Overview¶
Genesis Mesh ships client libraries for all major server-side runtimes. Every SDK wraps the same Network Authority HTTP API — the surface documented in Trust API — HTTP Reference.
SDKs are standalone packages: they live in separate repositories under the
GenesisMeshLabs organization and are not part of the Python main repo.
They share no runtime dependencies with the Python server.
Starting with the coordinated v0.56.0 release train, the reference implementation and every official SDK use the same product version. Earlier SDK version numbers remain in their changelogs as historical first-release markers.
Current release train¶
Version 0.60.0 is the coordinated source version. Registry publication occurs only after the complete release gate passes in every component repository.
The TypeScript SDK is the most complete client: from 0.59.1 it covers attestation-backed evaluation, the boundary policy lifecycle, the evidence store and offline verification, and from 0.60.0 failover across HA instances and readiness (see TypeScript SDK). The Go and .NET SDKs carry the coordinated version without these additions.
SDK |
Package |
Version |
Repo |
|---|---|---|---|
TypeScript / Node.js |
|
0.60.0 |
|
Go |
|
0.60.0 |
|
C# / .NET |
|
0.60.0 |
|
Rust SDK |
|
0.60.0 |
|
Rust gateway |
|
0.60.0 |
|
Rust is different in kind from the other three: it is not a thin HTTP client
for the NA. It ships the portable trust primitives as an embeddable crate
(genesis_mesh), plus CLI binaries and a production trust-verification
gateway built on top of that crate. See Rust and
Rust Trust Gateway.
Design principles¶
All SDKs mirror the main repo’s layer separation:
Layer |
TypeScript |
Go |
C# |
Rust |
Python equivalent |
|---|---|---|---|---|---|
Crypto |
|
|
|
|
|
HTTP transport |
|
|
|
|
|
Domain sub-clients |
|
|
|
none — see the gateway’s authority service proxy |
|
Types |
|
|
|
|
|
No runtime dependencies. SDKs use only the platform’s built-in fetch and crypto APIs.
Typed errors. Every HTTP error is mapped to a typed exception class
(BadRequestError, UnauthorizedError, ValidationError, etc.) with a
stable .code string matching the NA’s code field.
Dual-mode auth. Admin routes are signed with Ed25519 (four X-Admin-*
headers). Public verification routes are unauthenticated. The transport layer
handles the distinction — callers just use the right sub-client method.