Metadata-Version: 2.5
Name: aisoc-sdk
Version: 4.0.0
Summary: Python client SDK for AiSOC — typed httpx client
Project-URL: Homepage, https://github.com/beenuar/AiSOC
Project-URL: Documentation, https://beenuar.github.io/AiSOC
Project-URL: Repository, https://github.com/beenuar/AiSOC
Project-URL: Issues, https://github.com/beenuar/AiSOC/issues
Author-email: AiSOC Contributors <oss@aisoc.io>
License: MIT
Keywords: aisoc,client,sdk,security,soc
Requires-Python: >=3.10
Requires-Dist: httpx>=0.27.0
Requires-Dist: pydantic>=2.0.0
Provides-Extra: dev
Requires-Dist: mypy<3,>=2.3.1; extra == 'dev'
Requires-Dist: pytest-asyncio>=0.23; extra == 'dev'
Requires-Dist: pytest-httpx>=0.30; extra == 'dev'
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff<0.17,>=0.16.8; extra == 'dev'
Description-Content-Type: text/markdown

# aisoc-sdk

[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](../../LICENSE)
[![PyPI release](https://img.shields.io/badge/pypi-not%20yet%20published-f59e0b)](https://github.com/beenuar/AiSOC/blob/main/CHANGELOG.md)

Async Python client SDK for [AiSOC](https://github.com/beenuar/AiSOC).

> **Status — monorepo today, not yet on PyPI.** `pip install aisoc-sdk` does not resolve; install from the monorepo source path below. The import path (`aisoc_sdk`) and API surface stay identical once it ships.

## Installation

```bash
# Today (from this monorepo):
git clone https://github.com/beenuar/AiSOC.git
cd AiSOC && pip install -e packages/sdk-py

# Not yet on PyPI — the upload is blocked on registry credentials,
# which is an account action rather than a code change. Until then, install
# from source with the command above.
#   pip install aisoc-sdk
```

## Quick start

```python
import asyncio
from aisoc_sdk import AiSOCClient


async def main():
    async with AiSOCClient(
        base_url="https://your-aisoc.example.com",
        token="aisoc_...",
    ) as client:
        # List critical open alerts
        alerts = await client.alerts.list(severity="critical", status="open")
        print(f"Found {alerts.total} critical alerts")

        # Create a case
        case = await client.cases.create(
            title="Suspicious lateral movement",
            priority="high",
        )

        # Trigger a playbook
        run = await client.playbooks.run(
            "isolate-host",
            trigger_data={"host_id": "srv-prod-42", "case_id": case.id},
        )
        print("Playbook run:", run.run_id)


asyncio.run(main())
```

## GraphQL

```python
async with AiSOCClient(base_url="...", token="...") as client:
    result = await client.graphql("""
        query {
            alerts(pageSize: 10, status: "open") {
                items { id title severity }
            }
        }
    """)
```

## API reference

All resource methods are `async` and return typed Pydantic models.

| Attribute | Methods |
|---|---|
| `client.alerts` | `list(filters?)`, `get(id)`, `update(id, **data)` |
| `client.cases` | `list(filters?)`, `get(id)`, `create(**data)`, `update(id, **data)`, `delete(id)` |
| `client.detections` | `list(page, page_size)`, `get(id)` |
| `client.connectors` | `list(page, page_size)`, `get(id)` |
| `client.playbooks` | `list(page, page_size)`, `get(id)`, `create(**data)`, `update(id, **data)`, `delete(id)`, `run(id, trigger_data?)`, `get_run(run_id)` |
| `client.api_keys` | `list()`, `create(req)`, `revoke(id)` |

## Development

```bash
pip install -e ".[dev]"
pytest
```
