This release is a pre-release and may not be stable for production use.
Stigmem Reference Node
Single-host reference implementation of the Stigmem protocol. The modular protocol
specs live under ../spec/specs/, with the generated protocol
composition at ../spec/PROTOCOL.md.
Quick start
# install
pip install .
# run (auth disabled, local db)
stigmem-node
# run with auth
STIGMEM_AUTH_REQUIRED=true STIGMEM_DB_PATH=./data/stigmem.db stigmem-node
Default port: 8765. Override with STIGMEM_PORT.
Configuration
All settings via environment variables (prefix STIGMEM_):
| Variable | Default | Description |
|---|---|---|
STIGMEM_DB_PATH |
stigmem.db |
SQLite file path |
STIGMEM_HOST |
0.0.0.0 |
Bind host |
STIGMEM_PORT |
8765 |
Bind port |
STIGMEM_NODE_URL |
http://localhost:8765 |
Canonical URL for /.well-known/stigmem |
STIGMEM_AUTH_REQUIRED |
false |
Enforce API-key auth |
STIGMEM_LOG_LEVEL |
info |
uvicorn log level |
CORS
The Stigmem node ships with CORS disabled by default. Enable it only for the deployment shape you operate.
Local development (any localhost port)
STIGMEM_CORS_DEV_LOCALHOST=1
Accepts any Origin matching
^https?://(localhost|127\.0\.0\.1)(:\d+)?$. Use this when the UI and API run
on separate, dynamically chosen localhost ports.
Production with a known UI origin
STIGMEM_CORS_ALLOWED_ORIGINS=https://stigmem-ui.example.com
Production with multiple UI origins
STIGMEM_CORS_ALLOWED_ORIGINS=https://a.example.com,https://b.example.com
Self-managed regex (advanced)
STIGMEM_CORS_ALLOWED_ORIGIN_REGEX=^https://[a-z0-9-]+\.example\.com$
Credentials
STIGMEM_CORS_ALLOW_CREDENTIALS defaults to true and controls whether
browsers may send cookies or Authorization headers cross-origin. Set it to
false only when the deployment does not use credentialed browser requests.
Security note
Do not combine STIGMEM_CORS_DEV_LOCALHOST=1 with a production deployment. The
dev-localhost regex is intentionally permissive and must only run on
maintainer-controlled machines.
API
| Route | Description |
|---|---|
POST /v1/facts |
Assert a fact (Spec-03-HTTP-API) |
GET /v1/facts |
Query facts (Spec-03-HTTP-API) |
GET /.well-known/stigmem |
Node metadata (Spec-03-HTTP-API) |
GET /healthz |
Health check |
GET /docs |
OpenAPI UI |
Running tests
cd stigmem/node
pip install ".[dev]"
pytest
Docker
docker build -t stigmem-node .
docker run -p 8765:8765 -v $(pwd)/data:/data stigmem-node
Release files for stigmem-node 0.9.0a12
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| stigmem_node-0.9.0a12.tar.gz | 886.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| stigmem_node-0.9.0a12-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.4 MB
Release files / stigmem_node-0.9.0a12.tar.gz
| Download URL | stigmem_node-0.9.0a12.tar.gz |
|---|---|
| Size | 886.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5ff259a71c66d98867dd9d1bd7e66104faa4bb0fdfee108f9fbae9339e0f1054
|
|
BLAKE2b-256 checksum How to use checksums |
03f90f8912bc1fc52193014cfe161682da928c0f388c9115931763637625db6a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.
Transparency logRelease files / stigmem_node-0.9.0a12-py3-none-any.whl
| Download URL | stigmem_node-0.9.0a12-py3-none-any.whl |
|---|---|
| Size | 498.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8a478427a91ff4b0f2f295f49af212baf6f5e0accc861a2d8ea2c24584eb3ef7
|
|
BLAKE2b-256 checksum How to use checksums |
5451328caabc4b34f4f54353c88f790869960a07074b58ef1304e28fef105cbc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.
Transparency log