Skip to main content

refactron (Python wrapper)

The verification layer for AI code change. Refactron proves that a change, your AI agent's, a codemod's, or your own, preserved behavior. It applies the diff in an isolated shadow tree, runs your real test suite, and returns a three-way verdict: SAFE, UNSAFE, or UNPROVEN. Your working tree is never touched.

This package is a thin Python shim around the npm refactron package. It exists so a Python-first toolchain can put the refactron command on your PATH without adding Node to your project manifest. All the real work happens in the Node CLI.

Requirements

  • Node.js 18+ on your PATH. This wrapper does not remove the Node dependency; it only saves you from wiring the CLI in by hand.
  • Python 3.8+, plus coverage.py in the environment your tests run in if you want coverage-backed verdicts.

Install

pip install refactron==0.3.0
npm install -g refactron

Both lines matter. The pip package gives you the refactron entry point; the npm package is what it runs. Keep the two versions equal: the wrapper prints a warning to stderr when they disagree.

The wrapper does not install the npm package for you. A pip install that silently ran npm install -g would write outside your Python environment and would pull whatever version is latest, which is not necessarily the version you pinned. If the Node CLI is missing, the wrapper tells you the exact command to run and exits non-zero.

Prefer not to install globally? Skip the pip package and use npx refactron <command> directly.

Usage

Identical to the npm package. Every argument is passed straight through.

refactron login                                  # or set REFACTRON_TOKEN in CI
refactron verify-diff . --diff change.diff --test-cmd "python3 -m pytest -q"
refactron preflight ./my-sqlalchemy-app
refactron analyze .
refactron run --apply

verify-diff exits 1 on UNSAFE, 2 on bad input, 7 when unauthenticated, and 0 on both SAFE and UNPROVEN. UNPROVEN is a warning, not a rejection: read the verdict field from --json if you want CI to fail on it.

Coverage attestation is Python-only, via coverage.py. A TypeScript, mixed, or otherwise non-Python diff caps at UNPROVEN; it never returns a false SAFE.

MCP server

The npm package also ships a refactron-mcp binary, a stdio MCP server exposing a verify_change tool your agent calls before it lands a change. It is not routed through this wrapper: point your MCP client at refactron-mcp directly. See the MCP docs.

Environment variables

Variable Effect
REFACTRON_TOKEN Authenticates non-interactive runs (CI).
REFACTRON_SKIP_VERSION_CHECK Set to 1 to silence the wrapper's version-skew warning.

License

Apache-2.0. See LICENSE and NOTICE.

Full docs: https://docs.refactron.dev

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

refactron-0.4.1.tar.gz (10.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

refactron-0.4.1-py3-none-any.whl (11.2 kB view details)

Uploaded Python 3

File details

Details for the file refactron-0.4.1.tar.gz.

File metadata

  • Download URL: refactron-0.4.1.tar.gz
  • Upload date:
  • Size: 10.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for refactron-0.4.1.tar.gz
Algorithm Hash digest
SHA256 e7007f4edd2ee60a5516f9c4b8e69d5793ea6edb7483968c49458f1bae18091d
MD5 a1bb46e025ee06dca73511820110c4d9
BLAKE2b-256 b18da3cd926c7da2b36700dd0a19cd11d7ea6c9d657fece5bbc6a8260818fd2a

See more details on using hashes here.

Provenance

The following attestation bundles were made for refactron-0.4.1.tar.gz:

Publisher: release.yml on Refactron-ai/refactron

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file refactron-0.4.1-py3-none-any.whl.

File metadata

  • Download URL: refactron-0.4.1-py3-none-any.whl
  • Upload date:
  • Size: 11.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for refactron-0.4.1-py3-none-any.whl
Algorithm Hash digest
SHA256 13feff807d524b7004c8e0549c09960c25192e19c21c3b373deb301070d2d8d1
MD5 15c714324bdea7fec5b4e484846b68f4
BLAKE2b-256 c40add6ffcb9d5b447766c568a835d07594968069e4dc9c3520a6492081acc64

See more details on using hashes here.

Provenance

The following attestation bundles were made for refactron-0.4.1-py3-none-any.whl:

Publisher: release.yml on Refactron-ai/refactron

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page