Skip to main content

decentriq_platform

The Python package decentriq_platform provides all of the tools needed to interact with the Decentriq platform.

Functionality around the different types of Data Clean Rooms (DCRs) supported by the platform is provided by submodules. The submodule analytics, for example, provides classes and methods for creating and interacting with Analytics DCRs. Similarly, the submodule data_lab contains the code nessary to create and run DataLabs.

The package decentriq_platform can be used to

  • create DCRs (Data Clean Rooms)
  • encrypt and upload datasets
  • trigger computation of authorized computations

The currently available compute modules are:

  • decentriq_platform.sql - for SQL-based computations
  • decentriq_platform.container - for containerized Python-based computations

To learn more, click on these modules in the sidebar on the left.

The source code of the Decentriq Python SDK can be found on GitHub.


Installation​

Follow the Python SDK installation guide.

Available enclaves​

Browse through all available enclave workers in the Computations page.


Sub-modules​

  • decentriq_platform.admin
  • decentriq_platform.analytics
  • decentriq_platform.archv2
  • decentriq_platform.attestation
  • decentriq_platform.authentication
  • decentriq_platform.channel
  • decentriq_platform.connection
  • decentriq_platform.data_connectors
  • decentriq_platform.data_lab
  • decentriq_platform.endorsement
  • decentriq_platform.logger
  • decentriq_platform.media

Functions​

create_client​

def create_client(
user_email: str,
api_token: str,
*,
client_id: str = 'MHyVW112w7Ql95G96fn9rnLWkYuOLmdk',
api_host: str = 'api.decentriq.com',
api_port: int = 443,
api_use_tls: bool = True,
request_timeout: Optional[int] = None,
unsafe_disable_known_root_ca_check: bool = False,
) ‑> decentriq_platform.client.Client

The primary way to create a Client object.

Parameters:

  • api_token: An API token with which to authenticate oneself. The API token can be obtained in the user account settings in the Decentriq UI.
  • user_email: The email address of the user that generated the given API token.

Classes​

Client​

Client(
user_email: str,
enclave_api_token: str,
api: decentriq_platform.api.Api,
graphql: decentriq_platform.graphql.GqlClient,
request_timeout: Optional[int] = None,
unsafe_disable_known_root_ca_check: bool = False,
custom_mrsigner_driver_spec: Optional[attestation_pb2.AttestationSpecification] = None,
)

A Client object allows you to upload datasets and to create Session objects that can communicate with enclaves and perform essential operations such as publishing data rooms and execute computations and retrieve results.

Objects of this class can be used to create and run data rooms, as well as to securely upload data and retrieve computation results.

Objects of this class should be created using the create_client function.

Create a client instance.

Rather than creating Client instances directly using this constructor, use the function create_client.

Instance variables

decentriq_ca_root_certificate: bytes : Returns the root certificate used by the Decentriq identity provider. Note that when using this certificate in any authentication scheme, you trust Decentriq as an identity provider!

decentriq_pki_authentication: data_room_pb2.AuthenticationMethod : The authentication method that uses the Decentriq root certificate to authenticate users.

This method should be specified when building a data room in case you want to interact
with the that data room either via the web interface or with sessions created using
`create_auth_using_decentriq_pki`.
Note that when using this authentication method you trust Decentriq as an identity provider!

You can also create an `AuthenticationMethod` object directly and supply your own root certificate,
with which to authenticate users connecting to your data room.
In this case you will also need to issue corresponding user certificates and create your
own custom `decentriq_platform.authentication.Auth` objects.

check_enclave_availability​

def check_enclave_availability(
self,
specs: Dict[str, decentriq_platform.types.EnclaveSpecification],
)

Check whether the selected enclaves are deployed at this moment. If one of the enclaves is not deployed, an exception will be raised.

create_auth​

def create_auth(
self,
) ‑> decentriq_platform.authentication.Auth

Creates a decentriq_platform.authentication.Auth object which can be attached to decentriq_platform.session.Session.

create_auth_using_decentriq_pki​

def create_auth_using_decentriq_pki(
self,
enclaves: Dict[str, decentriq_platform.types.EnclaveSpecification],
) ‑> Tuple[decentriq_platform.authentication.Auth, decentriq_platform.endorsement.Endorser]

create_session​

def create_session(
self,
auth: decentriq_platform.authentication.Auth,
enclaves: Dict[str, decentriq_platform.types.EnclaveSpecification],
) ‑> decentriq_platform.session.Session

Creates a new decentriq_platform.session.Session instance to communicate with a driver enclave. The passed set of enclave specifications must include a specification for a driver enclave.

Messages sent through this session will be authenticated with the given authentication object.

create_session_from_data_room_description​

def create_session_from_data_room_description(
self,
data_room_description: decentriq_platform.types.DataRoomDescription,
specs: Optional[List[decentriq_platform.types.EnclaveSpecification]] = None,
) ‑> decentriq_platform.session.Session

Create a session for interacting with a DCR of the given data room description.

create_session_v2​

def create_session_v2(
self,
) ‑> decentriq_platform.archv2.session.SessionV2

Creates a new decentriq_platform.session.SessionV2 instance to communicate with a driver enclave.

delete_dataset​

def delete_dataset(
self,
manifest_hash: str,
force: bool = False,
)

Deletes the dataset with the given id from the Decentriq platform.

In case the dataset is still published to one or more data rooms, an exception will be thrown and the dataset will need to be unpublished manually from the respective data rooms using Session.remove_published_dataset. This behavior can be overridden by using the force flag. Note, however, that this might put some data rooms in a broken state as they might try to read data that does not exist anymore.

download_dataset​

def download_dataset(
self,
manifest_hash: str,
key: decentriq_platform.storage.Key,
) ‑> io.RawIOBase

download_job_result​

def download_job_result(
self,
job_id: str,
manifest_hash: str,
task_result_hash: str,
key: decentriq_platform.storage.Key,
) ‑> io.RawIOBase

get_available_datasets​

def get_available_datasets(
self,
) ‑> List[decentriq_platform.types.DatasetDescription]

Returns the a list of datasets that the current user uploaded, regardless of whether they have already been connected to a data room or not.

get_data_lab​

def get_data_lab(
self,
id: str,
) ‑> decentriq_platform.types.DataLabDefinition

Return the DataLab with the given ID.

Parameters:

  • id: ID of the DataLab to get.

get_data_room_description​

def get_data_room_description(
self,
data_room_hash,
enclave_specs=None,
) ‑> Optional[decentriq_platform.types.DataRoomDescription]

Get a single data room description.

get_data_room_descriptions​

def get_data_room_descriptions(
self,
*,
exclude_stopped_dcrs: bool = False,
) ‑> List[decentriq_platform.types.DataRoomDescription]

Returns a list of data room descriptions that a user has created or participates in.

Setting exclude_stopped_dcrs to True omits stopped data room descriptions from the returned list.

get_dataset​

def get_dataset(
self,
manifest_hash: str,
) ‑> Optional[decentriq_platform.types.DatasetDescription]

Returns information about a user dataset given a dataset id.

get_dataset_encryption_key_secret_id​

def get_dataset_encryption_key_secret_id(
self,
manifest_hash: str,
) ‑> Optional[str]

get_dataset_key​

def get_dataset_key(
self,
manifest_hash: str,
) ‑> decentriq_platform.storage.Key

get_media_insights_summary​

def get_media_insights_summary(
self,
data_room_id: str,
job_id: str,
audience_type: str,
) ‑> Dict[str, object]

Request an AI-generated summary of a Media DCR insights computation.

Hits POST /ai/mdcr/:data_room_id/insights/summary on api-platform, which enforces MDCR view permission on the caller, orchestrates a dqllm assistant run, and returns the assistant's structured output (chips + markdown blocks) verbatim.

Parameters:

  • data_room_id: The Media DCR id.
  • job_id: Completed computeInsights job id for the DCR.
  • audience_type: Exact seed audience to summarize.

Returns:

  • The structured output payload (templateValues + markdown), with its exact shape defined by the assistant's output schema.

list_data_labs​

def list_data_labs(
self,
filter: Optional[decentriq_platform.types.DataLabListFilter] = None,
) ‑> List[decentriq_platform.types.DataLabDefinition]

Return a list of DataLabs based on the filter criteria.

Parameters:

  • filter: Criteria used to filter the list. Can be one of the following values:
    • NONE: Display all DataLabs.
    • VALIDATED: Display DataLabs that have been validated.
    • UNVALIDATED: Display DataLabs that have not been validated.

list_data_labs_v2​

def list_data_labs_v2(
self,
) ‑> List[decentriq_platform.archv2.client.DataLabV2]

Return a list of DataLabs.

notify_participants​

def notify_participants(
self,
dcr_id: str,
description: Optional[str] = None,
enclave_specs: Optional[Dict[str, decentriq_platform.types.EnclaveSpecification]] = None,
) ‑> None

Send the DCR invitation email to all participants of dcr_id (except the owner), using the existing inviteParticipants GraphQL mutation. Reused across DCR kinds (Analytics, Media, ...).

description fills the DATA_ROOM_DESCRIPTION slot in the email template. Defaults to the DCR title when unset.

If enclave_specs is provided, get_data_room_description additionally verifies that the DCR's stored driver-attestation hash matches the hash derived from the specs (defense against a tampered or mismatched DCR record).

publish_analytics_dcr​

def publish_analytics_dcr(
self,
dcr_definition: decentriq_platform.analytics.analytics_dcr.AnalyticsDcrDefinition,
*,
enclave_specs: Optional[Dict[str, decentriq_platform.types.EnclaveSpecification]] = None,
) ‑> decentriq_platform.analytics.analytics_dcr.AnalyticsDcr

Publish an Analytics DCR.

Parameters:

  • dcr_definition: Definition of the Analytics DCR.
  • enclave_specs: The enclave specifications that are considered to be trusted. If not specified, all enclave specifications known to this version of the SDK will be used.

retrieve_analytics_dcr​

def retrieve_analytics_dcr(
self,
dcr_id,
enclave_specs: Optional[List[decentriq_platform.types.EnclaveSpecification]] = None,
) ‑> decentriq_platform.analytics.analytics_dcr.AnalyticsDcr

Retrieve an existing Analytics DCR.

Parameters:

  • dcr_id: Data Clean Room ID.
  • enclave_specs: The enclave specifications that are considered to be trusted. If not specified, all enclave specifications known to this version of the SDK will be used.

upload_dataset​

def upload_dataset(
self,
data: <class 'BinaryIO'>,
key: decentriq_platform.storage.Key,
file_name: str,
/,
*,
description: str = '',
chunk_size: int = 8388608,
parallel_uploads: int = 8,
usage: decentriq_platform.types.DatasetUsage = DatasetUsage.PUBLISHED,
secret_store_options: Optional[decentriq_platform.client.SecretStoreOptions] = None,
is_accessory: bool = False,
) ‑> str

Uploads data as a file usable by enclaves and returns the corresponding manifest hash.

Parameters:

  • data: The data to upload as a buffered stream. Such an object can be obtained by wrapping a binary string in a io.BytesIO() object or, if reading from a file, by using with open(path, "rb") as file.
  • key: Encryption key used to encrypt the file.
  • file_name: Name of the file.
  • description: An optional file description.
  • chunk_size: Size of the chunks into which the stream is split in bytes.
  • parallel_uploads: Whether to upload chunks in parallel.
  • usage: The usage of the dataset.
  • secret_store_options: Options for the secret store. It can be used to specify if the encryption key should be stored in the secret store and can also be used to provide a custom ACL for the encryption key.
  • is_accessory: Whether this dataset should be hidden from the datasets page.

DataLabBuilder​

DataLabBuilder(
client: decentriq_platform.client.Client,
)

A helper class to build a Data Lab.

build​

def build(
self,
) ‑> decentriq_platform.data_lab.data_lab_interface.DataLabInterface

Build the DataLab.

from_existing​

def from_existing(
self,
data_lab_id: str,
) ‑> Self

Construct a new DataLab from an existing DataLab with the given ID.

Parameters:

  • data_lab_id: The ID of the existing DataLab.

with_collaboration_types​

def with_collaboration_types(
self,
collaboration_types: list[decentriq_platform.media.media.CollaborationType],
) ‑> Self

Set the collaboration types for the DataLab.

with_demographics​

def with_demographics(
self,
) ‑> Self

Enable demographics in the DataLab.

with_disable_drop_invalid_rows​

def with_disable_drop_invalid_rows(
self,
)

Disable dropping of invalid rows in the Data Lab.

with_embeddings​

def with_embeddings(
self,
num_embeddings: int,
) ‑> Self

Enable embeddings in the DataLab.

Parameters:

  • num_embeddings: The number of embeddings the DataLab should use.

with_identifiers_config​

def with_identifiers_config(
self,
identifiers_config: list[decentriq_platform.data_lab.configs.IdentifiersConfig],
) ‑> Self

Set the identifiers config.

Parameters:

  • identifiers_config: The identifiers config to use.

with_matching_id_format​

def with_matching_id_format(
self,
matching_id: decentriq_platform.types.MatchingId,
) ‑> Self

Set the matching ID format.

Parameters:

  • matching_id: The type of matching ID to use.

with_name​

def with_name(
self,
name: str,
) ‑> Self

Set the name of the DataLab.

Parameters:

  • name: Name to be used for the DataLab.

with_num_identifiers_columns​

def with_num_identifiers_columns(
self,
num_identifiers_columns: int,
) ‑> Self

Set the expected number of columns in the identifiers dataset.

Parameters:

  • num_identifiers_columns: The number of columns in the identifiers dataset.

with_segments​

def with_segments(
self,
) ‑> Self

Enable segments in the DataLab.

EnclaveSpecifications​

EnclaveSpecifications(
specifications: Dict[str, decentriq_platform.types.EnclaveSpecification],
)

Provider of the available enclave specifications provided by the Decentriq platform.

Enclave specifications enable you to express which particular enclaves you trust. The field containing the measurement (e.g. mrenclave in the case of Intel SGX) identifies the exact binary that will process your data. Users of the Decentriq platform are encouraged to reproduce this value by building the enclave binary from audited source code and re-producing the measurement (in the case of Intel SGX, this would involve simply hashing the produced executable).

When connecting to the driver enclave, the configured attestation algorithm will guarantee that the enclave you connect to is the one corresponding to the enclave specification you chose. The associated root certificate will be used to verify that the attestation was signed by the expected party (e.g. Intel/AMD/Amazon, depending on the CC technology used).

Any communication between the driver enclave and worker enclaves handling your data will also first be secured by additional attestation procedures. Which enclaves are trusted by the driver enclave is controlled by choosing the additional enclave specs from the respective compute packages.

A list of enclave specifications, each encoding your trust in a particular enclave type, can be obtained by selecting a subset of the enclave specifications provided by the object decentriq_platform.enclave_specifications. Selecting the subset of versions should be done by calling its versions method.

all​

def all(
self,
) ‑> List[decentriq_platform.types.EnclaveSpecification]

Get a list of all available enclave specifications.

latest​

def latest(
self,
) ‑> Dict[str, decentriq_platform.types.EnclaveSpecification]

Select the latest specification of each enclave type

list​

def list(
self,
) ‑> List[str]

Get a list of all available enclave identifiers.

merge​

def merge(
self,
other,
)

Merge two sets of enclave specifications into a single set.

versions​

def versions(
self,
enclave_versions: List[str],
) ‑> Dict[str, decentriq_platform.types.EnclaveSpecification]

Get the enclave specifications for the given versioned enclave types.

Make sure to always include the specification of a driver enclave, e.g. "decentriq.driver:v1" as this is the node with which you communicate directly. Add additional versioned enclaves depending on the compute module you use. Refer to the main documentation page of each compute module to learn which enclaves are available.

Endorser​

Endorser(
auth: Auth,
client: Client,
enclaves: Dict[str, EnclaveSpecification],
)

Instance variables

auth: decentriq_platform.authentication.Auth :

dcr_secret_endorsement​

def dcr_secret_endorsement(
self,
dcr_secret: str,
) ‑> Tuple[identity_endorsement_pb2.EnclaveEndorsement, bytes]

decentriq_pki_endorsement​

def decentriq_pki_endorsement(
self,
) ‑> identity_endorsement_pb2.EnclaveEndorsement

pki_endorsement​

def pki_endorsement(
self,
cert_chain_pem: bytes,
) ‑> identity_endorsement_pb2.EnclaveEndorsement

Key​

Key(
material: Optional[bytes] = None,
)

This class wraps the key material that is used to encrypt the files that are uploaded to the decentriq platform.

Returns a new Key instance, can optional specify the raw key material.

Secret​

Secret(
secret: bytes,
state: decentriq_dcr_compiler._schemas.secret_store_entry_state.SecretStoreEntryState,
)

Secret(secret: bytes, state: decentriq_dcr_compiler._schemas.secret_store_entry_state.SecretStoreEntryState)

SecretStoreOptions​

SecretStoreOptions(
*,
store_encryption_key: bool = True,
encryption_key_acl: Union[Dict[str, ForwardRef('JSONType')], List[ForwardRef('JSONType')], str, int, float, bool, ForwardRef(None)] = None,
encryption_key_acl_version: int = 0,
)

validate_users​

def validate_users(
self,
client_user: str,
organization_user: List[decentriq_platform.types.OrganizationUser],
)

Session​

Session(
client: Client,
connection: Connection,
client_protocols: List[int],
auth: Auth,
)

Class for managing the communication with an enclave.

Session instances should not be instantiated directly but rather be created using a Client object using decentriq_platform.Client.create_session.

dcr_secret_endorsement​

def dcr_secret_endorsement(
self,
dcr_secret: str,
) ‑> identity_endorsement_pb2.DcrSecretEndorsementResponse

generate_merge_approval_signature​

def generate_merge_approval_signature(
self,
configuration_commit_id: str,
) ‑> bytes

Generate an approval signature required for merging a configuration commit.

To merge a specific configuration commit, each user referenced in the list of ids returned by retrieveConfigurationCommitApprovers needs to generate an approval signature using this method.

get_computation_result​

def get_computation_result(
self,
job_id: JobId,
/,
*,
interval: int = 5,
timeout: Optional[int] = None,
) ‑> bytes

Wait for the given job to complete and retrieve its results as a raw byte string.

The method will check for the job's completeness every interval seconds and up to an optional timeout seconds after which the method will raise an exception. If the job completes and the results can be retrieved successfully, a raw byte string will be returned. The bytes string can be transformed into a more useful object using a variety of helper methods. These helper methods are specific for the type of computation you ran and can be found in the corresponding packages.

get_computation_result_size​

def get_computation_result_size(
self,
job_id: JobId,
/,
*,
interval: int = 5,
timeout: Optional[int] = None,
) ‑> int

Wait for the given job to complete and retrieve its results size.

The method will check for the job's completeness every interval seconds and up to an optional timeout seconds after which the method will raise an exception. If the job completes and the results can be retrieved successfully, an int containing the raw result size is returned.

get_computation_status​

def get_computation_status(
self,
job_id: str,
) ‑> gcg_pb2.JobStatusResponse

Returns the status of the provided job_id which will include the names of the nodes that completed their execution

merge_configuration_commit​

def merge_configuration_commit(
self,
configuration_commit_id: str,
approval_signatures: Dict[str, bytes],
*,
new_high_level_representation: Optional[bytes] = None,
) ‑> gcg_pb2.MergeConfigurationCommitResponse

Request the enclave to merge the given configuration commit into the main data room configuration.

Parameters:

  • configuration_commit_id: The id of the commit to be merged.
  • approval_signatures: A dictionary containing the approval signature for each of the required approvers, e.g. { "some@email.com": signature }.
  • new_high_level_representation: The data room's high-level representation, recompiled to include the commit being merged.

The enclave overwrites the data room's stored high-level representation with whatever this method sends. Omitting new_high_level_representation for a DCR that has one therefore erases it, after which the DCR can no longer be retrieved as an Analytics DCR nor rendered in the web app. Pass it for any high-level DCR; see decentriq_platform.analytics.commit_helpers.

pki_endorsement​

def pki_endorsement(
self,
certificate_chain_pem: bytes,
) ‑> identity_endorsement_pb2.PkiEndorsementResponse

publish_data_room​

def publish_data_room(
self,
data_room_definition: DataRoom,
/,
*,
show_organization_logo: bool = False,
require_password: bool = False,
purpose: CreateDcrPurpose.V = 0,
kind: CreateDcrKind.V = 0,
high_level_representation: Optional[bytes] = None,
) ‑> str

Create a data room with the provided protobuf configuration object and have the enclave apply the given list of modifications to the data room configuration.

The id returned from this method will be used when interacting with the published data room (for example when running computations or publishing datasets).

publish_data_room_configuration_commit​

def publish_data_room_configuration_commit(
self,
configuration_commit: ConfigurationCommit,
*,
high_level_representation: Optional[bytes] = None,
) ‑> str

Publish the given data room configuration commit.

Configuration commits can be built using a DataRoomCommitBuilder object.

The id returned from this method will be used when running development computations or when trying to merge this commit into the main data room configuration.

Parameters:

  • configuration_commit: The commit to publish.
  • high_level_representation: The commit's high-level representation. Required for commits belonging to a high-level DCR (e.g. an Analytics DCR), as retrieve_configuration_commit can only return what was stored here.

publish_dataset​

def publish_dataset(
self,
data_room_id: str,
manifest_hash: str,
leaf_id: str,
key: Key,
*,
force: bool = False,
) ‑> gcg_pb2.PublishDatasetToDataRoomResponse

Publishes a file and its encryption key to a data room. Neither the file or the encryption key will ever be stored in unencrypted form.

This method will check whether the to-be-published file exists. If this is not the case, an exception will be raised. This behavior can be disabled by setting the force flag.

In case the original client was created with platform integration enabled, the method will further check whether there already is a dataset published for the given data room. In this case, an exception will be thrown and the dataset will need to be unpublished first.

A special note for when the referenced data room was created using the Decentriq UI: In this case, the leaf_id argument will have the format {NODE_ID}_leaf, where {NODE_ID} corresponds to the value that you see when hovering your mouse pointer over the name of the data node.

remove_published_dataset​

def remove_published_dataset(
self,
data_room_id: str,
leaf_id: str,
) ‑> gcg_pb2.RemovePublishedDatasetResponse

Removes a published dataset from the data room.

Parameters:

  • data_room_id: The ID of the data room that contains the given data set.
  • leaf_id: The ID of the data node from which the dataset should be removed. In case the referenced data room was created using the Decentriq UI, the leaf_id argument will have the special format @table/UUID/dataset (where UUID corresponds to the value that you see when hovering your mouse pointer over the name of the data node).

retrieve_audit_log​

def retrieve_audit_log(
self,
data_room_id: str,
) ‑> gcg_pb2.RetrieveAuditLogResponse

Returns the audit log for the data room.

retrieve_configuration_commit​

def retrieve_configuration_commit(
self,
configuration_commit_id: str,
) ‑> gcg_pb2.RetrieveConfigurationCommitResponse

Retrieve the content of given configuration commit id.

Returns: A ConfigurationCommit.

retrieve_configuration_commit_approver_groups​

def retrieve_configuration_commit_approver_groups(
self,
configuration_commit_id: str,
) ‑> List[decentriq_platform.session.ApproverGroup]

Retrieve the approvals a configuration commit needs before it can be merged.

Each affected data node yields one group made up of its data owners, of whom any single one can approve on the node's behalf. A change that needs every participant in person yields one group per participant.

Returns: The approver groups, each of which needs a merge signature from one of its members.

retrieve_configuration_commit_approvers​

def retrieve_configuration_commit_approvers(
self,
configuration_commit_id: str,
) ‑> List[str]

Retrieve the users who may approve the merger of a given configuration commit.

Not every one of them has to approve: the commit is mergeable once each of the groups returned by retrieve_configuration_commit_approver_groups holds a signature from one of its members.

Returns: A list of ids belonging to the users that may approve the configuration commit.

retrieve_current_data_room_configuration​

def retrieve_current_data_room_configuration(
self,
data_room_id: str,
) ‑> Tuple[data_room_pb2.DataRoomConfiguration, str]

Retrieve the current data room confguration, as well as the current "history pin".

A history pin is the hash of all the ids of configuration commits that make up the structure of a data room. This pin therefore uniquely identifies a data room's structure at a certain point in time. A data room configuration, as well as its associated history pin, can be used to extend an existing data room (for example by adding new compute nodes). Extending an existing data room is done using the DataRoomCommitBuilder class.

retrieve_data_room​

def retrieve_data_room(
self,
data_room_id: str,
) ‑> gcg_pb2.RetrieveDataRoomResponse

Returns the underlying protobuf object for the data room.

retrieve_data_room_json​

def retrieve_data_room_json(
self,
data_room_id: str,
) ‑> str

Get the JSON configuration file for the data room with the given ID. Returns a JSON string representing the configuration.

retrieve_data_room_status​

def retrieve_data_room_status(
self,
data_room_id: str,
) ‑> str

Returns the status of the data room. Valid values are "Active" or "Stopped".

retrieve_published_datasets​

def retrieve_published_datasets(
self,
data_room_id: str,
) ‑> gcg_pb2.RetrievePublishedDatasetsResponse

Returns the datasets published to the given data room.

retrieve_used_airlock_quotas​

def retrieve_used_airlock_quotas(
self,
data_room_id: str,
) ‑> Dict[str, decentriq_platform.session.AirlockQuotaInfo]

Retrieves the limit and used airlock quota for the current user.

run_computation​

def run_computation(
self,
data_room_id: str,
compute_node_id: str,
/,
*,
dry_run: Optional[DryRunOptions] = None,
parameters: Optional[Mapping[Text, Text]] = None,
) ‑> decentriq_platform.types.JobId

Run a specific computation within the data room with the given id.

The result will be an identifier object of the job executing the computation. This object is required for checking a job's status and retrieving its results.

run_computation_and_get_results​

def run_computation_and_get_results(
self,
data_room_id: str,
compute_node_id: str,
/,
*,
interval: int = 5,
timeout: Optional[int] = None,
parameters: Optional[Mapping[Text, Text]] = None,
) ‑> Optional[bytes]

Run a specific computation and return its results.

This method is simply a wrapper for running run_computation and get_computation_result directly after each other

run_dev_computation​

def run_dev_computation(
self,
data_room_id: str,
configuration_commit_id: str,
compute_node_id: str,
/,
*,
dry_run: Optional[DryRunOptions] = None,
parameters: Optional[Mapping[Text, Text]] = None,
) ‑> decentriq_platform.types.JobId

Run a specific computation within the context of the data room configuration defined by the given commit id. Such "development" computations can also be run for configuration commits that have not yet been merged.

The result will be an identifier object of the job executing the computation. This object is required for checking a job's status and retrieving its results.

send_compilable_request​

def send_compilable_request(
self,
compile_request: Callable[[CompilerRequest, Channel], bytes],
request: CompilerRequest,
decompile_response: Callable[[List[bytes]], CompilerResponse],
protocol: int,
) ‑> ~CompilerResponse

send_request​

def send_request(
self,
request: GcgRequest,
protocol: int,
) ‑> List[gcg_pb2.GcgResponse]

Low-level method for sending a raw GcgRequest to the enclave. Use this method if any of the convenience methods (such as run_computation) don't perform the exact task you want.

send_request_raw​

def send_request_raw(
self,
request: bytes,
protocol: int,
) ‑> List[bytes]

Low-level method for sending a raw GcgRequest to the enclave. Use this method if any of the convenience methods (such as run_computation) don't perform the exact task you want.

stop_data_room​

def stop_data_room(
self,
data_room_id: str,
)

Stop the data room with the given id, making it impossible to run new computations.

wait_until_computation_has_finished​

def wait_until_computation_has_finished(
self,
job_id: JobId,
/,
*,
interval: int = 5,
timeout: Optional[int] = None,
)

Wait for the given job to complete.

The method will check for the job's completeness every interval seconds and up to an optional timeout seconds after which the method will raise an exception.

wait_until_computation_has_finished_for_all_compute_nodes​

def wait_until_computation_has_finished_for_all_compute_nodes(
self,
job_id: str,
compute_node_ids: List[str],
/,
*,
interval: int = 5,
timeout: Optional[int] = None,
)

Wait for the given job to complete for all of the given compute nodes.

The method will check for the job's completeness every interval seconds and up to an optional timeout seconds after which the method will raise an exception.

SessionV2​

SessionV2(
client: Client,
connection: Connection,
)

Class for managing the communication with an enclave.

Session instances should not be instantiated directly but rather be created using a Client object using decentriq_platform.Client.create_session_v2.

create_materialization​

def create_materialization(
self,
source: MaterializationSource,
dataset: MaterializationDataset,
) ‑> str

Create a materialization and return the materialization ID.

Takes the source result to materialize and the dataset to produce; the enclave derives createdBy/createdAt/sourceActionId and signs the stored Materialization. Serialized as ddc JSON bytes — like dcrAction — since the entity is a ddc serde type, not a proto.

create_policy​

def create_policy(
self,
policy: ReleasePolicy,
) ‑> str

Create a release policy and return the policy ID.

create_secret​

def create_secret(
self,
secret: Secret,
) ‑> str

Store a secret in the user's own enclave-protected secret store

get_secret​

def get_secret(
self,
secret_id: str,
) ‑> Tuple[decentriq_platform.archv2.secret.Secret, int]

remove_secret​

def remove_secret(
self,
secret_id: str,
expected_cas_index: int,
) ‑> bool

send_authenticated_request​

def send_authenticated_request(
self,
authenticated_request: AuthenticatedRequest,
) ‑> gcg_pb2.AuthenticatedResponse

send_data_room_state_action_request​

def send_data_room_state_action_request(
self,
data_room_id: str,
action: JSONType,
) ‑> Union[Dict[str, JSONType], List[JSONType], str, int, float, bool, ForwardRef(None)]

Send a DCR action request.

send_export_result_as_dataset_request​

def send_export_result_as_dataset_request(
self,
job_id: str,
task_result_hash: str,
zip_path: Optional[str],
) ‑> Tuple[str, str, str]

Export a result as a dataset.

send_get_verification_key_request​

def send_get_verification_key_request(
self,
) ‑> bytes

Retrieve the verification key for a DCR.

send_retrieve_result_encryption_key_request​

def send_retrieve_result_encryption_key_request(
self,
job_id: str,
task_result_hash: str,
) ‑> Tuple[str, bytes]

Retrieve the manifest hash and encryption key for a result.

send_secret_store_request​

def send_secret_store_request(
self,
request: SecretStoreRequest,
) ‑> secret_store_pb2.SecretStoreResponse

update_secret_acl​

def update_secret_acl(
self,
secret_id: str,
new_acl: v0.SecretStoreEntryAcl,
expected_cas_index: int,
) ‑> bool

Update a secret ACL