Supply Chain Monkey
▓▓▓▓▓▓▓▓▓▓
▓▓▓▓▓▓▓▓▓▓▓▓▓▓
▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓
▓▓▓▓░░░░░░▓▓░░░░░░▓▓▓▓
░░░░▓▓░░░░░░░░░░░░░░░░░░▓▓░░░░
░░░░▓▓░░██ ░░░░░░██ ░░▓▓░░░░
░░▓▓░░████░░░░░░████░░▓▓░░
▓▓░░░░░░░░░░░░░░░░░░▓▓
▓▓░░░░░░░░░░░░░░▓▓
▓▓▓▓░░░░░░▓▓▓▓
▓▓▓▓▓▓ ░░
▓▓▓▓▓▓▓▓▓▓ ▓▓
▓▓▓▓▓▓▓▓▓▓ ▓▓▓▓
▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓
▓▓▓▓░░▓▓░░▓▓▓▓
Internal service for querying electronic component suppliers. It provides a unified HTTP API that centralizes vendor credentials and provider routing.
Use the documentation map for service operation, API exploration, Python and Rust consumption, contract authoring, and release material.
Status
2026.9.1 - TypeSpec-backed contracts, generated Python and Rust models, a
secure Rust client and test CLI, generic multi-provider search, and repaired
JLCPCB/LCSC search fallbacks.
The PyPI distribution is supply-chain-monkey. The Python import package is
scm.
Architecture
The repository contains four owned layers:
src/tsp/scm/v1: authored TypeSpec HTTP and JSON structural authority.scm.models: supported Python contract surface backed by generated Pydantic models.scm.client: HTTP client library for consumers.scm.server: FastAPI server with provider adapters and the status page.
The Rust workspace contains generated contracts, a secure async client, and the
scm proof CLI. It consumes the service and has no Appliku deployment role.
Providers
| Supplier | Backend | Credentials Required |
|---|---|---|
| JLCPCB | Public search, LCSC shared C-code resolution, plus hybrid detail | Optional; fallback works without credentials |
| LCSC | Primary and third-party website JSON APIs | None |
| Digikey | Official REST API v4 OAuth2 | Yes |
| Mouser | Official REST API v1 | Yes |
API
The health endpoint and root status page are public. Normal API operations require a bearer token; the deprecated streaming compatibility endpoint is the only query-token exception.
GET /v1/health
GET /v1/providers/status
GET /v1/search?supplier=jlcpcb&mpn=TPS543620RPYR
GET /v1/detail?supplier=jlcpcb&part=C2870085
GET /v1/spn?supplier=jlcpcb&spn=C2870085
POST /v1/spn/batch
GET /v1/search/stream?mpn=X&token=Y
The streaming endpoint pushes results per provider as they complete via
Server-Sent Events. It supports max_results and per-provider timeout, but is
a deprecated query-token compatibility surface. Never put a real service token
in its Swagger operation, logs, browser history, or a shared URL. New clients
use header-authenticated non-stream operations.
The root URL serves a status page with an interactive test panel.
Local and deployed servers expose:
/docsand/redocfor FastAPI's runtime OpenAPI document;/docs/typespecfor the canonical TypeSpec-generated OpenAPI document; and/openapi.jsonand/openapi-typespec.jsonfor their OpenAPI 3.1 JSON.
See API exploration for PowerShell and POSIX startup, authorization, safe smoke requests, and the distinction between the two documents.
Python client
Install the consumer client from PyPI:
python -m pip install "supply-chain-monkey[client]==2026.9.1"
from scm.client import SCMClient
from scm.models import PARAMETER_FIELD_NAMES, SUPPLIERS, SupplierType
client = SCMClient(url="https://your-scm.example.com", token="...")
result = client.search("jlcpcb", "TPS543620RPYR")
all_results = client.search_all("TPS543620RPYR")
detail = client.detail("jlcpcb", "C2870085")
print(SUPPLIERS)
Rust client
Before separately authorized crates.io publication, pin the reviewed immutable repository revision:
[dependencies]
scm-client = { package = "supply-chain-monkey-client", git = "https://github.com/wavenumber-eng/supply-chain-monkey.git", rev = "e7bc0587e7a4b6435b993ce982505fb604861d20" }
tokio = { version = "1.53.1", features = ["macros", "rt-multi-thread"] }
The Rust client guide provides compiling single-provider and concurrent-search examples, error classification, secure builder options, and generated-contract access. The CLI guide covers interactive tables and JSON.
Local Development
cp .env.template .env
# fill in SCM_SERVICE_TOKEN and any provider credentials
uv sync --group dev
PYTHONPATH=src/py uv run uvicorn scm.server.main:app --reload --env-file .env
Windows users can use the PowerShell commands in the API exploration guide.
Testing
uv run pytest -q
uv run rack run L99_signoff
npm run check:contracts
npm run check:python-generation
uv run python tests/scripts/scm_test_cli.py --token YOUR_TOKEN
uv run python tests/scripts/scm_test_cli.py --url https://your-scm.example.com --token YOUR_TOKEN
Deployment
The included appliku.yml uses Appliku's managed python-3.13-uv build image.
Only pushing production triggers the configured Appliku deployment; dev is
integration-only.
git checkout dev
# merge through PRs; do not develop directly on production
pyproject.toml must keep [tool.uv] package = false and
default-groups = []. The Dockerfile is inactive unless appliku.yml changes
to build_image: dockerfile. See CLAUDE.md for deployment constraints.
dev is the integration branch. main is the public source branch.
production is the Wavenumber deployment branch and must be updated only by
protected PR/merge flow.
Consumer Integration
Consumers should depend on the supply-chain-monkey[client] distribution and
import scm. Configure service URL and token outside source control.
Metadata
Release files for supply-chain-monkey 2026.9.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| supply_chain_monkey-2026.9.1.tar.gz | 851.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| supply_chain_monkey-2026.9.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 962.3 kB
Release files / supply_chain_monkey-2026.9.1.tar.gz
| Download URL | supply_chain_monkey-2026.9.1.tar.gz |
|---|---|
| Size | 851.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
19be16c7cf413b0795bc7df6aaea1720bb2da0c73546a5305ef6273174a4df2e
|
|
BLAKE2b-256 checksum How to use checksums |
d52353fb15886e9c6fe002f529cde0469e089e1f2b994f4f0ee4a5065f782980
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency logRelease files / supply_chain_monkey-2026.9.1-py3-none-any.whl
| Download URL | supply_chain_monkey-2026.9.1-py3-none-any.whl |
|---|---|
| Size | 111.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0083e75da7f535a787d6856950e19eb332015572b81e13656a4d22375e3178bd
|
|
BLAKE2b-256 checksum How to use checksums |
97ee14b63d89d5930fe3c56d52892ee39cd7b143b3750aa2dd2c46cee2eba915
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 1, 2026.
Transparency log