This release is a pre-release and may not be stable for production use.
SLIM Python Bindings (UniFFI)
Python bindings for SLIM (Secure Low-Latency Interactive Messaging) using UniFFI.
This provides a Python interface to the SLIM data plane, enabling secure, low-latency messaging with support for point-to-point and group (multicast) communication patterns.
Overview
These Python bindings are generated from the agntcy-slim-bindings-ffi crate
using UniFFI, providing a native
Python interface that wraps the high-performance Rust implementation.
Key Features
- Point-to-Point Messaging: Direct communication between two endpoints
- Group Messaging: Multicast communication with multiple participants
- Secure by Default: Support for TLS, mTLS, and various authentication methods
- MLS Encryption: End-to-end encryption for sessions
- Delivery Confirmation: Optional completion handles for reliable messaging
- Flexible Authentication: Shared secrets, JWT, SPIRE for app identity; Basic, JWT, SPIRE, and OIDC for the gRPC transport
- slimrpc Support: Protocol Buffers RPC over SLIM - see SLIMRPC.md for details
Architecture
The Python bindings are built using Maturin, which automatically generates Python bindings from the Rust UniFFI adapter:
slim-bindings/
├── rust/ # Rust UniFFI bindings (shared by Go, Python, etc.)
│ ├── src/
│ │ ├── app.rs
│ │ ├── build_info.rs
│ │ ├── client_config.rs
│ │ ├── common_config.rs
│ │ ├── completion_handle.rs
│ │ ├── config.rs
│ │ ├── errors.rs
│ │ ├── identity.rs
│ │ ├── identity_config.rs
│ │ ├── init_config.rs
│ │ ├── lib.rs
│ │ ├── message_context.rs
│ │ ├── name.rs
│ │ ├── server_config.rs
│ │ ├── service.rs
│ │ └── session.rs
│ └── Cargo.toml
├── go/ # Go-specific bindings and examples
└── python/ # Python-specific bindings and examples (this directory)
├── examples/ # Example applications
├── tests/ # Unit and integration tests
└── Taskfile.yaml # Build and development tasks
Prerequisites
- Rust toolchain (1.70+)
- Python (3.10+)
- uv (Python package manager): https://docs.astral.sh/uv/
- Task (optional, for convenient build commands)
Installation
Development Build
cd python
task python:bindings:build
This will:
- Install all dependencies
- Compile the Rust UniFFI adapter
- Generate Python bindings using Maturin
- Install the package in development mode
Creating Distribution Packages
Build Wheels for Multiple Python Versions
To create distributable wheel packages for Python 3.10, 3.11, 3.12, 3.13 and 3.14:
task python:bindings:packaging
Or directly with Maturin:
uv run maturin build --release -i 3.10 3.11 3.12 3.13
Maturin automatically:
- Compiles the Rust UniFFI adapter library
- Generates Python bindings from UniFFI scaffolding
- Bundles the native library into platform-specific wheels
- Creates wheels for each specified Python version
The resulting wheels are self-contained and ready for distribution.
Custom Build Options
You can customize the build with the following variables:
# Build for a specific target architecture
task python:bindings:packaging TARGET=aarch64-apple-darwin
# Build in debug mode (default is release)
task python:bindings:packaging PROFILE=debug
# Cross-compile for Linux on macOS
task python:bindings:packaging TARGET=x86_64-unknown-linux-gnu
Output Structure
After running the packaging task, you'll find:
dist/
├── slim_uniffi_bindings-0.7.0-cp310-*.whl # Python 3.10 wheel
├── slim_uniffi_bindings-0.7.0-cp311-*.whl # Python 3.11 wheel
├── slim_uniffi_bindings-0.7.0-cp312-*.whl # Python 3.12 wheel
└── slim_uniffi_bindings-0.7.0-cp313-*.whl # Python 3.13 wheel
Note: The native library is automatically bundled inside each wheel.
Installing from Wheel
Users can install the wheel package directly:
pip install slim_uniffi_bindings-0.7.0-cp310-*.whl
The native library is automatically included in the wheel and will be loaded at runtime.
Examples
Examples are a separate project in the examples/ directory.
See examples/README.md for detailed instructions.
Quick Start with Examples
cd examples
# View available examples
task
# Run simple example
task simple
# Run point-to-point examples
task p2p:alice # Terminal 1
task p2p:bob # Terminal 2
Quick Start
Simple Example
import slim_uniffi_bindings as slim
# Initialize crypto provider
slim.initialize_crypto_provider()
# Get version
print(f"SLIM Version: {slim.get_version()}")
# Create an app with shared secret authentication
app_name = {
'components': ['org', 'example', 'app'],
'id': None
}
app = slim.create_app_with_secret(app_name, "my-secret")
print(f"App ID: {app.id()}")
print(f"App Name: {'/'.join(app.name().components)}")
Run the simple example:
cd examples
task simple
Point-to-Point Communication
Terminal 1 - Receiver (Alice):
cd examples
task p2p:alice
Terminal 2 - Sender (Bob):
cd examples
task p2p:bob
Group Communication
Terminal 1 - Participant (Alice):
cd examples
task group:participant:alice
Terminal 2 - Participant (Bob):
cd examples
task group:participant:bob
Terminal 3 - Moderator:
cd examples
task group:moderator
For more details, see examples/README.md.
Transport Authentication (gRPC connection)
Separate from the app identity set at create_app_* time, the gRPC connection to a SLIM node
can carry its own credentials via ClientConfig.auth (and ServerConfig.auth when hosting).
Supported modes are BASIC, STATIC_JWT, JWT, SPIRE, and OIDC.
OIDC, client side (client-credentials flow):
import datetime
import slim_bindings
oidc = slim_bindings.OidcConfig(
issuer_url="https://auth.example.com",
client_id="my-client",
client_secret="s3cr3t",
audience=None,
refresh_token=None,
refresh_token_file=None,
access_token_file=None,
scope="openid profile",
timeout=datetime.timedelta(seconds=30),
jwks_ttl=None,
claim_cache_ttl=None,
policy=None,
)
base = slim_bindings.new_insecure_client_config("http://127.0.0.1:46357")
client_config = slim_bindings.ClientConfig(
**{**vars(base), "auth": slim_bindings.ClientAuthenticationConfig.OIDC(config=oidc)}
)
conn_id = await service.connect_async(client_config)
For the refresh-token flow set refresh_token (or refresh_token_file, which is rewritten in
place as tokens rotate) instead of client_secret.
Server side, verifying incoming JWTs against the issuer's JWKS endpoint, optionally restricting access by claim:
oidc = slim_bindings.OidcConfig(
issuer_url="https://auth.example.com",
client_id=None,
client_secret=None,
audience="slim", # required for verification
refresh_token=None,
refresh_token_file=None,
access_token_file=None,
scope=None,
timeout=None,
jwks_ttl=datetime.timedelta(hours=1),
claim_cache_ttl=datetime.timedelta(minutes=1),
policy=slim_bindings.OidcPolicyConfig.CEL(expression='"admin" in claims.groups'),
)
base = slim_bindings.new_insecure_server_config("127.0.0.1:46357")
server_config = slim_bindings.ServerConfig(
**{**vars(base), "auth": slim_bindings.ServerAuthenticationConfig.OIDC(config=oidc)}
)
policy accepts OidcPolicyConfig.CEL(expression=...), OidcPolicyConfig.REGO(text=...) (which
must define package slim.auth with default allow = false), or
OidcPolicyConfig.REGO_FILE(path=...). Client-only fields (scope, timeout) and server-only
fields (jwks_ttl, claim_cache_ttl, policy) are ignored by the other side.
From a config file — the examples read SLIM_CLIENT_CONFIG (or --slim-config <path>),
which covers every auth mode plus TLS material and backoff without any code change:
{
"endpoint": "http://127.0.0.1:46357",
"tls": { "insecure": true },
"auth": {
"type": "oidc",
"issuer_url": "https://auth.example.com",
"client_id": "my-client",
"client_secret": "s3cr3t",
"audience": "slim",
"policy": { "cel": "\"admin\" in claims.groups" }
}
}
The schema matches data-plane/core/config/src/grpc/schema/client-config.schema.json in the
slim repo. To load one yourself, call
slim_bindings.new_config_from_json(json_text).
API Overview
Application Creation
# Create app with shared secret
app = slim.create_app_with_secret(app_name, shared_secret)
# Get app information
app_id = app.id()
app_name = app.name()
Server Operations
# Connect to server
client_config = {
'endpoint': 'http://localhost:46357',
'tls': {'insecure': True, ...}
}
conn_id = app.connect(client_config)
# Run server
server_config = {
'endpoint': '127.0.0.1:46357',
'tls': {'insecure': True, ...}
}
app.run_server(server_config)
# Disconnect
app.disconnect(conn_id)
Session Management
# Create session
session_config = {
'session_type': 'PointToPoint', # or 'Group'
'enable_mls': False,
'max_retries': 3,
'interval_ms': 100,
'initiator': True,
'metadata': {}
}
session = app.create_session(session_config, destination_name)
# Listen for incoming session
session = app.listen_for_session(timeout_ms=30000)
# Delete session
app.delete_session(session)
Messaging
# Send message (fire-and-forget)
session.publish(data, "text/plain", metadata)
# Send with delivery confirmation
completion = session.publish_with_completion(data, "text/plain", metadata)
completion.wait() # Block until delivered
# Receive message
msg = session.get_message(timeout_ms=5000)
print(f"Payload: {msg.payload}")
print(f"From: {msg.context.source_name}")
print(f"Type: {msg.context.payload_type}")
# Reply to message
session.publish_to(msg.context, reply_data, "text/plain", None)
Group Operations
# Invite participant to group
session.invite(participant_name)
# Remove participant
session.remove(participant_name)
Examples
Examples Directory Structure
examples/
├── common/
│ └── common.py # Shared utilities
├── simple/
│ └── main.py # Basic functionality demo
├── point_to_point/
│ └── main.py # P2P messaging
└── group/
└── main.py # Group/multicast messaging
Running Examples
All examples require a running SLIM server. Start the Go server:
cd go
task example:server
Then run Python examples:
# Simple example
task example
# Point-to-point
task example:p2p:alice # Terminal 1
task example:p2p:bob # Terminal 2
# Group messaging
task example:group:participant:alice # Terminal 1
task example:group:participant:bob # Terminal 2
task example:group:moderator # Terminal 3
Testing
Unit Tests
task test
# or
python -m pytest tests/unit_test.py -v
Integration Tests
Integration tests require a running SLIM server:
# Terminal 1: Start server
cd ../go && task example:server
# Terminal 2: Run integration tests
SLIM_INTEGRATION_TEST=1 python -m pytest tests/integration_test.py -v -s
Development
Available Tasks
task # Show help
task build # Build package with Maturin
task test # Run tests
task python:bindings:packaging # Build wheels for multiple Python versions
task clean # Clean build artifacts
Project Structure
slim_uniffi_bindings/- Python package (bindings generated by Maturin)examples/- Example applicationstests/- Unit and integration testsTaskfile.yaml- Build automationpyproject.toml- Package configuration (Maturin build system)
Comparison with Go Bindings
Both Python and Go bindings use the same UniFFI adapter, ensuring API consistency:
| Feature | Python | Go |
|---|---|---|
| Binding Generation | uniffi-bindgen | uniffi-bindgen-go |
| API Style | Pythonic (snake_case) | Idiomatic Go (PascalCase) |
| Error Handling | Exceptions | Error returns |
| Async Support | Sync wrapper over async Rust | Sync wrapper over async Rust |
| Examples | ✅ | ✅ |
| Tests | ✅ | ✅ |
API Reference
Core Types
Name: Application/service identifier with components and optional IDSessionConfig: Configuration for creating sessionsTlsConfig: TLS settings for secure connectionsServerConfig: Server endpoint and TLS configurationClientConfig: Client endpoint and TLS configurationMessageContext: Message metadata (source, destination, type, metadata)ReceivedMessage: Received message with context and payload
Main Classes
BindingsAdapter: Main app interface for session managementBindingsSessionContext: Session interface for messagingFfiCompletionHandle: Completion handle for delivery confirmation
Session Types
PointToPoint: Direct one-to-one communicationGroup: One-to-many multicast communication
Troubleshooting
ImportError: Cannot find slim_uniffi_bindings
Make sure you've built the package:
task build
# or
uv run maturin develop
Connection Refused
Ensure the SLIM server is running:
cd ../go && task example:server
Build Errors
If you encounter build errors, try cleaning and rebuilding:
task clean
uv run maturin develop
Contributing
When contributing to the Python bindings:
- Maintain API consistency with Go bindings
- Follow Python naming conventions (snake_case)
- Add tests for new functionality
- Update examples if adding features
- Keep documentation up to date
License
Apache-2.0 - See LICENSE.md for details
See Also
- slimrpc Documentation - Protocol Buffers RPC over SLIM
- Go Bindings
- UniFFI Adapter
- SLIM Documentation
Metadata
Release files for slim-bindings 2.1.1rc3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| slim_bindings-2.1.1rc3-py3-none-win_arm64.whl | Python 3 | none | Windows ARM64 | Details |
| slim_bindings-2.1.1rc3-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_x86_64.whl | Python 3 | none | Linux musl 1.2+ x86-64 | Details |
| slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_aarch64.whl | Python 3 | none | Linux musl 1.2+ ARM64 | Details |
| slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_x86_64.whl | Python 3 | none | Linux glibc 2.28+ x86-64 | Details |
| slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_aarch64.whl | Python 3 | none | Linux glibc 2.28+ ARM64 | Details |
| slim_bindings-2.1.1rc3-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
| slim_bindings-2.1.1rc3-py3-none-macosx_10_12_x86_64.whl | Python 3 | none | macOS 10.12+ x86-64 | Details |
Total release size: 175.9 MB
Release files / slim_bindings-2.1.1rc3-py3-none-win_arm64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-win_arm64.whl |
|---|---|
| Size | 19.4 MB |
| Tags | Python 3 Windows ARM64 |
|
SHA-256 checksum How to use checksums |
558fae163df923467d20f4c13e31b5a2409801ee8241118a0acf8723a6dd73fc
|
|
BLAKE2b-256 checksum How to use checksums |
beeb889f8777ad60225458228dae78d97e7145f79b8f7027101d59d6faa4fb93
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-win_amd64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-win_amd64.whl |
|---|---|
| Size | 20.8 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
e5df07cb3ce8e12f3c34a5cc9169423863fe5ed8919084bcc3b70a8ab6beddea
|
|
BLAKE2b-256 checksum How to use checksums |
8683eb45012eb0df0a0686917cbba8cfa9fb14671ae8f67b047d0f6f3f98f8d2
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_x86_64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_x86_64.whl |
|---|---|
| Size | 23.3 MB |
| Tags | Linux musl 1.2+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
c1a29f97c579a512c7248f07044c843f3f17d811cf7f31a7da4d18b62960351d
|
|
BLAKE2b-256 checksum How to use checksums |
a6c99a7fbdd704d9335a886b3efa1a72b3b42dc610f77b88e97d518111717c11
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_aarch64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-musllinux_1_2_aarch64.whl |
|---|---|
| Size | 22.6 MB |
| Tags | Linux musl 1.2+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
2add8127ece22a2e321ffe5b72cafdd33b2225346c1df87378a627ea49563138
|
|
BLAKE2b-256 checksum How to use checksums |
e5d4aec5fc698556f38a95d1dcb78d256d9eb0ca8a6879397b63458756a10a3b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_x86_64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 23.3 MB |
| Tags | Linux glibc 2.28+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
a40e2b47918f07319ec0e1dc29bc426ed187c5ef2c87ba6ce6112a68208e49ee
|
|
BLAKE2b-256 checksum How to use checksums |
23c9b6f9ff0de66adcefe8c2fe563c4512a21507e8b6bde4e9bf130e2fb50f4a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_aarch64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-manylinux_2_28_aarch64.whl |
|---|---|
| Size | 22.6 MB |
| Tags | Linux glibc 2.28+ ARM64 Python 3 |
|
SHA-256 checksum How to use checksums |
730fe0221307cc9fd86953cc90d0ba1e6086bf60baa8d04d4f6ae4106438d1fb
|
|
BLAKE2b-256 checksum How to use checksums |
0a6a9f87c386384a6d8550057552a3df5c70ed84b991fd7f25f73a1b042919a9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-macosx_11_0_arm64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 21.5 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
b6629f89997e089c8cc20c7701986a6e3792363ca556a0acfebc18770ebf5ee1
|
|
BLAKE2b-256 checksum How to use checksums |
edd1478b3ce06b97a1cf44cf99a4e56dad156643123fa344af7ac1e5f8fcb9c7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / slim_bindings-2.1.1rc3-py3-none-macosx_10_12_x86_64.whl
| Download URL | slim_bindings-2.1.1rc3-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 22.3 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
e781a158ae4b4ea9d3e765db4cbe21a7b6b0c09d6a5a3f97fb621b7a3e8ad62f
|
|
BLAKE2b-256 checksum How to use checksums |
59c6dc8dd8f5aaaa3f7a0629bc7b3981587a8f0e91034c86c79a7dd088bf4c76
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency log