Skip to main content

SignalGate antifraud backend SDK for Python — thin HTTP forwarder to api.signalgate.ai

Project description

signalgate — Python backend SDK

Python 3.10+ License: Apache 2.0

Thin HTTP forwarder for SignalGate antifraud. Tenants embed this in their backend to call /v0/check (synchronous verdict) and /v0/log (async analytics). The SDK does no crypto — the opaque encrypted payload comes from @signalgate/frontend-js-sdk.

Install

pip install signalgate

For local development against an unpublished checkout:

pip install -e /path/to/backend-python-sdk

Quickstart

Rule: call check OR log for a given event, never both. As of v0.2.0 the server persists the event as part of /v0/check, so a follow-up log() with the same nonce is replay-rejected (422). Choose one path per event.

Path A — you need a verdict (call check only):

from signalgate import Client, Event, EncryptedPayload

client = Client(api_key="<your-jwt>")

event = Event(
    user_id="u_123",
    ip=request.headers.get("X-Forwarded-For", request.remote_addr),
    method="login",
    timestamp="2026-04-01T13:08:50+00:00",
    payload=EncryptedPayload(**frontend_payload_dict),  # verbatim from the browser
    custom={"plan": "pro"},
)

# check() sends to /v0/check, which returns a verdict AND persists the event
# server-side for analytics. Do NOT call log() afterwards.
verdict = client.check(event)
if verdict.action == "block":
    raise PermissionError("blocked by SignalGate")

Path B — fire-and-forget analytics only (no verdict needed):

# log() sends to /v0/log asynchronously. Use this for events you are not
# checking — background actions, page-view telemetry, etc.
client.log(event)

At process shutdown:

client.close()  # drains the log queue within 5 × log_timeout_ms

Or use it as a context manager:

with Client(api_key="...") as client:
    client.check(event)

Configuration

Override the defaults selectively:

Client(
    api_key="...",
    check_timeout_ms=3000,
    log_timeout_ms=1000,
    log_queue_capacity=10000,
    log_max_retries=3,
    fail_open=True,   # default: on timeout/5xx, check() returns allow
)

Error handling

check() raises on 4xx (tenant bug — bad JWT, malformed event). With fail_open=True (default), timeouts / network errors / 5xx return a synthesized CheckResult(action="allow", failed_open=True).

from signalgate import ServerError, TimeoutError, NetworkError

try:
    result = client.check(event)
except ServerError as e:
    # e.status_code, e.code, e.message, e.request_id, e.details
    ...

log() never raises. Failures are counted in client.metrics.

Metrics

client.metrics.get("check_total")
client.metrics.get("check_failed_open_total")
client.metrics.get("log_dropped_total", reason="queue_full")
client.metrics.snapshot()  # all counters

Full counter list:

Counter Labels Incremented when
check_total check() called
check_success_total check() returned a real verdict
check_failed_open_total check() returned a synthesized allow
check_error_total type check() raised
log_enqueued_total log() accepted into queue
log_sent_total server acknowledged a log event
log_http_error_total status a log retry was triggered
log_dropped_total reason queue_full / closed / retry_exhausted

Development

pip install -e ".[dev]"   # install with dev extras
pytest -q                 # run the test suite

CI runs pytest -q on every push and PR to main via .github/workflows/test.yml (Python 3.12, pip cache keyed on pyproject.toml).

License

Licensed under the Apache License, Version 2.0.

Links

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

signalgate-0.2.0.tar.gz (28.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

signalgate-0.2.0-py3-none-any.whl (15.6 kB view details)

Uploaded Python 3

File details

Details for the file signalgate-0.2.0.tar.gz.

File metadata

  • Download URL: signalgate-0.2.0.tar.gz
  • Upload date:
  • Size: 28.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.9

File hashes

Hashes for signalgate-0.2.0.tar.gz
Algorithm Hash digest
SHA256 0d4598ca81ef014cf621f54d2762994a4e25079d92eb49adce82079159e4126b
MD5 35e52ee7943c28c5898a0521bd8eeb7a
BLAKE2b-256 f381f2693c1804f843f603d9100ed440332b5e3d0118c8670663a7de1d4e54db

See more details on using hashes here.

File details

Details for the file signalgate-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: signalgate-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 15.6 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.11.9

File hashes

Hashes for signalgate-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 2c337a6eb612390845f44edb0dc715efc5fb4c8b98d1b0a8b7192ee12e59c59b
MD5 b71c846db21c0debe01cc17f83fb8986
BLAKE2b-256 a67ad7e01bc222cd0c337837dc14bd2a5bbfdb1a20e4e58dbf26b13f4ef275c9

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page