v0.1.1
v0.1.1
Release date: 2025-08-16
Package: matrix-python-sdk
Tagline: Deep links, safe local installs, and a tiny runtime—SDK-first, CLI-light.
Highlights
- Deep-link support (
matrix://install)
Newmatrix_sdk.deep_linkmodule to parse & execute one-click install links safely. - Local installer (plan → files → artifacts → env)
LocalInstallermaterializes Hub install plans, fetches artifacts (HTTP/ZIP/TAR, Git), writes/infersrunner.json, and prepares Python/Node environments. - Runtime helpers (no daemon)
Start/stop/status/logs/doctor for locally installed MCP servers with simple lock files under~/.matrix. - Hardened artifact fetchers
HTTP fetcher with SHA-256 verification + safe extraction; Git fetcher with allow-listed hosts, shallow clones, optional LFS, and ref validation. - Typed schemas (Pydantic v2)
Optional models for search results, entity details, and install outcomes.
This release is designed so a stable, UI-friendly CLI can do minimal orchestration while the SDK does all the heavy lifting.
What’s new (modules)
-
matrix_sdk/deep_link.pyparse(url) -> DeepLinkhandle_install(url, client, *, target) -> HandleResult- Strict validation: requires
id, optionalalias(^[a-z0-9][a-z0-9._-]{0,63}$), forbids control/path chars.
-
matrix_sdk/installer.pyLocalInstaller.plan(id, target)– calls Hub install endpoint.materialize(outcome, target)– writes files, fetches artifacts, emits/validatesrunner.json.prepare_env(target, runner)– Python venv viavenv(+ optionalpython_builder), Node via detected PM.build(id, *, target=None, alias=None)– plan + materialize + env in one call.- Dataclasses:
BuildReport,EnvReport,BuildResult.
-
matrix_sdk/runtime.pystart(target, *, alias=None, port=None) -> LockInfo(logs to~/.matrix/logs/<alias>.log, lock at~/.matrix/state/<alias>/runner.lock.json)stop(alias),status() -> list[LockInfo],tail_logs(alias, follow=False, n=20),doctor(alias)- Requires
runner.jsonwithtype(python/node) andentry. Python requires venv Python present.
-
matrix_sdk/archivefetch.pyfetch_http_artifact(url, target, dest=None, sha256=None, unpack=False, ...)- Safe ZIP/TAR extraction (no path traversal), optional checksum, optional unpack, flatten GH-style archives.
-
matrix_sdk/gitfetch.pyfetch_git_artifact(spec, target, *, allow_hosts=None, timeout=...)- Shallow clone, optional subdir sparse-checkout, optional LFS, optional
verify_sha. - Security: HTTPS only by default, host allow-list required (env or param), ref validation.
-
matrix_sdk/schemas.py- Pydantic models for
SearchItem,SearchResponse,EntityDetail,InstallStepResult,InstallOutcome. MatrixAPIError(optional generic error wrapper).
- Pydantic models for
-
matrix_sdk/cli/commands.py(optional CLI helper)- Typer command
bulk-addleveragingBulkRegistrarfor gateway registrations.
- Typer command
API surface (import paths)
from matrix_sdk import (
MatrixClient, MatrixError,
parse_deep_link, handle_deep_link_install,
)
from matrix_sdk.installer import LocalInstaller
from matrix_sdk.runtime import start as runtime_start, stop as runtime_stopNote: previous
MatrixHubClient/MatrixHubErrornaming has been unified asMatrixClient/MatrixError.
Quick start
Deep link → local install
from matrix_sdk import MatrixClient, handle_deep_link_install
from matrix_sdk.policy import default_install_target
client = MatrixClient(base_url="http://127.0.0.1:7300", token=None)
url = "matrix://install?id=mcp_server%3Ahello-sse-server%400.1.0&alias=hello-sse"
target = default_install_target("mcp_server:hello-sse-server@0.1.0", alias="hello-sse")
res = handle_deep_link_install(url, client, target=target)
print("installed to", res.target)Programmatic build
from matrix_sdk import MatrixClient
from matrix_sdk.installer import LocalInstaller
client = MatrixClient(base_url="http://127.0.0.1:7300")
installer = LocalInstaller(client)
result = installer.build("mcp_server:hello-sse-server@0.1.0", alias="hello-sse")
print(result.target, result.env.python_prepared, result.env.node_prepared)Run / stop / status
from matrix_sdk.runtime import start, stop, status, tail_logs, doctor
lock = start("/home/me/.matrix/runners/hello-sse/0.1.0", alias="hello-sse")
print(lock.pid, lock.port)
print(status())
print(doctor("hello-sse"))
stop("hello-sse")
for line in tail_logs("hello-sse", n=40):
print(line, end="")Configuration & env vars
-
General logging:
MATRIX_SDK_DEBUG=1(enables installer/runtime/archivefetch debug logs). -
Git fetcher:
MATRIX_GIT_ALLOWED_HOSTS(CSV; defaults togithub.com,gitlab.com,bitbucket.orgif unset and you pass none via API).MATRIX_GIT_ALLOW_INSECURE=1to permit http (discouraged).MATRIX_SDK_DEBUG_GIT=1to see git debug logs.
-
Home override:
MATRIX_HOME(default~/.matrix) for logs/state locations.
Breaking changes / migration notes
-
Renamed client/error types
MatrixHubClient→MatrixClientMatrixHubError→MatrixError
Update imports accordingly.
-
Runtime (Python) now requires a venv python when
runner.type == "python"; ensure your installer step creates it (handled byLocalInstaller.prepare_env) before callingruntime.start. -
Deep link parsing lives in the SDK; your CLI/GUI should compute a target path and pass it to
handle_deep_link_install(the SDK intentionally does not persist aliases).
For projects still on
0.1.1, the catalog methods are unchanged in behavior—only the class names moved. Most apps can update imports and continue.
Security & hardening
- No shell expansion from user input; deep-link validation is strict.
- HTTP artifacts: optional SHA-256 verification; safe ZIP/TAR extraction (prevents zip/tar-slip).
- Git artifacts: HTTPS by default, allow-listed hosts, shallow clones, ref checks, optional
verify_sha. - Runtime uses local files only; no background daemon or open server ports.
Known limitations
runtime.startassumes an SSE/HTTP-style runner; custom transports may need bespoke health checks.- If
runner.jsonlackstype/entry,installerattempts to infer; otherwise env prep is skipped. - Manifest resolver lives in
matrix_sdk.manifest(not changed in this drop); ensure you gate external hosts if you fetch manifests directly in apps.
Changelog
-
0.1.1
- Add
installer,runtime,archivefetch,gitfetch,schemas, CLIbulk-add. - Unify client naming (
MatrixClient,MatrixError). - Debug logging toggles + safer defaults.
- Add
deep_linkwithparse()andhandle_install().
- Add
Install / Upgrade
pip install -U matrix-python-sdkIf you previously imported MatrixHubClient/MatrixHubError, update to:
from matrix_sdk import MatrixClient, MatrixError