Metadata-Version: 2.4
Name: abstract-door
Version: 0.1.0
Summary: Expose named capabilities on a host through one locked-down SSH key: a forced-command dispatcher with per-key allow-lists and a call log, plus a thin client.
Author-email: putkoff <partners@abstractendeavors.com>
License: Proprietary
Requires-Python: >=3.9
Description-Content-Type: text/markdown

# abstract-door

Expose named capabilities on a host through one locked-down SSH key.

A *door* is an SSH key whose forced command is `door-serve`. The key can run nothing
else: no shell, no forwarding, only the capabilities installed packages register and
the key's allow-list permits. Every call is logged.

## Server (the host that owns the capability)

```
pip install abstract-door <package-that-registers-capabilities>
```

`~/.ssh/authorized_keys` of the account the capabilities must run as:

```
restrict,command="/path/to/venv/bin/door-serve --client claude@ae --allow 'vault.*'" ssh-ed25519 AAAA… claude@ae door
```

Calls are logged as JSON lines to `/var/log/abstract-door/door.log` (or
`~/.local/state/abstract-door/door.log`) and to syslog (`journalctl -t abstract-door`).

## Registering capabilities

A package adds capabilities through an entry point:

```toml
[project.entry-points."abstract_door.capabilities"]
"vault.export" = "pypit.door_caps:export"
```

A capability is `fn(args, stdin, stdout, ctx) -> int`: `args` are the request's
arguments, `stdin`/`stdout` the binary data channel, `ctx` holds `client`,
`capability` and `log(msg)` (notes added to the call's log line).

## Client

```
door <target> <capability> [args…]   # stdin/stdout pass through
door <target>                        # capabilities this key may run
```

`<target>` is an SSH alias `door-<target>` in `~/.ssh/config` (key, user, ProxyJump).
