Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

SLIM Python Bindings (UniFFI)

Python bindings for SLIM (Secure Low-Latency Interactive Messaging) using UniFFI.

This provides a Python interface to the SLIM data plane, enabling secure, low-latency messaging with support for point-to-point and group (multicast) communication patterns.

Overview

These Python bindings are generated from the agntcy-slim-bindings-ffi crate using UniFFI, providing a native Python interface that wraps the high-performance Rust implementation.

Key Features

  • Point-to-Point Messaging: Direct communication between two endpoints
  • Group Messaging: Multicast communication with multiple participants
  • Secure by Default: Support for TLS, mTLS, and various authentication methods
  • MLS Encryption: End-to-end encryption for sessions
  • Delivery Confirmation: Optional completion handles for reliable messaging
  • Flexible Authentication: Shared secrets, JWT, SPIRE for app identity; Basic, JWT, SPIRE, and OIDC for the gRPC transport
  • slimrpc Support: Protocol Buffers RPC over SLIM - see SLIMRPC.md for details

Architecture

The Python bindings are built using Maturin, which automatically generates Python bindings from the Rust UniFFI adapter:

slim-bindings/
├── rust/          # Rust UniFFI bindings (shared by Go, Python, etc.)
│   ├── src/
│   │   ├── app.rs
│   │   ├── build_info.rs
│   │   ├── client_config.rs
│   │   ├── common_config.rs
│   │   ├── completion_handle.rs
│   │   ├── config.rs
│   │   ├── errors.rs
│   │   ├── identity.rs
│   │   ├── identity_config.rs
│   │   ├── init_config.rs
│   │   ├── lib.rs
│   │   ├── message_context.rs
│   │   ├── name.rs
│   │   ├── server_config.rs
│   │   ├── service.rs
│   │   └── session.rs
│   └── Cargo.toml
├── go/               # Go-specific bindings and examples
└── python/           # Python-specific bindings and examples (this directory)
    ├── examples/              # Example applications
    ├── tests/                 # Unit and integration tests
    └── Taskfile.yaml          # Build and development tasks

Prerequisites

  • Rust toolchain (1.70+)
  • Python (3.10+)
  • uv (Python package manager): https://docs.astral.sh/uv/
  • Task (optional, for convenient build commands)

Installation

Development Build

cd python
task python:bindings:build

This will:

  1. Install all dependencies
  2. Compile the Rust UniFFI adapter
  3. Generate Python bindings using Maturin
  4. Install the package in development mode

Creating Distribution Packages

Build Wheels for Multiple Python Versions

To create distributable wheel packages for Python 3.10, 3.11, 3.12, 3.13 and 3.14:

task python:bindings:packaging

Or directly with Maturin:

uv run maturin build --release -i 3.10 3.11 3.12 3.13

Maturin automatically:

  1. Compiles the Rust UniFFI adapter library
  2. Generates Python bindings from UniFFI scaffolding
  3. Bundles the native library into platform-specific wheels
  4. Creates wheels for each specified Python version

The resulting wheels are self-contained and ready for distribution.

Custom Build Options

You can customize the build with the following variables:

# Build for a specific target architecture
task python:bindings:packaging TARGET=aarch64-apple-darwin

# Build in debug mode (default is release)
task python:bindings:packaging PROFILE=debug

# Cross-compile for Linux on macOS
task python:bindings:packaging TARGET=x86_64-unknown-linux-gnu

Output Structure

After running the packaging task, you'll find:

dist/
├── slim_uniffi_bindings-0.7.0-cp310-*.whl  # Python 3.10 wheel
├── slim_uniffi_bindings-0.7.0-cp311-*.whl  # Python 3.11 wheel
├── slim_uniffi_bindings-0.7.0-cp312-*.whl  # Python 3.12 wheel
└── slim_uniffi_bindings-0.7.0-cp313-*.whl  # Python 3.13 wheel

Note: The native library is automatically bundled inside each wheel.

Installing from Wheel

Users can install the wheel package directly:

pip install slim_uniffi_bindings-0.7.0-cp310-*.whl

The native library is automatically included in the wheel and will be loaded at runtime.

Examples

Examples are a separate project in the examples/ directory.

See examples/README.md for detailed instructions.

Quick Start with Examples

cd examples

# View available examples
task

# Run simple example
task simple

# Run point-to-point examples
task p2p:alice    # Terminal 1
task p2p:bob      # Terminal 2

Quick Start

Simple Example

import slim_uniffi_bindings as slim

# Initialize crypto provider
slim.initialize_crypto_provider()

# Get version
print(f"SLIM Version: {slim.get_version()}")

# Create an app with shared secret authentication
app_name = {
    'components': ['org', 'example', 'app'],
    'id': None
}
app = slim.create_app_with_secret(app_name, "my-secret")

print(f"App ID: {app.id()}")
print(f"App Name: {'/'.join(app.name().components)}")

Run the simple example:

cd examples
task simple

Point-to-Point Communication

Terminal 1 - Receiver (Alice):

cd examples
task p2p:alice

Terminal 2 - Sender (Bob):

cd examples
task p2p:bob

Group Communication

Terminal 1 - Participant (Alice):

cd examples
task group:participant:alice

Terminal 2 - Participant (Bob):

cd examples
task group:participant:bob

Terminal 3 - Moderator:

cd examples
task group:moderator

For more details, see examples/README.md.

Transport Authentication (gRPC connection)

Separate from the app identity set at create_app_* time, the gRPC connection to a SLIM node can carry its own credentials via ClientConfig.auth (and ServerConfig.auth when hosting). Supported modes are BASIC, STATIC_JWT, JWT, SPIRE, and OIDC.

OIDC, client side (client-credentials flow):

import datetime
import slim_bindings

oidc = slim_bindings.OidcConfig(
    issuer_url="https://auth.example.com",
    client_id="my-client",
    client_secret="s3cr3t",
    audience=None,
    refresh_token=None,
    refresh_token_file=None,
    access_token_file=None,
    scope="openid profile",
    timeout=datetime.timedelta(seconds=30),
    jwks_ttl=None,
    claim_cache_ttl=None,
    policy=None,
)

base = slim_bindings.new_insecure_client_config("http://127.0.0.1:46357")
client_config = slim_bindings.ClientConfig(
    **{**vars(base), "auth": slim_bindings.ClientAuthenticationConfig.OIDC(config=oidc)}
)
conn_id = await service.connect_async(client_config)

For the refresh-token flow set refresh_token (or refresh_token_file, which is rewritten in place as tokens rotate) instead of client_secret.

Server side, verifying incoming JWTs against the issuer's JWKS endpoint, optionally restricting access by claim:

oidc = slim_bindings.OidcConfig(
    issuer_url="https://auth.example.com",
    client_id=None,
    client_secret=None,
    audience="slim",                                   # required for verification
    refresh_token=None,
    refresh_token_file=None,
    access_token_file=None,
    scope=None,
    timeout=None,
    jwks_ttl=datetime.timedelta(hours=1),
    claim_cache_ttl=datetime.timedelta(minutes=1),
    policy=slim_bindings.OidcPolicyConfig.CEL(expression='"admin" in claims.groups'),
)

base = slim_bindings.new_insecure_server_config("127.0.0.1:46357")
server_config = slim_bindings.ServerConfig(
    **{**vars(base), "auth": slim_bindings.ServerAuthenticationConfig.OIDC(config=oidc)}
)

policy accepts OidcPolicyConfig.CEL(expression=...), OidcPolicyConfig.REGO(text=...) (which must define package slim.auth with default allow = false), or OidcPolicyConfig.REGO_FILE(path=...). Client-only fields (scope, timeout) and server-only fields (jwks_ttl, claim_cache_ttl, policy) are ignored by the other side.

From a config file — the examples read SLIM_CLIENT_CONFIG (or --slim-config <path>), which covers every auth mode plus TLS material and backoff without any code change:

{
  "endpoint": "http://127.0.0.1:46357",
  "tls": { "insecure": true },
  "auth": {
    "type": "oidc",
    "issuer_url": "https://auth.example.com",
    "client_id": "my-client",
    "client_secret": "s3cr3t",
    "audience": "slim",
    "policy": { "cel": "\"admin\" in claims.groups" }
  }
}

The schema matches data-plane/core/config/src/grpc/schema/client-config.schema.json in the slim repo. To load one yourself, call slim_bindings.new_config_from_json(json_text).

API Overview

Application Creation

# Create app with shared secret
app = slim.create_app_with_secret(app_name, shared_secret)

# Get app information
app_id = app.id()
app_name = app.name()

Server Operations

# Connect to server
client_config = {
    'endpoint': 'http://localhost:46357',
    'tls': {'insecure': True, ...}
}
conn_id = app.connect(client_config)

# Run server
server_config = {
    'endpoint': '127.0.0.1:46357',
    'tls': {'insecure': True, ...}
}
app.run_server(server_config)

# Disconnect
app.disconnect(conn_id)

Session Management

# Create session
session_config = {
    'session_type': 'PointToPoint',  # or 'Group'
    'enable_mls': False,
    'max_retries': 3,
    'interval_ms': 100,
    'initiator': True,
    'metadata': {}
}
session = app.create_session(session_config, destination_name)

# Listen for incoming session
session = app.listen_for_session(timeout_ms=30000)

# Delete session
app.delete_session(session)

Messaging

# Send message (fire-and-forget)
session.publish(data, "text/plain", metadata)

# Send with delivery confirmation
completion = session.publish_with_completion(data, "text/plain", metadata)
completion.wait()  # Block until delivered

# Receive message
msg = session.get_message(timeout_ms=5000)
print(f"Payload: {msg.payload}")
print(f"From: {msg.context.source_name}")
print(f"Type: {msg.context.payload_type}")

# Reply to message
session.publish_to(msg.context, reply_data, "text/plain", None)

Group Operations

# Invite participant to group
session.invite(participant_name)

# Remove participant
session.remove(participant_name)

Examples

Examples Directory Structure

examples/
├── common/
│   └── common.py          # Shared utilities
├── simple/
│   └── main.py            # Basic functionality demo
├── point_to_point/
│   └── main.py            # P2P messaging
└── group/
    └── main.py            # Group/multicast messaging

Running Examples

All examples require a running SLIM server. Start the Go server:

cd go
task example:server

Then run Python examples:

# Simple example
task example

# Point-to-point
task example:p2p:alice      # Terminal 1
task example:p2p:bob        # Terminal 2

# Group messaging
task example:group:participant:alice    # Terminal 1
task example:group:participant:bob      # Terminal 2
task example:group:moderator            # Terminal 3

Testing

Unit Tests

task test
# or
python -m pytest tests/unit_test.py -v

Integration Tests

Integration tests require a running SLIM server:

# Terminal 1: Start server
cd ../go && task example:server

# Terminal 2: Run integration tests
SLIM_INTEGRATION_TEST=1 python -m pytest tests/integration_test.py -v -s

Development

Available Tasks

task                           # Show help
task build                     # Build package with Maturin
task test                      # Run tests
task python:bindings:packaging # Build wheels for multiple Python versions
task clean                     # Clean build artifacts

Project Structure

  • slim_uniffi_bindings/ - Python package (bindings generated by Maturin)
  • examples/ - Example applications
  • tests/ - Unit and integration tests
  • Taskfile.yaml - Build automation
  • pyproject.toml - Package configuration (Maturin build system)

Comparison with Go Bindings

Both Python and Go bindings use the same UniFFI adapter, ensuring API consistency:

Feature Python Go
Binding Generation uniffi-bindgen uniffi-bindgen-go
API Style Pythonic (snake_case) Idiomatic Go (PascalCase)
Error Handling Exceptions Error returns
Async Support Sync wrapper over async Rust Sync wrapper over async Rust
Examples ✅ ✅
Tests ✅ ✅

API Reference

Core Types

  • Name: Application/service identifier with components and optional ID
  • SessionConfig: Configuration for creating sessions
  • TlsConfig: TLS settings for secure connections
  • ServerConfig: Server endpoint and TLS configuration
  • ClientConfig: Client endpoint and TLS configuration
  • MessageContext: Message metadata (source, destination, type, metadata)
  • ReceivedMessage: Received message with context and payload

Main Classes

  • BindingsAdapter: Main app interface for session management
  • BindingsSessionContext: Session interface for messaging
  • FfiCompletionHandle: Completion handle for delivery confirmation

Session Types

  • PointToPoint: Direct one-to-one communication
  • Group: One-to-many multicast communication

Troubleshooting

ImportError: Cannot find slim_uniffi_bindings

Make sure you've built the package:

task build
# or
uv run maturin develop

Connection Refused

Ensure the SLIM server is running:

cd ../go && task example:server

Build Errors

If you encounter build errors, try cleaning and rebuilding:

task clean
uv run maturin develop

Contributing

When contributing to the Python bindings:

  1. Maintain API consistency with Go bindings
  2. Follow Python naming conventions (snake_case)
  3. Add tests for new functionality
  4. Update examples if adding features
  5. Keep documentation up to date

License

Apache-2.0 - See LICENSE.md for details

See Also

Metadata

Release files for slim-bindings 2.1.1rc3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for slim-bindings 2.1.1rc3
File
slim_bindings-2.1.1rc3-py3-none-win_arm64.whl Python 3 none Windows ARM64 Details
slim_bindings-2.1.1rc3-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64 Details
slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64 Details
slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_x86_64.whl Python 3 none Linux glibc 2.28+ x86-64 Details
slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_aarch64.whl Python 3 none Linux glibc 2.28+ ARM64 Details
slim_bindings-2.1.1rc3-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details
slim_bindings-2.1.1rc3-py3-none-macosx_10_12_x86_64.whl Python 3 none macOS 10.12+ x86-64 Details

Total release size: 175.9 MB

Release files / slim_bindings-2.1.1rc3-py3-none-win_arm64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-win_arm64.whl
Size 19.4 MB
Tags Python 3 Windows ARM64
SHA-256 checksum
How to use checksums
558fae163df923467d20f4c13e31b5a2409801ee8241118a0acf8723a6dd73fc
BLAKE2b-256 checksum
How to use checksums
beeb889f8777ad60225458228dae78d97e7145f79b8f7027101d59d6faa4fb93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-win_amd64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-win_amd64.whl
Size 20.8 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
e5df07cb3ce8e12f3c34a5cc9169423863fe5ed8919084bcc3b70a8ab6beddea
BLAKE2b-256 checksum
How to use checksums
8683eb45012eb0df0a0686917cbba8cfa9fb14671ae8f67b047d0f6f3f98f8d2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_x86_64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_x86_64.whl
Size 23.3 MB
Tags Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
c1a29f97c579a512c7248f07044c843f3f17d811cf7f31a7da4d18b62960351d
BLAKE2b-256 checksum
How to use checksums
a6c99a7fbdd704d9335a886b3efa1a72b3b42dc610f77b88e97d518111717c11
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_aarch64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_aarch64.whl
Size 22.6 MB
Tags Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
2add8127ece22a2e321ffe5b72cafdd33b2225346c1df87378a627ea49563138
BLAKE2b-256 checksum
How to use checksums
e5d4aec5fc698556f38a95d1dcb78d256d9eb0ca8a6879397b63458756a10a3b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_x86_64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_x86_64.whl
Size 23.3 MB
Tags Linux glibc 2.28+ x86-64 Python 3
SHA-256 checksum
How to use checksums
a40e2b47918f07319ec0e1dc29bc426ed187c5ef2c87ba6ce6112a68208e49ee
BLAKE2b-256 checksum
How to use checksums
23c9b6f9ff0de66adcefe8c2fe563c4512a21507e8b6bde4e9bf130e2fb50f4a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_aarch64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_aarch64.whl
Size 22.6 MB
Tags Linux glibc 2.28+ ARM64 Python 3
SHA-256 checksum
How to use checksums
730fe0221307cc9fd86953cc90d0ba1e6086bf60baa8d04d4f6ae4106438d1fb
BLAKE2b-256 checksum
How to use checksums
0a6a9f87c386384a6d8550057552a3df5c70ed84b991fd7f25f73a1b042919a9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-macosx_11_0_arm64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-macosx_11_0_arm64.whl
Size 21.5 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
b6629f89997e089c8cc20c7701986a6e3792363ca556a0acfebc18770ebf5ee1
BLAKE2b-256 checksum
How to use checksums
edd1478b3ce06b97a1cf44cf99a4e56dad156643123fa344af7ac1e5f8fcb9c7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release files / slim_bindings-2.1.1rc3-py3-none-macosx_10_12_x86_64.whl

Download URL slim_bindings-2.1.1rc3-py3-none-macosx_10_12_x86_64.whl
Size 22.3 MB
Tags Python 3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
e781a158ae4b4ea9d3e765db4cbe21a7b6b0c09d6a5a3f97fb621b7a3e8ad62f
BLAKE2b-256 checksum
How to use checksums
59c6dc8dd8f5aaaa3f7a0629bc7b3981587a8f0e91034c86c79a7dd088bf4c76
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.

Transparency log

Release history Release notifications | RSS feed

2.2.0

8 release files

2.1.2

8 release files

2.1.1

8 release files

This release

2.1.1rc3 This release

8 release files

2.1.0

8 release files

2.0.0

8 release files

1.4.1

8 release files

1.4.0

8 release files

1.3.0

8 release files

1.2.0

8 release files

1.1.1

8 release files

1.1.0

8 release files

1.0.1

8 release files

1.0.0

8 release files

0.7.1

21 release files

0.7.0

21 release files

0.6.3

26 release files

0.6.2

26 release files

0.6.1

26 release files

0.5.0

26 release files

0.4.0

26 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page