Skip to content

Coming

SDKs ​

Coming No SDK is on a package registry yet. Until one is, any HTTPS client works: the bus

needs only an OAuth 2.0 client-credentials request and a JSON POST to publish, and a GET and a POST to consume (see Send your first message and the HTTPS pull API).

RND is building SDKs to one language-neutral design, so they behave the same in every language, and every SDK must pass one shared conformance kit. TypeScript comes first, as the reference implementation; Python, .NET and Java follow its design.

Where the code is ​

Everything you build with is open source (Apache 2.0) in sombus-dev-kit. The bus itself is a hosted service.

FolderWhat's there
sdk/The design every SDK follows, the conformance kit, and the TypeScript first slice
examples/A reference producer, and a consumer on the HTTPS pull API, to run against your vendor workspace
executors/Reference skill executors. First: raise-flag-on-match, which passes the skill harness
upstream/som-1.0/The SOM 1.0 schemas, examples and skill library 0.2.2 the bus pins

It's pre-release: names and details may change before the first published version. Found a problem or want a change? Open an issue or pull request there, or use Ask RND in the portal.

What an SDK does ​

ModuleDoesTypeScript
Envelope builderUUIDv7 ids, an RFC 3339 timestamp, som.<message_type> topic, causation_id for follow-upsBuilt
AuthOAuth 2.0 client credentials with a token cache; a static tokenBuilt
PublisherPublish with the retry policy below, and typed verdictsBuilt
SigV4For producers in AWSDesigned
ValidatorOffline validation against the pinned SOM 1.0 schemas, with the bus's rule idsDesigned
Dry runYour workspace's validate routeNot yet
Snapshot helperTracks a story's sequence and builds whole snapshotsDesigned
ConsumerA receive loop over the HTTPS pull APIDesigned; a reference loop is in examples/consumer/
Executor runtimeConsumer, skills and publisher in oneDesigned

See TypeScript for the first slice.

Behaviour every SDK shares ​

  • Three verdicts. Accepted (with any tolerated warnings), Duplicate (an earlier attempt got through: success) and Refused (with status, source, rule and path).
  • One retry policy. Timeouts, network errors, 408, 429 and 5xx are retried with backoff, honouring Retry-After. A 401 is retried once, at once, with a new token. Every other 4xx, every 409 included, is final. Defaults: 5 attempts, backoff from 0.5 seconds doubling to 30, with jitter, and 10 seconds per attempt.
  • The same bytes on every attempt. The message is serialised once, so a retry is always recognised as a duplicate, never refused as a reused message_id.
  • No payloads in logs. Events and errors carry identifiers (message_id, status, rule id), never message content, tokens or secrets.
  • Open enums. system_type, message_type and the rest accept values 1.0 doesn't know, because a 1.x producer may send them.
  • Suite-versioned. Each release says which suite it supports, such as som-1.0.0+lib-0.2.2.

Passing the conformance kit means "passes som-bus suite som-1.0.0+lib-0.2.2". It isn't certification, and it isn't endorsed by the SOM working group.

SOM is an open standard maintained by the SOM working group. This service is not endorsed by it.