client(..., method_path_to_patch=...) both POST to POST {RANBVAL_HOST}/api/telemetry. Use emit_telemetry when you own the HTTP/SDK call; use method_path_to_patch when you want a background ping after one wrapped method returns (generic counts unless you pass token fields yourself via emit_telemetry).

Variable Meaning
RANBVAL_HOST Password-manager origin (no /api). Defaults to hosted service.
RANBVAL_TELEMETRY 0 / false / off — disable
RANBVAL_TELEMETRY_DEBUG 1 / true — print POST failures to stderr

Auth service URL is not RANBVAL_HOST — telemetry goes to the password-manager API only.

SSL on macOS: certifi is used for HTTPS; pip install -U certifi if verify fails.

Git remote allowlist

Variable Meaning
RANBVAL_HOST Same origin as telemetry (/api/public/repo-policy).
RANBVAL_SKIP_REPO_CHECK 1 / true — skip (dev only).

See ranbval-password-manager README for ingest schema and dashboard behavior.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ranbval_sdk-0.4.1.tar.gz (11.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ranbval_sdk-0.4.1-cp312-cp312-macosx_26_0_arm64.whl (13.9 kB view details)

Uploaded CPython 3.12macOS 26.0+ ARM64

File details

Details for the file ranbval_sdk-0.4.1.tar.gz.

File metadata

  • Download URL: ranbval_sdk-0.4.1.tar.gz
  • Upload date:
  • Size: 11.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.3.2 CPython/3.12.0 Darwin/25.4.0

File hashes

Hashes for ranbval_sdk-0.4.1.tar.gz
Algorithm Hash digest
SHA256 19e5f1dffd6b27a9c6ef2c27cbb6b0fd9f2d75f3da3751203f2ff467e7dfbf93
MD5 45b3783a75b145c4d87ff4f612292eae
BLAKE2b-256 3c65e1c672c26abba1b835c132fb59c7b5ee01e859889bc7d9e0515031a579f6

See more details on using hashes here.

File details

Details for the file ranbval_sdk-0.4.1-cp312-cp312-macosx_26_0_arm64.whl.

File metadata

File hashes

Hashes for ranbval_sdk-0.4.1-cp312-cp312-macosx_26_0_arm64.whl
Algorithm Hash digest
SHA256 44105169998e5c7d47905dd677d369b4b86277890bfb531c7843e2f69fa74267
MD5 11ab0ff923ee98704a68e1f99bff725f
BLAKE2b-256 9b0363d2d1b86274b7286cd949594b2b48cd3c070a83cbdd3147880c62f0b9e6

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page