Metadata-Version: 2.4
Name: nexus-assurance-client
Version: 0.1.0b0
Summary: Standard-library Python client for the deployed Nexus Assurance beta API
Author: Nexus ReGen
License-Expression: MIT
Classifier: Development Status :: 4 - Beta
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Requires-Python: <3.12,>=3.11
Description-Content-Type: text/markdown
License-File: LICENSE
Dynamic: license-file

# Nexus Assurance Python client (beta)

`nexus-assurance-client` is a dependency-free Python 3.11 client for all 17 operations in the deployed `2026-06-18-beta` Nexus Assurance OpenAPI contract: connection; authorised project and location discovery; sites, movements, and loads; evidence-upload initiation/completion; and webhook endpoint records.

It does not imply support for future contract operations, webhook delivery, sandbox automation, asynchronous jobs, or upload renewal. The deployed OpenAPI reference remains the compatibility authority.

```python
import os

from nexus_assurance import NexusAssuranceClient

client = NexusAssuranceClient(api_key=os.environ["NEXUS_API_KEY"])
for movement in client.iterate_movements(limit=50):
    print(movement["ref"])
```

Download the versioned wheel and its SHA-256 file from the Developer Hub, verify it, then install it locally with `python -m pip install nexus_assurance_client-0.1.0b0-py3-none-any.whl`. This package is MIT-licensed and intentionally has no PyPI publication. Maintainers regenerate the committed download deliberately with `bun run generate:assurance-client-python-download`; CI only verifies source, wheel, and checksum agreement and never refreshes the public artifact.

Reads and POST/PATCH calls carrying a caller-provided idempotency key have bounded retries for `429`, `5xx`, and transport failures. `Retry-After` seconds and HTTP dates are honoured up to 30 seconds. The original deterministic JSON payload is retained across retries. DELETE is issued once only; an interrupted delete must be resolved by inspecting current state, because the deployed API has no safe DELETE replay contract. `NexusApiError` exposes `status`, `code`, `request_id`, and `details`; successful `Result` values expose `request_id`, `status`, and `attempts`.

Response date-times require an RFC 3339-shaped offset with hours `00`–`23` and minutes `00`–`59`; Python's standard-library parser remains the calendar and clock-time gate. Leap seconds (`:60`) are rejected because that parser does not support them, including where RFC 3339 permits them.

Keep API keys in server-side environment configuration, never in URLs or browser bundles.

## Discovery, pagination, retries, and errors

`list_projects`, `get_project`, `list_project_locations`, and `get_location` expose only resources the credential is authorised to read. They do not provide project or location provisioning.

`iterate_movements` follows `page.hasMore` and refuses a missing or repeated continuation cursor. The deployed beta does not offer an incremental change feed, so retain your own reconciliation state only where your integration needs it.

Reads and idempotent writes retry only bounded transient failures. Correct validation, authorisation, and version errors instead of retrying them blindly. Catch `NexusApiError` for safe `status`, `code`, `request_id`, and optional server `details`; a malformed successful response raises `NexusContractError`.
