Skip to main content

tessera-api

Turn messy curl commands and HTTP traces into a validated, secret-redacted API surface map.

tessera-api reads .curl / .sh files containing curl commands, parses each into a canonical ApiRequest, redacts every secret at parse time, profiles the API surface, and emits a catalog plus reports — including a redactions audit.

Scope (v0.1)

This pack parses and canonicalizes. It does not execute HTTP requests. Live calling, batch execution, and streaming response capture are runtime concerns with network side effects and are intentionally deferred to a later version. v0.1 is the offline, side-effect-free "what does this API surface look like, and does it leak secrets" pass.

Secret safety

Redaction happens before a value is ever written into an ApiRequest. The canonical records and every artifact hold only masked previews (a couple of leading characters plus a length, never the tail). Secrets are detected by:

  • known secret header names (Authorization, X-Api-Key, Cookie, ...)
  • known secret query parameter names (api_key, token, access_token, signature, ...)
  • -u user:pass basic-auth flags
  • secret-ish keys inside request bodies (password, client_secret, token, ...)
  • secret shape (v0.2) — values that look like secrets regardless of field name: AWS keys (AKIA…), GitHub tokens (ghp_…), Slack/Stripe/Google/OpenAI keys, JWTs, private-key blocks, and high-entropy token strings. This catches secrets hiding in custom auth headers, odd query params, or body fields, and raises secret_in_nonstandard_location so you know a credential is somewhere unexpected. UUIDs and other common identifiers are excluded to avoid false positives.

Compile an API pack

tessera api compile --input examples/api/ --output ./out/api_pack

Artifacts written:

index.jsonl              canonical, redacted ApiRequest rows
index.md                 human-readable catalog (method, host, path, auth, redactions)
validation_report.md     hygiene findings
coverage_report.md       method / host / auth-kind distribution
redactions_report.md     every redaction made, with masked previews (audit trail)

Validation rules

Per-request:

  • insecure_scheme — uses http:// (cleartext)
  • missing_host — no host could be parsed
  • secret_in_url_query — a secret was found in the URL query (URLs get logged; prefer a header)
  • no_auth_detected — no auth credential was found

Cross-request:

  • duplicate_request — identical method + url + body seen more than once
  • multiple_hosts — requests span more than one host (visibility, not an error)

Plus parse_error for any curl command that cannot be tokenized or has no URL.

Metadata

Release files for tesserakit-api 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tesserakit-api 0.4.0
File Size Uploaded
tesserakit_api-0.4.0.tar.gz 13.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tesserakit-api 0.4.0
File Interpreter ABI Platform
tesserakit_api-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 27.4 kB

Release files / tesserakit_api-0.4.0.tar.gz

Download URL tesserakit_api-0.4.0.tar.gz
Size 13.1 kB
Tags Source
SHA-256 checksum
How to use checksums
d33dd0c24a4ae227cb305ee647e0c1b41d4715bab4b4cf303088385e97adb4da
BLAKE2b-256 checksum
How to use checksums
4e9f5c64ec3fc5fb71eb61abf746201ed2d7640068045b5f0387337798ecccf2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release files / tesserakit_api-0.4.0-py3-none-any.whl

Download URL tesserakit_api-0.4.0-py3-none-any.whl
Size 14.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
406d623f30a6b5a14d559e31ade17f192b9d9f67fa9e65417f0d227b3ce8f1dd
BLAKE2b-256 checksum
How to use checksums
8f7d514f9bcc3d3bc7348d0258f9fdf4976f6d0ffb3bcaf9a9f3d3d6393e534f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

0.3.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page