Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Stigmem Reference Node

Single-host reference implementation of the Stigmem protocol. The modular protocol specs live under ../spec/specs/, with the generated protocol composition at ../spec/PROTOCOL.md.

Quick start

# install
pip install .

# run (auth disabled, local db)
stigmem-node

# run with auth
STIGMEM_AUTH_REQUIRED=true STIGMEM_DB_PATH=./data/stigmem.db stigmem-node

Default port: 8765. Override with STIGMEM_PORT.

Configuration

All settings via environment variables (prefix STIGMEM_):

Variable Default Description
STIGMEM_DB_PATH stigmem.db SQLite file path
STIGMEM_HOST 0.0.0.0 Bind host
STIGMEM_PORT 8765 Bind port
STIGMEM_NODE_URL http://localhost:8765 Canonical URL for /.well-known/stigmem
STIGMEM_AUTH_REQUIRED false Enforce API-key auth
STIGMEM_LOG_LEVEL info uvicorn log level

CORS

The Stigmem node ships with CORS disabled by default. Enable it only for the deployment shape you operate.

Local development (any localhost port)

STIGMEM_CORS_DEV_LOCALHOST=1

Accepts any Origin matching ^https?://(localhost|127\.0\.0\.1)(:\d+)?$. Use this when the UI and API run on separate, dynamically chosen localhost ports.

Production with a known UI origin

STIGMEM_CORS_ALLOWED_ORIGINS=https://stigmem-ui.example.com

Production with multiple UI origins

STIGMEM_CORS_ALLOWED_ORIGINS=https://a.example.com,https://b.example.com

Self-managed regex (advanced)

STIGMEM_CORS_ALLOWED_ORIGIN_REGEX=^https://[a-z0-9-]+\.example\.com$

Credentials

STIGMEM_CORS_ALLOW_CREDENTIALS defaults to true and controls whether browsers may send cookies or Authorization headers cross-origin. Set it to false only when the deployment does not use credentialed browser requests.

Security note

Do not combine STIGMEM_CORS_DEV_LOCALHOST=1 with a production deployment. The dev-localhost regex is intentionally permissive and must only run on maintainer-controlled machines.

API

Route Description
POST /v1/facts Assert a fact (Spec-03-HTTP-API)
GET /v1/facts Query facts (Spec-03-HTTP-API)
GET /.well-known/stigmem Node metadata (Spec-03-HTTP-API)
GET /healthz Health check
GET /docs OpenAPI UI

Running tests

cd stigmem/node
pip install ".[dev]"
pytest

Docker

docker build -t stigmem-node .
docker run -p 8765:8765 -v $(pwd)/data:/data stigmem-node

Release files for stigmem-node 0.9.0a12

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stigmem-node 0.9.0a12
File Size Uploaded
stigmem_node-0.9.0a12.tar.gz 886.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for stigmem-node 0.9.0a12
File Interpreter ABI Platform
stigmem_node-0.9.0a12-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / stigmem_node-0.9.0a12.tar.gz

Download URL stigmem_node-0.9.0a12.tar.gz
Size 886.6 kB
Tags Source
SHA-256 checksum
How to use checksums
5ff259a71c66d98867dd9d1bd7e66104faa4bb0fdfee108f9fbae9339e0f1054
BLAKE2b-256 checksum
How to use checksums
03f90f8912bc1fc52193014cfe161682da928c0f388c9115931763637625db6a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.

Transparency log

Release files / stigmem_node-0.9.0a12-py3-none-any.whl

Download URL stigmem_node-0.9.0a12-py3-none-any.whl
Size 498.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8a478427a91ff4b0f2f295f49af212baf6f5e0accc861a2d8ea2c24584eb3ef7
BLAKE2b-256 checksum
How to use checksums
5451328caabc4b34f4f54353c88f790869960a07074b58ef1304e28fef105cbc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page