Appearance
SDKs
Coming No SDK is on a package registry yet. Until one is, any HTTPS client works: the busneeds only an OAuth 2.0 client-credentials request and a JSON POST to publish, and a GET and a POST to consume (see Send your first message and the HTTPS pull API).
RND is building SDKs to one language-neutral design, so they behave the same in every language, and every SDK must pass one shared conformance kit. TypeScript comes first, as the reference implementation; Python, .NET and Java follow its design.
Where the code is
Everything you build with is open source (Apache 2.0) in sombus-dev-kit. The bus itself is a hosted service.
| Folder | What's there |
|---|---|
sdk/ | The design every SDK follows, the conformance kit, and the TypeScript first slice |
examples/ | A reference producer, and a consumer on the HTTPS pull API, to run against your vendor workspace |
executors/ | Reference skill executors. First: raise-flag-on-match, which passes the skill harness |
upstream/som-1.0/ | The SOM 1.0 schemas, examples and skill library 0.2.2 the bus pins |
It's pre-release: names and details may change before the first published version. Found a problem or want a change? Open an issue or pull request there, or use Ask RND in the portal.
What an SDK does
| Module | Does | TypeScript |
|---|---|---|
| Envelope builder | UUIDv7 ids, an RFC 3339 timestamp, som.<message_type> topic, causation_id for follow-ups | Built |
| Auth | OAuth 2.0 client credentials with a token cache; a static token | Built |
| Publisher | Publish with the retry policy below, and typed verdicts | Built |
| SigV4 | For producers in AWS | Designed |
| Validator | Offline validation against the pinned SOM 1.0 schemas, with the bus's rule ids | Designed |
| Dry run | Your workspace's validate route | Not yet |
| Snapshot helper | Tracks a story's sequence and builds whole snapshots | Designed |
| Consumer | A receive loop over the HTTPS pull API | Designed; a reference loop is in examples/consumer/ |
| Executor runtime | Consumer, skills and publisher in one | Designed |
See TypeScript for the first slice.
Behaviour every SDK shares
- Three verdicts.
Accepted(with anytoleratedwarnings),Duplicate(an earlier attempt got through: success) andRefused(withstatus,source,ruleandpath). - One retry policy. Timeouts, network errors,
408,429and5xxare retried with backoff, honouringRetry-After. A401is retried once, at once, with a new token. Every other4xx, every409included, is final. Defaults: 5 attempts, backoff from 0.5 seconds doubling to 30, with jitter, and 10 seconds per attempt. - The same bytes on every attempt. The message is serialised once, so a retry is always recognised as a duplicate, never refused as a reused
message_id. - No payloads in logs. Events and errors carry identifiers (
message_id, status, rule id), never message content, tokens or secrets. - Open enums.
system_type,message_typeand the rest accept values 1.0 doesn't know, because a 1.x producer may send them. - Suite-versioned. Each release says which suite it supports, such as
som-1.0.0+lib-0.2.2.
Passing the conformance kit means "passes som-bus suite som-1.0.0+lib-0.2.2". It isn't certification, and it isn't endorsed by the SOM working group.