Skip to main content
Official Python SDK for Westyx Nexus - the centralised secrets, feature flags, and config service.

What’s new in v0.11.0

A correctness and type-safety release. Nothing in the public API breaks.
  • Ships py.typed (PEP 561) for both packages. Without the marker, type checkers ignore an installed package’s annotations entirely - every SDK call resolved to Any in your project, however well annotated the SDK was. The SDK is now clean under both mypy --strict and pyright. See Type checking.
  • SSE reconnect fixes. A misconfigured sse_reconnect_cooldown used to kill the stream worker: the handler meant to fall back to the default schedule called a logger method that does not exist, and raised. The value is validated at create() now and rejected with a message naming the bad input. Separately, AsyncNexusClient ignored sse_reconnect_cooldown entirely and ended its stream permanently after three transient transport errors - it now reconnects on the configured schedule, matching NexusClient. See SSE live updates.
  • The SSE client now has a connect timeout. Lifting the read deadline on a long-lived stream is right; lifting the connect deadline with it was not, and a connect to a black-holed endpoint hung indefinitely with no error and no reconnect.
  • File-type secrets are written 0600, applied at creation. They were previously created under the process umask - typically 0644 in a shared temp directory, readable by any local user. Two clients holding the same secret also no longer share (and delete) one file. See File-type secret security.
  • A faulting stream observer is reported. Your observer still cannot break the SDK, but a callback that raises is logged with the hook name and the original exception instead of vanishing.
  • No assert in shipped code - python -O strips them, and the session-refresh precondition guard went with them.
  • CI gates on ruff, mypy, pyright and bandit, and the suite runs on Python 3.11 through 3.14 - every version this package advertises.

What’s new in v0.10.0

  • Version alignment across the Westyx Nexus SDK suite.

What’s new in v0.9.0

  • aws_iam WIF provider (AWS IAM Caller Identity) - authenticates non-EKS AWS compute (ECS/Fargate, Lambda, plain EC2) that has IAM credentials but no OIDC token. The SDK SigV4-signs an STS GetCallerIdentity request (never sent to AWS) and posts it to /v1/auth/token-exchange; Nexus replays it against a pinned STS endpoint to prove your IAM role. The signed X-Nexus-Server-ID is your service’s own base-URL host - a captured request is valid for that one service only, and there is nothing to configure. Requires the optional botocore dependency (pip install 'westyx-nexus-sdk[aws-iam]'). See Workload identity.
  • Azure Workload Identity (AKS) - the azure provider now prefers the projected federated token file ($AZURE_FEDERATED_TOKEN_FILE) before falling back to IMDS; auto-detection probes the file too.
  • Probe-based auto-detection - auto-detect now stats the Kubernetes / AWS-IRSA / Azure token files and live-probes the GCP and Azure metadata servers (~1 s timeout), instead of keying on environment variables absent on real cloud nodes.
  • Security hardening - both clients reject plain-http base_urls (loopback excepted); the Azure IMDS path refuses the generic default audience (must be api://<client-id>); the async client no longer blocks the event loop on metadata calls; the httpx.Client leak is fixed; metadata/exchange reads are bounded.

What’s new in v0.8.0

  • OpenFeature provider - new westyx-nexus-openfeature sub-package ships NexusProvider, an AbstractProvider for the OpenFeature Python SDK. Wraps an existing NexusClient; booleans via get_flag, string/integer/float/object via get_config. EvaluationContext is ignored. See OpenFeature provider.

What’s new in v0.5.1

  • Requires Python 3.11+ - Python 3.10 is EOL; minimum is now 3.11.
  • Security improvements - exception messages contain only status codes; file-type secret paths are fully hashed; WIF tokens stripped of whitespace on all providers.
  • WIF reliability - session refreshes before each SSE reconnect; expired sessions no longer cause permanent TTL-polling fallback.
  • CI - tests run on merge requests; publish restricted to main-branch tags.

What’s new in v0.5.0

  • Write API - set_secret, delete_secret, delete_secret_version for programmatic secret management. secret keys only; public keys raise NexusPublicKeyError immediately without a network call.
  • NexusRateLimitedError - new error for HTTP 429 on write endpoints.

What’s new in v0.4.0

  • Path prefix change - all API paths are now /v1/ (previously /api/v1/). Update base_url to use <slug>.westyx.dev.
  • NexusQuarantinedError - new typed error raised on 429 with quarantine body. Both sync and stream paths detect this.
  • on_quarantined(reason, expires_at) observer callback - StreamObserver gains a sixth callback; fires on quarantine events from both the stream and sync paths.
  • Quarantine backoff - stream sleeps until expires_at before reconnecting; background sync is paused during the quarantine window.
  • Removed ConfigEntry.is_public - the field is no longer populated.

Highlights

  • Python 3.11+ - single runtime dependency (httpx); the optional aws_iam WIF provider adds botocore via the [aws-iam] extra
  • Both sync and async APIs - NexusClient and AsyncNexusClient share the same cache + SSE protocol; only the I/O model differs
  • Optional framework adapters - Django, FastAPI, Flask integrations via extras (pip install "westyx-nexus-sdk[django]")
  • Thread-safe TTL cache with atomic snapshot replacement and ETag/304 support
  • SSE live updates - propagates remote changes within milliseconds; falls back to TTL polling after 3 transport errors
  • Typed error hierarchy - NexusError base + 13 subclasses for isinstance / except matching
  • Workload Identity Federation (v0.2.0) - Kubernetes / AWS IRSA / GCP / Azure auto-detection; bearer JWT auth; AWS IAM (aws_iam) for ECS/Fargate/Lambda/plain-EC2 (v0.9.0)
  • Stream observer hooks (v0.2.0) - structured callbacks for SSE lifecycle events
  • AB Testing (v0.3.0) - evaluate_ab for batch per-user flag evaluation
  • File-type secrets (v0.3.0) - get_secret_file_path materialises type: "file" secrets to temp files
  • OpenFeature provider (v0.8.0) - NexusProvider sub-package (westyx-nexus-openfeature) for the OpenFeature Python SDK
  • Fully typed (v0.11.0) - ships py.typed; clean under mypy --strict and pyright

Package

Hosted on the GitLab PyPI Package Registry. Install:
Latest release: v0.11.0 (2026-07-27 - py.typed, SSE reconnect fixes, 0600 file secrets).

Pages